Government Safe Data service already allows you to check if the PESEL number has been found in a leak from MyDr, which may affect 11.8 million people and over 12,000 facilities. The injured individual may claim compensation on the basis of Art. 82 GDPR, but must show the breach, harm and relation between them.
Government shows whose PESEL was in the leak
On the Safe Data page, you can check if the PESEL number is in the collection taken over during the attack on MyDr. Government service explainsthat the company's safety breach has been confirmed, but the service has not yet stated that the data has been made public. The State shall supply preventive information. This is an crucial distinction: the data has been taken over, but there is no confirmation that they have entered public circulation.
The consequence in the service will not show the full scope of leakage. The portal only responds to the question about PESEL. The details can be provided by the data administrator, a clinic or a cabinet utilizing MyDr. The patient should so contact the facility and ask for written information on the incident, erstwhile the facility learned about it and what protective measures it took.
The scale reaches millions of patients
Ministry of Digital Affairs reportedthat unauthorised access afraid historical data until April 2024. The possible scale is 18.8 million people and over 12,000 medical institutions. The incidental did not disturb the current issue of prescriptions or benefits.
However, the scope of the information may be serious. The prosecution indicated names, names, PESEL and telephone numbers, email addresses, as well as wellness data, including visit notes and prescription information. The investigation was initiated on 12 August, and it is managed by the Warsaw Management Board of the Central Bureau for Combating Cybercrime under the supervision of the territory Prosecutor's Office in Warsaw. The unsub remains unaccounted for.
The National diary has already described First questions about the liability of the State and the strategy operator. The PESEL verification tool is needed, but after many days of uncertainty. A citizen cannot be the last link in the chain of information about his own medical data.
Security first, then documenting the damage
The individual whose PESEL is in the database should consider his reservation in the mCicietel application or in the municipal office. We must besides be careful about telephones, messages and e-mails, especially erstwhile the sender requests additional data, authorization code or transfer. UODO recommends caution on phishing and recalls the anticipation of submitting a complaint to the administrator.
It is worth keeping the results of the check, messages from the facility, replies to requests, suspicious correspondence and evidence of costs. If, after an incident, there has been extortion, failure of money, the request for paid aid or another circumstantial loss, any paper may be relevant. For non-human injury, it will be crucial to describe the real consequences, specified as reasonable fear of utilizing or losing control of medical data.
Compensation is not automatic
Article 82 GDPR gives the right to compensation for property or non-material harm caused by violation of the regulation. The claim shall be directed towards a civilian road against the controller or processor, depending on the established responsibility. A complaint to the UODO may launch supervisory proceedings, but the office does not grant the victim money.
The EU Court of Justice indicatedthat it is essential to show 3 elements: the violation of the GDPR, the injury suffered and the causal link. The fact of the breach alone is not enough. At the same time, the non-material injury does not gotta exceed the artificial threshold of gravity. Each case requires its own evidence, which is why it is reasonable to consult a lawyer before the lawsuit.
A dispute over the reaction of the authorities after the attack on MyDr. must not overshadow the work to patients. Privacy, financial safety and trust in the digital state are at stake. Poland needs systems that defend the citizen from leakage, and after the incidental they rapidly tell him the fact and aid him to gain rights.
Source: Safety Data, Ministry of Digital Affairs, District Attorney’s Office in Warsaw, UODO















