The Polish authority intensifies inspections in the health sector following a massive leak of sensitive data
The Polish Data Protection Authority (UODO) has announced additional inspections in the health sector following a major patient data leak.
Following the largest recent patient data breach, the President of the Data Protection Authority (UODO) decided to launch additional inspections in the health sector before the end of 2026. An inspection was immediately initiated at the company MyDr, responsible for the leak, to examine the technical and organizational measures as well as the risk assessment carried out. In response to this cyberattack and other violations, the authority deemed it necessary to intensify monitoring of health data processing to verify how entities protect the data of data subjects, in accordance with the GDPR. These inspections add to those conducted since 2025, which focused on data security and then on video surveillance.
This decision leads to a modification of the sectoral inspection plan for 2026. Inspections planned for online delivery platforms, concerning data processing in the context of intermediary services, are postponed to the first and second quarters of 2027. However, the schedule is maintained for inspections of entities processing data in large-scale information systems of the European Union, such as the Schengen Information System (SIS) and the Visa Information System (VIS). Inspections targeting entities managing a Public Information Bulletin, notably on data anonymization, and marketing companies, on the legal bases of processing, also continue as planned.
Following the largest recent patient data breach, the President of the Data Protection Authority (UODO) decided to launch additional inspections in the health sector before the end of 2026. An inspection was immediately initiated at the company MyDr, responsible for the leak, to examine the technical and organizational measures as well as the risk assessment carried out. In response to this cyberattack and other violations, the authority deemed it necessary to intensify monitoring of health data processing to verify how entities protect the data of data subjects, in accordance with the GDPR. These inspections add to those conducted since 2025, which focused on data security and then on video surveillance.
This decision leads to a modification of the sectoral inspection plan for 2026. Inspections planned for online delivery platforms, concerning data processing in the context of intermediary services, are postponed to the first and second quarters of 2027. However, the schedule is maintained for inspections of entities processing data in large-scale information systems of the European Union, such as the Schengen Information System (SIS) and the Visa Information System (VIS). Inspections targeting entities managing a Public Information Bulletin, notably on data anonymization, and marketing companies, on the legal bases of processing, also continue as planned.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire