Additional inspections by the Personal Data Protection Office at organisations in the healthcare sector
In light of the recent largest-ever data breach involving patients’ personal data – in particular sensitive health data processed by medical facilities – the President of the Personal Data Protection Office, Mirosław Wróblewski, has decided to carry out inspections of further organisations in the healthcare sector before the end of this year to assess how the data of those using their services is protected.
Following media reports of a data breach at MyDr, Mirosław Wróblewski, President of the Personal Data Protection Office, immediately decided to carry out an inspection at the company. The inspection will focus on the technical and organisational measures in place and the risk assessment carried out by the company. Meanwhile, the Personal Data Protection Office continues to receive reports of data breaches from data controllers.
However, in light of the aforementioned cyberattack, as well as numerous other data breaches, the President of the Personal Data Protection Office has decided that a wider-scale inspection into the processing of health data is required before the end of this year. He has therefore decided to carry out inspections by the end of 2026, based on the aforementioned information obtained by the President of the Office and as part of monitoring compliance with Regulation 2016/679 amongst entities in the healthcare sector, in order to verify how they protect the data of individuals using their services.
At the same time, the President of the Personal Data Protection Office wishes to remind you that inspections of organisations in the healthcare sector have been carried out as part of the Personal Data Protection Office’s sector-specific inspections since 2025. In 2025, inspections in this sector focused on the security of personal data, whilst this year they have centred in particular on the use of video surveillance. However, the risks associated with the processing of medical data mean that additional, intensified inspections will need to be carried out later this year at further organisations, in particular to verify the security measures they have in place.
Consequently, it was necessary to amend the sectoral inspection plan for 2026. The sectoral inspections of online delivery platforms scheduled for this year (processing of personal data in connection with the provision of intermediary services for the sale of goods and services via online applications) have been postponed to the first and second quarters of 2027. However, sectoral inspections of bodies processing personal data in Large-Scale European Union Systems will proceed as planned, including the processing of SIS/VIS personal data pursuant to the provisions of the Act on the Participation of the Republic of Poland in the Schengen Information System and the Visa Information System, implementing acts and European Union legislation.
The plan for sector-specific inspections of entities operating the Public Information Bulletin and marketing organisations remains unchanged. In the case of the former, the audit focuses on the manner in which personal data is processed in connection with the obligation to maintain the Public Information Bulletin, in particular with regard to the anonymisation of data and the publication of the proceedings of local council meetings. The latter, meanwhile, are audited in particular with regard to the legal basis for the processing of personal data for marketing purposes.