Poland’s healthcare sector has come under sustained digital assault, with nearly 1,400 cyber attacks recorded, according to data reported by RMF24. The scale of the threat highlights the growing vulnerability of medical institutions to organised criminal groups and state-backed hackers.
Phishing operations accounted for the largest share of incidents, with almost 400 cases logged. These online scams typically involve fraudulent emails or messages designed to trick staff into revealing passwords or downloading malicious software.
Beyond phishing, attackers have systematically exploited weaknesses in hospital and clinic computer systems. Hackers search for gaps in software and take advantage of flaws in digital infrastructure to gain unauthorised access to sensitive patient data and critical systems.
International groups targeting Polish healthcare
Jeremi Olechnowicz, director of the IT Systems Exploitation Division at the Centre for e-Health (Centrum e-Zdrowia), told RMF FM that the threat comes from multiple sources. Dispersed hacking groups from around the world are focused on extracting money from healthcare providers, while other teams have links to foreign governments.
“There are hacking groups from all over the world, dispersed, that are focused on obtaining financial resources. Hacking groups are also linked to foreign governments,” Olechnowicz said.
He warned that the number of attacks is expected to rise year on year as criminals refine their methods and healthcare institutions remain attractive targets due to the valuable personal and medical information they hold.
New cybersecurity rules delayed
A complicating factor in Poland’s response to the growing threat is the delayed implementation of new cybersecurity guidelines for the health sector. These regulations will not come into force until next year, leaving a gap in enforcement.
Until the new rules take effect in 2025, authorities cannot require healthcare providers to adopt additional security measures, even as the volume and sophistication of attacks continue to climb. This leaves hospitals, clinics and other medical facilities operating without the benefit of updated mandatory protections.
What this means for Poles in Poland
If you have recently used Polish healthcare services, either in person or through online portals such as the Patient Internet Account (Internetowe Konto Pacjenta), your personal and medical data may be at heightened risk. Nearly 1,400 attacks on the health sector mean that patient records, including PESEL numbers, addresses and treatment history, could be targeted by criminals.
To protect yourself, be especially cautious of unsolicited emails or text messages claiming to be from your clinic, hospital or the National Health Fund (NFZ). Do not click links or download attachments unless you are certain of the sender. Enable two-factor authentication on any health-related online accounts where available.
For Poles living abroad who still access Polish medical records or insurance remotely, check your Patient Internet Account regularly for unusual activity. If you notice unauthorised logins or changes to your data, report them immediately to the institution concerned and consider changing your password.
Healthcare providers are not yet required to meet the stricter cybersecurity standards due in 2025, so assume that the systems you interact with may not be fully hardened against attack. Store any confirmation emails or sensitive documents securely and avoid sharing personal health information over unencrypted channels.

