17/08/2026
Up to 19 million people in Poland have had their medical data exposed.
Last week, a breach at a medical records provider (software running in over 12,000 healthcare facilities in the country) put 2 TB of patient data in someone else's hands. Names, ID numbers, phone numbers, visit notes, prescriptions. How it happened is still under investigation.
A clinical database collects for years, more services start reading from it, and at some point it holds more about a person than anyone planned for. We build systems like this, so we asked Mateusz, one of our fullstack developers, how he approaches patient data.
Five things he checks:
▪️ Most features don't need patient data at all
▪️ The ones that do need specific fields, not "the patient record"
▪️ A rare combination of ordinary details can still identify someone
▪️ Every service gets the smallest answer that does the job, even internal ones
▪️ An incident plan nobody has practised is just a document
The reasoning behind each one is in the carousel, along with the part he says is uncomfortable to put on a company page: most breaches he's seen didn't start in the code.