Third-party dependency Healthcare
How much depends on one vendor, and could you leave?
Records, appointments, prescriptions and billing usually sit on one supplier's platform, and your organisation remains the controller of all of it. This page sets out what can be verified about that dependency: whether a complete export of the records can be produced, whether the backup is independent of the same infrastructure and the same supplier, how fast one supplier's access can be cut without stopping care, and what happens if the supplier disappears, is acquired or changes its terms.
01 Scope
What we review
One question underlies the rest: how much of the work and how much of the record set are independent of a single supplier. The other areas are the same question at a finer grain, and most of them are answerable with evidence rather than with an opinion about the vendor.
- 01 Independence from the vendorCan a complete export of the medical records be produced today, in what format and in what time, and has anyone tried? Who inside the organisation can do it without the vendor's help? Is the backup independent of the same infrastructure and the same supplier? What happens to the work if the supplier stops trading, is acquired or changes its terms?
- 02 Vendor and support accessWho on the vendor's side can reach the system and the workstations? Is access granted for the length of a task, or does it stand permanently? Are support sessions recorded, and who inside the organisation approves them? If one component of the platform were reached, how far would that reach: one customer, or every customer on it?
- 03 Identity, permissions and account reachDoes every person have their own account, or is part of the work done on a shared one? Does sign-in require a second factor? How much does reception see, and how much does a clinician see? What happens to an account when somebody leaves?
- 04 Integrations and secretsWhich keys, tokens and service accounts connect the organisation to outside systems? Where are they held and who knows them? Can they be revoked in a day, without stopping appointments?
- 05 Backups and restoreIs there a copy outside the vendor's infrastructure? When was a restore last tested, and who confirmed it? How long does a restore take to the point where patients can be seen again?
- 06 Monitoring and evidence from logsWhat is recorded on the organisation's own side, and for how long? Can it be reconstructed who read or exported patient records, and when? Does anybody read those logs before they are needed?
- 07 Incident readiness and controller dutiesWho prepares the risk assessment, and who decides on a notification? Is there a template for notifying the individuals concerned? Who speaks to the vendor, in what mode, and with what record of what was agreed?
This is not a conformity assessment, a certification or a legal opinion. The work covers what is visible in the material provided and in the configuration the organisation can reach itself.
02 Register
One worked example, kept as a register
The questions above are not theoretical, and this register is the reason the page exists. It covers one incident at a practice-management software supplier in Poland, made public in August 2026. Every item is reproduced from one fact register together with its status, its source and the date the wording was last checked against that source. Nothing about that incident is asserted anywhere on this page except through these entries. State as at 13 August 2026.
The incident is described generically here, because the subject of this page is the pattern rather than one company: a supplier is compromised, and the practice that bought the software remains the controller of the records. The official communiques linked at each entry name the parties, and the link text names each publisher.
Confirmed by official sources
Statements by the ministries and the supervisory authority, each naming its source in the sentence itself and linking to it. All of these sources publish in Polish only, so the wording here is a translation rather than a quotation in the source's own words.
-
Confirmed
The supplier confirmed unauthorised access to historical data (up to April 2024) belonging to medical practices and held in its own systems.
Source: Ministry of Digital Affairs, communique of 12 August 2026. Verified: 13 August 2026.
-
Confirmed
The Ministry of Digital Affairs stated that the incident concerned only data held in the supplier's systems, with no effect on the day-to-day operation of healthcare providers, including issuing prescriptions to patients.
Source: Ministry of Digital Affairs, communique of 12 August 2026. Verified: 13 August 2026.
-
Confirmed
The Ministry of Health stated that the security of the central e-health services was not breached and that Centrum e-Zdrowia raised its level of monitoring.
Source: Ministry of Health, statement of 12 August 2026. Verified: 13 August 2026.
-
Confirmed
The Ministry of Digital Affairs stated that once it is established whose data was taken, the data identifying the people affected is to be passed to the bezpiecznedane.gov.pl service in stages, and that the process may take several days because the individual practices and facilities are the data controllers.
Source: Ministry of Digital Affairs, communique of 12 August 2026. Verified: 13 August 2026.
-
Confirmed
The Ministry of Digital Affairs stated that further action is coordinated with the special services coordinator, the Ministry of Health, the President of the Personal Data Protection Office (UODO), the National Prosecutor's Office and the Central Bureau for Combating Cybercrime (CBZC).
Source: Ministry of Digital Affairs, communique of 12 August 2026. Verified: 13 August 2026.
Claims, not findings
The scale figures in circulation trace back to the attackers' own description of the set they say they hold. A figure repeated in an official communique does not become an independent confirmation, so it stays marked here as a claim. Statements a vendor makes about itself sit in the same group.
-
Claim, not a finding
According to a communique from the Ministry of Digital Affairs, the incident may affect 18.8 million people and more than 12,000 medical facilities. The supplier has not confirmed that scale.
Source: Ministry of Digital Affairs, communique of 12 August 2026. Verified: 13 August 2026.
-
Claim, not a finding
The supplier stated that the data covered by the incident is most likely historical and comes from 2024 and earlier years.
Source: MyDr, information for customers, 12 August 2026, archived copy of 13 August 2026. Verified: 13 August 2026.
-
Claim, not a finding
The supplier claims there is no evidence that data from its systems has been published or made publicly available, and that at this stage it cannot confirm the quantity or the type of data exposed.
Source: MyDr, information for customers, 12 August 2026, archived copy of 13 August 2026. Verified: 13 August 2026.
Still open
Questions with no public answer today. Their presence carries the general lesson: an organisation that waits for these answers before looking at its own dependency is waiting on somebody else's timetable.
-
Still open
How the attackers obtained access to the data has not been publicly established by the authorities.
No public findings. Verified: 13 August 2026.
-
Still open
It has not been publicly established which facilities and which categories of data the incident covers. The supplier has announced that it will contact its customers once the scope is established.
No public findings. Verified: 13 August 2026.
-
Still open
The findings of the proceedings conducted by UODO, the National Prosecutor's Office and CBZC are not publicly known.
No public findings. Verified: 13 August 2026.
03 Duties
Where the duty sits when the breach is at a processor
A provider that buys a platform stays the controller of the records held on it, and the supplier that runs the platform processes those records on the provider's instructions. The two statements below were published on the same day: one addressed to a vendor's customers, one to controllers. Both are given in English translation, with a link to the Polish source.
The supplier told its customers that they currently need not take any action and that no notifications from facilities are required at present.
Source: MyDr, information for customers, 12 August 2026, archived copy of 13 August 2026. Verified: 13 August 2026.
UODO reminds the controllers that entrusted the processing of personal data to the supplier of their duty to analyse the risk to the rights and freedoms of natural persons, an analysis needed to assess whether a personal data breach has occurred that makes it necessary to notify the President of UODO and the individuals the breach concerns.
Source: UODO, the controller reports a breach that occurred at a processor, 12 August 2026. Verified: 13 August 2026.
Both statements appeared on the same day and address different roles. The two reminders below describe what the controller role means in practice.
-
Confirmed
UODO restates that a breach that occurs at a processor is reported by the data controller, without undue delay and no later than 72 hours after the breach is established.
Source: UODO, the controller reports a breach that occurred at a processor, 12 August 2026. Verified: 13 August 2026.
-
Confirmed
UODO points out that the duty to notify the individuals affected rests with the controllers that used the supplier's services.
Source: UODO, a data breach and what follows, 12 August 2026. Verified: 13 August 2026.
The same division of roles holds for every processor an organisation uses, whichever supplier happens to be in the news. It is the reason the questions in section 01 are worth answering before there is an incident to answer them about.
This page organises the technical and evidentiary layer. The legal qualification of a breach, and the decision to notify the authority or the individuals concerned, rest with the controller, in practice with the data protection officer or a law firm.
04 Process
Signal → check → evidence → decision
What connects the organisation to the vendor's systems?
Which of those connections can be verified today?
What can be demonstrated without the vendor's help?
What changes immediately, and what is planned?
05 Result
What the organisation receives
Three things, in this order: a picture of the dependency, a list of findings, a plan with dates.
- Exposure mapOne page showing the places where the organisation is joined to the vendor: accounts, integrations, systems, the records, and what the organisation can demonstrate on its own. Material for a conversation with the board and with the data protection officer.
- List of findingsSpecific observations with a priority, each stating what it rests on and what could not be checked.
- Action planImmediately: what can be closed within hours, usually access and secrets. 0 to 30 days: a backup independent of the vendor, a second factor for sign-in, logging of operations. 31 to 90 days: a test restore, a decision path for the next incident, contract terms with vendors.
We issue no certificate of compliance and no statement that an organisation is secure. The result describes the state on the day of the review, together with a plan, and is not a guarantee.
06 Checklist
Ten things to check without us
The full list is here, with no form and no mailing list sign-up. The documentation items, meaning the inventories, the agreements and the agreed responsibilities, can be closed within a few hours of internal work. Three of them take longer: the trial export, the tested restore and the rollout of a second factor.
- An inventory of the systems and services holding the organisation's data outside its own infrastructure.
- Current data processing agreements, and what each one commits each vendor to in practice.
- A named list of the people on the vendor side who can reach the organisation's systems.
- Confirmation that support access is granted for the length of a task rather than kept standing.
- A trial export of the complete records from the practice management system, with the format and the elapsed time recorded.
- A backup outside the vendor's infrastructure, with a test restore carried out within the last 12 months, its date and the name of the person who confirmed it.
- A second factor on every account that can reach patient records.
- A log of operations on patient records, retained for at least 12 months.
- An agreed decision path: who prepares the risk assessment, who signs a notification, who informs the individuals concerned.
- One named person for contact with the vendor, with a record of what the vendor said and when.
The twelve months in items 6 and 8 are a CZ Cybersecurity recommendation, not a legal requirement. Data protection law sets no single figure here, so we state one that can be measured and checked. An organisation may hold to a different figure where its own risk assessment supports it.
07 Who
Who does this
CZ Cybersecurity sp. z o.o. has been operating since 2014. The work is carried out by Helena Czarnecka: CISSP, GCFE, ISO 27001 Lead Auditor, ISA Senior Member.
The scope is the technical and evidentiary layer: vendor access, accounts and permissions, integrations, backups, logs. We do not practise medicine, we do not advise on the organisation of care, and we do not issue legal opinions.
08 Questions
Questions that come up most often
Does using a vendor that has had an incident mean our records were exposed?
Not on its own. In the case in the register above, it has not been publicly established which facilities and which categories of data the incident covers, and the vendor has announced that it will contact its customers once the scope is established. Using a system is therefore not the same thing as a breach at a given organisation, and it does not remove the controller's duty to assess.
Does a breach at a vendor have to be reported within 72 hours?
The controller's duty is to analyse the risk to the rights and freedoms of natural persons, in order to assess whether a breach has occurred at all. A report is made if that analysis shows a breach making it necessary to notify the President of UODO: then without undue delay and no later than 72 hours after the breach is established. Whether the individuals concerned are notified depends on the outcome of the same analysis. The legal qualification rests with the data protection officer or a law firm.
Can you establish whether our records were in the set that was taken?
We do not promise that. Establishing what exactly was taken rests with the authorities and the vendor. What can be established straight away is what the organisation has entrusted to which vendor and through which channels, and what follows from that for the risk assessment. According to the communique from the Ministry of Digital Affairs, data is to reach the bezpiecznedane.gov.pl service only once it is established whom the incident concerns, so a search there today settles nothing for a given organisation.
Is this a full security audit?
No. It is a review of the areas in which an event at a vendor turns into risk on the provider's side. A full audit has a wider scope, a longer timeline and a different price; if it turns out to be needed, we say so plainly.
Do you help with data protection duties?
With the technical part: what was entrusted and where, what traces remain in the logs, what can be reconstructed and demonstrated. The legal opinion, the qualification of a breach and the content of any notification remain with the data protection officer or a law firm.
Do you review vendors other than the practice management system?
Yes. The same set of questions applies to any vendor that processes the organisation's data or can reach its systems: laboratories, teleradiology, online booking, hosting, IT support. It holds outside healthcare as well; the wording of the questions changes, the questions do not.
09 Contact
Discuss vendor exposure
A few sentences about which systems the organisation uses, and what is already known, are enough to start. We will get back to you and determine whether and how we can help.
Prefer to pick a time straight away?
Book a meeting →Sources for the register: Ministry of Digital Affairs, Ministry of Health, UODO. Verification: CZ Cybersecurity sp. z o.o. State as at 13 August 2026.