Personal Data Controller: Kamila Stachura and Albert Stachura, SKINMEDIDERM II S.C.
Dear Sir or Madam,
We are writing to inform you of an incident related to the security of your or your child’s personal data.
What happened?
As a result of a cyberattack (known as “phishing”), an unknown and unauthorized third party fraudulently and illegally gained unauthorized access to our facility’s medical system. The incident was detected and blocked, and we have filed a report of the crime with the appropriate authorities.
What data was affected by the breach?
The unauthorized individual may have gained access to your basic identifying information (such as first name, last name, and PESEL number) as well as data contained in the medical records within the application, such as medical history and e-prescriptions.
Possible consequences of the breach:
The unauthorized access to your personal data may carry risks such as:
- attempts by third parties to fraudulently obtain loans or credit using the stolen data,
- attempts to open accounts at financial institutions using your information,
- attempts to gain access to other services requiring a PESEL number,
- loss of confidentiality regarding your health information.
What have we done to resolve the issue and secure your data?
- Access to the system was immediately blocked, which halted further data leakage.
- All logs and digital traces were secured as evidence for the authorities.
- We immediately notified the police, the CERT Polska (NASK) cybersecurity incident response team, and the Office for Personal Data Protection.
- We have changed our login security measures.
What can you do to further protect yourself? (Recommendations)
To minimize the risk of negative consequences resulting from the data breach, we strongly recommend taking the following steps:
1. Block your PESEL number — you can do this free of charge and immediately through the mObywatel app, the gov.pl website, or at any municipal office. Blocking your PESEL number prevents unauthorized individuals from taking out a loan or credit using your information.
2. Activate BIK Alerts – we recommend considering activating the alert service at the Credit Information Bureau (BIK), which will notify you via text message of any attempt to fraudulently obtain a loan using your information.
3. Exercise Caution – Please pay special attention to unexpected emails, text messages, or phone calls from individuals claiming to represent banks, debt collection agencies, or public institutions.
Where can you find additional information?
If you have any questions or concerns, please feel free to contact us; we’ll be happy to answer any questions you may have.
Email: biuro@klinikadrstachura.pl