Poland's Cyber Five: proposals that could reshape health-data protection
The ministry proposes supplier certification, minimum safeguards, patient alerts and new duties for large-scale health-data processors.
- AUTHOR
- Karol Rapacz / CEO of Breachroad · OSCP · PNPT
- PUBLISHED
- 1 October 2026
- READING TIME
- 10 min read
- TOPIC
- Governance and Compliance
Poland’s Ministry of Digital Affairs has presented the “Cyber Five”, a package of five proposals for protecting personal information with particular emphasis on health data. The ideas cover certification of processors working for healthcare providers, minimum technical requirements, clearer information about external processors, patient notifications about medical events, and additional duties for suppliers operating at scale.
One distinction is essential: these are ministry proposals, not a set of rules already in force. Legislative work is the stated next step. A clinic or technology supplier should not claim a new status of “Cyber Five compliance”. It can, however, use the policy direction to assess whether present contracts, systems and communications protect patients adequately.
The five proposed measures
First, processors entrusted with medical data would be subject to certification linked to Poland’s national cybersecurity certification system. For a healthcare provider, certification could become one piece of supplier assurance, but it cannot replace review of the particular service, data scope and access model.
Second, systems processing medical information would have to meet minimum technical requirements. Their detailed form will matter: useful requirements must be measurable and verifiable rather than limited to a general instruction to maintain security.
Third, patients would receive information about external processors, including the purpose and scope of processing and contact details. This could make today’s largely invisible supply chain easier to understand.
Fourth, patients could receive mObywatel and mojeIKP notifications about medical events such as an appointment, prescription or service, with details available after login. The mechanism could help someone identify an event they do not recognise.
Fifth, additional obligations would apply to processors operating at scale. The ministry refers to suppliers serving more than 100 controllers or handling information concerning more than 100,000 people.
What large processors may need to provide
Under the proposals, a large processor would disclose to customer organisations the safeguards it applies, its sub-processors, processing locations, and information about audits and testing. It would also perform a risk assessment before processing begins and update it after a significant change and at least every two years.
Following a breach, the supplier would transmit a minimal identity dataset—first name, surname and PESEL—to CSIRT NASK through the Police. Information could then be made available to individuals through bezpiecznedane.gov.pl. The precise route, legal basis, safeguards and triggering cases will need to be settled during legislative work.
For healthcare providers, the supply-chain visibility is important. A patient’s data may pass through practice-management software, hosting, backups, support, laboratory integrations and billing systems. A contract with the first supplier does not reveal the full picture if its downstream processors are unknown.
A patient alert can also be a security control
An appointment or prescription alert will not prevent every abuse, but it may shorten detection time. It works in a similar way to a banking transaction notification: the affected person has context that an automated system may lack.
The control is useful only with a clear response path. A notification must explain where details can be checked safely, how to report an unfamiliar event and what not to do. Criminals may imitate a new alert, so an SMS or email should not send the person directly to a page that asks for sensitive information.
Healthcare providers also need a process for incoming reports. Launching alerts without a triage route may simply move confusion to reception desks and helplines. Roles, response deadlines, evidence preservation and escalation into the personal-data breach process should be designed in advance.
What providers and suppliers can do now
There is no need to wait for legislation before identifying every processor, limiting access, verifying data locations, requesting test evidence and rehearsing an incident. A healthcare provider should maintain current records of systems and contracts, security contacts and a way to disconnect a supplier without losing medical documentation.
Suppliers can prepare a consistent assurance pack covering service architecture, sub-processors, retention, encryption, vulnerability management, backups, logs, audit results and incident-notification procedures. This is not only a regulatory response. It shortens procurement reviews and improves customer trust.
Our third-party risk management guide provides a framework for contracts, while data breach response covers the first actions after an incident. Providers, suppliers and communications teams can rehearse their shared response in an incident-readiness exercise.
Source facts and Breachroad conclusions
The Ministry of Digital Affairs Cyber Five announcement describes the five proposals, thresholds for large processors, proposed disclosures, risk-assessment cycle, planned post-breach data flow and next legislative steps.
The supply-chain analysis, conditions for useful patient alerts and suggested supplier assurance pack are Breachroad conclusions. We do not assume the final wording of future law, because the proposals may change during the legislative process.


