Adam Ptasiewicz · Reading time: 4 minutes
What else has to happen before we notice that secure solutions for protecting key information already exist on the market? For example, the recent incident involving MyDr systems shows the scale of the challenge. According to the government’s announcement, unauthorised access to historical data may affect 18.8 million people and more than 12,000 healthcare facilities. In addition, the compromised information may have included PESEL numbers (Polish national identification numbers), contact details, prescription information, visit notes and health data.
This is not about looking for someone to blame, nor about believing that a single tool can stop every cyberattack. It is, however, worth asking: when we design digital healthcare, do we use all the security mechanisms that are already available?
What NIS2 says
The NIS2 Directive classifies healthcare as a sector of high criticality. Article 24(1) also states that “Member States shall encourage essential and important entities to use qualified trust services”.
In fact, qualified trust services already operate on the Polish and European markets. They are supervised, regularly audited and subject to security requirements set out in law.
As a result, these services make it possible to effectively secure the entire life cycle of digital documents and data.
Mechanisms that are already available
For instance, the qualified electronic registered delivery service. It confirms the identity of the sender and the recipient, the integrity of the data transmitted, and the time the data was sent and received. It is not just a digital registered letter. It is a service that secures the transfer of data between the parties to a communication, and it will be used for data exchange within the European Digital Identity Wallet (EUDI Wallet). Therefore, in many processes, it can be a more secure way to send medical records and can replace ordinary email.
But e-Delivery (in Poland, e-Doręczenia) is only one of the available mechanisms.
- A qualified electronic signature confirms the identity of a document’s author and protects the document’s integrity.
- A qualified electronic seal confirms that a document comes from a specific healthcare facility, laboratory, pharmacy or other organisation.
- A qualified electronic time stamp provides reliable proof that specific data or a document existed at a given moment.
- A qualified electronic archiving service (e-archive) can support the long-term storage of documents while preserving their security, integrity and authenticity.
Preservation services for signatures and seals make it possible to confirm their validity many years later, despite technological change or the expiry of certificates.
This is particularly important in healthcare, because medical records must remain reliable, complete and verifiable for a long time.
Trust services as part of the security architecture
Trust service providers are required to ensure access management, secure data storage, network segmentation, backups, multi-factor authentication (MFA), incident monitoring and appropriate organisational procedures.
For this reason, they can be one of the core elements of such an architecture. Especially where data, not only medical data, is exchanged between healthcare facilities, doctors, laboratories, pharmacies, patients, and public and commercial systems.
From declarations to practice
Perhaps we do not need more declarations about the importance of cybersecurity. What we need is to put qualified trust services to practical use in healthcare processes by:
- replacing ordinary email with electronic registered delivery,
- signing and sealing medical records,
- reliably time-stamping documents,
- secure electronic archiving,
- long-term preservation of signatures and seals,
- interoperability and the freedom to choose from many qualified providers.
In short technological solutions, proven providers, and European legal frameworks and standards are already available on the market.
Situations like this remind us that, through the necessary national legislation and genuine public-private partnership, qualified trust services should become a natural part of security. Especially in digital healthcare and in the protection, exchange and storage of other key data. These solutions are ready. We just need to be willing to notice them.
Adam Ptasiewicz
Published: 3 September 2026

