MyDr, described as one of Poland's largest healthcare system providers, announced it is investigating a serious security incident after threat actors contacted journalists claiming to hold data from numerous Polish clinics. The attackers asserted access to 18,814,422 unique PESEL numbers — Poland's national personal identification numbers, which function similarly to Social Security numbers in the United States. If confirmed at anything near that scale, the incident would rank among the largest healthcare data exposures in European history.

What the attackers claimed

Reporting by Adam Haertle, published on DataBreaches.net, indicates the alleged perpetrators proactively reached out to journalists before any public disclosure by the company — a pattern increasingly common in extortion-driven intrusions where threat actors use media pressure to accelerate ransom negotiations or amplify reputational damage.

The specific claim centers on PESEL numbers sourced from records across multiple clinics served by MyDr's platform. PESEL numbers are government-issued identifiers embedded in nearly every Polish healthcare, insurance, and government transaction. Exposure at this scale would create long-tail identity and fraud risk for affected individuals across multiple systems well beyond the healthcare sector.

MyDr had not, at time of publication, confirmed the scope of the attackers' claims or provided technical detail about the intrusion vector.

Why this matters to US-based practices

Poland's healthcare data environment differs from the US in regulatory framework — the EU's GDPR and Poland's national implementing legislation govern breach response there, not HIPAA. However, several dynamics in this incident are directly relevant to US independent practices.

What this signals about platform-level exposure

The MyDr incident fits a pattern seen repeatedly in US healthcare over the past two years: large-scale breaches originating not at the clinical endpoint but at a technology intermediary serving many organizations. The 2024 Change Healthcare disruption affected a significant share of US medical claims processing for similar structural reasons — one platform, many dependent organizations, one intrusion with cascading consequences.

Independent practices in any jurisdiction benefit from understanding what data their platform vendors hold, where that data is stored, what network access the vendor has to clinic systems, and what contractual breach notification timelines apply. Business associate agreements and equivalent contractual instruments in other jurisdictions exist precisely to establish accountability for these questions — but they carry no protective value if the underlying data inventory and access controls are not periodically reviewed.

The MyDr investigation is ongoing. Regulatory and forensic findings, when published, will offer additional technical detail on intrusion method and confirmed data exposure.