MyDr, described as one of Poland's largest healthcare system providers, announced it is investigating a serious security incident after threat actors contacted journalist Adam Haertle claiming to have accessed patient data from numerous Polish clinics. The attackers allege they obtained 18,814,422 unique PESEL numbers — Poland's national personal identification numbers, which function similarly to Social Security numbers in the United States. If confirmed at that scale, the incident would rank among the largest healthcare data exposures in European history.
What the attackers claim
The threat actors reached out proactively to Haertle before MyDr made any public statement, a tactic that has become common in extortion-driven intrusions against healthcare networks. Proactive contact is typically intended to create pressure on the target organization before it has completed its own investigation or notified regulators.
PESEL numbers carry outsized harm potential. Unlike a compromised password, a national identification number cannot be changed. Exposure enables identity fraud, fraudulent insurance claims, and social-engineering attacks that can persist for years after the initial breach.
MyDr's network serves multiple clinics, meaning the blast radius of a single infrastructure compromise extends across organizations that may have had no independent security failure of their own.
Why the US healthcare market should watch this
Polish healthcare operates under GDPR rather than HIPAA, but the structural risk pattern is directly relevant to US practice administrators. Multi-site and network-model healthcare organizations — including physician management companies, regional health systems, and clinic aggregators — share the same architectural vulnerability: centralized patient data repositories that, once breached, expose every affiliated site simultaneously.
US healthcare has seen this pattern repeatedly. A compromise at the network or management-company layer bypasses the individual clinic's controls entirely, regardless of how carefully each site manages its own systems. The MyDr incident is a clean illustration of why third-party and shared-infrastructure risk reviews belong in a compliance program, not just audits of a practice's own environment.
The scale of the PESEL claim — nearly 19 million records — also reflects a broader shift in healthcare intrusions. Attackers are no longer consistently targeting billing data or ransomware payloads alone; structured demographic and identity data has independent value on secondary markets and in downstream fraud schemes.
What this signals for shared-infrastructure environments
Independent practices that participate in larger networks, use shared EHR environments, or contract with management service organizations should treat this incident as a prompt to ask specific questions about how their patient data is isolated, segmented, and monitored within any shared infrastructure.
Key areas worth reviewing include:
- Network segmentation controls — whether patient data is logically and technically separated between affiliated entities, so a breach in one segment cannot traverse to others.
- Third-party access governance — what access the network operator or MSO holds to clinic-level patient records, and under what audit controls.
- Incident notification timelines — whether the organization's agreements with network partners require prompt notification to individual clinics when a centralized system is compromised, and whether those timelines meet state and federal breach-reporting obligations.
- Identity data minimization — whether the centralized system holds more demographic and identification data than is required for care coordination, and whether data retention schedules are being enforced.
MyDr's investigation is ongoing. No independent confirmation of the attackers' claimed record count had been published at the time of the source report.