MyDr, described as one of Poland's largest healthcare platform providers serving multiple clinics, announced on August 12 that it is investigating a serious security incident affecting its network. Threat actors who contacted journalists before the disclosure claimed to hold 18,814,422 unique PESEL numbers — Poland's national personal identification numbers, which function similarly to Social Security numbers in the United States — along with patient data drawn from numerous Polish clinics operating on the platform. The incident illustrates a pattern seen repeatedly in US healthcare: a breach at a single shared-infrastructure vendor cascades across every clinical organization using that platform.

The structural problem with shared healthcare platforms

Healthcare technology providers that host data on behalf of multiple clinical organizations present a concentrated target. When one platform is compromised, every clinic whose records flow through that infrastructure becomes an affected party, regardless of the individual clinic's own security practices. The MyDr incident fits this model precisely: the threat actors reportedly did not breach individual clinics one by one but gained access at the platform layer, extracting records at scale.

This is the same architecture that amplified the impact of several high-profile US healthcare vendor incidents in recent years. A single point of failure at the infrastructure level can expose patient populations orders of magnitude larger than any individual practice would hold on its own.

What the PESEL exposure means for affected patients

Poland's PESEL number is a universal citizen identifier used across healthcare, banking, and government services. Exposure of PESEL numbers at this scale creates durable fraud risk: the identifier cannot be changed, so affected individuals carry the liability indefinitely. The harm profile is analogous to Social Security number exposure in a US breach — identity theft, fraudulent benefit claims, and synthetic identity fraud are all downstream risks.

The attackers contacting journalists before the formal disclosure is also a recognizable pressure tactic. Publishing the claim publicly before an organization has confirmed or contained the incident forces a faster, often less orderly, public response and can complicate forensic investigation by alerting other threat actors to an active, potentially still-accessible environment.

What this signals for US practice administrators

US healthcare organizations may view a Polish breach as geographically remote, but several dynamics make this incident directly relevant.

Where the investigation stands

MyDr had not confirmed the scope or origin of the incident at the time of reporting. The company stated it is actively investigating. No timeline for disclosure to affected clinics or patients had been announced. Investigators and affected organizations should treat attacker-claimed record counts as unverified until forensic analysis confirms or contradicts them — threat actors routinely overstate the volume of data obtained to amplify leverage and media attention.