MyDr, described as one of Poland's largest healthcare platform providers, announced on August 12 that it is investigating a serious security incident on its network after threat actors contacted security journalist Adam Haertle claiming to have exfiltrated patient data from numerous Polish clinics. The alleged attackers claim access to 18,814,422 unique PESEL numbers — Poland's national personal identification numbers, which function similarly to Social Security numbers in the US context. If confirmed at that scale, the incident would rank among the most significant healthcare data exposures in European history.
What the threat actors claim
According to reporting by Haertle at ZaufanaTrzeciaStrona, the individuals who contacted him said they had obtained data from multiple clinics that use MyDr's platform, not solely from MyDr's own internal systems. That distinction matters: it suggests the compromise may have occurred at the infrastructure or integration layer, potentially affecting any clinic that relies on the platform for records management, scheduling, or patient-facing services.
The attackers cited PESEL numbers specifically. Because PESEL is a lifelong, government-issued identifier that does not change, exposure creates a durable fraud and identity risk for affected individuals — a characteristic it shares with US Social Security numbers, where breach consequences can persist for decades.
Why this is relevant to US healthcare operators
Poland's healthcare data environment differs from the US in legal framework, but the technical threat pattern is directly applicable. Platform-level breaches — where a single vendor's compromise cascades across dozens or hundreds of client organizations — are an established and growing attack vector in US healthcare as well. Incidents at healthcare software vendors in recent years have demonstrated that a single point of failure in a shared platform can expose data held by practices that have no direct knowledge of or control over the underlying vulnerability.
US independent practices that rely on cloud-based EHR, practice management, or patient engagement platforms face structurally similar concentration risk. The question regulators and risk managers increasingly ask is not only whether an individual covered entity has adequate controls, but whether the business associate or subprocessor holding or routing protected health information does as well.
What this signals about platform-layer risk
The MyDr incident illustrates two converging pressures that compliance officers should track regardless of geography.
- Third-party enumeration. Attackers are increasingly targeting the connective tissue between healthcare organizations — billing platforms, scheduling tools, interoperability middleware — rather than individual practice systems. These systems often hold or transit data from many clients simultaneously, multiplying the yield from a single intrusion.
- Identifier permanence as a risk multiplier. When breached data includes permanent identifiers — national ID numbers, Social Security numbers, medical record numbers — the harm window extends far beyond the immediate incident. Breach response programs that treat notification as the end of the obligation are increasingly seen as inadequate by regulators and plaintiffs' counsel alike.
- Vendor transparency timelines. The fact that the threat actors contacted a journalist before MyDr made a public statement reflects a pattern seen in US incidents as well: affected patients and client organizations often learn of a compromise through media coverage rather than formal notification channels. Business associate agreement terms around notification timing are worth reviewing against this realistic scenario.
What independent practices should check
Practices evaluating their exposure to this class of risk should examine a few areas without delay.
First, the business associate agreements in place with any platform vendor handling patient data should specify breach notification timelines and the vendor's obligation to disclose incidents that may affect client data, even when the vendor itself is uncertain of the full scope.
Second, practices should understand whether their vendor agreements grant them the right to receive audit logs or third-party security assessment results. Vendors reluctant to provide evidence of security controls warrant closer scrutiny during contract renewal.
Third, incident response plans should account for the scenario in which a practice learns of a vendor-level breach through news media or a patient complaint rather than through the vendor's own notification. Knowing in advance who within the practice has authority to assess exposure and communicate with patients removes critical delay from the response.
The MyDr investigation is ongoing, and the full scope of affected records and organizations has not been confirmed. Further disclosures are expected as Polish data protection authorities engage.