MyDr, a platform serving a large share of Poland's private clinic market, disclosed on August 12 that it is investigating a serious security incident on its network after threat actors contacted the security publication ZaufanaTrzeciaStrona and claimed to have exfiltrated patient data from multiple clinics using the system. The alleged scope — 18,814,422 unique PESEL numbers, Poland's national personal identification numbers — would make this one of the largest healthcare data exposures in European history. The incident is still under investigation, but the public claim alone carries significant implications for US-headquartered vendors and compliance professionals watching cross-border healthcare data risk.
Why this matters beyond Polish borders
PESEL numbers function as a combined birth-date and national registry identifier, analogous to a Social Security number with demographic data embedded. In a clinical context, their exposure alongside medical records creates a durable fraud and identity-theft risk that does not expire when a password is changed.
MyDr describes itself as serving clinics across Poland, meaning the affected data would span many distinct covered entities — a structural pattern well-recognized in US breach law. When a single vendor holds data on behalf of dozens or hundreds of provider organizations, a single intrusion multiplies regulatory and patient-notification obligations across the entire customer base. US business associates operating a comparable aggregation model face the same structural amplification risk.
The alleged perpetrators disclosed the breach to a journalist rather than through a coordinated disclosure channel, which limited MyDr's ability to control the notification timeline — a dynamic OCR has addressed in US guidance requiring covered entities to assume breach and notify within 60 days regardless of whether an investigation is complete.
The aggregation risk at the vendor layer
Healthcare technology platforms that ingest data from many provider clients create what investigators sometimes call a single-point-of-collection exposure. A successful intrusion at the vendor tier yields records from every connected clinic simultaneously, without requiring a separate attack on each provider.
Several dynamics specific to clinic-management and EHR-adjacent platforms amplify this risk:
- Broad data scope. Scheduling, billing, and clinical record systems routinely hold the full set of identifiers needed for identity fraud — name, date of birth, contact information, insurance or national ID numbers, and diagnosis codes — in a single database or data pipeline.
- Extended dwell time. Threat actors who claim access before a vendor detects the intrusion suggest a monitoring gap. Retrospective forensics in comparable US cases has frequently found dwell times measured in weeks or months.
- Downstream notification complexity. When the breach occurs at the platform layer rather than the clinic layer, establishing which patient records belong to which covered entity — and which patients must be notified — becomes a substantial operational task under any notification framework.
What US compliance officers should take from this
The MyDr incident does not trigger direct US regulatory obligations for American providers, but it is a precise functional analog to risks that HHS's proposed HIPAA Security Rule updates are designed to address. The proposed 2024 NPRM from OCR emphasizes network segmentation, encryption of data at rest and in transit, and vulnerability scanning cadences for exactly the class of risk this incident illustrates.
Practices that rely on a single cloud-based management platform to hold scheduling, billing, and clinical data should confirm with their vendor how patient data is segmented across client accounts, what monitoring tools are in place to detect unauthorized bulk data access, and what the vendor's contractual obligations are under the business associate agreement if the vendor-tier system is the point of intrusion. The MyDr situation also illustrates that threat actors may choose public disclosure as a pressure tactic before formal ransom demands are made, collapsing the time window a covered entity or business associate would otherwise have to prepare notifications.
What this signals about the next 12 months
Large-scale vendor-tier intrusions in healthcare have increased in frequency since the 2024 Change Healthcare disruption drew sustained attention to the sector's dependence on centralized platforms. The MyDr incident, even outside US jurisdiction, reinforces that adversaries are actively mapping healthcare vendor infrastructure internationally and that the playbook — gain access, exfiltrate identifiers at scale, contact media — is now a documented pattern rather than an isolated tactic.
OCR's enforcement record over the past three years shows a consistent focus on risk analysis failures at entities that centralized data without proportionate access controls. The regulatory direction is toward demonstrable, documented risk management at the infrastructure layer — not simply the existence of a written policy.