MyDr, described as one of Poland's largest healthcare system providers, announced on August 12 that it is investigating a serious security incident after alleged attackers contacted journalists and claimed to hold patient data from numerous Polish clinics. The claim centers on 18,814,422 unique PESEL numbers — Poland's national identification numbers, which function similarly to Social Security numbers in the US. If the scope is confirmed, the incident would rank among the largest healthcare data exposures reported in Europe.
What the attackers claimed
The individuals who contacted journalist Adam Haertle at Zaufana Trzecia Strona said they had gained access to patient records spanning multiple clinics that use the MyDr platform. The specific figure — more than 18 million PESEL numbers — is notable because Poland's total population is approximately 38 million, meaning the dataset, if genuine, would represent roughly half the country's residents.
PESEL numbers are persistent, government-issued identifiers that do not change over a person's lifetime. Exposure of that identifier alongside healthcare records creates compounded risk: the combination enables identity fraud, benefits abuse, and targeted phishing that can persist for years after the initial breach.
MyDr confirmed it is investigating but had not, at time of publication, disclosed the attack vector, the number of affected clinics, or whether data had been exfiltrated or merely accessed.
The structural problem with multi-clinic platforms
MyDr operates as a shared infrastructure provider serving multiple independent clinical practices. That architecture concentrates risk: a single successful intrusion against the platform layer can expose patient data across every clinic connected to the system, regardless of the individual security controls each practice has in place.
This pattern has appeared repeatedly in US healthcare incidents. Third-party platforms — electronic health record systems, revenue cycle management tools, patient portal providers — aggregate data from dozens or hundreds of practices. A breach at the platform level bypasses practice-level controls entirely. The MyDr incident illustrates why downstream practices need contractual visibility into their vendors' incident response timelines, not just their security certifications.
The US-relevant lesson
US-based healthcare practices are not directly regulated by Polish data protection law, but the structural lesson transfers cleanly. Under HIPAA's business associate framework, covered entities are required to obtain satisfactory assurances from vendors who handle protected health information — including, in many cases, cloud-hosted EHR and practice management platforms. Those assurances should address breach notification timelines, forensic access, and data segmentation between clients.
The MyDr situation demonstrates what happens when a shared platform is compromised and individual practices have limited ability to assess their own exposure independently. Practices should review their business associate agreements to confirm they include:
- Breach notification timelines that meet or beat the 60-day HIPAA outer limit, with interim notice obligations
- Data segmentation requirements specifying how patient records from one covered entity are isolated from those of other clients on the same platform
- Audit log access provisions that allow a covered entity to conduct its own review of access to its data following a reported incident
- Right-to-terminate clauses that activate when a vendor cannot confirm the scope of unauthorized access within a defined window
What the next weeks will show
The credibility of the attackers' claims has not been independently verified. MyDr's investigation is ongoing. The key questions that will determine the incident's actual severity are whether the PESEL numbers are linked to clinical records or exist as standalone identifiers, which specific clinics are affected, and whether the data has appeared on criminal marketplaces.
For international healthcare security observers, the incident is worth tracking because Poland's healthcare infrastructure modernization over the past decade mirrors ongoing digitization efforts in many US regional health systems. The concentration of patient identifiers in shared cloud platforms — and the lag between intrusion and public disclosure — is a dynamic that US compliance officers should recognize as familiar.