MyDr, described as one of the largest healthcare system providers in Poland, disclosed on August 12 that it is investigating a serious security incident on its network. The alleged attackers contacted DataBreaches.net reporter Adam Haertle ahead of any public announcement and claimed to have obtained data from numerous Polish clinics served by the platform, including approximately 18,814,422 unique PESEL numbers — Poland's national personal identification numbers, which function as a permanent, lifelong identifier comparable in sensitivity to a U.S. Social Security number.
What the attackers claimed
According to Haertle's reporting, the individuals who contacted DataBreaches.net presented themselves as the perpetrators of the MyDr incident and asserted they had active access to patient data spanning a wide range of clinics connected to the platform. The claim centered specifically on PESEL numbers, a data element whose exposure carries long-term identity-fraud risk because the identifier cannot be changed and is required for nearly every interaction with Polish financial, medical, and government systems.
MyDr has confirmed it is investigating but has not yet verified or refuted the scope of the attackers' claims. The public disclosure followed, rather than preceded, outreach from the alleged attackers to a journalist — a sequencing that is increasingly common in extortion-oriented intrusions.
Why this matters beyond Poland
Healthcare platforms that aggregate data from multiple clinic customers represent a structural concentration point: a single intrusion can expose records from dozens or hundreds of independent practices simultaneously. That dynamic is not specific to any country's market. U.S. healthcare has seen parallel incidents where a vendor-level compromise propagated across its entire client base, most visibly in multi-practice clearinghouse and practice-management breaches.
The PESEL number's characteristics also draw a direct analogy to U.S. protected health information. When a static, government-issued identifier is combined with clinical records, the harm extends well beyond the initial breach event — affected individuals carry the exposure indefinitely. U.S. practices managing Social Security numbers alongside clinical data face the same irreversibility problem.
What independent practices should consider
The MyDr incident illustrates several patterns that apply regardless of jurisdiction:
- Vendor concentration risk. Practices that route patient data through shared platforms inherit the security discipline — or gaps — of that platform. Understanding exactly what data a vendor holds, in what form, and under what access controls is a prerequisite for meaningful risk assessment.
- Attacker-to-journalist disclosure timing. When threat actors contact media before an organization's public disclosure, it typically signals either an active extortion demand or a publicity-oriented leak strategy. Either scenario compresses the time available for affected organizations to notify patients and regulators before the story breaks publicly.
- Static identifier exposure. Breaches involving non-changeable identifiers — national ID numbers, dates of birth, biometrics — warrant more aggressive breach-response planning than breaches limited to credentials, because the harm horizon is indefinite. Practices should know which static identifiers they store and how those fields are protected at rest.
What this signals for cross-border vendor risk
The incident also has indirect relevance for U.S.-based healthcare organizations that use vendors with European operations or data centers. A vendor footprint in multiple regulatory environments does not automatically mean that the stronger framework governs all data. Practices contracting with vendors that have international operations should confirm which legal entity controls the data, where it is stored, and which breach-notification timeline and authority applies.
MyDr's investigation is ongoing. No regulatory findings, patient notifications, or law enforcement actions had been announced at the time of publication.