MyDr, described as one of the largest healthcare system providers in Poland, disclosed on August 12 that it is investigating a serious security incident on its network. The alleged attackers contacted DataBreaches.net reporter Adam Haertle ahead of any public announcement and claimed to have obtained data from numerous Polish clinics served by the platform, including approximately 18,814,422 unique PESEL numbers — Poland's national personal identification numbers, which function as a permanent, lifelong identifier comparable in sensitivity to a U.S. Social Security number.

What the attackers claimed

According to Haertle's reporting, the individuals who contacted DataBreaches.net presented themselves as the perpetrators of the MyDr incident and asserted they had active access to patient data spanning a wide range of clinics connected to the platform. The claim centered specifically on PESEL numbers, a data element whose exposure carries long-term identity-fraud risk because the identifier cannot be changed and is required for nearly every interaction with Polish financial, medical, and government systems.

MyDr has confirmed it is investigating but has not yet verified or refuted the scope of the attackers' claims. The public disclosure followed, rather than preceded, outreach from the alleged attackers to a journalist — a sequencing that is increasingly common in extortion-oriented intrusions.

Why this matters beyond Poland

Healthcare platforms that aggregate data from multiple clinic customers represent a structural concentration point: a single intrusion can expose records from dozens or hundreds of independent practices simultaneously. That dynamic is not specific to any country's market. U.S. healthcare has seen parallel incidents where a vendor-level compromise propagated across its entire client base, most visibly in multi-practice clearinghouse and practice-management breaches.

The PESEL number's characteristics also draw a direct analogy to U.S. protected health information. When a static, government-issued identifier is combined with clinical records, the harm extends well beyond the initial breach event — affected individuals carry the exposure indefinitely. U.S. practices managing Social Security numbers alongside clinical data face the same irreversibility problem.

What independent practices should consider

The MyDr incident illustrates several patterns that apply regardless of jurisdiction:

What this signals for cross-border vendor risk

The incident also has indirect relevance for U.S.-based healthcare organizations that use vendors with European operations or data centers. A vendor footprint in multiple regulatory environments does not automatically mean that the stronger framework governs all data. Practices contracting with vendors that have international operations should confirm which legal entity controls the data, where it is stored, and which breach-notification timeline and authority applies.

MyDr's investigation is ongoing. No regulatory findings, patient notifications, or law enforcement actions had been announced at the time of publication.