MyDr, described as one of Poland's largest healthcare system providers, disclosed on August 12 that it is investigating a serious security incident on its network. Threat actors who contacted the outlet reporting the story claimed access to 18,814,422 unique PESEL numbers — Poland's national personal identification numbers, which function similarly to Social Security numbers in the United States — drawn from records across numerous Polish clinics served by the platform. The scale of the claimed exposure places this incident among the larger healthcare data events reported in Europe in recent years.
What the attackers claim
The threat actors reached out to the publication before MyDr made its own disclosure, a sequencing that has become common in extortion-linked intrusions. Their specific claim — access to more than 18 million unique national identifiers — suggests the breach, if confirmed at the scale alleged, affected a significant share of Poland's total population of roughly 38 million people.
PESEL numbers carry risks analogous to Social Security numbers: they are used for identity verification across financial, government, and healthcare systems, meaning exposed patients face long-term identity fraud exposure beyond the immediate healthcare context. The involvement of clinic-level patient data also raises the possibility that diagnostic, treatment, or prescription records were accessible alongside the identifiers.
Why this matters outside Poland
Stories like this draw US relevance on two fronts. First, several healthcare technology vendors operating in Europe maintain overlapping infrastructure, data-sharing arrangements, or parent-company ties with platforms used by US practices. A supply-chain intrusion at a large platform provider can affect clients across jurisdictions when shared environments or common software components are involved.
Second, the incident illustrates a structural risk that US regulators have flagged repeatedly: large aggregator platforms that consolidate patient data from many smaller clinical sites create high-value single targets. When a platform provider is compromised, the exposure is not limited to one covered entity — it propagates across every clinic that shared data with the platform. The Department of Health and Human Services has emphasized business associate oversight as a core HIPAA Security Rule obligation precisely because of this dynamic.
What independent practices should consider
The MyDr incident offers a concrete checklist prompt for US healthcare administrators who rely on any third-party platform that aggregates patient data across sites:
- Inventory your aggregation points. Any vendor that receives data from multiple locations — scheduling systems, RCM platforms, lab interfaces, EHR cloud hosts — creates a consolidated exposure profile that mirrors the MyDr scenario.
- Review business associate agreement terms. BAAs should specify breach notification timelines, incident response obligations, and the vendor's duty to preserve forensic evidence. Vague language about "reasonable security" without defined controls is a gap.
- Confirm vendor breach notification procedures. The MyDr disclosure came after external parties — rather than the company itself — surfaced the incident publicly. Practices should know in advance how and when a vendor will notify them if a breach is suspected, and that timeline should be contractually defined rather than left to the vendor's discretion.
- Assess data minimization practices. The breadth of the claimed PESEL exposure suggests the platform retained large volumes of patient identifiers beyond what individual clinical encounters may have required. US practices should audit what data they transmit to third-party platforms and whether retention schedules limit unnecessary accumulation.
Confirmation of the full scope of the MyDr incident remains pending as the investigation continues. Regulatory proceedings under Poland's data protection authority, and any coordination with EU-level supervisory bodies, are expected to follow.