MyDr, described as one of Poland's largest healthcare system providers, disclosed on August 12 that it is investigating a serious security incident on its network. Threat actors who contacted the outlet reporting the story claimed access to 18,814,422 unique PESEL numbers — Poland's national personal identification numbers, which function similarly to Social Security numbers in the United States — drawn from records across numerous Polish clinics served by the platform. The scale of the claimed exposure places this incident among the larger healthcare data events reported in Europe in recent years.

What the attackers claim

The threat actors reached out to the publication before MyDr made its own disclosure, a sequencing that has become common in extortion-linked intrusions. Their specific claim — access to more than 18 million unique national identifiers — suggests the breach, if confirmed at the scale alleged, affected a significant share of Poland's total population of roughly 38 million people.

PESEL numbers carry risks analogous to Social Security numbers: they are used for identity verification across financial, government, and healthcare systems, meaning exposed patients face long-term identity fraud exposure beyond the immediate healthcare context. The involvement of clinic-level patient data also raises the possibility that diagnostic, treatment, or prescription records were accessible alongside the identifiers.

Why this matters outside Poland

Stories like this draw US relevance on two fronts. First, several healthcare technology vendors operating in Europe maintain overlapping infrastructure, data-sharing arrangements, or parent-company ties with platforms used by US practices. A supply-chain intrusion at a large platform provider can affect clients across jurisdictions when shared environments or common software components are involved.

Second, the incident illustrates a structural risk that US regulators have flagged repeatedly: large aggregator platforms that consolidate patient data from many smaller clinical sites create high-value single targets. When a platform provider is compromised, the exposure is not limited to one covered entity — it propagates across every clinic that shared data with the platform. The Department of Health and Human Services has emphasized business associate oversight as a core HIPAA Security Rule obligation precisely because of this dynamic.

What independent practices should consider

The MyDr incident offers a concrete checklist prompt for US healthcare administrators who rely on any third-party platform that aggregates patient data across sites:

Confirmation of the full scope of the MyDr incident remains pending as the investigation continues. Regulatory proceedings under Poland's data protection authority, and any coordination with EU-level supervisory bodies, are expected to follow.