MyDr, described as one of Poland's largest healthcare system providers, disclosed on August 12 that it is investigating a serious security incident on its network. Threat actors who contacted journalist Adam Haertle at Zaufana Trzecia Strona claimed to have extracted data from numerous Polish clinics, including 18,814,422 unique PESEL numbers — Poland's national identification equivalent. The scale of the claimed exposure places this among the largest healthcare data incidents reported in Europe this year.

What the threat actors claimed

The individuals who came forward before MyDr's public disclosure stated they had active access to patient data spanning multiple clinic systems connected to the MyDr platform. The anchor figure — nearly 19 million PESEL numbers — is significant because a PESEL number functions similarly to a Social Security number in US context: it encodes date of birth and sex, is used across government and financial systems, and cannot be reissued. Exposure of that identifier at scale creates durable identity-fraud risk that outlasts any single breach notification cycle.

MyDr has confirmed it is investigating but has not publicly validated the attackers' specific claims. The pattern of threat actors notifying journalists before or simultaneously with disclosure to the affected organization is consistent with tactics used to maximize leverage in extortion negotiations.

The US-relevant structural lesson

Although MyDr operates under Polish and EU regulatory frameworks rather than HIPAA, the structural risk it illustrates maps directly onto US healthcare practice. Multi-clinic platforms — whether EHR aggregators, revenue cycle management systems, practice management networks, or regional health information exchanges — concentrate patient records from dozens or hundreds of independent practices into a single logical environment. A single credential compromise or unpatched vulnerability at the platform layer can expose every downstream organization simultaneously.

Independent US practices that rely on shared platforms should treat the MyDr incident as a prompt to ask their vendors three concrete questions: what network segmentation exists between client environments, what detection controls would identify unauthorized bulk data queries, and what is the contractual notification timeline if the vendor discovers a breach affecting the practice's patient data.

What this signals for platform-dependent practices

The MyDr disclosure follows a pattern seen repeatedly in US healthcare: an aggregator platform is breached, and individual practices learn of their exposure only after the vendor completes its own internal investigation. Under HIPAA's Breach Notification Rule, a business associate is required to notify a covered entity without unreasonable delay and no later than 60 days after discovery — but discovery itself can lag weeks behind actual attacker access.

Practices that cannot independently detect anomalous activity in their vendor-hosted environments are wholly dependent on that vendor's detection capability. Controls worth auditing include whether audit logs from vendor-hosted systems are accessible to the practice, whether data access anomalies trigger alerts, and whether the practice's business associate agreement specifies breach-discovery notification timelines shorter than the regulatory maximum.

Where the investigation stands

As of the publication date, MyDr had confirmed the investigation without validating the scope of the claimed exposure. The involvement of a journalist as the initial point of contact from the threat actors suggests the incident may follow an extortion or data-leak pattern rather than a purely destructive attack. Further details are expected as the investigation progresses and Polish data protection authorities — operating under GDPR Article 33's 72-hour supervisory notification requirement — become involved.