MyDr, described as one of Poland's largest healthcare network providers, announced on August 12 that it is investigating a serious security incident after threat actors contacted journalist Adam Haertle and claimed to have extracted patient data from numerous Polish clinics. The alleged attackers say they obtained 18,814,422 unique PESEL numbers — Poland's national identification numbers, which function similarly to Social Security numbers in the United States. If confirmed at the scale claimed, the incident would rank among the largest healthcare data exposures in European history.
What the attackers claimed
The threat actors reached out to ZaufanaTrzeciaStrona, a Polish cybersecurity publication, ahead of MyDr's own disclosure — a pattern increasingly common in extortion-oriented intrusions where attackers seek media pressure before a ransom deadline. The claimed dataset centers on PESEL numbers, which are government-issued identifiers linked to birth records, insurance eligibility, and medical history access across Poland's healthcare system.
Healthcare identifiers of this type carry a different risk profile than payment card data. They cannot be reissued, they persist across a patient's lifetime, and they can be combined with clinical records to enable targeted fraud, insurance manipulation, or identity theft that surfaces years after the initial exposure.
The US-relevant pattern
American compliance officers and practice administrators may view a Polish breach as a distant concern, but the structural dynamics apply directly to domestic independent practices. Several features of this incident map onto recurring failure modes seen in US healthcare breaches:
- Network-wide lateral access. The attackers reportedly claim data from "numerous Polish clinics" served by the platform, suggesting a compromise at the infrastructure or aggregation layer rather than at a single practice. Healthcare technology vendors that aggregate patient records across multiple client organizations represent a single point of failure for every covered entity on that platform.
- Threat-actor media contact preceding disclosure. Attackers contacting journalists before notifying the affected organization is a pressure tactic designed to accelerate ransom payment. US practices should understand that public exposure may precede formal notification from a vendor, and breach response plans should account for that sequence.
- National identifier exposure. The HIPAA equivalent concern involves Social Security numbers and insurance member IDs, which appear in clinical and billing records. Any vendor that handles scheduling, billing, or eligibility verification across a practice network holds a concentrated identifier dataset that represents an outsized target.
What this signals for vendor oversight
The MyDr incident adds to a body of evidence that healthcare aggregators — platforms that consolidate records from multiple facilities or practices — attract sophisticated adversaries precisely because a single intrusion yields data at scale. That calculus makes third-party vendor risk assessment one of the more consequential components of a healthcare organization's security approach.
Independent practices in the US operating under HIPAA have a legal obligation to execute Business Associate Agreements with vendors who handle protected health information, and to conduct periodic assessments of those vendors' security controls. In practice, many small and mid-size practices sign BAAs without conducting meaningful follow-up review of vendor security documentation, penetration testing results, or incident response capabilities.
The MyDr investigation remains open and the full scope of the breach has not been independently confirmed. How the company responds — in terms of notification timing, transparency about affected clinic counts, and cooperation with Polish data protection authorities — will offer a case study that US healthcare legal and compliance teams should watch as European enforcement of healthcare data rules continues to mature.