MyDr, described as one of Poland's largest healthcare network providers, announced on August 12 that it is investigating a serious security incident after threat actors contacted journalist Adam Haertle and claimed to have extracted patient data from numerous Polish clinics. The alleged attackers say they obtained 18,814,422 unique PESEL numbers — Poland's national identification numbers, which function similarly to Social Security numbers in the United States. If confirmed at the scale claimed, the incident would rank among the largest healthcare data exposures in European history.

What the attackers claimed

The threat actors reached out to ZaufanaTrzeciaStrona, a Polish cybersecurity publication, ahead of MyDr's own disclosure — a pattern increasingly common in extortion-oriented intrusions where attackers seek media pressure before a ransom deadline. The claimed dataset centers on PESEL numbers, which are government-issued identifiers linked to birth records, insurance eligibility, and medical history access across Poland's healthcare system.

Healthcare identifiers of this type carry a different risk profile than payment card data. They cannot be reissued, they persist across a patient's lifetime, and they can be combined with clinical records to enable targeted fraud, insurance manipulation, or identity theft that surfaces years after the initial exposure.

The US-relevant pattern

American compliance officers and practice administrators may view a Polish breach as a distant concern, but the structural dynamics apply directly to domestic independent practices. Several features of this incident map onto recurring failure modes seen in US healthcare breaches:

What this signals for vendor oversight

The MyDr incident adds to a body of evidence that healthcare aggregators — platforms that consolidate records from multiple facilities or practices — attract sophisticated adversaries precisely because a single intrusion yields data at scale. That calculus makes third-party vendor risk assessment one of the more consequential components of a healthcare organization's security approach.

Independent practices in the US operating under HIPAA have a legal obligation to execute Business Associate Agreements with vendors who handle protected health information, and to conduct periodic assessments of those vendors' security controls. In practice, many small and mid-size practices sign BAAs without conducting meaningful follow-up review of vendor security documentation, penetration testing results, or incident response capabilities.

The MyDr investigation remains open and the full scope of the breach has not been independently confirmed. How the company responds — in terms of notification timing, transparency about affected clinic counts, and cooperation with Polish data protection authorities — will offer a case study that US healthcare legal and compliance teams should watch as European enforcement of healthcare data rules continues to mature.