MyDr, described as one of Poland's largest healthcare technology platforms, disclosed on August 12 that it is investigating a serious security incident on its network. Alleged perpetrators contacted security journalist Adam Haertle before the public announcement and claimed to hold patient data from numerous Polish clinics — including 18,814,422 unique PESEL numbers, Poland's national personal identification identifier. The scale of the claimed exposure places this among the largest healthcare data incidents reported in Europe this year.

What the attackers claim

The threat actors' decision to contact a journalist prior to any public disclosure is itself notable. That sequencing — attacker contact first, vendor announcement second — suggests the public statement was at least partially compelled by the prospect of imminent publication rather than by an independently initiated incident response timeline.

The claimed data set centers on PESEL numbers, which function in Poland similarly to Social Security numbers in the United States: a single identifier tied to an individual's civil records, usable for identity fraud, insurance fraud, and credential stuffing against health-adjacent financial accounts. If the claimed volume is verified, the breach would affect a significant share of Poland's total population of roughly 38 million.

MyDr's network spans clinics across the country, meaning the records at risk appear to originate from many distinct covered entities rather than a single facility — a pattern that amplifies downstream notification and remediation complexity.

Why this matters beyond Poland

Healthcare technology vendors that aggregate data across multiple provider clients represent a structurally elevated risk target. A single successful intrusion into a shared platform can yield records from dozens or hundreds of separate clinical sites, multiplying the impact far beyond what any individual clinic would hold.

That dynamic is not unique to Poland. US-based health IT platforms — practice management systems, electronic health records serving multiple independent practices, revenue cycle management vendors — operate on the same aggregation model. The MyDr incident is a current, concrete illustration of how a compromise at the platform layer propagates across the full client base simultaneously.

The incident also arrives as US regulators are actively tightening expectations around vendor risk management. The HHS proposed updates to the HIPAA Security Rule, published earlier this year, place new emphasis on business associate oversight, written risk assessments that address third-party technology dependencies, and documented incident response planning. Independent practices that have deferred formal vendor risk reviews have a narrowing window before those expectations carry enforcement weight.

What this signals for independent practices

Independent practices using shared health IT platforms should treat the MyDr incident as a prompt to examine their own vendor dependency picture. Key areas to assess:

The investigation is ongoing and MyDr has not confirmed the attackers' claims. Further detail is expected as the forensic review proceeds.