A major security incident at MyDr, a Polish healthcare management system provider serving numerous clinics, has drawn attention to the scale of exposure possible when a single healthcare technology intermediary is compromised. The alleged attackers contacted journalist Adam Haertle before the company's disclosure, claiming access to 18,814,422 unique PESEL numbers — Poland's national identification system, broadly analogous to Social Security numbers in the United States. MyDr confirmed it is investigating a serious incident on its network.

The structural problem

The MyDr situation illustrates a risk pattern that US compliance officers and practice administrators recognize: a healthcare technology vendor that aggregates patient records across many clinical sites becomes a single point of failure for all of them. When an attacker gains access to a platform provider rather than an individual practice, the blast radius scales with the vendor's customer base, not with any one organization's patient panel.

Poland's PESEL numbers are national identifiers used across healthcare, financial, and government systems, making their exposure a multi-sector harm. The US equivalent scenario — a breach exposing Social Security numbers alongside clinical data at an EHR or revenue cycle management vendor — carries a comparable harm profile and has materialized repeatedly in recent years.

What the attack sequence suggests

Threat actors contacting a journalist before the vendor's own public disclosure is a coercive tactic increasingly documented in healthcare-targeted attacks. The approach serves several goals simultaneously: it generates reputational pressure on the victim organization, establishes a public proof-of-access claim, and can complicate the victim's ability to control the narrative around notification timelines.

This sequencing — attacker disclosure before organizational disclosure — creates specific compliance complications for US-covered entities and business associates. Under the HIPAA Breach Notification Rule, covered entities have 60 days from discovery to notify affected individuals, but discovery can be triggered by third-party or media reporting, not only by internal detection. Practices that learn of a vendor incident through press coverage rather than vendor notification face an ambiguous clock.

Where this lands for US practices with international vendor footprints

MyDr operates in Poland, but the incident carries direct relevance for US healthcare organizations on two vectors. First, several healthcare technology platforms sold in the US maintain development, hosting, or data processing operations in European jurisdictions, meaning a breach in one geography can involve US patient data. Second, US-based multi-site clinic operators and health systems increasingly use internationally developed practice management or imaging software, sometimes without a complete map of where that software processes or stores data.

Business associate agreements are required under HIPAA when a vendor handles protected health information on behalf of a covered entity, but those agreements are only enforceable if the covered entity knows which vendors are in scope. A vendor with a non-US headquarters that also holds US patient data may fall into a compliance blind spot if procurement and legal teams did not document the data flow at the time of contracting.

What this signals about the next 12 months

Large-scale incidents at healthcare platform providers — whether in the US or abroad — continue to attract threat actors who recognize that clinical data aggregators offer a higher return per intrusion than single-site targets. The MyDr incident follows a well-established pattern: extortion or data-sale leverage derived from national-scale patient identifier exposure.

For US independent practices, the operational question is whether vendor risk reviews account for the full geography of data handling, not only whether a business associate agreement exists. Inventory of third-party integrations, contractual data-residency clauses, and incident-notification SLAs are the controls most directly tested when a platform-level event like this one occurs. Practices that have not reviewed those agreements since initial contracting are likely operating with outdated terms that do not reflect current regulatory expectations or the scale of harm that platform-level compromises now routinely produce.