MyDr, described as one of Poland's largest healthcare system providers, announced on August 12 that it is investigating a serious security incident on its network. Threat actors contacted security journalist Adam Haertle before the disclosure and claimed to have obtained records containing 18,814,422 unique PESEL numbers — Poland's national personal identification numbers, which function similarly to Social Security numbers in the US — drawn from patient data across numerous Polish clinics. The incident draws attention to the systemic exposure that emerges when a single platform aggregates records from many independent care sites.
The structural problem
Healthcare aggregators and multi-clinic software platforms concentrate patient records from dozens or hundreds of care sites into a shared infrastructure. That architecture creates efficiency for participating practices, but it also means a single successful intrusion can expose patients from facilities that individually maintain adequate controls. The MyDr incident illustrates how a breach at the platform layer bypasses protections that individual clinics may have in place at their own sites.
PESEL numbers carry particular sensitivity because they are used across healthcare, banking, and government services in Poland. Exposure of a PESEL number at scale enables identity fraud well beyond the healthcare context, a pattern that parallels the downstream risk when US Social Security numbers appear in healthcare breach datasets.
The international relevance for US practices
US healthcare operators may view a Polish incident as a distant concern, but several factors make it directly relevant.
- Vendor footprint: Healthcare software vendors increasingly operate across borders or maintain shared development and hosting infrastructure. A breach affecting a platform's European operations can reveal architectural weaknesses present in the same vendor's US-facing products.
- Regulatory mirroring: The EU's General Data Protection Regulation and the NIS2 Directive impose breach-notification and security-baseline requirements that increasingly parallel HIPAA Security Rule expectations. How regulators respond to the MyDr incident will signal enforcement appetite that often influences OCR and HHS policy discussions.
- Threat actor overlap: The groups targeting European healthcare networks are frequently the same ransomware and data-extortion operators active against US hospitals and clinics. Tactics validated in one market migrate rapidly.
What this signals for aggregated-data environments
Independent practices that participate in shared EHR platforms, regional health information exchanges, or third-party patient management systems carry inherited risk from those platforms' security disciplines. Several control gaps commonly appear in post-incident analyses of aggregator breaches.
- Insufficient network segmentation: When clinic data is co-mingled at the storage or application layer, lateral movement within the platform reaches records from all participating sites simultaneously.
- Weak contractual security obligations: Business associate agreements and vendor contracts that lack specific security baseline requirements, audit rights, and breach-notification timelines leave practices with limited recourse and delayed awareness.
- Delayed detection: In many aggregator incidents, the platform operator learns of the breach from external researchers or the threat actors themselves rather than from internal monitoring — a pattern that extends the window during which patient data remains accessible.
What independent practices should examine now
Practices operating inside shared or hosted platforms should confirm, at minimum, that their vendor agreements include defined incident-notification timelines, that they receive timely communication when the platform detects anomalous access, and that they understand which patient data fields are replicated or accessible at the platform level versus retained only locally. Reviewing third-party risk management documentation and verifying that vendors carry current security certifications are baseline steps that apply regardless of geography.
The MyDr investigation is ongoing. As details emerge, the incident is likely to inform EU regulatory guidance on platform-level healthcare security requirements — guidance that US compliance officers tracking international developments will want to monitor.