MyDr, described as one of Poland's largest healthcare system providers, announced on August 12 that it is investigating a serious security incident on its network. Threat actors contacted security journalist Adam Haertle before the disclosure and claimed to have obtained records containing 18,814,422 unique PESEL numbers — Poland's national personal identification numbers, which function similarly to Social Security numbers in the US — drawn from patient data across numerous Polish clinics. The incident draws attention to the systemic exposure that emerges when a single platform aggregates records from many independent care sites.

The structural problem

Healthcare aggregators and multi-clinic software platforms concentrate patient records from dozens or hundreds of care sites into a shared infrastructure. That architecture creates efficiency for participating practices, but it also means a single successful intrusion can expose patients from facilities that individually maintain adequate controls. The MyDr incident illustrates how a breach at the platform layer bypasses protections that individual clinics may have in place at their own sites.

PESEL numbers carry particular sensitivity because they are used across healthcare, banking, and government services in Poland. Exposure of a PESEL number at scale enables identity fraud well beyond the healthcare context, a pattern that parallels the downstream risk when US Social Security numbers appear in healthcare breach datasets.

The international relevance for US practices

US healthcare operators may view a Polish incident as a distant concern, but several factors make it directly relevant.

What this signals for aggregated-data environments

Independent practices that participate in shared EHR platforms, regional health information exchanges, or third-party patient management systems carry inherited risk from those platforms' security disciplines. Several control gaps commonly appear in post-incident analyses of aggregator breaches.

What independent practices should examine now

Practices operating inside shared or hosted platforms should confirm, at minimum, that their vendor agreements include defined incident-notification timelines, that they receive timely communication when the platform detects anomalous access, and that they understand which patient data fields are replicated or accessible at the platform level versus retained only locally. Reviewing third-party risk management documentation and verifying that vendors carry current security certifications are baseline steps that apply regardless of geography.

The MyDr investigation is ongoing. As details emerge, the incident is likely to inform EU regulatory guidance on platform-level healthcare security requirements — guidance that US compliance officers tracking international developments will want to monitor.