A major security incident at MyDr, one of Poland's largest healthcare system providers, has exposed the risk concentrated in centralized clinic networks after attackers claimed to have extracted 18,814,422 unique PESEL numbers — Poland's national personal identification numbers, functionally equivalent to Social Security numbers in the US context. The alleged perpetrators contacted journalist Adam Haertle directly before MyDr's public disclosure, a sequencing that limits the provider's ability to control the narrative or coordinate patient notification. The incident illustrates a pattern that US healthcare operators should recognize: large aggregators of patient identity data across multiple clinic sites represent a single point of failure for the entire patient population they serve.

The structural problem with centralized clinic networks

MyDr operates as a shared infrastructure platform for numerous Polish clinics, meaning that a breach of the central network exposes patient data from every facility plugged into it — regardless of whether any individual clinic was targeted or even aware of the compromise. That architecture mirrors how many US regional health information exchanges, practice management platforms, and EHR hosting environments are structured.

When a vendor or network operator holds data on behalf of dozens or hundreds of independent practices, the attack surface belongs to the aggregator, not to the individual practice. US independent practices that rely on a third-party platform for scheduling, billing, or clinical records often have limited visibility into the security controls that platform applies to their patients' data.

What the attacker contact pattern reveals

The alleged perpetrators reaching out to a journalist before the organization's formal disclosure is not incidental. It is a pressure tactic designed to accelerate ransom negotiations or maximize reputational damage, and it removes the breached organization's window to assess scope before going public. This pattern has appeared in US healthcare incidents as well, including attacks where threat actors post samples of stolen data to dark-web forums to validate their claims.

For compliance officers, the lesson is procedural: incident response plans should account for the possibility that external parties — journalists, regulators, or patients — will learn of a breach before the internal investigation is complete. Disclosure timelines, holding statements, and patient notification drafts should be prepared before an incident occurs, not during one.

Where this lands for US practices with third-party dependencies

The HIPAA Security Rule requires covered entities and business associates to conduct periodic risk analyses that account for the security practices of third parties handling protected health information. A breach of a platform vendor in another country does not trigger US notification obligations directly, but the structural scenario is identical to risks US practices carry today.

Key questions independent practices should be asking of their platform vendors:

What this signals about the next 12 months

Healthcare aggregators — whether cloud-hosted EHR platforms, RCM clearinghouses, or regional HIEs — will continue to attract sophisticated adversaries precisely because they concentrate patient identity data at scale. The economics favor the attacker: one successful intrusion yields records from hundreds of facilities simultaneously.

US regulators have signaled awareness of this dynamic. The HHS Office for Civil Rights has proposed updates to the HIPAA Security Rule that would impose more prescriptive controls on risk analysis and access management, with particular attention to third-party relationships. Whether or not those rule changes are finalized on their current timeline, the MyDr incident demonstrates that the underlying risk is not theoretical.