A major security incident at MyDr, one of Poland's largest healthcare system providers, has exposed the risk concentrated in centralized clinic networks after attackers claimed to have extracted 18,814,422 unique PESEL numbers — Poland's national personal identification numbers, functionally equivalent to Social Security numbers in the US context. The alleged perpetrators contacted journalist Adam Haertle directly before MyDr's public disclosure, a sequencing that limits the provider's ability to control the narrative or coordinate patient notification. The incident illustrates a pattern that US healthcare operators should recognize: large aggregators of patient identity data across multiple clinic sites represent a single point of failure for the entire patient population they serve.
The structural problem with centralized clinic networks
MyDr operates as a shared infrastructure platform for numerous Polish clinics, meaning that a breach of the central network exposes patient data from every facility plugged into it — regardless of whether any individual clinic was targeted or even aware of the compromise. That architecture mirrors how many US regional health information exchanges, practice management platforms, and EHR hosting environments are structured.
When a vendor or network operator holds data on behalf of dozens or hundreds of independent practices, the attack surface belongs to the aggregator, not to the individual practice. US independent practices that rely on a third-party platform for scheduling, billing, or clinical records often have limited visibility into the security controls that platform applies to their patients' data.
What the attacker contact pattern reveals
The alleged perpetrators reaching out to a journalist before the organization's formal disclosure is not incidental. It is a pressure tactic designed to accelerate ransom negotiations or maximize reputational damage, and it removes the breached organization's window to assess scope before going public. This pattern has appeared in US healthcare incidents as well, including attacks where threat actors post samples of stolen data to dark-web forums to validate their claims.
For compliance officers, the lesson is procedural: incident response plans should account for the possibility that external parties — journalists, regulators, or patients — will learn of a breach before the internal investigation is complete. Disclosure timelines, holding statements, and patient notification drafts should be prepared before an incident occurs, not during one.
Where this lands for US practices with third-party dependencies
The HIPAA Security Rule requires covered entities and business associates to conduct periodic risk analyses that account for the security practices of third parties handling protected health information. A breach of a platform vendor in another country does not trigger US notification obligations directly, but the structural scenario is identical to risks US practices carry today.
Key questions independent practices should be asking of their platform vendors:
- Segmentation controls. Are patient records from individual practices logically or physically isolated from those of other clients on the same platform, or does a single credential compromise expose all of them?
- Breach notification SLAs. What contractual obligation does the vendor have to notify a covered entity, and within what timeframe, if the vendor's own infrastructure is compromised?
- Third-party audit evidence. Has the vendor produced a recent SOC 2 Type II report or equivalent attestation, and does it cover the specific systems that hold patient data?
- Incident response rehearsal. Has the practice participated in a tabletop exercise that includes a scenario where the breach originates at the vendor, not internally?
What this signals about the next 12 months
Healthcare aggregators — whether cloud-hosted EHR platforms, RCM clearinghouses, or regional HIEs — will continue to attract sophisticated adversaries precisely because they concentrate patient identity data at scale. The economics favor the attacker: one successful intrusion yields records from hundreds of facilities simultaneously.
US regulators have signaled awareness of this dynamic. The HHS Office for Civil Rights has proposed updates to the HIPAA Security Rule that would impose more prescriptive controls on risk analysis and access management, with particular attention to third-party relationships. Whether or not those rule changes are finalized on their current timeline, the MyDr incident demonstrates that the underlying risk is not theoretical.