MyDr, described as one of Poland's largest healthcare system providers, announced it is investigating a serious security incident after threat actors reached out to security journalist Adam Haertle claiming access to patient data spanning numerous Polish clinics. The attackers say they obtained 18,814,422 unique PESEL numbers — Poland's national identification number, functionally equivalent to a US Social Security number combined with a date of birth — making this one of the largest healthcare data exposures reported in European history. The scale and structure of the incident carry direct lessons for US multi-site practice networks and healthcare technology aggregators.

What the attackers claim

The threat actors contacted Haertle proactively, a pattern increasingly common in extortion campaigns where public disclosure pressure is used as a negotiating lever before a ransom deadline. Their claim centers on PESEL numbers, which in the Polish system serve as the primary key linking a person's identity across healthcare, government, and financial services. Exposure of that identifier at scale is roughly analogous to a breach that simultaneously exposed patient names, dates of birth, and Social Security numbers across nearly half a country's population.

MyDr's public statement confirmed an investigation is underway but did not validate or dispute the specific figure cited by the attackers. That gap — between attacker claims and confirmed organizational facts — is typical at this stage of an incident and does not reduce the obligation to notify affected individuals once the scope is established.

The structural problem this illustrates

MyDr functions as an aggregated platform serving multiple independent clinics, not a single-site operator. That architecture — a central technology layer connecting dozens or hundreds of smaller practices — creates a single-compromise, multi-victim exposure profile. When the platform layer is breached, every clinic whose data flows through it is potentially affected regardless of the individual clinic's own security discipline.

US healthcare operates under an analogous model at significant scale. Regional health information exchanges, cloud-hosted EHR platforms, revenue cycle management aggregators, and multi-tenant patient engagement tools all concentrate data from independent practices into shared infrastructure. A breach at the platform level affects every downstream covered entity and their patients, even if no individual practice was directly targeted.

The MyDr incident is a concrete demonstration of why business associate agreements and vendor security assessments cannot be treated as one-time paperwork events. The risk profile of a platform vendor changes as that vendor grows, as it acquires new clinic customers, and as its data holdings expand — all factors that increase its attractiveness as an attack target.

What this signals for US multi-site and platform-dependent practices

The attacker's decision to go public before any confirmed ransom deadline suggests a calculated effort to maximize reputational and regulatory pressure. US practices should expect this pattern to continue: threat actors increasingly use media contacts and public disclosure as an independent tool, separate from any ransomware deployment. An incident does not have to involve encrypted systems to trigger HIPAA breach notification obligations — unauthorized access to protected health information is sufficient.

For practices that rely on a shared platform — whether a hosted EHR, a centralized scheduling system, or a multi-clinic analytics layer — several operational questions apply directly:

The MyDr investigation is ongoing. As scope and method are confirmed, the incident will likely serve as a reference case for how aggregated healthcare platforms manage — or fail to manage — the concentration risk that comes with scale.