A major breach at MyDr, a Polish healthcare platform serving numerous clinics, is drawing attention across the industry after the alleged attackers contacted journalists directly to claim access to 18,814,422 unique PESEL numbers — Poland's national identification system, analogous to Social Security numbers in the United States. MyDr confirmed it is investigating a serious security incident on its network. The scale of the claimed exposure, if verified, would place this among the largest healthcare data compromises in European history and carries direct lessons for US-based independent practices operating multi-clinic or federated health IT platforms.

The structural problem

Healthcare platforms that aggregate patient records across many affiliated clinics create a single point of failure that amplifies breach impact far beyond what any individual practice could generate on its own. MyDr's model — serving numerous Polish clinics through a shared infrastructure — mirrors the vendor-consolidation trend common in the United States, where independent practices increasingly route scheduling, records, and billing through centralized cloud platforms.

When that central infrastructure is compromised, every affiliated clinic's patient population is exposed simultaneously. The attacker's claimed figure of nearly 19 million unique identifiers suggests the breach was not limited to one clinic's dataset but pulled from an aggregated pool, which is precisely the risk that regulators and security researchers have flagged about multi-tenant healthcare platforms.

What the attacker behavior signals

The threat actors in this incident chose to contact a journalist before — or alongside — any ransom demand or public disclosure, a tactic increasingly used to pressure organizations into faster payment by demonstrating the credibility of their access. This approach bypasses the period of quiet negotiation that many organizations rely on to assess and contain incidents before public exposure.

This pattern has appeared in several high-profile US healthcare incidents and changes the calculus for breach response teams. Detection-to-disclosure timelines that assume a private negotiation window may no longer hold. Organizations that have not rehearsed a scenario in which a threat actor independently publicizes an intrusion should treat this as a gap in incident response planning.

The US-relevance of a European healthcare breach

PESEL numbers function similarly to Social Security numbers, making their exposure a template for understanding what large-scale national-identifier theft looks like in a healthcare context. US practices should note that:

What independent practices should examine now

The MyDr incident reinforces a pattern that appears repeatedly in large healthcare breaches: centralized platforms with broad clinic-level access and inadequate segmentation between client data environments. Independent practices evaluating or currently using shared health IT platforms should ask vendors specifically how patient data is isolated between clients, what monitoring exists for anomalous cross-client data access, and what the vendor's public disclosure obligations are if their infrastructure — rather than a single client — is the source of an incident.

Contractual business associate agreements in the US context should address these scenarios explicitly. A breach originating at a vendor's infrastructure layer still triggers covered-entity notification requirements under HIPAA, and "we didn't know until the hacker contacted a reporter" is not a defense that satisfies the 60-day breach notification clock.