MyDr, described as one of Poland's largest healthcare system providers, announced on August 12 that it is investigating a serious security incident on its network. Threat actors who contacted the outlet DataBreaches.net ahead of the announcement claimed to have extracted data from numerous Polish clinics served by the platform, including 18,814,422 unique PESEL numbers — Poland's national identification number, functionally analogous to a Social Security number in the United States. The scale of the claimed exposure, if confirmed, would place this among the largest healthcare data incidents ever recorded in Europe.
What the attackers are claiming
The individuals who contacted DataBreaches.net said they held access to patient data spanning a large portion of MyDr's clinic network. The specific figure — more than 18.8 million unique national identifiers — is notable because PESEL numbers are permanent, government-issued, and tied to identity across healthcare, financial, and government services. Unlike passwords or payment card numbers, they cannot be changed, making their exposure a long-term identity-risk problem for affected individuals.
MyDr has confirmed only that an investigation is underway. No statement has yet been released on the scope of compromised data, the attack vector used, or the timeline of the intrusion.
Why US-based practices should pay attention
At first glance, a Polish healthcare incident may appear irrelevant to US compliance operations. Three factors argue otherwise.
- Shared vendor footprint. Healthcare technology platforms increasingly operate across borders or license software to organizations with international affiliates. US-based practices should verify whether any vendors in their supply chain have European operations or shared infrastructure that could be affected by a breach at a connected entity.
- Regulatory mirroring. The EU's GDPR and NIS2 Directive impose breach-notification timelines and security-baseline requirements that are influencing US state-level rulemaking. How MyDr responds — and how Polish and EU regulators treat the incident — will likely inform future arguments about adequate healthcare security standards on both sides of the Atlantic.
- Attack-pattern applicability. Threat actors who successfully extract patient records at scale from one national healthcare platform frequently reuse techniques against similar architectures elsewhere. The methods used here, once disclosed, warrant review against the access-control and network-segmentation practices of any healthcare system provider operating at comparable scale.
What the incident illustrates about platform-level risk
Healthcare system providers — vendors that supply scheduling, records, or clinical workflow tools to multiple independent clinics under a shared platform — create a concentration of patient data that makes them high-value targets. A single successful intrusion can expose records from dozens or hundreds of downstream clinical sites simultaneously, regardless of each clinic's individual security practices.
This is the same structural dynamic seen in several large US healthcare vendor breaches in recent years, where independent practices suffered patient-data exposure through a shared platform without any direct compromise of their own systems. Independent practices that rely on third-party platforms should confirm that their business associate agreements address breach notification timelines, require minimum-security controls at the platform level, and specify what audit-log access the practice retains in the event of a platform-side incident.
What this signals about the next 12 months
Large-scale exfiltration from healthcare platforms — rather than individual clinic systems — is an established pattern that shows no sign of slowing. Regulators in the US and EU are both moving toward holding platform vendors to explicit security baselines rather than relying on contractual pass-through from covered entities. Practices evaluating new platform vendors should treat evidence of the vendor's network-segmentation architecture, encryption practices, and incident-response testing as baseline due-diligence items, not optional disclosures.
The MyDr investigation is ongoing. Further technical detail on the attack vector is expected as Polish regulatory authorities become involved.