MyDr, described as one of Poland's largest healthcare system providers, confirmed it is investigating a serious security incident after threat actors contacted journalists and claimed to hold patient data from numerous Polish clinics. The attackers alleged access to 18,814,422 unique PESEL numbers — Poland's national personal identification numbers, which function similarly to Social Security numbers in the United States and carry lifelong identity-verification significance. The scale of the claimed exposure, if confirmed, would place this among the largest healthcare data breaches recorded in Europe.
What the attackers claimed
The threat actors reached out to journalist Adam Haertle before MyDr made any public disclosure, a sequencing that has become common in extortion-oriented intrusions. By contacting the press first, attackers create reputational pressure independent of any ransom negotiation — a tactic observed repeatedly against hospital systems and health-plan administrators in the United States over the past three years.
The specific claim centers on PESEL numbers, not merely contact or billing records. Because PESEL numbers are used across healthcare, banking, tax administration, and government services, their exposure creates downstream fraud risk that extends well beyond the healthcare context — a characteristic shared with Social Security number exposure in US breach scenarios.
MyDr's network serves multiple clinics, meaning the affected population may span dozens of separate care sites that share a common infrastructure layer. That aggregation model — a single platform carrying data from many independent practices — concentrates risk in ways that individual clinic operators may not fully appreciate until an incident occurs.
The US-relevant pattern
US healthcare operators are not directly exposed to this incident, but the structural dynamics mirror conditions common to American group-practice management systems, revenue cycle platforms, and EHR hosting arrangements. A single vendor compromise that propagates across hundreds of client organizations is the same threat model behind several major US healthcare breaches in recent years.
The PESEL-exposure dimension has a direct analogue in US regulatory terms. OCR guidance treats Social Security numbers as among the most sensitive categories of protected health information when combined with clinical data, because the combination enables both identity fraud and targeted medical fraud. A breach that yields national ID numbers alongside patient records from clinical settings carries the same compounded risk profile.
For practices that rely on shared infrastructure — whether a cloud-hosted EHR, a centralized billing platform, or a regional health information exchange — this incident illustrates that the blast radius of a vendor-side compromise is determined by the vendor's footprint, not by any individual practice's security controls.
What independent practices should check
The MyDr incident is an opportunity for practice administrators to re-examine their vendor risk documentation before a comparable event forces the question.
- Business associate agreements and subcontractor chains. Verify that all platform vendors serving your practice have executed current BAAs and that those agreements address subprocessors who may themselves hold patient data. A breach at a sub-vendor may still trigger your notification obligations.
- Data minimization at the platform level. Confirm what data your practice is transmitting to shared platforms and whether all fields transmitted are operationally necessary. Unnecessary data sent upstream becomes unnecessary exposure in a vendor compromise.
- Incident notification timelines in vendor contracts. Review whether your agreements require the vendor to notify your practice of a suspected incident within a defined window — and whether that window is short enough to meet HHS's 60-day breach notification rule if PHI is involved.
- Concentration risk assessment. If a single vendor holds records from every patient your practice has treated over multiple years, the potential notification burden from a vendor-side breach is the same as if your own systems were compromised. That exposure should be factored into vendor selection and contract terms.
What this signals about the next 12 months
Threat actors have demonstrated consistent interest in healthcare aggregation platforms precisely because they offer high data yields per intrusion. The MyDr incident follows a pattern in which attackers target the infrastructure layer shared across many organizations rather than attacking individual targets one at a time. US regulators, including OCR, have signaled increasing attention to vendor risk management as a component of the HIPAA Security Rule's required risk analysis process. The proposed Security Rule updates circulating within HHS in recent years would make vendor oversight obligations more explicit. Practices that treat vendor risk as a documentation formality rather than an active control discipline are likely to find that standard increasingly difficult to defend in the event of a third-party-originating breach.