MyDr, described as one of Poland's largest healthcare system providers, confirmed it is investigating a serious security incident after threat actors contacted journalists and claimed to hold patient data from numerous Polish clinics. The attackers alleged access to 18,814,422 unique PESEL numbers — Poland's national personal identification numbers, which function similarly to Social Security numbers in the United States and carry lifelong identity-verification significance. The scale of the claimed exposure, if confirmed, would place this among the largest healthcare data breaches recorded in Europe.

What the attackers claimed

The threat actors reached out to journalist Adam Haertle before MyDr made any public disclosure, a sequencing that has become common in extortion-oriented intrusions. By contacting the press first, attackers create reputational pressure independent of any ransom negotiation — a tactic observed repeatedly against hospital systems and health-plan administrators in the United States over the past three years.

The specific claim centers on PESEL numbers, not merely contact or billing records. Because PESEL numbers are used across healthcare, banking, tax administration, and government services, their exposure creates downstream fraud risk that extends well beyond the healthcare context — a characteristic shared with Social Security number exposure in US breach scenarios.

MyDr's network serves multiple clinics, meaning the affected population may span dozens of separate care sites that share a common infrastructure layer. That aggregation model — a single platform carrying data from many independent practices — concentrates risk in ways that individual clinic operators may not fully appreciate until an incident occurs.

The US-relevant pattern

US healthcare operators are not directly exposed to this incident, but the structural dynamics mirror conditions common to American group-practice management systems, revenue cycle platforms, and EHR hosting arrangements. A single vendor compromise that propagates across hundreds of client organizations is the same threat model behind several major US healthcare breaches in recent years.

The PESEL-exposure dimension has a direct analogue in US regulatory terms. OCR guidance treats Social Security numbers as among the most sensitive categories of protected health information when combined with clinical data, because the combination enables both identity fraud and targeted medical fraud. A breach that yields national ID numbers alongside patient records from clinical settings carries the same compounded risk profile.

For practices that rely on shared infrastructure — whether a cloud-hosted EHR, a centralized billing platform, or a regional health information exchange — this incident illustrates that the blast radius of a vendor-side compromise is determined by the vendor's footprint, not by any individual practice's security controls.

What independent practices should check

The MyDr incident is an opportunity for practice administrators to re-examine their vendor risk documentation before a comparable event forces the question.

What this signals about the next 12 months

Threat actors have demonstrated consistent interest in healthcare aggregation platforms precisely because they offer high data yields per intrusion. The MyDr incident follows a pattern in which attackers target the infrastructure layer shared across many organizations rather than attacking individual targets one at a time. US regulators, including OCR, have signaled increasing attention to vendor risk management as a component of the HIPAA Security Rule's required risk analysis process. The proposed Security Rule updates circulating within HHS in recent years would make vendor oversight obligations more explicit. Practices that treat vendor risk as a documentation formality rather than an active control discipline are likely to find that standard increasingly difficult to defend in the event of a third-party-originating breach.