MyDr, a clinic management and patient-records platform serving a broad network of Polish healthcare providers, disclosed on August 12 that it is investigating a serious security incident on its network. Threat actors who contacted reporters before the public announcement claimed to hold 18,814,422 unique PESEL numbers — Poland's equivalent of a national patient identifier — extracted from the systems of numerous clinics that rely on MyDr's platform. If the claim is substantiated, the breach would rank among the largest healthcare data exposures in European history and carries direct lessons for US practices that depend on centralized health information platforms.
The structural problem
MyDr's situation illustrates a risk pattern that recurs across every market where clinic networks consolidate on a shared technology platform: a single successful intrusion into the platform layer can expose records across dozens or hundreds of independent provider organizations simultaneously. Each clinic's patients had no individual point of failure on their own premises. The failure occurred upstream, at the software or infrastructure layer the clinics shared.
US healthcare operates with a structurally similar dependency. Independent practices, specialty groups, and community health centers frequently run their scheduling, billing, and clinical records through a handful of dominant cloud-hosted platforms. When those platforms are compromised, the downstream exposure can dwarf what any individual practice could generate on its own.
What the attackers' timeline suggests
The detail that attackers contacted journalists before MyDr made a public announcement is not incidental. It indicates the threat actors had already completed data extraction and moved into an extortion or publicity phase before the organization had finished determining the scope of the incident. This sequencing — attacker disclosure preceding organizational disclosure — has become a deliberate tactic designed to pressure victims into faster ransom payment and to undermine confidence in the provider's incident response.
For compliance officers, the practical consequence is that relying on internal discovery timelines to manage public communication is no longer a reliable strategy. Attackers increasingly control the information release clock, not the affected organization.
The PESEL identifier dimension
PESEL numbers function in Poland much as Social Security numbers do in the United States — they are durable, government-issued identifiers that cannot be easily changed after exposure. In a healthcare context, the combination of a national identifier with clinical or demographic data creates a long-lived fraud and identity-theft risk for affected individuals. The US parallel is the pairing of Social Security numbers with dates of birth and insurance identifiers, all of which regularly appear in healthcare databases.
This category of identifier exposure is qualitatively different from a breach of contact information alone. It creates downstream liability for affected providers and, in the US context, triggers specific HIPAA breach notification requirements and potential FTC scrutiny when secondary harm to patients can be demonstrated.
What this signals for US practice administrators
The MyDr incident does not require a US regulatory hook to be instructive. Several implications are directly transferable:
- Third-party platform risk reviews. Practices should confirm that their business associate agreements with platform vendors specify breach notification timelines, right-to-audit provisions, and minimum security control requirements — not just data-use limitations.
- Segmentation of patient identifier data. Where platform architecture allows, national or government-issued identifiers should be stored in segregated data environments with narrower access controls than general demographic fields.
- Incident response plan coordination. If a shared platform is breached, individual practices may need to activate their own notification procedures independent of the platform vendor's timeline. Plans should account for the scenario in which the vendor is slow, contested, or silent.
- Monitoring attacker-side disclosure channels. Security and compliance teams increasingly need awareness of threat-actor communication channels — forums, journalist tip lines, dark-web postings — as an early-warning input, not just internal log monitoring.
The MyDr investigation is ongoing and the full scope of compromised data has not been confirmed. Polish data protection authorities have not yet made a public statement. The case will be worth tracking as details emerge, both for the technical specifics of how the intrusion succeeded and for how regulators respond when a platform-level breach cascades across a large provider network.