France’s data protection authority has fined Hôpital privé de la Loire €500,000 after a data breach exposed sensitive information belonging to more than 727,000 people.

The French hospital data breach affected 524,867 patients and 202,246 people listed as trusted third parties. The CNIL found that the hospital failed to implement adequate safeguards for the data.

Breach exposed data from hundreds of thousands

The incident occurred during the summer of 2025 after an attacker gained access to the hospital’s electronic patient record system.

Hôpital privé de la Loire is a general hospital in Saint-Étienne and part of the Ramsay Santé healthcare group. It provides medical, surgical, maternity, cancer, intensive-care and emergency services.

The attacker extracted sensitive data from people who had received care at the hospital, accompanied patients or otherwise assisted them.

CNIL identifies major security failures

The CNIL investigation found several GDPR compliance failures behind the French hospital data breach.

External users, including private-practice doctors, could access the system without a virtual private network or multi-factor authentication. In addition, weak access controls allowed a compromised account to view records for all hospital patients.

The regulator also found that the hospital lacked real-time or near-real-time monitoring. As a result, the attacker could explore the system and extract a large volume of data over several days without detection.

The hospital informed affected patients about the breach. However, it did not directly notify the 202,246 trusted third parties whose data was also stolen.

Hospital strengthened its security measures

The CNIL said Hôpital privé de la Loire introduced several security improvements during the enforcement process. Nevertheless, the regulator concluded that the organisation had breached its obligations under Articles 32 and 34 of the GDPR.

A teenage hacker using the alias “Marak” claimed responsibility for the attack. The attacker allegedly gained initial access through a single doctor’s account, which provided access to the hospital’s internal system.

The attacker reportedly tried to sell the stolen data for between €2,000 and €5,000. Later reports indicated that the data was neither sold nor published.


0 responses to “French Hospital Fined €500,000 Over Data Breach”