Breaking
Cyber CrimeDeveloping Story

French hospital fined €500,000 after breach exposes data of 727,000

CNIL fines Hôpital privé de la Loire for security failures that led to a breach exposing data of over 727,000 people.

··1 hour ago·3 min read
a man in scrubs and a stethoscope looking at a monitor
Photo by César Badilla Miranda on Unsplash

The French data protection authority has imposed a €500,000 fine on a hospital in Saint-Étienne after an investigation found that weak security practices allowed an attacker to steal sensitive data belonging to more than 727,000 patients and their relatives. The penalty, announced by the Commission Nationale de l'Informatique et des Libertés (CNIL), highlights the consequences of failing to protect health data under the General Data Protection Regulation (GDPR).

A breach that exposed hundreds of thousands

Hôpital privé de la Loire (HPL), a general hospital that is part of the Ramsay Santé healthcare group, came under attack in the summer of 2025. The intruder broke into the hospital's electronic patient record system and extracted sensitive data of more than 727,000 people who had received care at HPL, escorted patients there, or helped them in some way.

The breach affected 524,867 patients and 202,246 individuals designated as trusted third parties.

CNIL investigation reveals multiple GDPR violations

Following the incident, the CNIL conducted an investigation, which identified several failures to comply with the hospital's obligations under the General Data Protection Regulation (GDPR). The agency concluded that HPL had not adequately protected the data it was entrusted with, leading to the breach.

The violations relate to Article 32 and Article 34 of the GDPR, which concern the security of processing and communication of a personal data breach to the data subject.

Security shortcomings behind the breach

The CNIL's investigation pinpointed specific deficiencies in the hospital's security measures. Among the most critical was that external users, including private-practice physicians, could access the system without a VPN or multi-factor authentication.

Inadequate access controls allowed the compromised account to access records for all hospital patients, not just a limited set. The hospital also lacked real-time or near-real-time monitoring and alerting, which allowed the attacker to explore the system and extract a large volume of data over several days without detection.

The hospital informed affected patients of the breach, but it did not directly notify the 202,246 trusted third parties whose data was also stolen.

Hacker claimed responsibility

A teen hacker using the alias “Marak” claimed responsibility for the attack. Marak contacted the French outlet Le Progrès over Telegram at the time and said the attack began with a breach of a single doctor’s account, which allowed access to HPL’s entire internal system.

The hacker attempted to sell the stolen data to a single buyer for a price between €2,000 and €5,000, although it was later reported that the data was neither sold nor published.

Response and mitigation efforts

The committee also noted that HPL took several security strengthening measures during the proceedings. The hospital, which employs a staff of 650, including 180 doctors, and has 333 beds across five clinical divisions, with a reported 60,000 patients yearly, has been working to address the identified vulnerabilities.

Key facts and figures

  • €500,000 ($580,000) fine imposed by the CNIL
  • 727,000+ people affected in the breach
  • 524,867 patients' data exposed
  • 202,246 trusted third parties' data exposed
  • Attack occurred in summer 2025
  • Hacker claimed to have breached a single doctor's account
  • Stolen data offered for €2,000 to €5,000

Why it matters for healthcare organizations

This case serves as a stark reminder that healthcare institutions, which handle highly sensitive personal data, must implement robust security measures, including multi-factor authentication, strict access controls, and continuous monitoring. The CNIL's decision underscores the regulatory consequences of failing to meet GDPR standards.

#data-breach#cnil#gdpr#healthcare#france#hospital

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories