French hospital fined €500,000 after a breach exposed data on 727,000 people

French hospital fined €500,000 after a breach exposed data on 727,000 people

French hospital fined €500,000 after a breach exposed data on 727,000 people

The French Data Protection Agency (CNIL) has fined the Hôpital privé de la Loire 500,000 euros ($580,000) for failing to adequately protect the data of patients and their relatives.

According to the French authority, the security deficiencies led to a data breach in the summer of 2025 that exposed sensitive data of 524,867 patients and an additional 202,246 people classified as trusted third parties.

The Hôpital Privé de la Loire (HPL) is a general hospital in Saint-Étienne, part of the Ramsay Santé healthcare group, offering medical, surgical, maternity, cancer, intensive care and emergency services.

The hospital employs 650 people, including 180 doctors, and has 333 beds in five clinical departments, including: reported 60,000 patients annually.

Last year, an attacker accessed the hospital’s electronic medical records system and extracted sensitive data from more than 727,000 people who were treated at HPL, accompanied patients there or helped them in some way.

Following the incident, the CNIL conducted an investigation which found several breaches by the hospital of its obligations under the General Data Protection Regulation (GDPR).

The deficiencies identified by the CNIL during its investigation include, among others:

  • External users, including practicing physicians, could access the system without a VPN or multi-factor authentication.
  • Due to inadequate access controls, the compromised account was able to access the records of all hospital patients.
  • The hospital lacked real-time or near real-time monitoring and alerting, allowing the attacker to explore the system and extract large amounts of data over several days without being detected.
  • The hospital notified affected patients but did not directly notify the 202,246 trusted third parties whose data was also stolen.

The violations mentioned above refer to Art. 32 and Art. 34 GDPR. The Committee also noted that HPL took several security-enhancing measures during the procedure.

A teenage hacker using the pseudonym “Marak” claimed responsibility and contacted the French outlet Progress on Telegram at the time, saying the attack began with a violation of a Individual doctor accountwhich provided access to HPL’s entire internal system.

However, the hacker attempted to sell the stolen data to a single buyer for a price between 2,000 and 5,000 euros it was reported later that the data was neither sold nor published.


Item image

Overall prevention scores can hide what happens after the first access. Once attackers use valid credentials, prevention drops sharply.

The 2026 Blue Report measures defense technology for technology in 338 million simulations conducted in customer production environments.

Get the report

Leave a Reply

Your email address will not be published. Required fields are marked *