France’s data protection authority has imposed a €500,000 fine on Hôpital privé de la Loire after an investigation found that inadequate security measures contributed to a major breach of patient and third-party data.

 

 

Hôpital privé de la Loire is a general hospital in Saint-Étienne and part of the Ramsay Santé healthcare group. It provides medical, surgical, maternity, cancer, intensive-care, and emergency services. The hospital has 333 beds and treats approximately 60,000 patients each year.

The incident occurred during the summer of 2025, when an attacker gained access to the hospital’s computerized patient record system. According to France’s data protection authority, CNIL, the intruder accessed information belonging to 524,867 patients and another 202,246 people who had been designated by patients as trusted third parties.

CNIL subsequently investigated the breach and concluded that the hospital had failed to meet several obligations under the EU’s General Data Protection Regulation (GDPR).

One of the central problems involved remote access to the patient record system. External users, including independent doctors, could connect without a VPN or multi-factor authentication. CNIL determined that the attacker exploited this weakness to enter the system.

Access controls inside the platform were also considered insufficient. Permissions were not adequately restricted according to which healthcare professionals were actually involved in an individual’s treatment. As a result, credentials associated with a single user account provided the attacker with access to information covering the hospital’s entire patient population.

The investigation also found shortcomings in monitoring. The hospital did not have adequate mechanisms to quickly identify suspicious activity within its patient record system and generate alerts. This allowed the attacker to explore the environment for several days and extract a substantial amount of information before the activity was detected.

CNIL considered the number of affected people, sensitivity of the compromised information and deficiencies in basic security protections when determining the €500,000 penalty.

The regulator identified a separate GDPR violation involving how people were informed after the breach. Although affected patients received notifications, the 202,246 trusted third parties whose information had also been stolen were not directly notified.

CNIL concluded that this prevented those individuals from receiving information about the breach, its potential consequences, and measures they could take to reduce the risk of their information being misused.

The hospital has introduced several security improvements since the incident. CNIL has ordered it to finish implementing the required measures within deadlines ranging from three to 15 months, depending on the specific security control involved.

The €500,000 penalty was formally announced on September 3rd, 2026, with CNIL citing both inadequate protection of personal data and the failure to directly notify all affected individuals.

Leave a Reply