Summary
- CNIL fined Hôpital Privé de la Loire €500,000 after an attacker accessed data relating to 524,867 patients.
- The regulator found weaknesses in remote authentication, access controls, near-real-time monitoring, and breach notification.
- The decision links cyber controls directly to GDPR accountability where sensitive health information is involved.
France’s privacy regulator has fined Hôpital Privé de la Loire €500,000 after finding that inadequate security controls contributed to a breach affecting hundreds of thousands of patients and their contacts.
The Commission nationale de l’informatique et des libertés, or CNIL, said an attacker gained access to the hospital’s computerised patient record system during the summer of 2025. The system centralised information about people receiving care at the Saint-Étienne hospital.
The attacker accessed data relating to 524,867 patients, including health information in some cases, as well as 202,246 people identified by patients as trusted third parties.
CNIL’s subsequent investigation found infringements of both Article 32 of the General Data Protection Regulation, which requires appropriate security of personal data, and Article 34, which governs communication of certain personal-data breaches to affected people.
One of the central findings concerned remote authentication. External users, including independent doctors, could connect to the patient system without a virtual private network or multifactor authentication. CNIL said the attacker exploited this weakness to gain access to the data.
The regulator also found that the hospital’s access-control policy did not adequately apply the concept of a patient’s care team. Credentials for one user account consequently provided access to information covering the hospital’s entire patient population rather than only records connected to that professional’s work.
A further weakness concerned monitoring. CNIL said the hospital lacked measures capable of detecting suspicious activity within the patient system in real time or very shortly afterwards and triggering an alert. The attacker was able to explore the environment over several days and extract a large volume of information without the activity being detected.
The enforcement decision shows how regulatory scrutiny after a cyber incident can move beyond whether an organisation had a security product or written policy. The assessment centred on whether controls were appropriate to the sensitivity and scale of the information being processed, and whether they limited the consequences of a compromised account.
Healthcare systems expose that distinction particularly clearly. Medical records combine sensitive clinical information with identity and contact data, while access must remain available to a broad and changing group of professionals. Weak identity boundaries can therefore turn the compromise of one account into access across a much larger population.
The sanction also addresses the period after the breach. CNIL said affected patients were informed, but the 202,246 trusted third parties whose information had also been stolen did not receive direct notification. The regulator concluded that the omission deprived them of information needed to understand the nature and likely consequences of the attack.
Incident response is therefore not complete when systems have been contained or when the most obvious class of affected people has been contacted. Organisations handling interconnected records must establish whose information appears in a compromised dataset, including people who may not have had a direct service relationship with the organisation itself.
CNIL said it took the number of people affected, the nature of the information, the security shortcomings, and the hospital’s financial capacity into account when setting the €500,000 penalty. It also recognised that the hospital strengthened several controls during the regulatory process.
The hospital has been ordered to complete the remaining improvements within periods ranging from three to 15 months. The case leaves it with both a financial penalty and a formal requirement to finish correcting the controls that failed to contain the original intrusion.





