French privacy regulator fines hospital €500,000 over 2025 patient-data breach

France’s data protection regulator has imposed a €500,000 fine on Hôpital privé de la Loire (HPL), finding that weaknesses in its security controls contributed to a 2025 breach involving highly sensit...

France’s data protection regulator has imposed a €500,000 fine on Hôpital privé de la Loire (HPL), finding that weaknesses in its security controls contributed to a 2025 breach involving highly sensitive healthcare information.

The Commission nationale de l’informatique et des libertés (CNIL) said the incident affected 524,867 patients as well as 202,246 individuals listed as trusted contacts or third parties, for a total of more than 727,000 people. HPL, located in Saint-Étienne, is part of the Ramsay Santé healthcare group and provides medical, surgical, maternity, oncology, intensive-care and emergency services.

Findings from the investigation

According to CNIL, an attacker gained access to the hospital’s electronic patient-record platform during the summer of 2025 and was able to extract data over multiple days. The regulator concluded that the organization did not provide safeguards appropriate to the risks associated with processing health information.

  • External users, including independent physicians, could connect without using a virtual private network or multi-factor authentication.
  • Permissions were overly broad, allowing a compromised account to reach records across the hospital’s patient population.
  • The hospital lacked sufficiently timely monitoring and alerting to identify unusual activity and large-scale data extraction.
  • While HPL notified affected patients, it did not directly inform the trusted third parties whose information was also exposed.

CNIL said the failures breached GDPR requirements concerning security of processing and notifications following a personal-data breach. The authority also noted that HPL introduced security improvements while the case was under review.

Reported attack details

At the time of the breach, a person using the online alias “Marak” told French media that access began with the compromise of a physician’s account, allegedly opening the way to the hospital’s internal systems. The individual reportedly sought to sell the data, but subsequent reports indicated that the information was neither sold nor publicly released.

The enforcement action highlights the heightened regulatory expectations placed on healthcare providers, particularly around identity protection, access segmentation, detection capabilities and notification procedures when sensitive medical data is involved.