France’s data protection authority, the CNIL, has fined Hôpital privé de la Loire (HPL) €500,000 ($580,000) for failing to adequately protect the personal and medical data of patients and their trusted third parties.
The data breach, which occurred during the summer of 2025, exposed sensitive information belonging to 524,867 patients and 202,246 people designated as trusted third parties, including relatives and others who assisted patients.
Hôpital privé de la Loire is a general hospital in Saint-Etienne operated by the Ramsay Santé Healthcare Group. The facility provides medical, surgical, obstetric, oncology, intensive care, and emergency services.
The hospital employs approximately 650 people, including 180 physicians, and operates 333 beds across five departments. According to information published by the hospital, HPL treats around 60,000 patients each year.
In 2025, attackers gained access to the hospital’s electronic patient records system and extracted sensitive data on more than 727,000 people who received treatment, accompanied a patient, or otherwise interacted with HPL.
Following the incident, the CNIL launched an investigation and identified several violations of the hospital’s obligations under the European Union’s General Data Protection Regulation (GDPR).
The security and data protection shortcomings identified by the CNIL included:
- External users, including medical practitioners, could access the system without using a virtual private network (VPN) or multi-factor authentication.
- Insufficient access controls allowed the compromised account to access the records of all inpatients.
- The hospital did not have effective real-time or near-real-time monitoring and alerting. As a result, attackers were able to explore the system and extract large volumes of data over several days without detection.
- Although the hospital notified affected patients, it did not directly notify the 202,246 trusted third parties whose personal data was also stolen.
The CNIL said these violations breached Articles 32 and 34 of the GDPR, which address data security and the notification of affected individuals following a personal data breach. In its decision, the committee noted that HPL implemented several security improvements during the proceedings.
A teenage hacker using the pseudonym “Malak” claimed responsibility for the attack and spoke with the French press. Le Progrès reported that the hacker said the intrusion began after a single doctor’s account was compromised. According to a report shared on LinkedIn, the stolen credentials provided access to HPL’s wider internal system.
The attackers reportedly attempted to sell the stolen data to a single buyer for between €2,000 and €5,000. However, later reports indicated that the data was not sold or publicly released.
A strong prevention score can conceal weaknesses that emerge after an attacker gains initial access. When criminals use valid credentials, existing security defenses can be significantly reduced.
The Blue Report 2026 evaluates defensive techniques across different technologies using 338 million simulations conducted in customer production environments.
Source: www.bleepingcomputer.com



