Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsStudyTraining
ProjectsChecklistsAI RankingsNewsletterStatusTagsAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Study
Training
Projects
Checklists
AI Rankings
Newsletter
Status
Tags
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

429+ Articles
114+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Cegedim Santé Breach Exposes 15.8 Million French Healthcare Records Including HIV Status
Cegedim Santé Breach Exposes 15.8 Million French Healthcare Records Including HIV Status
NEWS

Cegedim Santé Breach Exposes 15.8 Million French Healthcare Records Including HIV Status

A cyberattack on French healthcare software vendor Cegedim Santé exposed 15.8 million patient records from 3,800 doctors, with leaked data including...

Dylan H.

News Desk

March 22, 2026
4 min read

15.8 Million French Patient Records Stolen in Healthcare Software Breach

Cegedim Santé, a major French healthcare software vendor, confirmed that attackers exfiltrated approximately 15.8 million administrative medical files after compromising its MonLogicielMedical (MLM) platform — software used by 3,800 doctors across France. The breach included highly sensitive medical information such as HIV/AIDS diagnoses and sexual orientation data.


AttributeValue
VictimCegedim Santé (healthcare software vendor)
Records Exposed15.8 million administrative files
Doctors Affected1,500 of 3,800 using the MLM platform
Sensitive Records165,000 files containing doctor's clinical notes
Data TypesNames, gender, DOB, phone, address, email, medical history
DetectionLate 2025 (abnormal application requests)
NotificationJanuary 2026
Notable VictimsFrench politicians identified among the exposed

What Was Exposed

The breach compromised Cegedim's MonLogicielMedical (MLM) software through abnormal application requests on doctors' accounts. The stolen data includes:

  • Personal identifiers — full names, gender, dates of birth, phone numbers, residential addresses, and email IDs
  • Administrative records — 15.8 million files covering patient registration and appointment data
  • Clinical notes — approximately 165,000 files containing doctors' handwritten notes, which in some cases included:
    • HIV/AIDS status
    • Sexual orientation
    • Mental health diagnoses
    • Substance use details

High-Profile Victims

French media reported that top politicians were among the individuals whose information was extracted, adding a political dimension to what is already France's largest healthcare data breach.

Timeline of Events

  1. Late 2025 — Cegedim Santé detects abnormal application requests on doctor accounts
  2. January 2026 — All affected doctors and patients notified
  3. February-March 2026 — Investigation reveals full scope: 15.8 million records across 1,500 doctor practices
  4. March 2026 — Additional security measures implemented; CNIL investigation ongoing

Impact AreaDescription
Patient Privacy15.8 million records exposed, including children
Medical ConfidentialityHIV status and sexual orientation data leaked
Political RiskPolitician medical records among the exposed
RegulatoryGDPR Article 9 (special categories) violation investigation
Healthcare TrustErodes patient confidence in digital health records
Identity FraudFull PII available for social engineering attacks

Recommendations

For Affected Patients

  • Monitor for phishing attempts referencing your doctor or medical practice
  • Request a copy of your data from your healthcare provider under GDPR rights
  • Be alert for insurance fraud or identity theft using medical information
  • Contact CNIL if you believe your sensitive medical data was exposed

For Healthcare Organizations

  • Implement anomaly detection on application-level requests to patient data
  • Encrypt sensitive clinical notes at rest with per-record keys
  • Segment administrative and clinical data with different access controls
  • Conduct regular third-party security audits of SaaS healthcare platforms

Key Takeaways

  1. 15.8 million records make this France's largest healthcare breach — affecting roughly one in four French citizens
  2. HIV/AIDS status and sexual orientation were among the most sensitive data exposed, creating risks of discrimination
  3. 165,000 clinical notes with detailed medical histories were stolen — far beyond basic PII
  4. Politicians are among the identified victims, adding national security dimensions
  5. The breach went undetected for months before abnormal API requests triggered investigation
  6. Healthcare SaaS vendors remain high-value targets — a single platform compromise exposed data from 1,500 medical practices

Sources

  • 15.8M medical records stolen from French health ministry — The Register
  • Doctors' records hit by cyberattack: up to 15 million patients in France affected — Connexion France
  • Centralized Healthcare System Data Breach Leaks Medical Records — CPO Magazine
  • 15M French citizens affected by massive data breach — Anadolu Agency
#Data Breach#Healthcare#France#Privacy

Related Articles

3.1 Million Impacted by QualDerm Partners Data Breach

QualDerm Partners, a national dermatology network operating 158 practices across 17 states, disclosed a December 2025 data breach that exposed the medical...

3 min read

Two US Cybersecurity Professionals Plead Guilty to BlackCat Ransomware Attacks

Former incident responder Ryan Goldberg and ransomware negotiator Kevin Martin admitted to running ALPHV/BlackCat ransomware operations against five US...

3 min read

Navia Data Breach Impacts 2.7 Million People

Navia Benefit Solutions has confirmed a data breach that exposed personal and health plan information belonging to approximately 2.7 million individuals,...

5 min read
Back to all News