CNIL Fines Hôpital Privé de la Loire €500,000 Over 2025 Breach
France's data protection authority, CNIL, has fined Hôpital privé de la Loire (HPL) — a general hospital in Saint-Étienne operated by the Ramsay Santé healthcare group — €500,000 (roughly $580,000) after a summer 2025 breach exposed the personal data of 727,113 people.
Scope of the Breach
The exposed data spanned two groups:
- 524,867 patient records
- 202,246 records belonging to trusted third parties (relatives and other contacts listed in patient files)
How the Attack Happened
According to CNIL's findings, an attacker — a teenager using the alias "Marak" — compromised a single external physician's account and used it to gain access to the hospital's full patient record system. The attacker attempted to sell the stolen data on underground forums for €2,000 to €5,000, though the data was ultimately neither sold nor published.
GDPR Violations Cited by CNIL
CNIL found that HPL violated Articles 32 and 34 of the GDPR (security of processing, and notification of a data breach to affected individuals), pointing to several concrete failures:
- External physicians could authenticate to hospital systems without a VPN or multi-factor authentication
- Access controls were inadequate, allowing a single compromised account to retrieve the entire patient database rather than a limited subset
- The hospital lacked real-time or near-real-time monitoring and alerting that could have flagged the attacker's multi-day data extraction as it happened
- HPL failed to directly notify the 202,246 third parties whose data was compromised, relying instead on indirect notice
Response and Remediation
CNIL acknowledged that HPL has since implemented security improvements during the course of the proceedings, though the regulator determined the fine was still warranted given the scale of exposure and the duration the intrusion went undetected.
Why It Matters
The case reinforces a now-familiar pattern in healthcare breaches: attackers rarely need a sophisticated exploit when a single set of credentials — especially one belonging to a third party without strong authentication requirements — provides a path to an entire patient database. CNIL's emphasis on the missing MFA/VPN requirement for external clinicians and the absence of real-time monitoring highlights two of the most common, and most fixable, gaps in healthcare IT environments.
Sources: BleepingComputer, CNIL (Commission Nationale de l'Informatique et des Libertés)