Skip to content
Unlisted Report logoUnlisted ReportSubscribe
Privacy

French hospital fined €500,000 after patient data breach

CNIL fined Hôpital Privé de la Loire after an attacker accessed data on 524,867 patients through a login with no VPN or MFA.

By · Published · Updated · 8 min read

French hospital fined €500,000 after patient data breach

France's privacy regulator, the CNIL, has fined Hôpital Privé de la Loire €500,000 for failing to protect patient data, the CNIL announced.

What happened

In summer 2025, an attacker logged in to the hospital's computerised patient summary, which holds all records of people in its care. They accessed data on:

  • 524,867 patients, some including health data
  • 202,246 people listed as "trusted third parties"

The CNIL's final decision was issued on 3 September 2026. Under GDPR rules, the sanction cites breaches of Article 32 (security of processing) and Article 34 (communication of a personal data breach to the data subject), according to the European Data Protection Board's own published summary of the case (EDPB).

What the CNIL found

  • The login used by outside doctors was not protected by a VPN or multi-factor authentication — the attacker exploited this.
  • Access controls were inadequate: the hospital's system did not implement the concept of a "care team," meaning any single compromised account could access the records of every patient in the hospital, not just those under that clinician's actual care (CNIL).
  • There was no system in place to quickly detect abnormal activity within the computerised patient record, which allowed the attacker to extract the records of hundreds of thousands of patients using just one compromised account without triggering any alert.

The fine reflected a lack of awareness of basic security principles, the number of people affected, the sensitivity of the data and the hospital's finances.

How the attack reportedly unfolded

According to the CNIL's own account, confirmed by French regional broadcaster TL7, the intrusion took place during the summer of 2025, when an attacker managed to connect to the hospital's Dossier Patient Informatisé (DPI, or Computerised Patient Summary) — the central system that holds every record of patients treated by the hospital (TL7). The authentication method used by clinicians outside the hospital, including independent doctors not formally affiliated with it, relied on neither a VPN nor multi-factor authentication. The attacker is understood to have exploited this gap using the login of a single external user, and because the hospital's access-control policy did not restrict what each account could see based on actual care relationships, that one compromised account was enough to reach every patient record in the system.

Why it matters

This breach was preventable with standard measures. Regulators are increasingly treating the absence of multi-factor authentication as a clear failure under Article 32 of the GDPR. The size of the fine — €500,000, among the larger health-data sanctions the CNIL has issued — signals that French regulators consider basic authentication hygiene for remote clinical access to be a non-negotiable baseline, not an optional extra, especially for organisations holding highly sensitive medical records on hundreds of thousands of people.

Lessons for healthcare providers

  • Require MFA for every remote login, including external clinicians.
  • Limit what each user can see to the patients they treat.
  • Log and review access to patient records.
  • Build in automated alerting for abnormal bulk access patterns, since the CNIL specifically flagged the absence of any mechanism to detect unusual activity within the patient record system.

Why hospitals keep getting hit

Healthcare organisations hold some of the most sensitive data there is, often run older systems, and need to give access to many outside users — visiting doctors, labs, insurers. Every remote login point is a possible way in. In France, hospitals have faced a string of cyberattacks in recent years, some forcing them to cancel operations and divert emergency patients.

Stolen login details are one of the most common ways attackers get in. Without multi-factor authentication, a single password bought from a criminal marketplace or captured in a phishing attack is enough.

What the CNIL expects

The CNIL has made clear in several decisions that remote access to sensitive data must be protected by strong authentication. For health data in particular, it expects:

  • Multi-factor authentication for remote and external users
  • Access limited to the patients each professional actually treats
  • Logging and monitoring that can spot unusual mass access

What affected patients can do

  • Be wary of calls, texts or emails mentioning your hospital stay or treatment and asking for payment or bank details.
  • Never confirm your social security number or bank details to an unsolicited caller.
  • You can ask the hospital what data about you was involved, using your right of access under the GDPR.

What readers should do

  • If you or a family member received care at Hôpital Privé de la Loire, you can formally request confirmation of whether your data was among the 524,867 affected patient records, under your GDPR right of access.
  • Watch especially closely for scam calls or messages referencing real details of your medical history, treatment dates, or hospital stay — attackers who steal health records often use these specifics to make fraud attempts more convincing.
  • If you were listed as a "trusted third party" (such as a next of kin or emergency contact) rather than a patient yourself, you are still entitled to ask what data about you was exposed, since over 200,000 such contacts were also affected.
  • Report any suspicious contact referencing this breach to French consumer-fraud authorities or, outside France, to your own country's equivalent agency if you are contacted despite living abroad.
  • If you work in healthcare IT, treat this case as a concrete example to bring to leadership when arguing for MFA and VPN requirements for all remote clinical logins — regulators have shown they will fine organisations specifically for omitting these basic controls.

Sources

The broader regulatory trend in France

The Hôpital Privé de la Loire sanction adds to a growing list of CNIL decisions against healthcare organisations for inadequate authentication and access controls. France's hospital sector has been a repeated target of ransomware and intrusion attempts in recent years, and the CNIL has increasingly used its enforcement powers to push providers toward baseline practices — VPNs and MFA for remote clinicians, care-team-based access restrictions, and anomaly detection — that security professionals have recommended for years but which many smaller or financially constrained hospitals have been slow to adopt.

Read next