French hospital fined €500,000 after breach exposes data of 727,000

France’s data protection authority (CNIL) has fined Hôpital privé de la Loire €500,000 ($580,000) for failing to adequately protect patients’ and their relatives’ data.

The French agency says that the security failures led to a data breach in the summer of 2025, exposing sensitive data belonging to 524,867 patients and another 202,246 people designated as trusted third parties.

Hôpital privé de la Loire (HPL) is a general hospital in Saint-Étienne, part of the Ramsay Santé healthcare group, providing medical, surgical, maternity, cancer, intensive-care, and emergency services.

The hospital employs a staff of 650, including 180 doctors, and has 333 beds across five clinical divisions, with a reported 60,000 patients yearly.

Last year, an attacker accessed the hospital’s electronic patient record system and extracted sensitive data of more than 727,000 people who had received care at HPL, escorted patients there or helped them in some way.

Following the incident, the CNIL conducted an investigation, which identified several failures to comply with the hospital’s obligations under the General Data Protection Regulation (GDPR).

Some of the shortcomings CNIL’s investigation identified include:

The violations above relate to Article 32 and Article 34 of the GDPR. The committee also noted that HPL took several security strengthening measures during the proceedings.

A teen hacker using the alias “Marak” claimed responsibility, contacting the French outlet Le Progrès over Telegram at the time and saying the attack began with a breach of a single doctor’s account, which allowed access to HPL’s entire internal system.

The hacker attempted to sell the stolen data to a single buyer for a price between €2,000 and €5,000, although it was later reported that the data was neither sold nor published.

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

Hospital operator Nutex Health says data stolen in cyberattack

France fines unemployment agency €5 million over data breach

Novocure data breach affects more than 1,400 cancer patients

Aesto Health says data breach affects over 9.5 million patients

McKesson discloses breach after ShinyHunters claims patient data theft

Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks

Recently patched PaperCut zero-days used in data theft attacks

Dropbox accounts breached through Lenovo email verification flaw

AI-driven vulnerability discovery is accelerating. See how Action1 helps remediation keep pace.

Identity, Data Governance & Threat Detection in One Platform: Take our In-Browser Tour

Unify ransomware protection and recovery for every client

Can you trust every session? See how session enrichment enables better authentication decisions.

Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure

Read our posting guidelinese to learn what content is prohibited.