Skip to main content
ShareEmailLinkedInXWhatappsFacebook
feedback
Share

Health data breach: the CNIL fined Hôpital Privé de la Loire 500 000 EUR

Background information

  • Date of final decision: 3 September 2026
  • National case
  • Controller: Hôpital Privé de la Loire
  • Legal Reference: Article 32 (Security of processing), Article 34 (Communication of a personal data breach to the data subject), 
  • Decision: Administrative fine
  • Keywords: Cybersecurity, Personal data breaches, Health and research

Summary of the Decision

Origin of the case

In summer 2025, an attacker managed to connect to the Computerised Patient Summary (DPI) of the Hôpital Privé de la Loire (Loire’s private hospital), which centralises all the data of the individuals under care. It thus accessed the data of 524 867 patients (some of them health data) and 202 246 persons designated as “trusted third parties”. As a result of this data breach, the CNIL carried out a check that identified several failures of the Hôpital Privé de la Loire to comply with the obligations laid down in the General Data Protection Regulation (GDPR).

Key findings

  • Failure to ensure the security of personal data (Article 32 GDPR)
    The authentication procedure to connect to the hospital’s e-Health Patient Summary, used by users outside the hospital, in particular doctors not affiliated with the hospital, was not sufficiently robust, due to the lack of VPNs and multifactor authentication means. The attacker took advantage of this vulnerability to access the data. Moreover, the access control policy was inadequate: it did not take account of the concept of care team, so that only professionals actually involved in the care of a patient had access to the information covered by medical confidentiality. This lack of access limitation allowed the attacker, using the credentials of a single user account, to access the data of all hospital patients. Finally, the hospital had not taken measures to detect suspicious activity within the e-Health Patient Summary in real time or in the very short term, and to trigger an alert mechanism if necessary. In those circumstances, the attacker was able to explore the hospital’s e-Health Patient Summary for several days and extract a very large volume of data, without that abnormal activity being detected. This vulnerability has contributed to exacerbating the scale of the data breach.
  • Failure to inform data subjects about the data breach (Article 34 GDPR)
    Finally, the restricted committee found that only the patients of the Hôpital Privé de la Loire concerned by the data breach had been informed, but that no direct information had been provided to the 202 246 individuals designated by patients as trusted third parties, even though their personal data had also been stolen by the attacker.

Decision

The restricted committee – the body of the CNIL responsible for issuing sanctions – imposed a fine of 500 000 EUR on the Hôpital Privé de la Loire, taking into account, inter alia, the lack of awareness of essential security principles, the number of persons concerned, the nature of the data compromised and its financial capacities.

Further information: