← Hôpital privé de la Loire

2025 Hôpital privé de la Loire — EPR breach; 727,113 people; CNIL €500k fine (Sep 2026)

2025 727.1K records affected Share on X

Data compromised

Sensitive patient and trusted-third-party data from the hospital’s electronic patient record system (524,867 patients + 202,246 trusted third parties per CNIL)

Technical writeup

Verified CNIL decision and trade press — September 3, 2026. France’s CNIL fined Ramsay Santé’s Hôpital privé de la Loire (Saint-Étienne) €500,000 for GDPR security failures tied to a summer 2025 electronic patient-record breach. CNIL reported sensitive data of 524,867 patients and 202,246 trusted third parties (727,113 total) were extracted after an attacker used a compromised doctor account with overly broad access; external clinician access lacked VPN/MFA, monitoring was inadequate, and trusted third parties were not directly notified. A teen claiming the alias “Marak” said the motive was financial; French reporting later indicated the dump was neither sold nor published. recordsAffected 727113 from CNIL patient + third-party totals via BleepingComputer; companyConfirmed true (regulator-attested incident).

Root cause

Unauthorized access to electronic patient records after compromise of a physician account; CNIL later found GDPR Article 32/34 security and notification failures

References