2025 Hôpital privé de la Loire — EPR breach; 727,113 people; CNIL €500k fine (Sep 2026)
Data compromised
Sensitive patient and trusted-third-party data from the hospital’s electronic patient record system (524,867 patients + 202,246 trusted third parties per CNIL)
Technical writeup
Verified CNIL decision and trade press — September 3, 2026. France’s CNIL fined Ramsay Santé’s Hôpital privé de la Loire (Saint-Étienne) €500,000 for GDPR security failures tied to a summer 2025 electronic patient-record breach. CNIL reported sensitive data of 524,867 patients and 202,246 trusted third parties (727,113 total) were extracted after an attacker used a compromised doctor account with overly broad access; external clinician access lacked VPN/MFA, monitoring was inadequate, and trusted third parties were not directly notified. A teen claiming the alias “Marak” said the motive was financial; French reporting later indicated the dump was neither sold nor published. recordsAffected 727113 from CNIL patient + third-party totals via BleepingComputer; companyConfirmed true (regulator-attested incident).
Root cause
Unauthorized access to electronic patient records after compromise of a physician account; CNIL later found GDPR Article 32/34 security and notification failures
References
- https://www.cnil.fr/fr/sanction-hopital-prive-loire
- https://www.bleepingcomputer.com/news/security/french-hospital-fined-500-000-after-breach-exposes-data-of-727-000/
- https://www.leprogres.fr/faits-divers-justice/2026/09/03/piratage-de-donnees-medicales-le-hpl-condamne-par-la-cnil-a-500-000-euros-d-amende