2026-09-04 · view entry permalink →
CNIL fines Hôpital privé de la Loire EUR 500,000 over a 727,000-record breach traced to a single unprotected external physician account
France's CNIL imposed a EUR 500,000 GDPR fine on 3 September 2026 against Hôpital privé de la Loire (HPL, Saint-Étienne, part of the Ramsay Santé group) over a summer-2025 breach of its externally-reachable electronic patient-record system, which exposed 524,867 patients and 202,246 people designated as "trusted third parties", 727,113 individuals total (CNIL, 2026-09-03). CNIL's investigation names three compounding failures. First, the authentication procedure for external users (private-practice physicians accessing the record system from outside the hospital) required no VPN and no multi-factor authentication, and the attacker used the credentials of a single compromised physician account to get in. Second, the access-control model had no concept of "care team" restricting an account to the patients that physician actually treats, so one set of valid credentials opened every hospital patient's record. Third, with no real-time or near-real-time anomaly detection on the record system, the attacker was able to enumerate and extract records over several days undetected; CNIL states this absence "contributed to exacerbating the scale of the data breach." A self-identified attacker using the alias "Marak" told the French outlet Le Progrès via Telegram at the time that the intrusion began with a single doctor's account, and separately attempted to sell the stolen data for EUR 2,000-5,000; it was later reported that the data was in fact neither sold nor published. These are unconfirmed criminal self-claims, consistent with but not independently verified against CNIL's own findings (BleepingComputer, 2026-09-03).
CNIL separately sanctioned HPL under GDPR Article 34 for notifying only the direct patients affected and never notifying the 202,246 trusted third parties whose data was also taken. HPL has begun remediation and has three to fifteen months, depending on measure type, to complete it.
The authentication procedure to connect to the hospital's e-Health Patient Summary, used by users outside the hospital, in particular liberal doctors, was not sufficiently robust, due to the lack of VPNs and multifactor authentication means. The attacker took advantage of this vulnerability to access the data.
This lack of access limitation allowed the attacker, using the credentials of a single user account, to access the data of all hospital patients.
the attacker was able to explore the hospital's e-Health Patient Summary for several days and extract a very large volume of data, without that abnormal activity being detected