CTIPilot
← Back to Daily brief 2026-09-04
NOTABLENATOA2incident

CNIL fines Hôpital privé de la Loire EUR 500,000 over a 727,000-record breach traced to a single unprotected external physician account

France's data regulator details exactly how one compromised doctor account exposed an entire hospital's patient records

Analysis

France's CNIL imposed a EUR 500,000 GDPR fine on 3 September 2026 against Hôpital privé de la Loire (HPL, Saint-Étienne, part of the Ramsay Santé group) over a summer-2025 breach of its externally-reachable electronic patient-record system, which exposed 524,867 patients and 202,246 people designated as "trusted third parties", 727,113 individuals total (CNIL, 2026-09-03). CNIL's investigation names three compounding failures. First, the authentication procedure for external users (private-practice physicians accessing the record system from outside the hospital) required no VPN and no multi-factor authentication, and the attacker used the credentials of a single compromised physician account to get in. Second, the access-control model had no concept of "care team" restricting an account to the patients that physician actually treats, so one set of valid credentials opened every hospital patient's record. Third, with no real-time or near-real-time anomaly detection on the record system, the attacker was able to enumerate and extract records over several days undetected; CNIL states this absence "contributed to exacerbating the scale of the data breach." A self-identified attacker using the alias "Marak" told the French outlet Le Progrès via Telegram at the time that the intrusion began with a single doctor's account, and separately attempted to sell the stolen data for EUR 2,000-5,000; it was later reported that the data was in fact neither sold nor published. These are unconfirmed criminal self-claims, consistent with but not independently verified against CNIL's own findings (BleepingComputer, 2026-09-03).

CNIL separately sanctioned HPL under GDPR Article 34 for notifying only the direct patients affected and never notifying the 202,246 trusted third parties whose data was also taken. HPL has begun remediation and has three to fifteen months, depending on measure type, to complete it.

Cited evidence

The authentication procedure to connect to the hospital's e-Health Patient Summary, used by users outside the hospital, in particular liberal doctors, was not sufficiently robust, due to the lack of VPNs and multifactor authentication means. The attacker took advantage of this vulnerability to access the data.

This lack of access limitation allowed the attacker, using the credentials of a single user account, to access the data of all hospital patients.

the attacker was able to explore the hospital's e-Health Patient Summary for several days and extract a very large volume of data, without that abnormal activity being detected

CNIL

Sources3

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.