Hôpital privé de la Loire (HPL), a general hospital in Saint-Étienne, has been fined €500,000 by the French data protection authority, CNIL. The fine follows a data breach in the summer of 2025 that exposed sensitive data belonging to 524,867 patients and 202,246 trusted third parties.
An attacker, identified by the alias “Marak,” accessed HPL’s electronic patient record system. The hacker claimed the attack began by compromising a single doctor’s account, which then provided access to the entire internal system. The stolen data was reportedly not sold or published, despite an attempt to sell it for €2,000 to €5,000.
CNIL's investigation revealed several failures to comply with GDPR Articles 32 and 34. Key shortcomings included allowing external users, such as private-practice physicians, to access the system without a VPN or multi-factor authentication. Additionally, inadequate access controls permitted the compromised account to access records for all hospital patients. The hospital also lacked real-time monitoring, which allowed the attacker to extract a large volume of data over several days without detection. Furthermore, HPL informed affected patients but did not directly notify the 202,246 trusted third parties whose data was also stolen.
The breach affected a significant number of individuals who had received care at HPL or were associated with patients. The committee noted that HPL implemented several security strengthening measures during the proceedings following the incident.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
France's data protection authority (CNIL) fined Hôpital privé de la Loire €500,000 after a data breach exposed sensitive information of 727,000 patients and third parties. The fine was issued due to the hospital's failure to comply with GDPR obligations, including inadequate access controls and lack of real-time monitoring.