← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

French Hospital Fined €500,000 for Data Breach Exposing 727,000 Records

🔄 Updated 1h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Hôpital privé de la Loire fined €500,000 by CNIL.
  • Data breach exposed 727,000 patient and third-party records.
  • Violations included lack of VPN/MFA for external users and poor access controls.
  • Hospital failed to notify all affected third parties directly.

Hospital Fined for Data Protection Failures

Hôpital privé de la Loire (HPL), a general hospital in Saint-Étienne, has been fined €500,000 by the French data protection authority, CNIL. The fine follows a data breach in the summer of 2025 that exposed sensitive data belonging to 524,867 patients and 202,246 trusted third parties.

Details of the Breach

An attacker, identified by the alias “Marak,” accessed HPL’s electronic patient record system. The hacker claimed the attack began by compromising a single doctor’s account, which then provided access to the entire internal system. The stolen data was reportedly not sold or published, despite an attempt to sell it for €2,000 to €5,000.

GDPR Violations Identified

CNIL's investigation revealed several failures to comply with GDPR Articles 32 and 34. Key shortcomings included allowing external users, such as private-practice physicians, to access the system without a VPN or multi-factor authentication. Additionally, inadequate access controls permitted the compromised account to access records for all hospital patients. The hospital also lacked real-time monitoring, which allowed the attacker to extract a large volume of data over several days without detection. Furthermore, HPL informed affected patients but did not directly notify the 202,246 trusted third parties whose data was also stolen.

Impact and Remediation

The breach affected a significant number of individuals who had received care at HPL or were associated with patients. The committee noted that HPL implemented several security strengthening measures during the proceedings following the incident.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~23 min · 21 stories · Sep 03

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

France's data protection authority (CNIL) fined Hôpital privé de la Loire €500,000 after a data breach exposed sensitive information of 727,000 patients and third parties. The fine was issued due to the hospital's failure to comply with GDPR obligations, including inadequate access controls and lack of real-time monitoring.