France’s data protection authority, CNIL, has fined Hôpital privé de la Loire €500,000 ($580,000) for failing to adequately protect patients’ and their relatives’ data.
CNIL said security failures led to a breach in the summer of 2025. The incident exposed data belonging to 524,867 patients and 202,246 people designated as trusted third parties, affecting 727,113 people in total.
The hospital, also known as Hôpital privé de la Loire (HPL), is a general hospital in Saint-Étienne and part of the Ramsay Santé healthcare group. It provides medical, surgical, maternity, cancer, intensive-care, and emergency services.
CNIL’s investigation identified several failures to comply with obligations under the General Data Protection Regulation (GDPR). The violations related to Articles 32 and 34 of the GDPR. The authority also noted that HPL adopted several security-strengthening measures during the proceedings.
A teenager using the alias “Marak” claimed responsibility at the time, telling the French outlet Le Progrès over Telegram that the attack began with a breach of one doctor’s account. The hacker claimed this provided access to HPL’s internal system and attempted to sell the stolen data to one buyer for between €2,000 and €5,000. Later reports said the data was neither sold nor published.
Comments
0No comments yet. Be the first to comment.