CNIL fines Hôpital Privé de la Loire EUR 500,000 for data security failures and breach notification violations
Original title: Health data breach: the CNIL fined Hôpital Privé de la Loire EUR 500 000
The French Data Protection Authority (CNIL) fined Hôpital Privé de la Loire EUR 500,000 following a 2025 data breach that exposed personal and health data of 524,867 patients and 202,246 trusted third parties. The hospital failed to implement adequate security controls including multifactor authentication, VPNs, real-time activity monitoring, and proper access limitation based on care team involvement. Additionally, the hospital did not directly inform the 202,246 trusted third parties whose data was compromised, violating Article 34 GDPR breach notification requirements. Healthcare providers and controllers must ensure robust authentication mechanisms, granular access controls, continuous security monitoring, and comprehensive breach notification to all affected data subjects.
What changed
- Enforcement decision: CNIL issued an administrative fine of EUR 500,000 against Hôpital Privé de la Loire for security and notification violations identified following a summer 2025 data breach affecting over 727,000 individuals
- Article 32 GDPR violation: Hospital lacked multifactor authentication and VPN requirements for remote access to its e-Health Patient Summary system, enabling attackers to compromise patient data
- Access control deficiency: Hospital's access control policy failed to implement care team-based limitation, allowing a single compromised user account to access data of all patients rather than only those under that professional's care
- Monitoring failure: Hospital did not establish real-time or near-real-time detection mechanisms for suspicious activity in the e-Health Patient Summary, permitting the attacker to operate undetected for several days and extract large data volumes
- Article 34 GDPR violation: Hospital failed to directly notify 202,246 trusted third parties designated by patients, despite their personal data being stolen, notifying only direct patients of the breach
Who is affected
Healthcare providers in the EU, particularly private hospitals and healthcare controllers processing large volumes of patient and personal data subject to GDPR Article 32 security and Article 34 breach notification obligations
Summary generated by a language model; the official text prevails. Not legal advice.