CNIL fines Hôpital Privé de la Loire EUR 500,000 for health data breach
Original title: Health data breach: the CNIL fined Hôpital Privé de la Loire EUR 500 000
The French Data Protection Authority (CNIL) has fined Hôpital Privé de la Loire EUR 500,000 following a data breach in summer 2025 that exposed personal and health data of 524,867 patients and 202,246 trusted third parties. The hospital failed to implement sufficient technical and organizational security measures, including weak authentication procedures, inadequate access controls, and lack of real-time monitoring to detect suspicious activity, which allowed an attacker to access and extract large volumes of data over several days. Additionally, the hospital failed to inform all affected data subjects, particularly the 202,246 trusted third parties whose data was compromised. Healthcare providers must ensure robust security controls including multi-factor authentication, granular access limitations based on actual care responsibilities, and active monitoring systems, while also maintaining comprehensive breach notification procedures for all affected parties.
What changed
- CNIL enforcement action: Administrative fine of EUR 500,000 imposed on healthcare provider for violations of Articles 32 and 34 GDPR involving a breach affecting 524,867 patients and 202,246 trusted third parties
- Article 32 GDPR (Security of processing) violation: Authentication procedures lacked VPNs and multi-factor authentication; access control policy did not restrict data access based on care team involvement, allowing unauthorized access through a single compromised user account
- Article 32 GDPR violation continued: Absence of real-time or near-real-time detection mechanisms for suspicious activity and alert triggers within the e-Health Patient Summary system, enabling the attacker to explore and extract data over several days without detection
- Article 34 GDPR (Communication of a personal data breach to the data subject) violation: Failure to directly inform 202,246 individuals designated as trusted third parties whose personal data was compromised, despite notification of affected patients
Who is affected
Healthcare providers (hospitals), particularly those operating e-Health systems and patient data platforms with external user access; French jurisdiction (CNIL); affects data controllers in healthcare sector
Summary generated by a language model; the official text prevails. Not legal advice.