Info Enforcement Other eu

CNIL fines Hôpital Privé de la Loire 500,000 EUR for inadequate security and data breach notification failures

Original title: Health data breach: the CNIL fined Hôpital Privé de la Loire 500 000 EUR

The French Data Protection Authority (CNIL) fined Hôpital Privé de la Loire 500,000 EUR for GDPR violations following a summer 2025 data breach that exposed the personal and health data of 524,867 patients and 202,246 trusted third parties. The hospital failed to implement adequate security measures, including the absence of multi-factor authentication and VPNs for external users, insufficient access control policies, and lack of real-time monitoring to detect suspicious activity. Additionally, the hospital failed to directly inform 202,246 trusted third parties whose data was compromised, notifying only the patients themselves. Organizations must implement robust authentication mechanisms, role-based access controls, continuous security monitoring, and ensure all affected data subjects are notified in case of a breach.

What changed

  • CNIL establishes that lack of multi-factor authentication and VPN protections on e-Health Patient Summary systems used by external users constitutes inadequate security of processing under Article 32 GDPR, allowing attackers to exploit weak authentication procedures.
  • Inadequate access control policy that fails to implement the concept of care team—limiting access only to professionals directly involved in patient care—enables unauthorized access to all patient records with a single compromised user credential, aggravating breach severity.
  • Absence of real-time or near-real-time monitoring and alert mechanisms within e-Health systems to detect suspicious activity prolongs unauthorized data access, allowing attackers to extract large volumes of data undetected over several days.
  • Failure to directly notify all individuals whose personal data was compromised, specifically the 202,246 designated trusted third parties, violates Article 34 GDPR notification requirements even when alternative notification channels were available.

Who is affected

Healthcare providers (hospitals and medical facilities) in the EU, particularly those managing centralized patient records and providing external access to clinical systems for affiliated and non-affiliated healthcare professionals. Private and public health institutions of any size that process sensitive personal and health data.

Language
EN

Frameworks

GDPR

Open the original source