French Hospital Fined €500,000 for Major Data Breach, Ordered to Boost Cybersecurity Measures
September 3, 2026
The CNIL criticized the hospital for lacking measures to detect suspicious IT activity and for failing to inform trusted third parties about the data breach, leaving anomalous access undetected for an extended period and a large volume of data exposed.
Hospital leadership, including Xavier Claris, said they may appeal the decision while noting that some security measures, such as two-factor authentication, have been completed and others are underway.
Two GDPR infringements were identified: failure to ensure data security and failure to notify victims of data breaches, with the CNIL ordering security improvements to be implemented within a set timeframe and potential daily penalties if not.
The CNIL fined the Hôpital privé de la Loire in Saint-Étienne 500,000 euros for insufficient data protection after a summer 2025 cyberattack that exposed personal and health data of more than 500,000 patients and over 200,000 designated trusted third parties.
The breach stemmed from inadequate access controls for external users, such as general practitioners, allowing attackers to infiltrate and exfiltrate patient data over several days.
The CNIL also faulted the hospital for not informing trusted third parties designated by patients who could access their health data about the breach.
Essential security failures included inadequate access controls for external medical professionals, enabling attackers to access patient records for days and extract a large volume of data.
The CNIL identified two GDPR violations and required concrete security improvements within 3 to 15 months, with the possibility of daily penalties if not implemented.
The CNIL criticized the hospital for not implementing detection measures to identify suspicious IT activity, meaning anomalous access went undetected and data was exfiltrated.
Summary based on 2 sources