France’s data protection authority has fined Hôpital privé de la Loire €500,000 after a security breach exposed sensitive information belonging to more than 727,000 people.
The French National Commission on Informatics and Liberties (CNIL) said the hospital failed to adequately protect the personal data of 524,867 patients and 202,246 people listed as trusted third parties. Hôpital privé de la Loire, located in Saint-Étienne, is part of the Ramsay Santé healthcare group and provides a range of medical services, including surgery, maternity care, cancer treatment, intensive care, and emergency services.
The breach occurred in the summer of 2025 after an attacker gained access to the hospital’s electronic patient record system and extracted sensitive information belonging to people who had received treatment, accompanied patients, or otherwise interacted with the hospital.
A CNIL investigation found several security weaknesses that violated the hospital’s obligations under the General Data Protection Regulation. External users, including private-practice doctors, could access the hospital’s systems without using a VPN or multi-factor authentication. Investigators also found that access controls were too broad, allowing the compromised account to reach records belonging to all hospital patients.
The hospital also lacked real-time or near-real-time monitoring and alerting. This allowed the attacker to move through the system and extract a large amount of data over several days without being detected.
CNIL also found that although the hospital informed affected patients about the incident, it did not directly notify the 202,246 trusted third parties whose information had also been stolen. The violations concerned Articles 32 and 34 of the GDPR.
The hospital strengthened several of its security measures during the proceedings, which CNIL took into account when issuing the €500,000 fine.
A teenage hacker using the alias “Marak” previously claimed responsibility for the attack. The hacker told French newspaper Le Progrès that the incident began after compromising a single doctor’s account, which allegedly provided access to the hospital’s wider internal systems.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
The attacker later attempted to sell the stolen information to a single buyer for between €2,000 and €5,000. The data was reportedly never sold or publicly released.





