A French hospital has been fined €500,000 after a cyber attack exposed the personal data of more than 727,000 patients and people connected to their care.
France’s data protection regulator, the CNIL, said Hôpital privé de la Loire in Saint-Étienne failed to put adequate safeguards in place to protect the information held in its electronic patient record system.
The breach, which took place in the summer of 2025, affected 524,867 patients and 202,246 people listed as trusted third parties. The latter category included individuals who had accompanied patients or assisted them during their treatment.
Hôpital privé de la Loire data breach
The hospital, part of the Ramsay Santé healthcare group, provides medical, surgical, maternity, cancer, intensive-care and emergency services. It has about 650 employees, including 180 doctors, and treats roughly 60,000 patients a year.
CNIL investigators found that external users, including doctors working in private practice, could connect to the hospital’s system without using a virtual private network or multi-factor authentication.
They also found that access controls were too broad, allowing the compromised account to view the records of all patients. The hospital did not have real-time or near-real-time monitoring capable of detecting the attacker’s activity, meaning large quantities of data could be examined and extracted over several days.
The regulator said Hôpital privé de la Loire notified affected patients but did not contact the 202,246 trusted third parties whose information had also been taken.
The failures were found to breach Articles 32 and 34 of the General Data Protection Regulation, which cover the security of personal data and the notification of data breaches. The CNIL said the hospital introduced a number of measures to strengthen security while the investigation was under way.
A teenager using the alias “Marak” claimed responsibility for the attack at the time, telling French newspaper Le Progrès via Telegram that it began with the compromise of a doctor’s account. The hacker alleged that the account provided access to the hospital’s wider internal system.
Marak reportedly tried to sell the stolen information to a single buyer for between €2,000 and €5,000. The data was later reported not to have been sold or published.
