CNIL (France) - SAN-2026-009
CNIL fines French hospital €500K for inadequate security measures enabling patient data breach.
Summary
France's CNIL issued a €500,000 fine against Hôpital Privé de la Loire for violating Article 32 GDPR by failing to implement adequate technical and organizational security measures. An attacker exploited weak remote access controls (no MFA or VPN) to extract 524,867 patient records between June-July 2025. The hospital also failed to notify 202,246 trusted third parties whose data was compromised, violating Article 34 GDPR notification requirements.
Full text
Help CNIL (France) - SAN-2026-009: Difference between revisions From GDPRhub Jump to:navigation, search Newer edit →VisualWikitext Revision as of 12:45, 3 September 2026 view source Bms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators296 edits Tag: Decisions [1.0]Newer edit → (No difference) Revision as of 12:45, 3 September 2026 CNIL - SAN-2026-009 Authority: CNIL (France) Jurisdiction: France Relevant Law: Article 32 GDPR Article 34 GDPR L. 1110-4 French Public Health CodeL. 1110-12 French Public Health Code Type: Investigation Outcome: Violation Found Started: 04.06.2025 Decided: 21.07.2026 Published: 03.09.2026 Fine: 500000.0 EUR Parties: Hôpital Privé de la Loire National Case Number/Name: SAN-2026-009 European Case Law Identifier: n/a Appeal: Unknown Original Language(s): French Original Source: Legifrance (in FR) Initial Contributor: bms The DPA fined a hospital €500,000 for insufficient security measures which enabled a major data breach and for failing to inform 202,246 affected third parties of the breach. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts In June 2025, an attacker obtained the credentials of a doctor affiliated with Hôpital Privé de la Loire, the controller, and used them to access the hospital's electronic patient record system. Between 26 June and 1 July 2025, the attacker extracted 524,867 patient records. The compromised data included identification and contact information, social security numbers and, in some cases, identity documents and health data. The records also contained personal data relating to 202,246 persons designated by patients as trusted third parties. After discovering the breach, the controller notified the CNIL, the DPA, and informed the affected patients through different communication channels. However, it did not directly inform the 202,246 trusted third parties whose data had also been compromised. The DPA subsequently carried out an on-site investigation into the controller's data processing practices. The investigation identified several security deficiencies in the electronic patient record system. External users could access it remotely using only a username and password, without a VPN or multi-factor authentication. Moreover, healthcare professionals could access patient records even when they were not involved in the patient's care, the system lacked adequate proactive analysis of access logs, and the software provider had permanent access to the system without prior authorisation by the controller. Following the breach, the controller had also temporarily assigned the same password to all external practitioners when resetting their credentials. Holding The DPA found that the controller violated Article 32 GDPR by failing to implement appropriate technical and organisational measures to secure the electronic patient record system. The DPA first considered that remote access by external practitioners was insufficiently protected because it relied only on a username and password, without multi-factor authentication or a VPN. Given the sensitivity and volume of the health data processed, stronger authentication measures were required. The lack of such safeguards also facilitated the breach, as the attacker accessed the system using compromised credentials. The DPA further found that the controller's access-rights policy was too broad, since healthcare professionals could access records of patients for whose care they were not responsible. In addition, although access logs were collected, they were not analysed in real time or shortly afterwards to detect abnormal activity. This allowed the attacker to extract a very large number of records over several days without triggering an alert. The DPA also considered that confidentiality was insufficiently protected because, after the breach, the controller temporarily assigned the same password to all external practitioners. Moreover, the software provider had permanent access to the system without prior authorisation by the controller. The DPA additionally found a violation of Article 34 GDPR because the controller did not directly inform the 202,246 trusted third parties whose personal data had been compromised. A general notice published on the hospital's website was not sufficient to meet the obligation to communicate a high-risk personal data breach to affected data subjects. The DPA fined the controller €500,000 and ordered it to improve log monitoring, revise its access-rights policy and restrict the software provider's access to situations where prior authorisation had been granted. The orders were subject to a penalty payment of €1,000 per day of delay. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the French original. Please refer to the French original for more details. Decision SAN-2026-009 of July 21, 2026 National Commission for Information Technology and Civil Liberties Nature of the decision: Sanction Date of publication on Légifrance: Thursday, September 3, 2026 Decision No. SAN-2026-009 of the Select Panel dated July 21, 2026, concerning the company HOPITAL PRIVE DE LA LOIRE The National Commission for Information Technology and Civil Liberties, meeting in its select panel composed of Mr. Philippe-Pierre CABOURDIN, Chair, Mr. Vincent LESCLOUS, Vice Chair, Ms. Laurence FRANCESCHINI and Ms. Isabelle LATOURNARIE-WILLEMS, Mr. Didier KLING and Mr. Bertrand du MARAIS, members, Having regard to Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data; Having regard to Law No. 78-17 of January 6, 1978, on Information Technology, Filing Systems, and Civil Liberties, in particular articles 20 et seq.; Having regard to the Public Health Code; Having regard to Decree No. 2019-536 of May 29, 2019, adopted to implement Law No. 78-17 of January 6, 1978, on Information Technology, Filing Systems, and Civil Liberties; Having regard to Resolution No. 2013-175 of July 4, 2013, adopting the regulations of the National Commission on Information Technology and Civil Liberties; Having regard to Decision No. 2025-1154 QPC of August 8, 2025, of the Constitutional Council; Having regard to Decision No. 2025-125C of July 7, 2025, by the President of the National Commission for Information Technology and Civil Liberties, instructing the Secretary General to conduct or arrange for an audit of the processing operations carried out by or on behalf of the company HOPITAL PRIVE DE LA LOIRE; Whereas the President of the National Commission for Information Technology and Civil Liberties issued a decision on February 19, 2026, appointing a rapporteur to the select panel; Whereas the report by Ms. Anne DEBET, the reporting commissioner, was served on HOPITAL PRIVE DE LA LOIRE on March 5, 2026; Whereas the written observations submitted by HOPITAL PRIVE DE LA LOIRE on April 3, 2026; Having regard to the closure of the investigation, notified to the company on May 18, 2026; Having regard to the letter from the chair of the restricted panel dated May 18, 2026, informing the company that the case was on the agenda of the restricted panel meeting on June 18, 2026; Whereas oral observations were made during the session of the select panel on June 18, 2026; Whereas the other documents in the case file, The following were present at the session of the select panel on June 18, 2026: - Ms. Anne DEBET, commissioner, whose report was heard; Acting as representatives of HOPITAL PRIVE DE LA LOIRE: - […] The company HOPITAL PRIVE DE LA LOIRE having been informed of its right to remain silent regarding the allegations against it and having been given the last oppo