Back to Feed
PolicySep 16, 2026

CNIL (France) - SAN-2026-009

French DPA fines hospital €500,000 for data breach and failure to notify affected third parties.

Summary

France's CNIL has fined Hôpital Privé de la Loire €500,000 following a data breach that exposed over 524,000 patient records. The hospital failed to implement adequate security measures, such as multi-factor authentication, and did not directly notify 202,246 affected third parties whose data was compromised, violating GDPR Articles 32 and 34.

Full text

Help CNIL (France) - SAN-2026-009: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 14:47, 15 September 2026 view sourceLs (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators422 editsTag: Visual edit← Older edit Latest revision as of 12:04, 16 September 2026 view source Sf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators79 editsmTag: Visual edit Line 96: Line 96: }}}} The DPA found that a hospital, victim of a data breach, lacked sufficient measures to protect the patients data pre breach and that its reaction to the breach - assigning a shared password and failing to inform 202,246 affected third parties of the breach - was in violation of Articles XX. The DPA fined the hospital €500,000.The DPA found that a hospital, victim of a data breach, lacked sufficient measures to protect the patients data pre breach and that its reaction to the breach - assigning a shared password and failing to inform 202,246 affected third parties of the breach - was in violation of Articles 32 and 34 GDPR. The DPA fined the hospital €500,000. == English Summary ==== English Summary == Latest revision as of 12:04, 16 September 2026 CNIL - SAN-2026-009 Authority: CNIL (France) Jurisdiction: France Relevant Law: Article 32 GDPR Article 34 GDPR L. 1110-4 French Public Health CodeL. 1110-12 French Public Health Code Type: Investigation Outcome: Violation Found Started: 04.06.2025 Decided: 21.07.2026 Published: 03.09.2026 Fine: 500000.0 EUR Parties: Hôpital Privé de la Loire National Case Number/Name: SAN-2026-009 European Case Law Identifier: n/a Appeal: Unknown Original Language(s): French Original Source: Legifrance (in FR) Initial Contributor: bms The DPA found that a hospital, victim of a data breach, lacked sufficient measures to protect the patients data pre breach and that its reaction to the breach - assigning a shared password and failing to inform 202,246 affected third parties of the breach - was in violation of Articles 32 and 34 GDPR. The DPA fined the hospital €500,000. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts In June 2025, an attacker obtained the credentials of a doctor affiliated with Hôpital Privé de la Loire, the controller, and used them to access the hospital's electronic patient record system. Between 26 June and 1 July 2025, the attacker extracted 524,867 patient records. The compromised data included identification and contact information, social security numbers and, in some cases, identity documents and health data. The records also contained personal data relating to 202,246 persons designated by patients as trusted third parties. After discovering the breach, the controller notified the CNIL, the DPA, and informed the affected patients through different communication channels. However, it did not directly inform the 202,246 trusted third parties whose data had also been compromised. The DPA subsequently carried out an on-site investigation into the controller's data processing practices. The investigation identified several security deficiencies in the electronic patient record system. External users could access it remotely using only a username and password, without a VPN or multi-factor authentication. Moreover, healthcare professionals could access patient records of patients they had no relation with, the system lacked adequate proactive analysis of access logs, and the software provider had permanent access to the system without prior authorisation by the controller. Following the breach, the controller had also temporarily assigned the same password to all external practitioners when resetting their credentials. Holding The DPA found that the controller violated Article 32 GDPR by failing to implement appropriate technical and organisational measures to secure the electronic patient record system. The DPA first considered that remote access by external practitioners was insufficiently protected because it relied only on a username and password, without multi-factor authentication or a VPN. Given the sensitivity and volume of the health data processed, stronger authentication measures were required. The lack of such safeguards also facilitated the breach, as the attacker accessed the system using compromised credentials. The DPA further found that the controller's access-rights policy was too broad, since healthcare professionals could access records of patients for whose care they were not responsible. In addition, although access logs were collected, they were not analysed in real time or shortly afterwards to detect abnormal activity. This allowed the attacker to extract a very large number of records over several days without triggering an alert. The DPA also considered that confidentiality was insufficiently protected because, after the breach, the controller temporarily assigned the same password to all external practitioners. Moreover, the software provider had permanent access to the system without prior authorisation by the controller. The DPA additionally found a violation of Article 34 GDPR because the controller did not directly inform the 202,246 trusted third parties whose personal data had been compromised. A general notice published on the hospital's website was not sufficient to meet the obligation to communicate a high-risk personal data breach to affected data subjects. The DPA fined the controller €500,000 and ordered it to improve log monitoring, revise its access-rights policy and restrict the software provider's access to situations where prior authorisation had been granted. The orders were subject to a penalty payment of €1,000 per day of delay. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the French original. Please refer to the French original for more details. Decision SAN-2026-009 of July 21, 2026 National Commission for Information Technology and Civil Liberties Nature of the decision: Sanction Date of publication on Légifrance: Thursday, September 3, 2026 Decision No. SAN-2026-009 of the Select Panel dated July 21, 2026, concerning the company HOPITAL PRIVE DE LA LOIRE The National Commission for Information Technology and Civil Liberties, meeting in its select panel composed of Mr. Philippe-Pierre CABOURDIN, Chair, Mr. Vincent LESCLOUS, Vice Chair, Ms. Laurence FRANCESCHINI and Ms. Isabelle LATOURNARIE-WILLEMS, Mr. Didier KLING and Mr. Bertrand du MARAIS, members, Having regard to Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data; Having regard to Law No. 78-17 of January 6, 1978, on Information Technology, Filing Systems, and Civil Liberties, in particular articles 20 et seq.; Having regard to the Public Health Code; Having regard to Decree No. 2019-536 of May 29, 2019, adopted to implement Law No. 78-17 of January 6, 1978, on Information Technology, Filing Systems, and Civil Liberties; Having regard to Resolution No. 2013-175 of July 4, 2013, adopting the regulations of the National Commission on Information Technology and Civil Liberties; Having regard to Decision No. 2025-1154 QPC of August 8, 2025, of the Constitutional Council; Having regard to Decision No. 2025-125C of July 7, 2025, by the President of the National Commission for Information Technology and Civil Liberties, instructing the Secretary General to conduct or arrange for an audit of the processing operations carried out by or on behalf of the company HOPITAL PRIVE DE LA LOIRE; Whereas the President of the National Commission for Information Technology and Civil Liberties issued a decision on February 19,

Entities

CNIL (vendor)Hôpital Privé de la Loire (product)