[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fQD5Dzr9qwOMzwQFXfunq6mFvprK6vAYPkIDZ0dpsWec":3},{"article":4,"iocs":47},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":24,"category":25,"article_tags":29},"de7616be-8f9a-4dd0-8906-a89d03422c2b","CNIL (France) - SAN-2026-009","cnil-france-san-2026-009-6299e2","← Older revision Revision as of 14:47, 15 September 2026 Line 96: Line 96: }} }} The DPA fined a hospital €500,000 for insufficient security measures which enabled a major data breach and for failing to inform 202,246 affected third parties of the breach. The DPA found that a hospital, victim of a data breach, lacked sufficient measures to protect the patients data pre breach and that its reaction to the breach - assigning a shared password and failing to inform 202,246 affected third parties of the breach - was in violation of Articles XX. The DPA fined the hospital €500,000. == English Summary == == English Summary == === Facts === === Facts === In June 2025, an attacker obtained the credentials of a doctor affiliated with Hôpital Privé de la Loire, the controller, and used them to access the hospital's electronic patient record system. Between 26 June and 1 July 2025, the attacker extracted 524,867 patient records. The compromised data included identification and contact information, social security numbers and, in some cases, identity documents and health data. The records also contained personal data relating to 202,246 persons designated by patients as trusted third parties. In June 2025, an attacker obtained the credentials of a doctor affiliated with Hôpital Privé de la Loire, the controller, and used them to access the hospital's electronic patient record system. Between 26 June and 1 July 2025, the attacker extracted 524,867 patient records. The compromised data included identification and contact information, social security numbers and, in some cases, identity documents and health data. The records also contained personal data relating to 202,246 persons designated by patients as trusted third parties. After discovering the breach, the controller notified the CNIL, the DPA, and informed the affected patients through different communication channels. However, it did not directly inform the 202,246 trusted third parties whose data had also been compromised. The DPA subsequently carried out an on-site investigation into the controller's data processing practices. After discovering the breach, the controller notified the CNIL, the DPA, and informed the affected patients through different communication channels. However, it did not directly inform the 202,246 trusted third parties whose data had also been compromised. The DPA subsequently carried out an on-site investigation into the controller's data processing practices. The investigation identified several security deficiencies in the electronic patient record system. External users could access it remotely using only a username and password, without a VPN or multi-factor authentication. Moreover, healthcare professionals could access patient records even when they were not involved in the patient's care, the system lacked adequate proactive analysis of access logs, and the software provider had permanent access to the system without prior authorisation by the controller. Following the breach, the controller had also temporarily assigned the same password to all external practitioners when resetting their credentials. The investigation identified several security deficiencies in the electronic patient record system. External users could access it remotely using only a username and password, without a VPN or multi-factor authentication. Moreover, healthcare professionals could access patient records of patients they had no relation with, the system lacked adequate proactive analysis of access logs, and the software provider had permanent access to the system without prior authorisation by the controller. Following the breach, the controller had also temporarily assigned the same password to all external practitioners when resetting their credentials. === Holding === === Holding === The DPA found that the controller violated [[Article 32 GDPR]] by failing to implement appropriate technical and organisational measures to secure the electronic patient record system. The DPA found that the controller violated [[Article 32 GDPR]] by failing to implement appropriate technical and organisational measures to secure the electronic patient record system.","France's data protection authority (CNIL) has fined Hôpital Privé de la Loire €500,000 for security failures that led to a major data breach. The hospital lacked adequate security measures, allowing an attacker to access and extract over 524,000 patient records, including sensitive health data and social security numbers. Additionally, the hospital failed to notify 202,246 trusted third parties whose data was also compromised, violating GDPR requirements.","France's CNIL fines a hospital €500,000 for data breach and failure to notify third parties.","Help CNIL (France) - SAN-2026-009: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 12:49, 3 September 2026 view sourceBms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators309 editsTag: Visual edit← Older edit Latest revision as of 14:47, 15 September 2026 view source Ls (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators415 editsTag: Visual edit Line 96: Line 96: }}}} The DPA fined a hospital €500,000 for insufficient security measures which enabled a major data breach and for failing to inform 202,246 affected third parties of the breach.The DPA found that a hospital, victim of a data breach, lacked sufficient measures to protect the patients data pre breach and that its reaction to the breach - assigning a shared password and failing to inform 202,246 affected third parties of the breach - was in violation of Articles XX. The DPA fined the hospital €500,000. == English Summary ==== English Summary == === Facts ====== Facts === In June 2025, an attacker obtained the credentials of a doctor affiliated with Hôpital Privé de la Loire, the controller, and used them to access the hospital's electronic patient record system. Between 26 June and 1 July 2025, the attacker extracted 524,867 patient records. The compromised data included identification and contact information, social security numbers and, in some cases, identity documents and health data. The records also contained personal data relating to 202,246 persons designated by patients as trusted third parties.In June 2025, an attacker obtained the credentials of a doctor affiliated with Hôpital Privé de la Loire, the controller, and used them to access the hospital's electronic patient record system. Between 26 June and 1 July 2025, the attacker extracted 524,867 patient records. The compromised data included identification and contact information, social security numbers and, in some cases, identity documents and health data. The records also contained personal data relating to 202,246 persons designated by patients as trusted third parties. After discovering the breach, the controller notified the CNIL, the DPA, and informed the affected patients through different communication channels. However, it did not directly inform the 202,246 trusted third parties whose data had also been compromised. The DPA subsequently carried out an on-site investigation into the controller's data processing practices.After discovering the breach, the controller notified the CNIL, the DPA, and informed the affected patients through different communication channels. However, it did not directly inform the 202,246 trusted third parties whose data had also been compromised. The DPA subsequently carried out an on-site investigation into the controller's data processing practices. The investigation identified several security deficiencies in the electronic patient record system. External users could access it remotely using only a username and password, without a VPN or multi-factor authentication. Moreover, healthcare professionals could access patient records even when they were not involved in the patient's care, the system lacked adequate proactive analysis of access logs, and the software provider had permanent access to the system without prior authorisation by the controller. Following the breach, the controller had also temporarily assigned the same password to all external practitioners when resetting their credentials.The investigation identified several security deficiencies in the electronic patient record system. External users could access it remotely using only a username and password, without a VPN or multi-factor authentication. Moreover, healthcare professionals could access patient records of patients they had no relation with, the system lacked adequate proactive analysis of access logs, and the software provider had permanent access to the system without prior authorisation by the controller. Following the breach, the controller had also temporarily assigned the same password to all external practitioners when resetting their credentials. === Holding ====== Holding === The DPA found that the controller violated [[Article 32 GDPR]] by failing to implement appropriate technical and organisational measures to secure the electronic patient record system.The DPA found that the controller violated [[Article 32 GDPR]] by failing to implement appropriate technical and organisational measures to secure the electronic patient record system. Latest revision as of 14:47, 15 September 2026 CNIL - SAN-2026-009 Authority: CNIL (France) Jurisdiction: France Relevant Law: Article 32 GDPR Article 34 GDPR L. 1110-4 French Public Health CodeL. 1110-12 French Public Health Code Type: Investigation Outcome: Violation Found Started: 04.06.2025 Decided: 21.07.2026 Published: 03.09.2026 Fine: 500000.0 EUR Parties: Hôpital Privé de la Loire National Case Number\u002FName: SAN-2026-009 European Case Law Identifier: n\u002Fa Appeal: Unknown Original Language(s): French Original Source: Legifrance (in FR) Initial Contributor: bms The DPA found that a hospital, victim of a data breach, lacked sufficient measures to protect the patients data pre breach and that its reaction to the breach - assigning a shared password and failing to inform 202,246 affected third parties of the breach - was in violation of Articles XX. The DPA fined the hospital €500,000. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts In June 2025, an attacker obtained the credentials of a doctor affiliated with Hôpital Privé de la Loire, the controller, and used them to access the hospital's electronic patient record system. Between 26 June and 1 July 2025, the attacker extracted 524,867 patient records. The compromised data included identification and contact information, social security numbers and, in some cases, identity documents and health data. The records also contained personal data relating to 202,246 persons designated by patients as trusted third parties. After discovering the breach, the controller notified the CNIL, the DPA, and informed the affected patients through different communication channels. However, it did not directly inform the 202,246 trusted third parties whose data had also been compromised. The DPA subsequently carried out an on-site investigation into the controller's data processing practices. The investigation identified several security deficiencies in the electronic patient record system. External users could access it remotely using only a username and password, without a VPN or multi-factor authentication. Moreover, healthcare professionals could access patient records of patients they had no relation with, the system lacked adequate proactive analysis of access logs, and the software provider had permanent access to the system without prior authorisation by the controller. Following the breach, the controller had also temporarily assigned the same password to all external practitioners when resetting their credentials. Holding The DPA found that the controller violated Article 32 GDPR by failing to implement appropriate technical and organisational measures to secure the electronic patient record system. The DPA first considered that remote access by external practitioners was insufficiently protected because it relied only on a username and password, without multi-factor authentication or a VPN. Given the sensitivity and volume of the health data processed, stronger authentication measures were required. The lack of such safeguards also facilitated the breach, as the attacker accessed the system using compromised credentials. The DPA further found that the controller's access-rights policy was too broad, since healthcare professionals could access records of patients for whose care they were n","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=CNIL_(France)_-_SAN-2026-009&diff=53038&oldid=52910","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002Fthumb\u002F0\u002F0f\u002FLogoFR.png\u002F1200px-LogoFR.png","2026-09-15T14:47:08+00:00","2026-09-15T16:00:45.478174+00:00",8,[18,21],{"name":19,"type":20},"CNIL","vendor",{"name":22,"type":23},"electronic patient record system","product","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":24,"icon":26,"name":27,"slug":28},null,"Policy","policy",[30,35,40,42],{"category":31},{"id":32,"icon":26,"name":33,"slug":34},"2e06f76c-d5b9-4f54-9eef-4d3447b10730","Breaches","breaches",{"category":36},{"id":37,"icon":26,"name":38,"slug":39},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":41},{"id":24,"icon":26,"name":27,"slug":28},{"category":43},{"id":44,"icon":26,"name":45,"slug":46},"d95477d7-eb04-4fad-a2dc-be1428040ce7","Privacy Fines","privacy-fines",[]]