CNIL (France) - SAN-2026-009
CNIL fines French healthcare provider €500K for weak MFA, unauthorized vendor access, and inadequate breach
Summary
France's data protection authority (CNIL) issued a €500,000 fine to a French healthcare provider for critical security failures in its electronic patient record system. The investigation revealed external users could access the system remotely with only username and password (no MFA or VPN), healthcare staff had excessive access rights, a software vendor had permanent unauthorized system access, and the provider failed to notify 202,246 affected individuals of a data breach. The DPA found violations of GDPR Articles 32 (technical safeguards) and 34 (breach notification), and ordered remediation including improved log monitoring and access control restrictions.
Full text
Help CNIL (France) - SAN-2026-009: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Revision as of 12:45, 3 September 2026 view sourceBms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators296 edits Tag: Decisions [1.0] Latest revision as of 12:49, 3 September 2026 view source Bms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators296 editsTag: Visual edit Line 106: Line 106: The investigation identified several security deficiencies in the electronic patient record system. External users could access it remotely using only a username and password, without a VPN or multi-factor authentication. Moreover, healthcare professionals could access patient records even when they were not involved in the patient's care, the system lacked adequate proactive analysis of access logs, and the software provider had permanent access to the system without prior authorisation by the controller. Following the breach, the controller had also temporarily assigned the same password to all external practitioners when resetting their credentials.The investigation identified several security deficiencies in the electronic patient record system. External users could access it remotely using only a username and password, without a VPN or multi-factor authentication. Moreover, healthcare professionals could access patient records even when they were not involved in the patient's care, the system lacked adequate proactive analysis of access logs, and the software provider had permanent access to the system without prior authorisation by the controller. Following the breach, the controller had also temporarily assigned the same password to all external practitioners when resetting their credentials. === Holding ====== Holding === The DPA found that the controller violated [[Article 32 GDPR|Article 32 GDPR]] by failing to implement appropriate technical and organisational measures to secure the electronic patient record system.The DPA found that the controller violated [[Article 32 GDPR]] by failing to implement appropriate technical and organisational measures to secure the electronic patient record system. The DPA first considered that remote access by external practitioners was insufficiently protected because it relied only on a username and password, without multi-factor authentication or a VPN. Given the sensitivity and volume of the health data processed, stronger authentication measures were required. The lack of such safeguards also facilitated the breach, as the attacker accessed the system using compromised credentials.The DPA first considered that remote access by external practitioners was insufficiently protected because it relied only on a username and password, without multi-factor authentication or a VPN. Given the sensitivity and volume of the health data processed, stronger authentication measures were required. The lack of such safeguards also facilitated the breach, as the attacker accessed the system using compromised credentials. Line 117: Line 115: The DPA also considered that confidentiality was insufficiently protected because, after the breach, the controller temporarily assigned the same password to all external practitioners. Moreover, the software provider had permanent access to the system without prior authorisation by the controller.The DPA also considered that confidentiality was insufficiently protected because, after the breach, the controller temporarily assigned the same password to all external practitioners. Moreover, the software provider had permanent access to the system without prior authorisation by the controller. The DPA additionally found a violation of [[Article 34 GDPR|Article 34 GDPR]] because the controller did not directly inform the 202,246 trusted third parties whose personal data had been compromised. A general notice published on the hospital's website was not sufficient to meet the obligation to communicate a high-risk personal data breach to affected data subjects.The DPA additionally found a violation of [[Article 34 GDPR]] because the controller did not directly inform the 202,246 trusted third parties whose personal data had been compromised. A general notice published on the hospital's website was not sufficient to meet the obligation to communicate a high-risk personal data breach to affected data subjects. The DPA fined the controller €500,000 and ordered it to improve log monitoring, revise its access-rights policy and restrict the software provider's access to situations where prior authorisation had been granted. The orders were subject to a penalty payment of €1,000 per day of delay.The DPA fined the controller €500,000 and ordered it to improve log monitoring, revise its access-rights policy and restrict the software provider's access to situations where prior authorisation had been granted. The orders were subject to a penalty payment of €1,000 per day of delay. Latest revision as of 12:49, 3 September 2026 CNIL - SAN-2026-009 Authority: CNIL (France) Jurisdiction: France Relevant Law: Article 32 GDPR Article 34 GDPR L. 1110-4 French Public Health CodeL. 1110-12 French Public Health Code Type: Investigation Outcome: Violation Found Started: 04.06.2025 Decided: 21.07.2026 Published: 03.09.2026 Fine: 500000.0 EUR Parties: Hôpital Privé de la Loire National Case Number/Name: SAN-2026-009 European Case Law Identifier: n/a Appeal: Unknown Original Language(s): French Original Source: Legifrance (in FR) Initial Contributor: bms The DPA fined a hospital €500,000 for insufficient security measures which enabled a major data breach and for failing to inform 202,246 affected third parties of the breach. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts In June 2025, an attacker obtained the credentials of a doctor affiliated with Hôpital Privé de la Loire, the controller, and used them to access the hospital's electronic patient record system. Between 26 June and 1 July 2025, the attacker extracted 524,867 patient records. The compromised data included identification and contact information, social security numbers and, in some cases, identity documents and health data. The records also contained personal data relating to 202,246 persons designated by patients as trusted third parties. After discovering the breach, the controller notified the CNIL, the DPA, and informed the affected patients through different communication channels. However, it did not directly inform the 202,246 trusted third parties whose data had also been compromised. The DPA subsequently carried out an on-site investigation into the controller's data processing practices. The investigation identified several security deficiencies in the electronic patient record system. External users could access it remotely using only a username and password, without a VPN or multi-factor authentication. Moreover, healthcare professionals could access patient records even when they were not involved in the patient's care, the system lacked adequate proactive analysis of access logs, and the software provider had permanent access to the system without prior authorisation by the controller. Following the breach, the controller had also temporarily assigned the same password to all external practitioners when resetting their credentials. Holding The DPA found that the controller violated Article 32 GDPR by failing to implement appropriate technical and organisational measures to secure the electronic patient record system. The DPA first considered that remote access by external practitioners was insufficiently protected because it relied only on a username and password, without multi-factor authentication or a VPN. Given the sensitivity and volume of the health data processed, stronger authentication measures were required. The lack of such safeguards al