Back to Feed
PolicySep 9, 2026

Health data breach: the CNIL fined Hôpital Privé de la Loire 500 000 EUR

CNIL fines Hôpital Privé de la Loire €500,000 for a health data breach affecting 524,867 patients.

Summary

The CNIL has fined Hôpital Privé de la Loire €500,000 following a data breach that exposed the personal and health data of 524,867 patients and 202,246 trusted third parties. The breach occurred due to insufficient security measures, including a weak authentication process for external access and inadequate access controls, allowing an attacker to exfiltrate a large volume of data over several days undetected. The hospital also failed to directly inform all affected trusted third parties about the breach.

Full text

Health data breach: the CNIL fined Hôpital Privé de la Loire 500 000 EUR National News 09 September 2026 fr Background informationDate of final decision: 3 September 2026National caseController: Hôpital Privé de la LoireLegal Reference: Article 32 (Security of processing), Article 34 (Communication of a personal data breach to the data subject), Decision: Administrative fineKeywords: Cybersecurity, Personal data breaches, Health and researchSummary of the DecisionOrigin of the caseIn summer 2025, an attacker managed to connect to the Computerised Patient Summary (DPI) of the Hôpital Privé de la Loire (Loire’s private hospital), which centralises all the data of the individuals under care. It thus accessed the data of 524 867 patients (some of them health data) and 202 246 persons designated as “trusted third parties”. As a result of this data breach, the CNIL carried out a check that identified several failures of the Hôpital Privé de la Loire to comply with the obligations laid down in the General Data Protection Regulation (GDPR).Key findingsFailure to ensure the security of personal data (Article 32 GDPR)The authentication procedure to connect to the hospital’s e-Health Patient Summary, used by users outside the hospital, in particular doctors not affiliated with the hospital, was not sufficiently robust, due to the lack of VPNs and multifactor authentication means. The attacker took advantage of this vulnerability to access the data. Moreover, the access control policy was inadequate: it did not take account of the concept of care team, so that only professionals actually involved in the care of a patient had access to the information covered by medical confidentiality. This lack of access limitation allowed the attacker, using the credentials of a single user account, to access the data of all hospital patients. Finally, the hospital had not taken measures to detect suspicious activity within the e-Health Patient Summary in real time or in the very short term, and to trigger an alert mechanism if necessary. In those circumstances, the attacker was able to explore the hospital’s e-Health Patient Summary for several days and extract a very large volume of data, without that abnormal activity being detected. This vulnerability has contributed to exacerbating the scale of the data breach.Failure to inform data subjects about the data breach (Article 34 GDPR)Finally, the restricted committee found that only the patients of the Hôpital Privé de la Loire concerned by the data breach had been informed, but that no direct information had been provided to the 202 246 individuals designated by patients as trusted third parties, even though their personal data had also been stolen by the attacker.DecisionThe restricted committee – the body of the CNIL responsible for issuing sanctions – imposed a fine of 500 000 EUR on the Hôpital Privé de la Loire, taking into account, inter alia, the lack of awareness of essential security principles, the number of persons concerned, the nature of the data compromised and its financial capacities.Further information:Violation de données en matière de santé : sanction de 500 000 euros à l’encontre de l’HÔPITAL PRIVÉ DE LA LOIREHealth data breach: EUR 500,000 fine against HÔPITAL PRIVÉ DE LA LOIRE Relevant topics Cybersecurity Personal data breaches Health and research Latest news National News ie Data Protection Commission announces Final Decision following Inquiry into the Health Service Executive (HSE)03 September 2026 EDPB News Stakeholder event on guidelines on the interplay between data protection and competition law: overview of topics available30 July 2026 EDPB News Stakeholder event on guidelines on the interplay between data protection and competition law: save the date23 July 2026All news

Entities

CNIL (vendor)Computerised Patient Summary (DPI) (product)e-Health Patient Summary (product)