France’s Hôpital privé de la Loire (HPL) has been hit with a hefty €500,000 fine for its egregious failure to protect sensitive patient data. The breach, which occurred in summer 2025, exposed the personal information of an astonishing 727,000 individuals – including patients and their relatives who were designated as trusted third parties.
The hospital’s electronic patient record system was compromised when an attacker gained access to a single doctor’s account, allowing them to explore the entire internal system without detection. The hacker, known by the alias “Marak”, claimed responsibility for the breach, stating that they had attempted to sell the stolen data to a single buyer for between €2,000 and €5,000.
The investigation into the breach was conducted by France’s data protection authority (CNIL), which identified several critical shortcomings in HPL’s security measures. One of the most glaring issues was the lack of robust access controls, allowing external users – including private-practice physicians – to access the system without multi-factor authentication or a virtual private network (VPN). This made it easy for the attacker to navigate the system and extract sensitive data.
CNIL also found that HPL lacked real-time monitoring and alerting capabilities, which would have enabled the hospital to detect the breach sooner. As a result, the attacker was able to roam the system undetected, extracting large volumes of data over several days. The hospital’s slow response to the incident was also criticized, as they failed to directly notify the 202,246 trusted third parties whose data had been stolen.
The breaches identified by CNIL relate to Article 32 and Article 34 of the General Data Protection Regulation (GDPR), which stipulate that organizations must implement adequate security measures to protect personal data and notify affected individuals in the event of a breach. While HPL has since taken steps to strengthen its security, the fine serves as a stark reminder of the importance of prioritizing data protection.
The aftermath of the breach highlights the growing threat posed by insider threats – where attackers use valid credentials to gain access to sensitive systems. According to recent research, once attackers have gained access using valid credentials, only 37% of their actions are blocked, highlighting the need for organizations to invest in robust security measures that can detect and respond to insider threats.
For HPL, the fine serves as a warning that data protection must be taken seriously. For healthcare organizations everywhere, it’s a stark reminder that protecting sensitive patient data is not just a regulatory requirement, but a moral obligation. As we continue to navigate the complex landscape of cybersecurity threats, one thing is clear: data protection must remain a top priority for all organizations handling sensitive personal information.
Source: Bleeping Computer — 2026-09-03