French hospital fined €500,000 after breach exposes data of 727,000

French Hospital Fined €500,000 After Massive Data Breach Exposes Sensitive Information of Over 727,000 Individuals

A major French hospital has been slapped with a hefty fine of €500,000 for its failure to adequately protect patients’ and their relatives’ data. The breach, which occurred in the summer of 2025, exposed sensitive information belonging to an astonishing 524,867 patients and another 202,246 people designated as trusted third parties.

Hôpital privé de la Loire (HPL), a general hospital in Saint-Étienne with over 650 staff members and 333 beds across five clinical divisions, was found to have several security shortcomings. According to the investigation conducted by France’s data protection authority (CNIL), the hospital failed to implement proper access controls, allowing external users, including private-practice physicians, to access the system without multi-factor authentication. Moreover, the hospital lacked real-time monitoring and alerting capabilities, enabling the attacker to extract a large volume of data over several days without detection.

The breach was attributed to an attacker using the alias “Marak,” who claimed responsibility for the attack through a French outlet. According to Marak’s statement, the attack began with a breach of a single doctor’s account, which granted access to HPL’s entire internal system. The stolen data was reportedly not sold or published.

The CNIL investigation identified several failures to comply with the General Data Protection Regulation (GDPR), specifically Article 32 and Article 34. While the hospital has taken some measures to strengthen its security since the incident, it is clear that more needs to be done to prevent such breaches in the future.

This case highlights the critical importance of robust access controls, timely monitoring, and alerting in preventing data breaches. It also underscores the need for healthcare institutions to prioritize patient data protection and adhere to regulatory requirements. With over 727,000 individuals affected by this breach, it is imperative that hospitals take proactive measures to safeguard sensitive information.

For readers, a key takeaway from this incident is the importance of regular security audits and vulnerability assessments to identify potential weaknesses in access controls and monitoring systems. By staying vigilant and proactive, healthcare institutions can minimize the risk of data breaches and protect their patients’ sensitive information.


Source: Bleeping Computer — 2026-09-03