< Back to all clusters
[TECHNOLOGY] · France · 3 sources

started · updated

Hôpital Privé de la Loire fined 500,000 euros after major cyberattack

The French data protection authority, CNIL, has fined the Hôpital Privé de la Loire 500,000 euros following a cyberattack that exposed the personal and health data of over 727,000 individuals.

The breach, which occurred in the summer of 2025, compromised the records of 524,867 patients and 202,246 designated “trusted persons.” Investigations revealed critical security failures, including the lack of a Virtual Private Network (VPN) and the absence of multi-factor authentication (MFA) for external users, such as doctors accessing the computerized patient record system.

Furthermore, the hospital failed to implement adequate access controls. Once the attacker obtained a single set of credentials, the lack of data compartmentalization allowed them to access the entire patient database rather than being restricted to specific care teams. CNIL noted that the hospital also lacked effective mechanisms to detect suspicious behavior within its information system in real time.

Entities

CNIL · Hôpital Privé de la Loire