started · updated
Hôpital Privé de la Loire fined 500,000 euros after major data breach
The French data protection authority, CNIL, has imposed a 500,000 euro fine on the Hôpital Privé de la Loire (HPL) following a major cyberattack in the summer of 2025. The breach resulted in the theft of personal and health data belonging to approximately 524,867 patients and 202,246 designated “trusted third parties.”
CNIL identified several critical security failures under the General Data Protection Regulation (GDPR). Specifically, the authority noted that authentication procedures for external users, such as general practitioners, were insufficiently robust due to a lack of VPNs and multi-factor authentication. Furthermore, the hospital failed to implement adequate measures to detect suspicious IT activity, allowing the attacker to explore and extract large volumes of data over several days without detection.
The regulator also cited failures in the hospital's authorization policies and its failure to inform the affected trusted third parties about the breach. The board of directors for HPL LDA is currently considering an appeal to the Council of State regarding the decision.