Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [ACTIVE] · [TECHNOLOGY]
2 clusters · 11 sources · 5 days · First seen · Last updated
Hôpital Privé de la Loire data breach and CNIL fine
Overview
The French data protection authority, CNIL, has imposed a 500,000 euro fine on Hôpital Privé de la Loire (HPL) following a major cyberattack that occurred in the summer of 2025. The breach compromised the personal and health data of approximately 524,867 patients and 202,246 designated “trusted third parties” or “trusted persons.”
Investigations into the incident revealed several critical security failures under the General Data Protection Regulation (GDPR). CNIL identified that authentication procedures for external users, such as general practitioners, were insufficiently robust due to a lack of Virtual Private Networks (VPNs) and multi-factor authentication (MFA).
Additionally, the hospital lacked adequate access controls and data compartmentalization. Once an attacker obtained a single set of credentials, they were able to access the entire patient database rather than being restricted to specific care teams. The regulator also noted that the hospital failed to implement effective mechanisms to detect suspicious IT activity in real time, allowing the attacker to extract large volumes of data over several days.
Furthermore, the hospital failed to inform affected trusted third parties about the breach. The HPL board of directors is currently considering an appeal to the Council of State regarding the fine.
Entities
Timeline
-
5 days ago
[TECHNOLOGY] 3 sourcesHôpital Privé de la Loire fined 500,000 euros after major cyberattackFrance's CNIL fined Hôpital Privé de la Loire 500,000 euros after a cyberattack exposed the data of over 727,000 people due to inadequate authentication and access controls.
-
9 days ago
[TECHNOLOGY] 8 sourcesHôpital Privé de la Loire fined 500,000 euros after major data breachFrance's CNIL fined Hôpital Privé de la Loire 500,000 euros after a 2025 cyberattack compromised the health data of over 524,000 patients due to inadequate security measures.
Sources
blogspan.net · cybernoz.com · edpb.europa.eu · entrevue.fr · leprogres.fr · notretemps.com · oceans.ubc.ca · pplware.sapo.pt · silicon.fr · sudouest.fr · unamglobal.unam.mx