French Hospital Fined €500,000 for Major Data Breach Exposing 727,000 Records
France's data protection authority, the **CNIL**, has issued a hefty €500,000 fine to **Hôpital privé de la Loire** (**HPL**) following a significant data breach. The incident, which occurred in the summer of 2025, exposed sensitive information belonging to over 727,000 patients and their trusted third parties, highlighting critical security lapses.
The **CNIL** concluded its investigation into the 2025 cyberattack on **Hôpital privé de la Loire** (**HPL**), a general hospital in Saint-Étienne and part of the **Ramsay Santé** healthcare group. The findings reveal a series of security failures that led to the compromise of data for 524,867 patients and an additional 202,246 individuals designated as trusted third parties.

### GDPR Violations Uncovered
The **CNIL**'s investigation identified several key areas where **HPL** failed to meet its obligations under the **General Data Protection Regulation** (**GDPR**), specifically citing violations of Articles 32 (Security of processing) and 34 (Communication of a personal data breach to the data subject).
Key shortcomings included:
* **Inadequate Access Controls**: External users, such as private-practice physicians, could access the system without the mandatory use of a **VPN** or multi-factor authentication (**MFA**).
* **Overly Permissive Access**: A single compromised account gained access to the records of all hospital patients due to insufficient access segmentation.
* **Lack of Real-time Monitoring**: The absence of real-time or near-real-time monitoring and alerting systems allowed the attacker to explore the internal system and exfiltrate a large volume of data over several days without detection.
* **Notification Failures**: While affected patients were informed, the 202,246 trusted third parties whose data was also stolen were not directly notified by the hospital.
### The Attack Vector and Aftermath
The breach, claimed by a teen hacker using the alias “**Marak**,” reportedly began with the compromise of a single doctor’s account. This initial access then granted the attacker entry to **HPL**’s entire internal system.
**Marak** attempted to sell the stolen data for a price between €2,000 and €5,000. However, subsequent reports indicated that the data was neither successfully sold nor publicly disseminated. The **CNIL** noted that **HPL** has implemented several security strengthening measures during the proceedings, a positive step in addressing the identified vulnerabilities.