EnforcementEU

Health data breach: the CNIL fined Hôpital Privé de la Loire 500 000 EUR

Published by European Data Protection Board on 2026-09-09

Issued by
European Data Protection Board
Jurisdiction
EU
Takes effect
Not stated
Comments close
Not applicable

In the issuer’s words

Background information

  • Date of final decision: 3 September 2026
  • National case
  • Controller: Hôpital Privé de la Loire
  • Legal Reference: Article 32 (Security of processing), Article 34 (Communication of a personal data breach to the data subject), 
  • Decision: Administrative fine
  • Keywords: Cybersecurity, Personal data breaches, Health and research

Summary of the Decision

Origin of the case

In summer 2025, an attacker managed to connect to the Computerised Patient Summary (DPI) of the Hôpital Privé de la Loire (Loire’s private hospital), which centralises all the data of the individuals under care. It thus accessed the data of 524 867 patients (some of them health data) and 202 246 persons designated as “trusted third parties”. As a result of this data breach, the French Data Protection Authority (CNIL) carried out a check that identified several failures of the Hôpital Privé de la Loire to comply with the obligations laid down in the General Data Protection Regulation (GDPR).

Key findings

  • Failure to ensure the security of personal data (Article 32 GDPR)
    The authentication procedure to connect to the hospital’s e-Health Patient Summary, used by users outside the hospital, in particular doctors not affiliated with the hospital, was not sufficiently robust, due to the lack of VPNs and multifactor authentication means. The attacker took advantage of this vulnerability to access the data. Moreover, the access control policy was inadequate: it did not take account of the concept of care team, so that only professionals actually involved in the care of a patient had access to the information covered by medical confidentiality. This lack of access limitation allowed the attacker, using the credentials of a single user account, to access the data of all hospital patients. Finally, the hospital had not taken measures to detect suspicious activity within the e-Health Patient Summary in real time or in the very short term, and to trigger an alert mechanism if necessary. In those circumstances, the attacker was able to explore the hospital’s e-Health Patient Summary for several days and extract a very large volume of data, without that abnormal activity being detected. This vulnerability has contributed to exacerbating the scale of the data breach.
  • Failure to inform data subjects about the data breach (Article 34 GDPR)
    Finally, the restricted committee found that only the patients of the Hôpital Privé de la Loire concerned by the data breach had been informed, but that no direct information had been provided to the 202 246 individuals designated by patients as trusted third parties, even though their personal data had also been stolen by the attacker.

Decision

The restricted committee – the body of the CNIL responsible for issuing sanctions – imposed a fine of 500 000 EUR on the Hôpital Privé de la Loire, taking into account, inter alia, the lack of awareness of essential security principles, the number of persons concerned, the nature of the data compromised and its financial capacities.

Further information:

© European Union. Reproduced from the European Data Protection Board under Commission Decision 2011/833/EU on the reuse of Commission documents.

Related regimes

Read it at European Data Protection Board
Every entry here is reproduced from the body that issued it, under the licence named above it, and links to the original. Whether an obligation applies to your organisation is a question for your counsel, not for a tracker.