French Hospital Hit With $580,000 Fine After Hack Exposes 727,000 Records
France's data protection authority, CNIL, fines Hôpital Privé de la Loire (HPL) €500,000 ($580,000) after a data breach exposes sensitive information belonging to more than 727,000 people. The incident, which occurs in the summer of 2025, affects 524,867 patients and 202,246 trusted third parties at the Saint-Étienne hospital, which is part of the Ramsay Santé healthcare group.
CNIL's investigation identifies multiple GDPR violations that enable the breach. External users, including private-practice physicians, access the electronic patient record system without a VPN or multi-factor authentication, and inadequate access controls allow a single compromised doctor's account to reach records for all hospital patients. The hospital also lacks real-time monitoring, letting the attacker explore the system and extract data over several days without detection, while failing to directly notify the trusted third parties whose data is stolen.
A teenage hacker using the alias Marak claims responsibility, telling the French outlet Le Progrès that the attack begins with a single doctor's account. The hacker attempts to sell the stolen data for between 2,000 and 5,000, though reports indicate the data is never sold or published. CNIL notes that HPL takes several security strengthening measures during the proceedings, but the fine stands as a warning about healthcare cybersecurity obligations under GDPR Articles 32 and 34.