Health data breach: EUR 500,000 fine against HÔPITAL PRIVÉ DE LA LOIRE
03 September 2026
On 3 September 2026, the CNIL imposed a penalty of EUR 500,000 on HÔPITAL PRIVÉ DE LA LOIRE for failing to take appropriate measures to ensure the security of the data of its patients and some of their relatives.
Background information
In summer 2025, an attacker managed to connect to the Computerised Patient Summary (DPI) of the HÔPITAL PRIVÉ DE LA LOIRE (Loire’s private hospital), which centralises all the data of the individuals under care. It thus accessed the data of 524,867 patients (some of them health data) and 202 246 persons designated as “trusted third parties”.
As a result of this data breach, the CNIL carried out a check that identified several failures of the HÔPITAL PRIVÉ DE LA LOIRE to comply with the obligations laid down in the General Data Protection Regulation (GDPR).
Consequently, the restricted committee – the body of the CNIL responsible for issuing sanctions – imposed a fine of EUR 500,000 on the HÔPITAL PRIVÉ DE LA LOIRE, taking into account, inter alia, the lack of knowledge of essential security principles, the number of persons concerned, the nature of the data compromised and its financial capacities.
The infringements sanctionned
Failure to ensure the security of personal data (Article 32 GDPR)
The restricted committee found that at the time of the data breach, the HÔPITAL PRIVÉ DE LA LOIRE had not implemented some basic security measures that could have made the attack more difficult.
The authentication procedure to connect to the hospital’s e-Health Patient Summary, used by users outside the hospital, in particular liberal doctors, was not sufficiently robust, due to the lack of VPNs and multifactor authentication means. The attacker took advantage of this vulnerability to access the data.
Moreover, the access control policy was inadequate: it did not take account of the concept of care team, so that only professionals actually involved in the care of a patient had access to the information covered by medical confidentiality. This lack of access limitation allowed the attacker, using the credentials of a single user account, to access the data of all hospital patients.
Finally, the hospital had not taken measures to detect suspicious activity within the e-Health Patient Summary in real time or in the very short term, and to trigger an alert mechanism if necessary. In those circumstances, the attacker was able to explore the hospital’s e-Health Patient Summary for several days and extract a very large volume of data, without that abnormal activity being detected. This vulnerability has contributed to exacerbating the scale of the data breach.
Given the number and nature of the data processed, the restricted training considered that the security measures deployed by the HÔPITAL PRIVÉ DE LA LOIRE to ensure their confidentiality were not sufficient. It recalled that, even if it is impossible to eliminate any risk, appropriate safety measures can reduce its probability and severity.
The restricted formation also noted that the HÔPITAL PRIVÉ DE LA LOIRE had taken several measures in the course of the procedure to increase its level of security. It required the hospital to complete the implementation of those measures within a period of between three and 15 months (depending on the type of measures).
Failure to inform data subjects about the data breach (Article 34 GDPR)
Finally, the restricted committee found that only the patients of the HÔPITAL PRIVÉ DE LA LOIRE concerned by the data breach had been informed, but that no direct information had been provided to the 202,246 individuals designated by patients as trusted third parties, even though their personal data had also been stolen by the attacker.
It considered that that omission had, inter alia, deprived those individuals of the information necessary to understand the nature of the attack and its likely consequences, as well as to know the measures to limit its consequences and to guard against any malicious use of their data.