A €500,000 fine: at Hôpital privé de la Loire, one account was all it took

An attacker used a doctor's credentials and exfiltrated 524,867 patient records. The alert came not from any system detecting the extraction, but from a practitioner who could no longer log in. The CNIL's decision shows what must protect the data once the first barrier gives way.
By a decision dated 21 July 2026, published on Légifrance on 3 September 2026, the restricted committee of the CNIL, France's data protection authority, imposed a €500,000 fine on Hôpital privé de la Loire, a private hospital in Saint-Étienne belonging to the Ramsay Santé group. It found two breaches of the GDPR: inadequate data security under Article 32, and incomplete information to the people affected by the breach under Article 34.
It is worth being precise about what this decision penalises, and what it does not.
Falling victim to a cyberattack does not, in itself, establish a GDPR breach. The CNIL says so expressly: the security obligation is an obligation of means, not of result. The analysis bears on the protections actually in place, whether they matched the risks, and whether they could reduce the likelihood of a breach or limit its consequences.
In this case, it was precisely those protections that were found wanting.
What was exfiltrated: the figures, without distortion
On 26 June 2025, an attacker logged into the electronic patient record (EPR) using the credentials of a private practitioner attached to the hospital. Between 26 June and 1 July, they extracted 524,867 patient records. On 1 July, a practitioner reported a login problem, which triggered the hospital's investigation; the hospital notified the CNIL on 4 July. An on-site inspection took place on 29 July 2025.
Paragraph 12 of the decision details the content of the exfiltrated records:
| Scope established | Data mentioned in the decision |
|---|---|
| 524,867 patient records | Including civil status, social security number, contact details and the patient's permanent identifier. |
| 46,185 of those records | Also the front of the national identity card of the patient or their legal representative. |
| 43 of those records | Health data. |
| 202,246 of those records | Information about the trusted contact designated by the patient: relationship, surname, first name and telephone number. |
These categories overlap: they must not be added together. And 524,867 exfiltrated patient records does not mean 524,867 complete medical files stolen. Precision does not soften the seriousness of the incident; it allows it to be described correctly.
Three failures enabled or aggravated the attack
The restricted committee reasons from the defence-in-depth principle of ANSSI, the French cybersecurity agency: security must never rest on a single element. It therefore examines, one after the other, the barriers that should have compensated for a compromised password.
1. Insufficiently protected remote access
At the time of the breach, around 450 external users, private practitioners, their secretariats and some employees of the software vendor, could reach the EPR over the internet with a username and password, with no prior VPN connection and no two-factor authentication. The CNIL also notes that the deployed version of the software already offered multi-factor authentication, which had not been switched on.
The attacker exploited this weakness. The CNIL stresses that a second factor would have been an additional obstacle: holding the password would not have been enough without that factor. It notes, however, that the hospital has since deployed multi-factor authentication and is now compliant on this point.
This analysis should not be turned into a universal formula mechanically requiring "VPN plus MFA" at every level. The electronic identification framework for digital health services, made binding by the ministerial order of 28 March 2022 and cited in the decision, provides in particular that two-factor authentication when opening the VPN dispenses with requiring it again for the services reached through that VPN. The requirement is effective protection of the access path.
2. Access rights defined by role, but not by patient
The hospital did have an authorisation matrix distinguishing roles and EPR modules. The problem lay elsewhere: records were not partitioned according to the patients actually under a practitioner's care.
A practitioner could therefore open the records of every patient, for the modules their profile allowed, even without taking part in their care. The CNIL considers that this shortcoming directly contributed to the scale of the breach: with partitioning, the leak would have been limited to the patients of the doctor whose credentials were stolen.
An authorisation policy must therefore answer two distinct questions: which information may this professional consult given their duties, and for which patients do they need to consult it? This is the care-team concept of Articles L. 1110-4 and L. 1110-12 of the French Public Health Code, which the CNIL had already recalled in its decision of 29 October 2021 on access management, and which the national health information security policy (PGSSI-S) of the Digital Health Agency spells out for facilities. Emergencies can be handled through a "break-the-glass" mechanism, whose use must be logged and monitored.
The hospital objected that its software did not allow such partitioning. The restricted committee's answer deserves to be quoted verbatim: "the technical limitations of the software do not exonerate the controller, who must ensure that the tool chosen is in line with the state of the art".
3. A mass extraction that never triggered the expected alert
The post-incident analysis revealed a reconnaissance phase of about twelve hours, comprising 665 requests, followed by automated extraction over five days. The CNIL calculates an average of 73 patient records consulted per minute. This abnormal activity was not detected; only a user's report brought the breach to light.
The hospital did have endpoint detection on workstations and servers, a security operations centre and application logs. But those logs were only examined on request, and the network load generated by the attack never crossed the thresholds of the tools in place. The restricted committee stresses that recording and automatically analysing application logs could have revealed the abnormal volume of consultations from a single account, in real time or shortly after, and stopped the exfiltration sooner.
Keeping logs lets you understand what happened. Exploiting them quickly can let you act while it is happening.
The inspection reveals two further shortcomings
One temporary password for every external practitioner. After discovering the incident, the hospital reset the passwords of external users. It assigned the same temporary password to all of them, handed to the chair of the medical committee, who was to pass it on. Valid for one week, the password had to be changed at first login.
The hospital invoked urgency, continuity of care and the technical limits of the software. The decision nevertheless recalls that a password, even a temporary one, must be transmitted in conditions that guarantee its confidentiality, and describes the practice as negligent. Crisis management does not suspend that requirement.
Permanent vendor access to the EPR. The CNIL also notes that the software vendor's employees could access the EPR on their own initiative, without prior authorisation from the hospital. It considers that these rights exceeded what their support and maintenance mission required.
An important point: the later introduction of a bastion host did not cure this breach. The problem was not only securing the connection, but the right to reach the data without prior validation. The CNIL requires a technical mechanism that prevents such access until the facility has authorised it.
A secure connection does not automatically make the access it enables legitimate.
The detail not to miss: the risk was already in the DPIA
The decision reports that a data protection impact assessment carried out in 2021 had already identified the lack of record partitioning as a major threat of illegitimate access. It rated the severity of the risk as maximal, while judging its likelihood limited.
This calls for an essential distinction: identifying a vulnerability is not the same as fixing it. Here, the CNIL notes that the hospital knew how serious the risk was and that it was for the hospital to implement security measures commensurate with it. This is the basis on which the committee finds the breaches negligent.
Our operational recommendation is simple: for every significant risk identified in a DPIA, the compliance review should be able to trace the measure decided, its owner, its deadline, its deployment status and the evidence that it works.
A DPIA should help steer the protection of individuals, not merely document their exposure.
Trusted contacts were entitled to be informed too
On informing patients, the decision is explicit: the CNIL accepts that the hospital's communication was compliant, through a public statement, 126,000 emails, 210,000 text messages and 88,000 letters. It would therefore be inaccurate to say that the hospital informed no one.
No direct information, however, was given to the 202,246 people designated as trusted contacts, whose data had also been taken.
The hospital took the view that this information, which it considered fragmentary, created no high risk. The CNIL reached a different conclusion: names, contact details and family relationships must be assessed together with the information about the patient to whom they are linked. That combination can be used for phishing or identity theft. These are risks identified by the authority, not fraud that the decision establishes actually occurred.
The statement published on the hospital's website was not considered sufficient to inform these people. More generally, Article 34 requires communication to individuals when a breach is likely to result in a high risk, subject to the exceptions it sets out. A public communication therefore does not freely replace direct information; where direct information would involve disproportionate effort, the public communication must be equally effective.
The operational lesson goes beyond this case: in a breach, identify everyone whose data is compromised, not only the holders of the records.
Do not confuse the two communications
Notification to the CNIL, under Article 33, must take place without undue delay and, where feasible, no later than 72 hours after becoming aware of the breach, unless the breach is unlikely to result in a risk to rights and freedoms. Any delay must be justified.
Communication to individuals, under Article 34 in the event of a high risk, must take place without undue delay. That article sets no general 72-hour deadline. They are two distinct obligations.
The penalty: €500,000 and three measures imposed under periodic penalty payments
To set the amount, the restricted committee reasoned at the level of the economic unit to which the hospital belongs, the Ramsay Santé group, in line with the case law of the Court of Justice of the European Union. This is why a hospital running at a loss was fined €500,000. The fine comes with a compliance injunction comprising three measures, each backed by a penalty of €1,000 per day of delay:
| Measure imposed on the facility | Deadline |
|---|---|
| Set up logging and proactive analysis, in real time or very shortly after, capable of detecting abnormal behaviour and triggering appropriate alerts and responses. | 3 months |
| Revise authorisations on a need-to-know and care-team basis, with a break-the-glass mechanism for emergencies. | 15 months |
| Technically prevent the vendor from accessing the EPR without the hospital's prior authorisation. | 3 months |
The facility must provide evidence of compliance. The decision also provides for publication on the CNIL and Légifrance websites, with the company's name removed after two years.
These deadlines apply to this case. They are not a grace period offered to other facilities. Likewise, €500,000 is not an automatic tariff: the CNIL weighs, among other things, the seriousness of the breaches, the compliance steps taken and the financial capacity of the entity fined.
Seven checks to put on your facility's agenda
The checks below are our operational reading of the decision. They replace neither the risk analysis specific to each facility nor a review of the applicable frameworks.
| Question to ask | Concrete evidence to request |
|---|---|
| Is remote access genuinely protected? | A demonstration of the authentication path, including external practitioners and contractors. |
| Do authorisations restrict access to the right records? | Tests by profile and by patient, plus a check of the break-the-glass mechanism. |
| Does abnormal activity trigger a response? | A controlled test showing detection, the alert and how it is handled. |
| Do password resets preserve confidentiality? | A tested procedure, with no shared temporary secret distributed to several users. |
| Is maintenance access under control? | Proof of prior authorisation, of a bounded access window and of its effective closure. |
| Are all categories of affected people identified? | A map including third parties present in the records, a risk assessment and suitable ways of informing them. |
| Do identified risks lead to verifiable action? | A remediation log with owners, deadlines and evidence of completion and testing. |
To test the whole, we recommend a crisis exercise bringing together management, IT, security, the DPO and business representatives. Its frequency should fit the context: the decision does not create a general obligation to hold exactly one exercise a year.
The question to ask before the next incident
This case does not show that a facility could guarantee the absence of any cyberattack. It illustrates the importance of complementary protections: securing the entry point, limiting the data reachable, detecting abnormal behaviour, controlling contractor access and informing the people exposed.
At your next compliance review, do not only ask whether the procedures exist. Ask for a demonstration that they work.
If an account is compromised tomorrow, which records will remain protected, which alert will fire, and who will respond? That is where the conversation should begin.
This article presents the findings of decision SAN-2026-009 of 21 July 2026 and distinguishes them from our editorial team's operational recommendations. The decision may be appealed before the Conseil d'État within two months of its notification; it is not presented here as a final judicial ruling.
Official sources
- Health data breach: EUR 500,000 fine against HÔPITAL PRIVÉ DE LA LOIRE — CNIL, 3 September 2026
- Decision of the restricted committee no. SAN-2026-009 of 21 July 2026 concerning HOPITAL PRIVE DE LA LOIRE — Légifrance (in French)
- Violation de données en matière de santé : sanction de 500 000 euros — CNIL (French press release)
- Sanctions issued by the CNIL — CNIL
- Regulation (EU) 2016/679 (GDPR), Articles 32, 33 and 34 — EUR-Lex
