500,000 Euro Fine Imposed on Hôpital Privé de la Loire for Health Data Breach
The National Commission on Informatics and Liberty (CNIL) sanctioned a hospital for serious security failures that allowed access to the data of more than 700,000 individuals, and for only informing part of the victims of the breach.
Facts and Context
The National Commission on Informatics and Liberty (CNIL) issued a sanction decision against HÔPITAL PRIVÉ DE LA LOIRE, including a fine of €500,000, for failures related to the security of patient data and the information of individuals following a data breach.
The case originated from a data breach that occurred during the summer of 2025, during which an attacker accessed the hospital's computerized patient records, compromising the data of 524,867 patients and 202,246 "trusted third parties."
Reasons for the Decision
- Obligation to ensure the security of personal data (Article 32 of the GDPR): The restricted committee found that the security measures were insufficient given the nature and volume of data processed. It noted that the authentication procedure for external users of the computerized patient record lacked a multi-factor authentication mechanism and did not rely on a virtual private network. Furthermore, the authorization policy did not limit data access to only professionals involved in patient care, allowing the attacker, via a single account, to access all records. Finally, the absence of suspicious activity detection measures allowed the attacker to extract a considerable volume of data over several days without being detected.
- Obligation to inform data subjects about the breach (Article 34 of the GDPR): The authority found that the hospital did not communicate the data breach to the 202,246 individuals designated as "trusted third parties," whose personal data had been compromised. This omission deprived these individuals of essential information to understand the risks and take measures to protect themselves against malicious use of their data.
Authority's Decision
Consequently, the authority imposed a fine of €500,000 on HÔPITAL PRIVÉ DE LA LOIRE.
Additionally, the authority ordered the hospital to complete the implementation of corrective security measures within three to fifteen months.
Lessons Learned
This decision reminds that:
- The security of health data requires the implementation of cumulative technical measures, including strong authentication for external access, strict authorization management based on the need to know, and monitoring mechanisms to detect abnormal activities.
- The obligation to inform in case of a data breach, as provided in Article 34 of the GDPR, extends to all natural persons whose data have been compromised, not only those at the core of the main processing (here, the patients).
- The adequacy of security measures must be assessed in light of the risks, and although zero risk does not exist, the absence of basic measures in the face of high risks constitutes a failure.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire