Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Sep 06, 2026 · 6 min read

CNIL Fines Hospital €500K After 727,000 Records Leak

The regulator did not punish the intrusion. It punished three controls that were missing before it and one letter that never got sent after.

One doctor's login. That was the whole attack. A physician working in private practice signed into the patient record system at Hôpital privé de la Loire in Saint-Étienne the way he always did, across the open internet, with a password and nothing else. Someone else eventually signed in as him and spent days reading medical files belonging to half a million people, unnoticed. On September 3, 2026, France's data protection regulator priced that failure at €500,000.

Key Takeaways

  • France's CNIL fined Hôpital privé de la Loire €500,000 on September 3, 2026 over a summer 2025 breach affecting 524,867 patients and 202,246 trusted third parties, per the CNIL's published decision.
  • The CNIL found infringements of GDPR Article 32 on security of processing and Article 34 on communicating a breach to the people affected.
  • Multi factor authentication had been available in the hospital's patient record software since 2024 and was never enabled for the external physicians, who also connected without a VPN.
  • One compromised account could read every patient file in the system, and no alerting flagged an extraction that ran for days.
  • Beyond the fine, the CNIL ordered access logging within 3 months and a rebuild of access authorizations within 15 months, under a penalty of €1,000 per day of delay, and published the decision under the hospital's name for two years.

What Did CNIL Actually Fine the Hospital For?

Not for being breached. The CNIL fined Hôpital privé de la Loire for three security gaps that existed before anyone broke in, plus one notification duty it failed afterwards.

The Article 32 findings read like an internal audit nobody acted on:

  • External users authenticated with a password alone. Physicians in private practice reached the patient record without a VPN and without a second factor, though the vendor had shipped multi factor authentication in 2024.
  • Access was not scoped to the care relationship. Authorizations never limited an account to the patients it was actually treating.
  • Nothing was watching. No detection or alerting on suspicious activity existed, so a bulk read of the database looked like a busy clinic day.

Article 32 of the General Data Protection Regulation names no specific technology. It requires security appropriate to the risk, and this decision makes that abstraction concrete: when the data is 500,000 health records, appropriate means the controls your own vendor already sold you.

How Did One Account Reach 727,000 Records?

Because the hospital's access model treated any authenticated physician as authorized to read every patient in the building.

A teenager using the handle "Marak" claimed the attack on Telegram, telling French outlet Le Progrès that compromising one doctor's account handed him the entire internal system. He then tried to sell the file to a single buyer for €2,000 to €5,000. As BleepingComputer reported, the data was never sold and never published.

Hold that detail. No victim was defrauded, no dataset surfaced on a forum, and the fine landed anyway. Regulators assess controls, not the body count, and a lucky outcome buys nothing at the hearing. It is the same logic behind the €5 million CNIL fine against France Travail in January 2026.

A dim hospital administrative office at night with an unattended workstation glowing on a desk beside stacked patient file folders and a badge reader by the closed door

Why Does Article 34 Matter Here?

Because 202,246 of the people in that database had never been patients of the hospital at all.

Under French health law a patient names a personne de confiance, a trusted third party who can be consulted if that patient cannot speak for themselves. Spouses, adult children, close friends. They filled in no admission form and often never knew a hospital held their contact details at all. The hospital notified its patients. It did not directly notify those 202,246 people, and that omission is the Article 34 half of the fine.

This is the failure mode most breach playbooks share. Notification workflows get built on the customer table, because that is the table holding verified addresses. Emergency contacts, beneficiaries and dependents sit outside the query and therefore outside the letter. The EDPB guidelines on personal data breach notification work through example by example when direct communication is owed.

Article 34 rarely carries a fine alone, and the numbers stay small when it does; Poland's regulator assessed roughly €6,800 against the County Hospital in Września on Articles 33 and 34. Pairing it with Article 32 is what makes this decision worth reading twice. The same identification problem is playing out live in Germany, where Rhysida published 16,389 Berlin email addresses and plaintext logins and the city had to stand up a task force just to work out who was in the file.

The Part That Costs More Than the Fine

Every headline led with €500,000. Divided across 727,113 affected people, that is 69 cents each, and it is the cheapest part of the decision.

When the CNIL hit Free Mobile with €42 million after 24 million customer records walked out, that came to about €1.75 per record. A hospital holding health data, the most sensitive category the GDPR recognizes, was assessed at roughly a third of that rate per person. Turnover caps and cooperation credit explain most of the gap.

The injunctions bite harder. Effective access logging within 3 months. A full revision of access authorizations within 15 months. Miss either and the meter runs at €1,000 per day, so a year of slippage costs €365,000, close to the fine again. Add two years of the decision sitting on the CNIL's public sanctions register under the hospital's name. The fine is a line item. The injunction is a project plan with a price attached to every slipped sprint.

What Should Compliance Teams Change This Quarter?

Start with the assumption the CNIL started with: a valid credential is not an authorization, and no alert means no discovery.

  • Inventory every external account touching production data. Contractors, affiliated practitioners, partner sites. They almost always predate the identity policy that would have covered them.
  • Ask whether the control exists but is switched off. The most expensive detail here is that the vendor shipped multi factor authentication in 2024. Enforced second factor authentication is baseline guidance in NIST SP 800-63B, and a licensed but unused feature looks worse at a hearing than a missing one.
  • Test the blast radius of one account. Log in as an average user and try to pull the whole table. If you can, so can whoever phishes that user.
  • Alert on volume, not only on failure. This extraction ran for days; a threshold on records read per session would have caught it.
  • Map every category of data subject to a notification channel. Any category with no verified contact method is your Article 34 exposure, documented now or discovered mid incident.

CNIL Is Enforcing Across Its Whole Surface

Reading this as a healthcare security story understates it. The same regulator issued roughly €486.8 million in fines during 2025 and opened 2026 with €47 million in January alone, a pace visible across its published sanctions record. It fined IQVIA Operations France €5 million in May over health data warehouse governance, and it published an April recommendation on consent for marketing measurement whose transition period closed on July 14, 2026.

Those look like unrelated files. They are one posture, and each gets read against the same question: did the controller do the thing it could have done? That question is now the European norm rather than a French quirk, which is why cumulative GDPR penalties crossed €7 billion in 2026.

The hospital fixed its problems during the proceedings and still paid. Remediation is a mitigating factor, never a defense. Every control the CNIL asked about existed before the breach, and what separated a €500,000 decision from an unremarkable Tuesday was somebody deciding the configuration could wait.

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.