France’s data protection authority has fined Hopital prive de la Loire €500K, about $580K, over security failures that preceded a 2025 breach of more than 727,000 people’s health records. The CNIL published its sanction on September 3 after investigating the intrusion at the Saint-Etienne hospital, part of the Ramsay Sante group.
The agency said the hospital broke GDPR rules on data security and breach notification. Outside clinicians could reach the electronic patient record system without a VPN or multi-factor authentication, access controls let the compromised account read records for every patient in the facility, and the hospital lacked real-time monitoring, so the attacker explored systems and extracted data over several days unnoticed. Direct notification obligations were also missed for 202,246 people recorded as trusted third parties, on top of 524,867 patients.
A teenage hacker using the alias Marak told local media the attack began with the compromise of a single doctor’s account. He tried to sell the data for €2K to €5K, but reports later said the records were neither sold nor published.
The CNIL noted that Hopital prive de la Loire strengthened its security during the proceedings. The fine adds to a growing list of European enforcement actions against healthcare operators over basic access hygiene.