524,867 patient records leaked: €500,000 fine for French hospital
France's CNIL has fined Hôpital privé de la Loire €500,000, a year after the data of 524,867 patients was exfiltrated. The ruling describes basic failures: no VPN, no two-factor authentication, no monitoring of access.

On 3 September 2026, France’s data protection authority, the CNIL, issued a €500,000 fine against Hôpital privé de la Loire, a facility belonging to the Ramsay Santé group. The information is reported by Next, working from the authority’s ruling; it is to date the only available source on the case. The penalty concerns a data breach that occurred in June 2025 on the facility’s computerised patient record system (dossier patient informatisé, DPI). Next notes that the CNIL rarely imposes heavy penalties on hospital organisations, and tends instead to guide them towards better security.
Remote access held together by a username and a password
The attacker connected to the DPI using the credentials of a self-employed doctor attached to the facility. Those credentials were enough: at the time of the events, external users signed in with a username and password, with no prior VPN connection and no two-factor electronic identification.
This was not a point open to interpretation. A security framework covering the electronic identification of users of digital health services has existed since a decree published on 28 March 2022, and it expressly requires those mechanisms to secure external connections. The CNIL also recalls that the security obligation set out in Article 32 of the GDPR is “an obligation of means”: what the hospital is faulted for is failing to put appropriate measures in place to secure that access.
A week of extraction, not one alert
The second failure identified concerns detection. The facility did have a security operations centre (SOC), a supervision system and logging that recorded application traces. What was missing was the activation of automated real-time analysis of those traces on the DPI.
The ruling puts a figure on the consequence: during the automated extraction phase, the attacker’s system was reading an average of 73 patient records per minute, and it did so for close to a week, between 26 June and 1 July 2025. After analysing the logs, the CNIL considers that automated monitoring would probably have spotted that activity.
What the records contained
The exfiltration covered 524,867 patient records containing civil status details, social security number, postal and email contact details, and the permanent patient identifier. More than 46,000 of them were associated with the front of an identity card. More than 202,000 included data on the trusted person designated by the patient — Next refers to 202,246 trusted third parties affected. Finally, 43 records contained health data.
This is the kind of information you cannot revoke: a social security number and an identity document are not changed the way a password is.
After the incident, one temporary password for everyone
The CNIL finally faults the hospital for a measure taken after the breach: issuing an identical temporary password to all practitioners. A credential reset meant to limit the damage thus turned into a secret shared among every user concerned.
It is this accumulation that the authority sums up in the formula it settled on, the absence of “elementary security measures”. None of the three points raised involves advanced technology or a budget out of reach: authenticate remote access, monitor the logs, do not hand the same password to everyone.
The fine penalises the facility. The data of 524,867 people left more than a year ago, and nothing in this decision brings it back.
Sources (1)
Written with AI assistance from the sources cited above, then reviewed and approved before publication by Sébastien Soulier.


