BTC$84,744-0.06% LTC$70.31+4.13% XMR$539.16-1.74%
TorPortal TorPortalMarkets, mirrors, dark web news
BleepingComputer · Sep 3, 2026 · 2 min read · Original story

French hospital fined €500,000 after breach exposes data of 727,000

French hospital fined €500,000 after breach exposes data of 727,000

France’s data protection authority (CNIL) has fined Hôpital privé de la Loire €500,000 ($580,000) for failing to adequately protect patients’ and their relatives’ data.

The French agency says that the security failures led to a data breach in the summer of 2025, exposing sensitive data belonging to 524,867 patients and another 202,246 people designated as trusted third parties.

Hôpital privé de la Loire (HPL) is a general hospital in Saint-Étienne, part of the Ramsay Santé healthcare group, providing medical, surgical, maternity, cancer, intensive-care, and emergency services.

The hospital employs a staff of 650, including 180 doctors, and has 333 beds across five clinical divisions, with a reported 60,000 patients yearly.

Last year, an attacker accessed the hospital’s electronic patient record system and extracted sensitive data of more than 727,000 people who had received care at HPL, escorted patients there or helped them in some way.

Following the incident, the CNIL conducted an investigation, which identified several failures to comply with the hospital's obligations under the General Data Protection Regulation (GDPR).

Some of the shortcomings CNIL’s investigation identified include:

  • External users, including private-practice physicians, could access the system without a VPN or multi-factor authentication.
  • Inadequate access controls allowed the compromised account to access records for all hospital patients.
  • The hospital lacked real-time or near-real-time monitoring and alerting, allowing the attacker to explore the system and extract a large volume of data over several days without detection.
  • The hospital informed affected patients but did not directly notify the 202,246 trusted third parties whose data was also stolen.

The violations above relate to Article 32 and Article 34 of the GDPR. The committee also noted that HPL took several security strengthening measures during the proceedings.

A teen hacker using the alias “Marak” claimed responsibility, contacting the French outlet Le Progrès over Telegram at the time and saying the attack began with a breach of a single doctor’s account, which allowed access to HPL’s entire internal system.

The hacker attempted to sell the stolen data to a single buyer for a price between €2,000 and €5,000, although it was later reported that the data was neither sold nor published.

References in this story

  1. Présentation de l'établissement | Hôpital privé de la Loire hopital-prive-de-la-loire-saint-etienne.ramsaysante.fr
  2. Violation de données en matière de santé : sanction de 500 000 euros à l’encontre de l’HÔPITAL PRIVÉ DE LA LOIRE www.cnil.fr Le contexte Au cours de l'été 2025, un attaquant est parvenu à se connecter au dossier patient informatisé (DPI) de l’HÔPITAL PRIVÉ DE LA LOIRE, qui centralise l’ensemble des données des personnes prises en charge.
  3. Loire. Il affirme avoir dérobé 530 000 données de patients du HPL : « L’argent est ma motivation » www.leprogres.fr Le groupe Ramsay santé fait l’objet de menaces suite au piratage informatique dont l’Hôpital privé de la Loire (HPL), à Saint-Etienne, a été la ...
  4. 🎥SaxX x M6, 🇫🇷 Cyberattaque Hôpital Privé de la Loire (HPL) à Saint-Étienne - Tout ce qu'il faut savoir sur les 530… www.linkedin.com 🎥SaxX x M6, 🇫🇷 Cyberattaque Hôpital Privé de la Loire (HPL) à Saint-Étienne - Tout ce qu
  5. Loire. Sensible aux «témoignages des patients», le pirate du HPL ne publiera pas les données www.leprogres.fr Le hacker de 16 ans qui a dérobé plus de 530 000 dossiers de patients de l’Hôpital privé de la Loire assure qu’il renonce à mettre ses menaces à exécution.

Guides related to this story

← Back to all news