What Changed
- The CNIL restricted committee imposed a EUR 500,000 fine on Hôpital Privé de la Loire on 3 September 2026 for GDPR breaches.
- Investigation found Article 32 GDPR violations due to missing MFA/VPNs, lack of care-team access restrictions, and absence of intrusion alerts.
- The authority found an Article 34 GDPR violation because the hospital failed to directly notify 202,246 trusted third parties whose data was stolen.
Healthcare providers, data controllers, and cybersecurity professionals operating within the European Union face strict compliance obligations under the General Data Protection Regulation (GDPR) regarding technical security and breach notifications. On 3 September 2026, the restricted committee of the French Data Protection Authority (CNIL)—the body responsible for issuing sanctions—fined Hôpital Privé de la Loire EUR 500,000 for violations of Articles 32 and 34 of the GDPR.
The sanction follows an incident in summer 2025, when an attacker illegally accessed the hospital's Computerised Patient Summary (DPI), compromising personal data belonging to 524,867 patients (including sensitive health data) and 202,246 individuals designated as trusted third parties.
A subsequent CNIL investigation revealed multiple security compliance failures under Article 32 GDPR:
- Weak Authentication: External access to the e-Health Patient Summary, used notably by non-affiliated doctors, lacked essential safeguards such as Virtual Private Networks (VPNs) and multi-factor authentication (MFA).
- Inadequate Access Control: Access policies failed to incorporate the 'care team' concept. As a result, credentials from a single user account enabled full access to data across all hospital patients.
- Absence of Intrusion Detection: The hospital lacked mechanisms to detect abnormal activity or trigger alerts in real time or within a short timeframe, allowing the attacker to explore system data undetected for several days.
Additionally, the CNIL established a failure under Article 34 GDPR regarding data subject breach notifications. While the hospital notified affected patients, it failed to provide direct notification to the 202,246 designated trusted third parties whose personal data was also stolen.
In setting the fine at EUR 500,000, the CNIL considered the hospital's disregard for core security principles, the number of individuals affected, the nature of compromised data, and the controller's financial capacity.
Who May Be Affected
Healthcare entities, data controllers, cybersecurity officers operating in the EU, patients of Hôpital Privé de la Loire, and their designated trusted third parties.
Cross-Border Context
Applies across the European Union under GDPR requirements governing health data protection, cybersecurity controls, and personal data breach notifications.
What to check next
- Check the CNIL website for the full official decision text concerning Hôpital Privé de la Loire.
This article provides general information and does not constitute legal advice. Consult the official text and obtain advice appropriate to your circumstances where needed.