Health data breach: the CNIL fined Hôpital Privé de la Loire 500 000 EUR
Background informationDate of final decision: 3 September 2026National caseController: Hôpital Privé de la LoireLegal Reference: Article 32 (Security of processing), Article 34 (Communication of a personal data breach to the data subject), Decision: Administrative fineKeywords: Cybersecurity, Personal data breaches, Health and researchSummary of the DecisionOrigin of the caseIn summer 2025, an attacker managed to connect to the Computerised Patient Summary (DPI) of the Hôpital Privé de la Loire
How it connects
Related across sources
Full text
Background informationDate of final decision: 3 September 2026National caseController: Hôpital Privé de la LoireLegal Reference: Article 32 (Security of processing), Article 34 (Communication of a personal data breach to the data subject), Decision: Administrative fineKeywords: Cybersecurity, Personal data breaches, Health and researchSummary of the DecisionOrigin of the caseIn summer 2025, an attacker managed to connect to the Computerised Patient Summary (DPI) of the Hôpital Privé de la Loire (Loire’s private hospital), which centralises all the data of the individuals under care. It thus accessed the data of 524 867 patients (some of them health data) and 202 246 persons designated as “trusted third parties”. As a result of this data breach, the French Data Protection Authority (CNIL) carried out a check that identified several failures of the Hôpital Privé de la Loire to comply with the obligations laid down in the General Data Protection Regulation (GDPR).Key findingsFailure to en