ON September 3, 2026, the CNIL fined Loire Private Hospital €500,000 for failing to secure patient data after a breach in summer 2025, exposing information of 524,867 patients and 202,246 relatives. The breach occurred when an attacker accessed the hospital's electronic patient records. An audit revealed compliance failures with GDPR. The CNIL considered the breach's impact and the hospital's financial situation when imposing the fine. A hacker known as 'Marak' claimed responsibility, attempting to sell the data but ultimately did not publish it.
CNIL: Health data breach: €500,000 fine imposed on the Loire Private Hospital
Article by CyberSIXT