Incident
Published 2026-09-03
Verified 2026-09-19

CNIL fines Hôpital privé de la Loire €500k after 727k-person EPR breach (summer 2025)

BleepingComputer (3 September 2026) reports France’s CNIL fined Hôpital privé de la Loire (HPL, Ramsay Santé group, Saint-Étienne) €500,000 for GDPR security and notification failures after a summer 2025 intrusion into the electronic patient record system exposed sensitive data of 524,867 patients plus 202,246 trusted third parties (about 727,000 people). CNIL findings cited include external physician access without VPN or multi-factor authentication, overly broad access once an account was compromised, lack of near-real-time monitoring that let exfiltration run for days, and failure to directly notify the trusted-third-party cohort (Articles 32 and 34 GDPR). A teen using the alias “Marak” claimed the path began with one doctor’s account and tried to sell the data; reporting says it was neither sold nor published. HPL strengthened controls during proceedings. Practitioners: remote clinical access needs MFA and VPN; least privilege on EPR; detection that catches multi-day bulk extract; notify every category of affected individual.

Product
Hôpital privé de la Loire / Ramsay Santé EPR
Exploited in Australia?
no
Patch to
MFA+VPN for remote EPR; least-privilege clinical accounts; near-real-time bulk-export detection; notify all affected cohorts

Primary: BleepingComputer (3 Sep 2026) · Vendor: CNIL (French DPA; decision text not loaded this pass — wire pending official release page)

breaches identity