Hôpital Privé de la Loire – €500,000 Fine (France, 2026)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Hôpital Privé de la Loire was fined after a major data breach exposed the personal information of over 524,000 patients. This incident is crucial because it shows the serious consequences of inadequate security in healthcare settings.
What happened
An attacker accessed the hospital's electronic patient record system and extracted sensitive data of 524,867 patients.
Who was affected
Patients whose personal and health information was compromised in the data breach.
What the authority found
The CNIL found that the hospital failed to implement sufficient security measures to protect patient data under GDPR.
Why this matters
This case highlights the critical need for healthcare providers to enhance their data security practices. Hospitals must invest in robust systems to protect patient information from breaches.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
National Law Articles
In June 2025, an attacker obtained the credentials of a doctor affiliated with Hôpital Privé de la Loire, the controller, and used them to access the hospital's electronic patient record system. Between 26 June and 1 July 2025, the attacker extracted 524,867 patient records. The compromised data included identification and contact information, social security numbers and, in some cases, identity documents and health data. The records also contained personal data relating to 202,246 persons designated by patients as trusted third parties. After discovering the breach, the controller notified the CNIL, the DPA, and informed the affected patients through different communication channels. However, it did not directly inform the 202,246 trusted third parties whose data had also been compromised. The DPA subsequently carried out an on-site investigation into the controller's data processing practices. The investigation identified several security deficiencies in the electronic patient record system. External users could access it remotely using only a username and password, without a VPN or multi-factor authentication. Moreover, healthcare professionals could access patient records of patients they had no relation with, the system lacked adequate proactive analysis of access logs, and the software provider had permanent access to the system without prior authorisation by the controller. Following the breach, the controller had also temporarily assigned the same password to all external practitioners when resetting their credentials. The DPA found that the controller violated Article 32 GDPR by failing to implement appropriate technical and organisational measures to secure the electronic patient record system. The DPA first considered that remote access by external practitioners was insufficiently protected because it relied only on a username and password, without multi-factor authentication or a VPN. Given the sensitivity and volume of the health data processed, stro
Related Enforcement Actions (0)
No other enforcement actions found for Hôpital Privé de la Loire in FR
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
21 July 2026
Authority
Commission Nationale de l'Informatique et des Libertés
Fine Amount
€500,000
Enforcement Tracker ID
3233
GDPRhub ID
gdprhub-10244About this data
Cite as: Cookie Fines. Hôpital Privé de la Loire - France (2026). Retrieved from cookiefines.eu
Last updated: