CNIL Fines HÔPITAL PRIVÉ DE LA LOIRE €500,000
French regulator CNIL fined HÔPITAL PRIVÉ DE LA LOIRE for inadequate security preceding the exfiltration of data belonging to 727,113 people.

CNIL’s fine against the hospital HÔPITAL PRIVÉ DE LA LOIRE, totaling €500,000, concerns inadequate security during the large-scale exfiltration of health and identification data. On September 3, 2026, France’s data protection authority announced that the healthcare facility had violated Articles 32 and 34 of the GDPR. The regulator adopted the decision, SAN-2026-009, on July 21, 2026.
According to CNIL, an attacker used the login credentials of an external physician’s account between June 26 and July 1, 2025. The attacker subsequently obtained and exfiltrated 524,867 patient records. The incident also affected 202,246 people listed in patient records as “trusted third parties.” The total number of people affected therefore reached 727,113.
CNIL fines hospital over security shortcomings
The regulator emphasized that the sanction is not punishment for the cyberattack itself. It concerns inadequate technical and organizational measures that, according to CNIL, enabled or facilitated the attack.
The decision identifies several specific shortcomings involving remote access and account management:
- external access was not protected through a VPN,
- multifactor authentication had not been implemented for external users,
- access rights were not restricted sufficiently,
- the hospital did not detect suspicious activity in time.
According to CNIL, the combination of password-only access, broad permissions, and a lack of timely detection enabled or facilitated the attack. The external physician’s account therefore provided access to a large volume of records.
Patients were notified, but not all third parties
CNIL also criticized the hospital’s handling of incident notifications. The facility informed patients but did not directly contact all people listed in its systems as trusted third parties. Their data was nevertheless within the scope of the unauthorized access and exfiltration described in the decision.
The regulator refers to unauthorized access to the data and its exfiltration. However, the decision does not confirm that the data was subsequently published, sold, or otherwise misused. It also does not confirm the attacker’s identity.
Measures ordered within deadlines of up to 15 months
The fine is not the only outcome of the proceedings. CNIL ordered the hospital to complete the strengthening of its security measures. Depending on the type of remediation, the deadlines range from three to 15 months.
For future developments, it will be important whether HÔPITAL PRIVÉ DE LA LOIRE fulfills these obligations within the specified deadlines and whether it takes legal action against the decision. It also remains open whether the regulator or the hospital will later confirm subsequent misuse of the exfiltrated data.
Sources
- CNIL – Confirms the fine, the numbers of patients and third parties, the security shortcomings, and the ordered remediation measures.
- Légifrance – Délibération SAN-2026-009 – The published full CNIL decision gives the exact time of the attack, the scope of the exfiltration, the data categories, and the legal reasoning behind the sanction.
- BleepingComputer – Independently summarizes the CNIL announcement and the scope of the incident; claims about the alleged perpetrator are not used as confirmed facts.
Verified and updated: 09/04/2026 10:51



