French hospital hit with €500,000 fine after data breach exposes over 500K patient records
Proper cybersecurity apparently isn’t covered by basic health care.

Nurse in a hospital corridor. Photo by Pascal Bachelet/BSIP/Universal Images Group/Getty Images
- CNIL fined the private French hospital €500,000 ($581,000) after hackers stole data from 524,867 patients.
- Regulators said external access lacked virtual private network protection and multi-factor login checks, enabling broad database access.
- The hospital added security measures during the enforcement process.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
A private hospital in France was slapped with a €500,000 ($581,000) fine by the French data protection authority for a data breach in which hackers stole both personal information and health data from over half a million patients.
During the summer of 2025, an attacker exfiltrated sensitive information belonging to 524,867 patients, including health data, as well as data from 202,246 people who were listed as trusted contacts.
Following the data breach, the Commission Nationale de l’Informatique et des Libertés (CNIL), France’s data protection authority, launched a formal investigation to see whether appropriate security measures were in place at the time of the incident.
According to the privacy regulator, the security of the hospital’s electronic health records (EHRs) was inadequate, thereby violating several provisions of the GDPR.
For starters, external users could access the hospital’s EHR system without a virtual private network (VPN) or multi-factor authentication (MFA). The attacker exploited this vulnerability to steal patient records.
In addition, the authorization policy was inadequate. The attacker used a single user’s credentials, allowing him to access the hospital’s entire patient database.
There was also no effective monitoring to detect suspicious activity in real time on the hospital’s internal network, thereby enabling the hacker to access patient health records for several days and extract large volumes of data.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Lastly, the CNIL found that the private hospital had only notified all affected patients. The affected 202,246 trusted contacts whose data was also stolen weren’t directly informed of the breach.
Failing to implement appropriate security measures to protect the personal data of patients is a violation of Article 32 of the General Data Protection Regulation (GDPR). Not informing all affected individuals infringes Article 34 GDPR.
Given the lack of basic security measures, the nature of the compromised data, and the private hospital’s financial capabilities, the CNIL issued a €500,000 fine.
During the enforcement procedure, the hospital implemented additional measures to bolster its security.