Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Oura files to go public

    September 3, 2026

    French hospital fined €500,000 after breach exposes data of 727,000

    September 3, 2026

    Utah Becomes First State to Target VPNs in Age-Verification Crackdown

    September 3, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Oura files to go public
    • French hospital fined €500,000 after breach exposes data of 727,000
    • Utah Becomes First State to Target VPNs in Age-Verification Crackdown
    • Each extra hour of prolonged sitting linked to 9% higher cancer death risk
    • American Oversight Investigating CDC’s Apparent Manipulation of Measles Death Data At Kennedy’s Command
    • The USS Abraham Lincoln Is a Troubling Metaphor for the Iran War
    • Did Trump say US has ‘too many non-working holidays’ that cost country ‘billions’?
    • Tunisia court upholds prison sentences of up to 45 years for opposition figures
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, September 3
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    French hospital fined €500,000 after breach exposes data of 727,000

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 3, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    France’s data protection authority (CNIL) has fined Hôpital privé de la Loire €500,000 ($580,000) for failing to adequately protect patients’ and their relatives’ data.

    The French agency says that the security failures led to a data breach in the summer of 2025, exposing sensitive data belonging to 524,867 patients and another 202,246 people designated as trusted third parties.

    Hôpital privé de la Loire (HPL) is a general hospital in Saint-Étienne, part of the Ramsay Santé healthcare group, providing medical, surgical, maternity, cancer, intensive-care, and emergency services.

    The hospital employs a staff of 650, including 180 doctors, and has 333 beds across five clinical divisions, with a reported 60,000 patients yearly.

    Last year, an attacker accessed the hospital’s electronic patient record system and extracted sensitive data of more than 727,000 people who had received care at HPL, escorted patients there or helped them in some way.

    Following the incident, the CNIL conducted an investigation, which identified several failures to comply with the hospital’s obligations under the General Data Protection Regulation (GDPR).

    Some of the shortcomings CNIL’s investigation identified include:

    • External users, including private-practice physicians, could access the system without a VPN or multi-factor authentication.
    • Inadequate access controls allowed the compromised account to access records for all hospital patients.
    • The hospital lacked real-time or near-real-time monitoring and alerting, allowing the attacker to explore the system and extract a large volume of data over several days without detection.
    • The hospital informed affected patients but did not directly notify the 202,246 trusted third parties whose data was also stolen.

    The violations above relate to Article 32 and Article 34 of the GDPR. The committee also noted that HPL took several security strengthening measures during the proceedings.

    A teen hacker using the alias “Marak” claimed responsibility, contacting the French outlet Le Progrès over Telegram at the time and saying the attack began with a breach of a single doctor’s account, which allowed access to HPL’s entire internal system.

    The hacker attempted to sell the stolen data to a single buyer for a price between €2,000 and €5,000, although it was later reported that the data was neither sold nor published.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    breach data exposes Fined French hospital
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    American Oversight Investigating CDC’s Apparent Manipulation of Measles Death Data At Kennedy’s Command

    AI data centres are booming in Australia – but at what cost?

    Capsule Security Launches ‘AI Circuit Breaker’ to Stop Rogue Agents

    Coder’s registry infrastructure compromised to push malicious modules

    Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

    ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Oura files to go public

    September 3, 2026

    French hospital fined €500,000 after breach exposes data of 727,000

    September 3, 2026

    Utah Becomes First State to Target VPNs in Age-Verification Crackdown

    September 3, 2026

    Each extra hour of prolonged sitting linked to 9% higher cancer death risk

    September 3, 2026
    Latest Posts

    Ultrafast X-rays capture chemistry unfolding atom by atom

    July 31, 2026

    How a PPE company’s highly publicized $32M Bitcoin strategy quietly expired without purchasing a single coin

    July 31, 2026

    Critical Flaw Led to Azure Cosmos DB Pwnage

    July 31, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Oura files to go public

    September 3, 2026

    French hospital fined €500,000 after breach exposes data of 727,000

    September 3, 2026

    Utah Becomes First State to Target VPNs in Age-Verification Crackdown

    September 3, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.