Medium Guidance eu

Health data breach: the CNIL fined Hôpital Privé de la Loire 500 000 EUR

On 3 September 2026, the French data protection authority (CNIL) issued an administrative fine of 500 000 EUR against Hôpital Privé de la Loire for failures to comply with GDPR obligations following a data breach affecting 524 867 patients and 202 246 trusted third parties in summer 2025. Key findings include inadequate security measures (Article 32 GDPR) — specifically insufficient authentication procedures lacking VPNs and multifactor authentication, and inadequate access control policies — and failures in breach notification procedures (Article 34 GDPR). This enforcement decision demonstrates GDPR compliance requirements for healthcare data controllers regarding technical and organisational security measures and personal data breach management.

What changed

Who is affected

Healthcare institutions and data controllers processing health data subject to GDPR, particularly those operating patient management systems and e-health platforms with external access

Action
Action required
Language
EN

Frameworks

GDPR

Open the original source