Low Guidance eu

Health data breach: the CNIL fined Hôpital Privé de la Loire 500 000 EUR

The European Data Protection Board published a case summary regarding a CNIL enforcement decision against Hôpital Privé de la Loire. On 3 September 2026, the CNIL imposed a fine of EUR 500,000 for failures to comply with GDPR Articles 32 and 34. The hospital's authentication system lacked VPNs and multifactor authentication, allowing an attacker to access data of 524,867 patients and 202,246 trusted third parties. The hospital also failed to adequately monitor suspicious activity and did not inform all affected data subjects (particularly the 202,246 trusted third parties) about the breach.

What changed

Who is affected

Healthcare providers subject to GDPR, particularly those processing patient data and managing external access through e-Health systems

Language
EN

Frameworks

GDPR

Open the original source