Health data breach: the CNIL fined Hôpital Privé de la Loire 500 000 EUR
The European Data Protection Board published a case summary regarding a CNIL enforcement decision against Hôpital Privé de la Loire. On 3 September 2026, the CNIL imposed a fine of EUR 500,000 for failures to comply with GDPR Articles 32 and 34. The hospital's authentication system lacked VPNs and multifactor authentication, allowing an attacker to access data of 524,867 patients and 202,246 trusted third parties. The hospital also failed to adequately monitor suspicious activity and did not inform all affected data subjects (particularly the 202,246 trusted third parties) about the breach.
What changed
- EDPB published case summary of CNIL enforcement decision against Hôpital Privé de la Loire
- Administrative fine of EUR 500,000 imposed for Article 32 (Security of processing) violations
- Administrative fine imposed for Article 34 (Notification of data breach) violations
Who is affected
Healthcare providers subject to GDPR, particularly those processing patient data and managing external access through e-Health systems
- Language
- EN