France's data protection authority has fined a private hospital in Saint-Étienne €500,000 for a breach of its patient record system that exposed 727,113 people, and the decision, published September 3, reads less like a penalty for one attack than an audit of an industry's security habits. The regulator found that a single compromised account could read every patient file in the hospital, that external doctors reached the system without a VPN or multifactor authentication, and that no monitoring caught the attacker's activity over several days.
The breach itself ran from June 26 to July 1, 2025, at the Hôpital privé de la Loire, owned by Ramsay Santé. Attackers gained access to the hospital's computerized patient record through one account, reportedly a doctor's, and exfiltrated data in volume before anyone inside noticed. The CNIL's final count is stark: 524,867 patients, including health data, which European law treats as a special category, plus 202,246 "tiers de confiance," the relatives, attending physicians and emergency contacts patients designate.
The findings: security as an afterthought
The regulator's findings under Article 32 of the GDPR, which requires appropriate security, are a sequence of absences. External doctors, the liberal practitioners who refer patients to the hospital, reached the record system with no VPN and no multifactor authentication. Access rights ignored the "équipe de soins" concept under which each professional should see only the patients in their care, so one account could open any file. And the hospital had no detection that could flag abnormal activity in real time or even near it, which is how an exfiltration spanning days went unnoticed until the intrusion was discovered in early July 2025.
The second finding concerns what happened after. Under Article 34, the hospital notified patients of the breach. It did not notify the 202,246 third parties whose data was also exposed, and the regulator treated that omission as its own violation. The fine's size reflects the sensitivity of health data and the number of people affected, while crediting the hospital for remediation during the proceedings and allowing three to fifteen months for the remaining measures. The CNIL also said, in its published reasoning, that "zero risk" does not exist, which is the regulator's way of distinguishing this case from an impossible standard: the failure here was not that an attacker got in. It was that the door was a single lock, and the lock opened everything.
The criminal case behind the breach
The breach has a parallel track in the criminal courts. In June 2026, French cyber police arrested five French nationals aged 16 to 22, and three have been charged, two of them minors, in connection with the hacking group known as "Marak," which allegedly carried out the hospital attack and offered roughly 525,000 patient records for sale. The group is accused of a broader campaign against French health institutions totaling about four million patient files, including attacks on the national health insurance system. Charges are allegations, and no one has been convicted.
The group's profile, teenagers using a stolen credential, is the detail that makes the CNIL findings land hardest. This was not a sophisticated state actor defeating layered defenses. It was a single account, allegedly phished or stolen, granted access broad enough to drain a hospital. The attack's simplicity is the finding's severity.
The sector pattern
The case sits inside a wave. In February 2024, the French third-party payment operators Viamedis and Almerys were breached, exposing data on roughly 33 million insured people, again through compromised credentials of health professionals. The CNIL had already signaled its expectation of multifactor authentication in January 2025 and issued a dedicated recommendation that April. Its enforcement record is growing with the threat: eleven security sanctions in 2024, and in 2026 alone fines of €42 million against the telecom operator Free, €5 million against the employment agency France Travail, and €5 million against the health-data firm IQVIA. The Saint-Étienne fine is the healthcare-specific entry in that series, and at about €0.69 per affected person it is calibrated less for the hospital's size than for the message.
Hospitals face a structural disadvantage in this fight. Their systems must be open enough for hundreds of external clinicians to work, their budgets go to care first, and their data is worth more than a bank's on the markets where stolen files are sold. The CNIL's decision does not solve that tension. It sets a floor: whatever else a hospital does, the accounts that can reach every patient must be fewer, authenticated twice, and watched.
For the 727,113 people in the regulator's count, the breach's consequence is permanent in the way health data breaches always are. A password can be changed. A medical history cannot. The €500,000 fine is what one hospital pays for learning that too slowly. The question the decision leaves for every other hospital in Europe is whether it is still learning it at all.
Primary sources
- CNIL decision SAN-2026-009 as analyzed by Solutions Numériques for the findings and fine basis.
- franceinfo for the breach timeline, the hospital's notification, and the criminal case.
- Ramsay Santé's July 2025 statement for the hospital's response and initial scope estimate.
- silicon.fr for the CNIL's enforcement record and the sector's security guidance.
- franceinfo coverage of the Viamedis and Almerys breach for the sector context.