CNIL fine against Hôpital privé de la Loire over GDPR breach
Regulatory/Legal Action
Summary
Hide ▲
Show ▼
France’s CNIL fined Hôpital privé de la Loire €500,000 after finding GDPR security failures that contributed to a breach affecting patients and trusted third parties. The enforcement action covers a summer 2025 exposure that reached 524,867 patients and 202,246 trusted third parties. The penalty raises the compliance stakes for hospital systems handling sensitive health data.
Related Happenings
Hôpital privé de la Loire data breach
Data Leak
H score60
First: 04.09.2026 01:01
Last: 04.09.2026 01:01
Sources 1
How related:
The French agency says that the security failures led to a data breach in the summer of 2025, exposing sensitive data belonging to 524,867 patients and another 202,246 people designated as trusted third parties.
About this happening:
A summer 2025 data breach exposed sensitive data from Hôpital privé de la Loire, affecting 524,867 patients and 202,246 trusted third parties. The leak involve...
Hôpital privé de la Loire data breach
Data LeakHow related: The French agency says that the security failures led to a data breach in the summer of 2025, exposing sensitive data belonging to 524,867 patients and another 202,246 people designated as trusted third parties.
About this happening: A summer 2025 data breach exposed sensitive data from Hôpital privé de la Loire, affecting 524,867 patients and 202,246 trusted third parties. The leak involve...
Hôpital privé de la Loire hit by network compromise
Incident
H score54
First: 04.09.2026 01:01
Last: 04.09.2026 01:01
Sources 1
How related:
Last year, an attacker accessed the hospital’s electronic patient record system and extracted sensitive data of more than 727,000 people who had received care at HPL, escorted patients there or helped them in some way.
About this happening:
Hôpital privé de la Loire suffered a data breach after an attacker accessed its electronic patient record system and extracted sensitive data tied to more than 727,0...
Hôpital privé de la Loire hit by network compromise
IncidentHow related: Last year, an attacker accessed the hospital’s electronic patient record system and extracted sensitive data of more than 727,000 people who had received care at HPL, escorted patients there or helped them in some way.
About this happening: Hôpital privé de la Loire suffered a data breach after an attacker accessed its electronic patient record system and extracted sensitive data tied to more than 727,0...
DGFiP data leak after ZeroBytes sale claim
Data Leak
H score78
First: 17.08.2026 13:09
Last: 17.08.2026 13:09
Sources 1
About this happening:
The French Ministry of the Economy and Finance disclosed a DGFiP data breach after an attacker claimed access and put stolen data up for sale, exposing records for 678,0...
DGFiP data leak after ZeroBytes sale claim
Data LeakAbout this happening: The French Ministry of the Economy and Finance disclosed a DGFiP data breach after an attacker claimed access and put stolen data up for sale, exposing records for 678,0...
23AndMe multistate genetic-data settlement and ICO fine
Regulatory/Legal Action
H score35
First: 16.07.2026 16:47
Last: 16.07.2026 16:47
Sources 1
About this happening:
23andMe agreed to pay $18 million to settle multistate claims over its failure to protect customers' genetic data, extending the legal fallout from the 2023 breach. Re...
23AndMe multistate genetic-data settlement and ICO fine
Regulatory/Legal ActionAbout this happening: 23andMe agreed to pay $18 million to settle multistate claims over its failure to protect customers' genetic data, extending the legal fallout from the 2023 breach. Re...
NHS awareness campaign and guidance on unauthorized patient-data access
Public Sector Action
H score8
First: 10.07.2026 12:00
Last: 10.07.2026 12:00
Sources 1
About this happening:
The NHS launched a new awareness-raising campaign and guidance to curb unauthorized access to patient data across staff and healthcare organizations. The initi...
NHS awareness campaign and guidance on unauthorized patient-data access
Public Sector ActionAbout this happening: The NHS launched a new awareness-raising campaign and guidance to curb unauthorized access to patient data across staff and healthcare organizations. The initi...
Timeline
-
04.09.2026 01:01 2 articles · 1h ago
CNIL fine against Hôpital privé de la Loire over GDPR breach
Initial DisclosureCNIL moved from breach investigation to enforcement by fining Hôpital privé de la Loire €500,000 over inadequate protection of sensitive health data. The action follows a summer 2025 breach affecting both patients and trusted third parties.
Show sources
- French hospital fined €500,000 after breach exposes data of 727,000 — www.bleepingcomputer.com — 04.09.2026 01:01
- French hospital fined €500,000 after breach exposes data of 727,000 — www.bleepingcomputer.com — 04.09.2026 01:01