Find notable cyber news and cases, enriched with sources, timelines, and signals.

CNIL fine against Hôpital privé de la Loire over GDPR breach

Regulatory/Legal Action
First reported
Last updated
Happening score
H score 50
1 unique sources, 1 articles

Summary

Hide ▲

France’s CNIL fined Hôpital privé de la Loire €500,000 after finding GDPR security failures that contributed to a breach affecting patients and trusted third parties. The enforcement action covers a summer 2025 exposure that reached 524,867 patients and 202,246 trusted third parties. The penalty raises the compliance stakes for hospital systems handling sensitive health data.

Related Happenings

Hôpital privé de la Loire data breach

Data Leak
H score60 First: 04.09.2026 01:01 Last: 04.09.2026 01:01 Sources 1

How related: The French agency says that the security failures led to a data breach in the summer of 2025, exposing sensitive data belonging to 524,867 patients and another 202,246 people designated as trusted third parties.

About this happening: A summer 2025 data breach exposed sensitive data from Hôpital privé de la Loire, affecting 524,867 patients and 202,246 trusted third parties. The leak involve...

Hôpital privé de la Loire hit by network compromise

Incident
H score54 First: 04.09.2026 01:01 Last: 04.09.2026 01:01 Sources 1

How related: Last year, an attacker accessed the hospital’s electronic patient record system and extracted sensitive data of more than 727,000 people who had received care at HPL, escorted patients there or helped them in some way.

About this happening: Hôpital privé de la Loire suffered a data breach after an attacker accessed its electronic patient record system and extracted sensitive data tied to more than 727,0...

DGFiP data leak after ZeroBytes sale claim

Data Leak
H score78 First: 17.08.2026 13:09 Last: 17.08.2026 13:09 Sources 1

About this happening: The French Ministry of the Economy and Finance disclosed a DGFiP data breach after an attacker claimed access and put stolen data up for sale, exposing records for 678,0...

23AndMe multistate genetic-data settlement and ICO fine

Regulatory/Legal Action
H score35 First: 16.07.2026 16:47 Last: 16.07.2026 16:47 Sources 1

About this happening: 23andMe agreed to pay $18 million to settle multistate claims over its failure to protect customers' genetic data, extending the legal fallout from the 2023 breach. Re...

NHS awareness campaign and guidance on unauthorized patient-data access

Public Sector Action
H score8 First: 10.07.2026 12:00 Last: 10.07.2026 12:00 Sources 1

About this happening: The NHS launched a new awareness-raising campaign and guidance to curb unauthorized access to patient data across staff and healthcare organizations. The initi...

Timeline

  1. 04.09.2026 01:01 2 articles · 1h ago

    CNIL fine against Hôpital privé de la Loire over GDPR breach

    Initial Disclosure

    CNIL moved from breach investigation to enforcement by fining Hôpital privé de la Loire €500,000 over inadequate protection of sensitive health data. The action follows a summer 2025 breach affecting both patients and trusted third parties.

    Show sources