Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    French hospital fined €500,000 after breach exposes data of 727,000

    September 3, 2026

    Flock Taught Cops How to Surveil No Kings Protesters

    September 3, 2026

    InfoSec News Nuggets – 09/03/2026 – AboutDFIR

    September 3, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»French hospital fined €500,000 after breach exposes data of 727,000
    News

    French hospital fined €500,000 after breach exposes data of 727,000

    adminBy adminSeptember 3, 2026No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    French hospital fined €500,000 after breach exposes data of 727,000

    France’s data protection authority (CNIL) has fined Hôpital privé de la Loire €500,000 ($580,000) for failing to adequately protect patients’ and their relatives’ data.

    The French agency says that the security failures led to a data breach in the summer of 2025, exposing sensitive data belonging to 524,867 patients and another 202,246 people designated as trusted third parties.

    Hôpital privé de la Loire (HPL) is a general hospital in Saint-Étienne, part of the Ramsay Santé healthcare group, providing medical, surgical, maternity, cancer, intensive-care, and emergency services.

    The hospital employs a staff of 650, including 180 doctors, and has 333 beds across five clinical divisions, with a reported 60,000 patients yearly.

    Last year, an attacker accessed the hospital’s electronic patient record system and extracted sensitive data of more than 727,000 people who had received care at HPL, escorted patients there or helped them in some way.

    Following the incident, the CNIL conducted an investigation, which identified several failures to comply with the hospital’s obligations under the General Data Protection Regulation (GDPR).

    Some of the shortcomings CNIL’s investigation identified include:

    • External users, including private-practice physicians, could access the system without a VPN or multi-factor authentication.
    • Inadequate access controls allowed the compromised account to access records for all hospital patients.
    • The hospital lacked real-time or near-real-time monitoring and alerting, allowing the attacker to explore the system and extract a large volume of data over several days without detection.
    • The hospital informed affected patients but did not directly notify the 202,246 trusted third parties whose data was also stolen.

    The violations above relate to Article 32 and Article 34 of the GDPR. The committee also noted that HPL took several security strengthening measures during the proceedings.

    A teen hacker using the alias “Marak” claimed responsibility, contacting the French outlet Le Progrès over Telegram at the time and saying the attack began with a breach of a single doctor’s account, which allowed access to HPL’s entire internal system.

    The hacker attempted to sell the stolen data to a single buyer for a price between €2,000 and €5,000, although it was later reported that the data was neither sold nor published.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleFlock Taught Cops How to Surveil No Kings Protesters
    admin
    • Website

    Related Posts

    News

    Flock Taught Cops How to Surveil No Kings Protesters

    September 3, 2026
    News

    InfoSec News Nuggets – 09/03/2026 – AboutDFIR

    September 3, 2026
    News

    Microsoft: KB5120998 mouse reset bug affects only non-English PCs

    September 3, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202643 Views

    IP Address Investigations and Local OSINT

    March 20, 202640 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202643 Views

    IP Address Investigations and Local OSINT

    March 20, 202640 Views
    Our Picks

    French hospital fined €500,000 after breach exposes data of 727,000

    September 3, 2026

    Flock Taught Cops How to Surveil No Kings Protesters

    September 3, 2026

    InfoSec News Nuggets – 09/03/2026 – AboutDFIR

    September 3, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.