French hospital breach exposes 727,000 records
An attacker accessed patient and relative records at Hôpital privé de la Loire in Saint-Étienne during 2025. France's CNIL later fined the hospital €500,000 over inadequate data protection.
- Started
- Jun 1, 2025
- Latest activity
- Sep 3, 2026
- Attributed to
- Not confirmedNo credible attribution yet
- Where
- France
- Sectors
- Healthcare
- Scale
- One private hospital; 727,000 patients and relatives affected
Current status
The latest confirmed update was CNIL's fine on 2026-09-03, with no newer attack activity reported.
Dormant: No new confirmed activity for a while, and nobody has called an official all clear.
Impact
Patient and relative data was accessed and stolen. The hospital's operation was not reported as disrupted.
What to do
Affected people should watch for direct notices from the hospital and suspicious messages using medical or identity details.
Timeline
-
Sep 3, 2026
CNIL fined Hôpital privé de la Loire €500,000 for failing to adequately protect the affected data.
Dormantbleepingcomputer.com -
Jun 1, 2025
An attacker accessed and stole data from the hospital's patient records system during 2025.
Dormantradioscoop.com
Sources
- French hospital fined €500,000 after breach exposes data of 727,000 BleepingComputer Sep 3, 2026
- Cyberattaque : l'Hôpital privé de la Loire sanctionné de 500.000 euros par la CNIL Anadolu Ajansı Sep 3, 2026
- Piratage de données médicales : l'Hôpital privé de la Loire condamné à 500 000 euros d'amende Le Progrès Sep 3, 2026
Related reports
- French hospital fined for patient data breach Sep 3, 2026