CNIL fines France’s Hôpital privé de la Loire €500,000 over patient-record security failures
The CNIL imposed a €500,000 fine on Hôpital privé de la Loire for failures in securing patient records.
Article prepared with AI assistance, then verified, edited, and approved by Nicolas Coutant.
In brief
On 3 September 2026, the CNIL announced a €500,000 sanction against the facility. The data involved concern 524,867 patients and 202,246 trusted third parties. The facts were reported by Next and Le Progrès. The decision highlighted deficiencies in the protection of external connections to the computerized patient records. The sanction reflects the regulatory assessment of the security measures that were in place at the time of the intrusion. Coverage in the cited publications summarized the key elements of the case without providing additional technical details beyond those confirmed by the authority. This summary does not extend to internal network architecture or to any other categories of data processing that may exist within the facility; it remains limited to the documented shortcomings in remote-access controls.
How it works
At the end of June 2025, an intrusion allowed access to the computerized patient records of Hôpital privé de la Loire in Saint-Étienne. Investigations revealed the absence of a virtual private network for external connections and the absence of multi-factor authentication for those accesses. Without a virtual private network, external connections travel over open pathways that do not create an isolated and encrypted tunnel between the remote user and the internal system, leaving data exchanges exposed to interception or unauthorized entry points. The lack of multi-factor authentication means that a single credential suffices for entry, removing the additional verification step that would normally require a second, independent confirmation of identity before granting access. After the incident, practitioners continued to use an identical temporary password to connect to the system. This practice meant that the same credential remained valid across multiple sessions and users, eliminating any rotation that would normally limit the window during which a compromised password could be exploited. The breach exposed the facility’s reliance on basic access methods that did not incorporate additional layers of protection for remote or external users. This configuration left the patient records system open during the period when the intrusion took place. The continued use of the same temporary password after the event further illustrated that the initial security shortcomings were not immediately addressed through changes in authentication practices. In other words, the system did not shift from a single-layer model to one that combines network isolation with identity verification, nor did it replace static credentials with time-limited or user-specific alternatives once the intrusion had been detected.
What is sourced
The sources indicate that external access to the computerized patient records occurred without a virtual private network and without multi-factor authentication. After the end-of-June 2025 incident, an identical temporary password was maintained for practitioners. The number of individuals concerned is 524,867 patients and 202,246 trusted third parties. Reporting from Next, Le Progrès, and Solutions Numériques consistently describes these access conditions and the post-incident password practice. The published accounts focus on the absence of the two security mechanisms and the reuse of the temporary credential. No other technical specifics or timelines beyond the end-of-June 2025 intrusion are supplied in the available coverage. These accounts therefore do not address whether similar configurations existed for non-external users or whether additional protective measures were applied to other parts of the information system.
Caveats
The available information comes from statements and articles published on 3 September 2026. The figures cited are those reported by the sources and may be subject to later updates. No definitive conclusion on the exact scale of the intrusion is provided beyond the published elements. The CNIL decision rests on the observations made during the investigation period, and subsequent reviews could modify the understanding of the events. Readers should note that the reported numbers of affected individuals originate directly from the authority’s announcement and the accompanying press coverage. This material does not claim to represent an exhaustive technical audit; it records only the deficiencies that were identified and documented by the authority at the time of its review.
What happens next
The facility will have to implement corrective measures for external accesses. The CNIL rendered its decision on the basis of the elements observed at the date of the investigation. Future compliance steps are expected to address the identified gaps in network and authentication controls. The sanction serves as a formal requirement to strengthen the protection of the computerized patient records system. Ongoing monitoring by the authority may verify that the necessary adjustments have been applied to external connection procedures. Such adjustments would typically involve establishing an encrypted tunnel for remote sessions and requiring at least two independent factors for authentication, while also ensuring that temporary credentials are replaced promptly and are not shared across multiple practitioners.
Going further
The articles published on 3 September 2026 detail the shortcomings identified. Readers can consult the sources to follow the evolution of the case.
Sources
Found an error? Email us — we correct factual mistakes and note significant updates on the article. Contact us
Keep exploring
Passkeys: What They Change for Account Security and What Remains Fragile
A breakdown of how passkeys reduce phishing risks through cryptographic binding, while revealing why synced keys and endpoint compromises still pose account risks.
Read the article →How a SIM swap takes over a phone number without stealing the handset
How carrier account takeover moves a number to an attacker’s SIM, breaks SMS two-factor codes, and differs from a simple network outage.
Read the article →Remote work monitoring software: what is measured, what is restricted, and the gap with performance
A breakdown of activity logs, screenshots, and productivity scores in remote work tools, alongside EU legal limits on data collection.
Read the article →