Security1 distinct publisher3 min readPublished
Hôpital privé de la Loire lost records on 727,113 people over several days in the summer of 2025. CNIL's decision names each control that was missing. It prices the whole set at about 69 cents a record.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Nothing in the chain CNIL laid out required a novel technique. External users of the patient record system, including private-practice physicians, could reach it with no VPN and no multi-factor authentication [5]. Authorization inside the system was flat, so the one compromised account could pull records for every patient in the hospital [6]. There was no real-time or near-real-time monitoring, which is why the attacker browsed and extracted a large volume of data across several days with nobody watching [7].
A teenager using the alias Marak claimed the intrusion, telling the Saint-Étienne daily Le Progrès over Telegram that it began with a single doctor's account and opened onto the entire internal system [10]. That account of the entry point comes from the attacker, not from the regulator. It is consistent with what CNIL found about access scoping, and it is the part of the story that remains unverified.
The arithmetic is the part that travels into a budget conversation. 524,867 patients plus 202,246 trusted third parties is 727,113 people [1], and €500,000 divided across them is about 69 cents each [2]. HPL reports roughly 60,000 patients a year [4], so the stolen set is a little over twelve years of intake [5]. Marak tried to sell it to one buyer for €2,000 to €5,000 [12]. The fine is at least a hundred times the top of that range [4]. Whatever the data was worth to a buyer, the regulator valued the failure to protect it far higher.
The Article 34 finding tends to get skipped in a readout of a case like this. HPL told the patients and did not directly notify the 202,246 trusted third parties whose data was also taken [8], which is 27.8% of the affected population [3] left to hear about it some other way. These are people who escorted a patient or helped one [11]; they never chose a relationship with the hospital, and they had no route to act. CNIL cited Article 32 for the security failures and Article 34 for the notification gap in the same decision [9].
CNIL also recorded that HPL strengthened its security during the proceedings [13]. That went in as mitigation, not as grounds to drop the sanction. For a hospital with 650 staff, 180 of them doctors, and 333 beds across five clinical divisions [4], every item on the regulator's list is a configuration and monitoring decision rather than a capital program: a VPN and MFA requirement for outside clinicians, role scoping in the record system, and an alert on bulk record reads. That is the comparison to bring to a finance discussion. The controls have a known cost, and the decision now attaches one to skipping them as well.
Ranked by verification strength, evidence, and original report placement.
France's data protection authority CNIL fined Hôpital privé de la Loire €500,000 ($580,000) for failing to adequately protect patients' and relatives' data.
CNIL says the security failures led to a data breach in the summer of 2025 that exposed sensitive data belonging to 524,867 patients.
The same breach exposed data belonging to another 202,246 people designated as trusted third parties.
Hôpital privé de la Loire is a general hospital in Saint-Étienne, part of the Ramsay Santé group, with 650 staff including 180 doctors, 333 beds across five clinical divisions, and a reported 60,000 patients yearly.
CNIL found that external users, including private-practice physicians, could access the hospital system without a VPN or multi-factor authentication.
CNIL found that inadequate access controls allowed the compromised account to access records for all hospital patients.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 3, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
NIST's multi-cloud tally: one resilience win against 23 new problems1 distinct publisher
security
Uber's 825 million euro lesson: the missing human is the violation2 distinct publishers
security
UDS Core's default operator authentication accepted any client secret for three release trains1 distinct publisher
security
McKesson's 8-K locates the stolen data inside third-party applications8 distinct publishers
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One outlet, reading one decision
The precision is real — 524,867, 202,246, Articles 32 and 34 — and it all comes from a regulator that had subpoena power and an open proceeding, which is about as good as breach numbers get. But it reaches us entirely through BleepingComputer's summary; CNIL's own text is described, never quoted or linked, and the attacker's account of starting from one doctor's login is a claim he made to Le Progrès over Telegram, repeated here without corroboration. Strong provenance, single channel.
Enforcement landed; the fix is a phrase
Two things demonstrably happened: the penalty was issued and the hospital hardened something while the case was open. What that hardening amounted to is left as CNIL's wording, 'several security strengthening measures,' with no list, no dates and no confirmation that the unnotified third parties were ever contacted. Beyond this one Saint-Étienne site there is nothing on whether other Ramsay Santé hospitals or French health providers changed anything, and we should not pretend otherwise.
Sold as a fine, matters as a design failure
Nothing here is inflated: the number is official, the findings are itemised, and BleepingComputer does not reach for words like 'unprecedented'. If anything the framing undersells it. A €500,000 headline invites a shrug at about 69 cents per person, while the durable finding sits in the bullets — a single external clinician's credential, usable with no VPN and no second factor, that opened every record the hospital held.
Everyone in the chain wants something
Three pulls worth naming. The piece ends with a pitch for a vendor's own defence-measurement report, placed directly after the observation that prevention collapses once attackers hold valid credentials — exactly the lesson the product addresses. The intruder's version of events came via Telegram to a local paper, and claiming a clean single-account entry flatters the intruder. And the hospital's 'strengthening measures' were delivered inside a proceeding where visible cooperation reduces exposure.
Firm facts, one narrow pipe
We would defend the numbers and the four findings without hesitation — they are specific, internally consistent and attributed to a regulator's decision. What holds this back from higher is structural: one publisher, no primary document in hand, no hospital or group response, and an attacker narrative nobody has tested. The arithmetic on top of it is ours and is only as good as the counts it divides.