France’s data protection authority has handed Hôpital Privé de la Loire a GDPR fine of €500,000 after a breach exposed the sensitive records of more than 727,000 people, patients, relatives and trusted contacts alike. The decision, issued on 21 July 2026 according to DataGuidance, lands a year after the attack and makes uncomfortable reading for anyone still relying on perimeter security alone.
The hospital, known as HPL, is a general hospital in Saint-Étienne. It has been part of the Ramsay Santé healthcare group since 2008, according to Captain Compliance, and provides a broad range of services including medical, surgical, maternity, cancer, intensive-care and emergency care. The hospital employs 650 staff, among them 180 doctors, operates 333 beds across five clinical divisions, and sees around 60,000 patients a year.
How the breach unfolded
The attack began on 26 June 2025, when an attacker gained access to HPL’s electronic patient record system and extracted data belonging to 524,867 patients along with another 202,246 people recorded as trusted third parties, relatives or others who had accompanied or assisted patients. The system held records concerning roughly 530,000 patients by 2025, Captain Compliance reported. In total, more than 727,000 individuals were affected.
A teen hacker using the alias ‘Marak’ later claimed responsibility, contacting the French outlet Le Progrès via Telegram and stating that the attack began with a breach of a single doctor’s account, which then provided access to HPL’s entire internal system. Marak attempted to sell the stolen data to a single buyer for a price between €2,000 and €5,000, though it was later reported that the data was neither sold nor published.
What made the breach possible, and what kept it running undetected for several days, was a cluster of security failures that the CNIL laid out in its investigation.
The GDPR failures the CNIL found at Hôpital Privé de la Loire
External users, including private-practice physicians, could access the patient record system without a VPN or multi-factor authentication. Once inside, the compromised account faced no meaningful access controls: it could reach records for every patient in the hospital, not just those relevant to the account holder’s practice. That combination is about as close to an open door as a healthcare system can get.
Compounding the problem, HPL had no real-time or near-real-time monitoring and alerting in place. The attacker was therefore able to explore the system and extract a large volume of data over several days without triggering any alarm. By the time the breach was discovered, the damage was done.
On the notification side, HPL informed affected patients of the breach but did not directly notify the 202,246 trusted third parties whose data had also been stolen. The CNIL tied these failures to violations of Article 32 and Article 34 of the GDPR, covering security obligations and communication of breaches to individuals respectively. The committee did note that HPL took several security-strengthening measures during the proceedings.
The €500,000 penalty reflects both the scale of the exposure and the nature of the data involved. Healthcare records sit at the top of the GDPR’s sensitivity hierarchy, and a breach that swept up the data of over half a million patients through a single compromised account, with no detection for days, is precisely the scenario the regulation’s Article 32 was designed to prevent. The case is a pointed reminder that valid credentials, once obtained, can move very far through a system that lacks internal controls.

