France's data protection authority, CNIL, has fined Hôpital privé de la Loire — a Saint-Étienne hospital operated by Ramsay Santé, treating around 60,000 patients a year — €500,000 over a breach in the summer of 2025.
An attacker reached the electronic patient record system and took data on 524,867 patients and 202,246 trusted third parties: the family members and carers patients had named as their contacts. 727,113 people in total.
A teenager using the alias Marak claimed responsibility and offered the data for €2,000 to €5,000. It was never sold and never published.
The failures CNIL cited are ordinary
Under GDPR Articles 32 and 34, the regulator found:
- External users, including private-practice physicians, could access the record system without a VPN and without multi-factor authentication.
- Access controls were inadequate, allowing broad access across patient records.
- There was no real-time monitoring, so the attacker operated undetected for days.
- The hospital notified patients, but did not directly contact the 202,246 third parties.
Nothing on that list is advanced. There is no zero-day, no supply chain, no nation-state. A teenager walked into a system that had no second factor in front of it and nobody watching it.
That is the useful part of a regulator's finding: it describes what was missing rather than what the attacker was clever at.
The people nobody told
The Article 34 finding deserves more attention than it will get.
The 202,246 third parties are in that database because a patient wrote their name down as a person to contact. They never signed up for anything. They have no account, no relationship with the hospital, and no reason to be watching for a notification.
They are also the group the hospital did not tell.
That is a structural problem, not an oversight by one organisation. Systems routinely hold data about people who are not the customer — emergency contacts, dependants, referrers, next of kin — and breach notification processes are built around the customer list. If your notification plan is "email the account holders", you have already decided not to tell everyone else.
€2,000 asked, €500,000 fined
The gap between those numbers is the whole economics of this in one line.
The attacker valued 727,000 people's medical records at somewhere between two and five thousand euros. The regulator valued the failure to protect them at half a million — a hundred to two hundred and fifty times the asking price — and did so for a breach where nothing was sold and nothing was published.
CNIL is not pricing the harm that happened. It is pricing the absence of controls, which is the only thing a regulator can price reliably, because whether stolen medical data surfaces later is not something anyone can know at the time.
The comparison worth making is with the Dutch DPA's €825 million against Uber. Different scale, same logic: the penalty attaches to the practice, not to the outcome.
And a number that is a number
727,113 records is 727,113 records. Unlike the McKesson figure, where the attacker's count of records was reported as a count of people, CNIL's numbers come from the regulator, split into two named populations, and describe individuals.
CNIL notes the hospital strengthened its security during the proceedings. It has not published how the fine was calculated.
What to do
- Find the external access paths into your clinical or customer systems. Private-practice physicians, contractors, partner clinics — the accounts that belong to people not on your payroll are the ones least likely to have MFA.
- Count the people in your data who are not your customers, and check whether your breach notification plan can reach them. If it cannot, that is the finding, before anyone breaches you.
- Real-time monitoring is a regulatory expectation, not a maturity goal. "Undetected for days" was cited as a failing, not as context.
- Do not calibrate risk to whether data gets sold. In this case it did not, and the fine was €500,000 anyway.
What is not established
- How the fine was calculated. CNIL has not published the methodology.
- Whether the hospital is appealing. No response is reported.
- What happened to Marak, or whether charges followed.
- Whether the data still exists anywhere outside the hospital.
- What specifically was exposed per record, beyond that it was patient data and named contacts.