The attacker asked €2,000 for the data. The regulator fined the hospital €500,000
2026-09-05Security
CNIL penalised Hôpital privé de la Loire over a 2025 breach reaching 524,867 patients and 202,246 family members and carers. External physicians could reach the record system with no VPN and no MFA, and nobody was watching. The data was never sold.