French hospital fined €500,000 after breach exposes data of 727,000

French hospital fined €500,000 after breach exposes data of 727,000
France’s CNIL fined Hôpital privé de la Loire €500,000 after a 2025 data breach exposed sensitive information belonging to more than 727,000 people linked to the hospital. The investigation found major GDPR security failures, including weak access controls, lack of VPN and multi-factor authentication, and insufficient monitoring; the teen hacker “Marak” later claimed responsibility. #HôpitalPrivéDeLaLoire #CNIL #Marak #GDPR

Keypoints

  • CNIL fined Hôpital privé de la Loire €500,000 for poor data protection.
  • The breach exposed data on 524,867 patients and 202,246 trusted third parties.
  • Attackers accessed the hospital’s electronic patient record system in 2025.
  • CNIL found missing VPN, no multi-factor authentication, and weak access controls.
  • The hacker “Marak” claimed the attack and tried to sell the stolen data.

Read More: https://www.bleepingcomputer.com/news/security/french-hospital-fined-500-000-after-breach-exposes-data-of-727-000/