CNIL Fines French Hospital EUR 500,000 Over Breach Notification Failure

Independently fact-checkedBy Recording Law Editorial Team9 min read

Independently fact-checked against primary sources (last audited September 3, 2026). · 4 primary sources cited on this page. How we verify our legal content

CNIL Fines French Hospital EUR 500,000 Over Breach Notification Failure

Frequently Asked Questions

How much did the CNIL fine Hôpital Privé de la Loire?

EUR 500,000. The CNIL published the decision on September 3, 2026; the deliberation, numbered SAN-2026-009, is dated July 21, 2026 in the regulator's own reference to it.

How many people were affected by the breach?

The attacker reached data on 524,867 patients, including health data for some of them, and on 202,246 people whom patients had designated as trusted third parties, more than 727,000 people in total.

What security failures did the CNIL identify?

Three. Remote access to the patient record system lacked both a VPN and multi-factor authentication; the authorisation policy did not restrict access to the care team, so one compromised account could reach every patient's records; and there was no capability to detect suspicious activity in real time, so the attacker explored the system for several days undetected.

Why was the hospital penalised over notification when it did tell patients?

Because GDPR Article 34 runs to everyone affected by the breach, not only to the organisation's own patients or customers. The CNIL found the hospital gave no direct information to the 202,246 designated trusted third parties whose data was also stolen.

What is a 'tiers de confiance' in this decision?

The CNIL describes them as people designated by patients as trusted third parties. Their personal data was held in the hospital's patient record system and was taken in the same intrusion, which is what brought them within the notification duty.

Does GDPR Article 34 apply to people who were never customers?

The duty is owed to data subjects affected by the breach. This decision applies it to individuals whose data was in the breached system because someone else named them, rather than because they had a relationship with the controller.

What is the difference between Article 33 and Article 34 of the GDPR?

Article 33 concerns notifying the supervisory authority about a breach; Article 34 concerns communicating it to the affected individuals. They are separate obligations and an organisation can comply with one and not the other. The CNIL's findings in this case were under Articles 32 and 34.

Does the fine mean affected people get compensation?

No. A CNIL fine is a regulatory penalty paid to the state, not a compensation fund. The GDPR provides a separate route for individuals to seek compensation for damage through the courts.

What must the hospital do now besides pay?

The CNIL noted the hospital had already taken several measures to strengthen its security during the proceedings, and required it to finish implementing them within deadlines of between three and fifteen months depending on the type of measure.

Updates

Published after an independent adversarial fact-check against the CNIL's own French-language decision announcement.

Independently fact-checked against the cited primary sources

Sources and References

  1. CNIL, 'Violation de donnees en matiere de sante : sanction de 500 000 euros a l'encontre de l'HOPITAL PRIVE DE LA LOIRE', published 3 September 2026, reporting deliberation of the formation restreinte no. SAN-2026-009 of 21 July 2026(cnil.fr).gov
  2. Deliberation de la formation restreinte no. SAN-2026-009 du 21 juillet 2026 concernant la societe HOPITAL PRIVE DE LA LOIRE, official text on Legifrance (the full CNIL decision imposing the EUR 500,000 fine under GDPR Articles 32 and 34)(legifrance.gouv.fr).gov
  3. General Data Protection Regulation, Article 32 (security of processing), official French text hosted by the CNIL(cnil.fr).gov
  4. General Data Protection Regulation, Article 34 (communication of a personal data breach to the data subject), official French text hosted by the CNIL(cnil.fr).gov
Share: