What an Attacker Actually Walked Into
An attacker reached Hopital Prive de la Loire's Computerised Patient Summary system in the summer of 2025 by using weak remote-access credentials; the facility had deployed neither a VPN nor multi-factor authentication to protect that entry point, CNIL's investigation found. Once inside, a single set of login credentials could reach every patient's full record on the system, with no segmentation by department, care team, or need-to-know.
Nothing flagged the unusual volume of records being pulled over the following days, so the extraction ran undetected until it was already complete. CNIL's decision treats that absence of real-time alerting as its own separate finding, not a footnote to the missing VPN and MFA.
The Fine Is Not the Story; the Standard Is
CNIL's EUR 500,000 penalty, announced 3 September 2026, is modest next to the GDPR fines levied against large tech platforms, but the reasoning behind it matters more than the amount. The regulator did not need to show the hospital's security was sophisticated-adversary-proof; it only had to show two specific, well-documented controls were absent. That is a much lower bar for enforcement, and it is the bar CNIL is now applying to any organisation holding special-category health data over a remote connection.
For a private clinic group the size of Ramsay Sante, EUR 500,000 is a rounding error. For a smaller clinic, dental practice, or health-tech vendor running the same setup, the same finding, VPN and MFA missing on remote access to health records, would trigger the identical enforcement logic against a much less forgiving balance sheet.
The Numbers CNIL Put on the Record
Three figures from the decision give any data controller a rough yardstick for its own exposure.
| Figure | Value |
|---|---|
| Patients with health data exposed | 524,867 |
| Associated third parties exposed, not notified | 202,246 |
| Fine issued | EUR 500,000 |
| Fine per affected patient | Under EUR 1 |
| Deadline to fix each control gap | 3 to 15 months |
Under one euro per record is not a figure CNIL published directly, it is simple division, but it is the number a board actually asks for once a breach report lands on the table.
The Gap Nobody Is Asking About Yet
CNIL's decision confirms that Hopital Prive de la Loire notified the 524,867 patients whose records were compromised, but not the 202,246 people recorded in the system only as associated third parties, such as referring practitioners, emergency contacts, or guarantors, whose personal data sat in the same exposed database.
GDPR's breach-notification duty runs to every data subject at meaningful risk, not only to the person the record is nominally about. Whether a third party's inclusion in a health record without direct notification survives a future challenge is an open question this decision does not settle, and it is exactly the kind of gap a determined complainant or a follow-up CNIL inquiry could reopen.
What This Changes for Anyone Running Remote Access to Health Data
Three practical changes follow directly from this decision for a clinic, hospital group, or health-tech vendor anywhere in the EU: treat VPN and MFA on remote access as a compliance floor rather than a budget line to defer, split record access by role so no single login can reach an entire patient population, and add real-time alerting on unusual data volumes pulled from any one account.
A fourth, less obvious change: audit who else's data lives inside a patient record, referring doctors, emergency contacts, guarantors, and confirm the organisation's breach-notification list actually reaches all of them, not just the patient whose name is on the file.
Servola Journal
We do this for everyone trying to keep up with what technology is doing to our lives. The people who build it, and the people it happens to. The Servola Journal exists so that what we learn belongs to all of them.
Nobody pays us for this. No ads, no paywall, free to everyone. We just believe that understanding what's happening to all of us shouldn't depend on who can afford to pay for it.
If it gave you something today, tell us to keep going. Follow us, leave a like, or write a positive comment. We read every one, and they are what keeps us going.
Read next: If Your Company Fails, Your Emails Get Sold | Second LED Patch, Same Unanswered CNIL Objection



