Hospital cyberattack: 5 lessons from the €500,000 CNIL fine

Remote access without MFA, logs nobody reviewed, a vendor with free rein: what the CNIL held against a hospital, and what autumn 2026 confirms.

· 8 min read
Illustration: a glass medical cross protected by a cracked shield

A hospital cyberattack does not always start with ransomware. At the Hôpital privé de la Loire, a private hospital in France, the login of a single independent doctor was enough to copy 524,867 patient records from the electronic health record (EHR). On 3 September 2026, the CNIL, France's data protection authority, published a €500,000 fine against the hospital. Its findings boil down to five lessons: protect remote access, limit access rights to the care team, analyse the logs, keep the software vendor in check and prepare for the crisis. Here is what every healthcare organisation can take from it, with recent cases to back it up.

01

Hospital cyberattack at the Hôpital privé de la Loire: how it unfolded

The facts are set out in deliberation SAN-2026-009 of 21 July 2026, summarised by the CNIL and analysed by Next and Caducée. In late June 2025, an attacker logged into the hospital's EHR, part of the Ramsay Santé group, using the account of an independent doctor. The decision does not say how those credentials were obtained.

According to the post-incident analysis, the intruder spent about 12 hours exploring the tool (665 queries), then automated the extraction for five days, from 26 June to 1 July 2025: roughly 73 records per minute, a pace no clinician could keep up. In total, 524,867 patient records were taken (civil status, social security number, contact details), 46,185 of them with the front of an ID card and 43 containing health data, along with information on 202,246 trusted persons designated by patients. The hospital notified the CNIL on 4 July 2025, and that part was not held against it.

  • Late June 2025: login to the EHR with an independent doctor's credentials, without VPN or two-factor authentication.
  • About 12 hours of reconnaissance: 665 queries.
  • 26 June to 1 July 2025: automated extraction, about 73 records per minute, with no alert.
  • Outcome: 524,867 patient records and 202,246 trusted persons.
  • 4 July 2025: notification to the CNIL. 3 September 2026: the fine is published.

The CNIL's restricted committee found two GDPR breaches: Article 32 (security of processing) and Article 34 (informing data subjects). It imposed a €500,000 fine and gave the hospital three to fifteen months to complete its measures, depending on their type. As Caducée points out, the decision creates no new standard: it applies existing requirements to a real case. That is exactly what makes it useful to every healthcare organisation.

The five failures, lesson by lesson
  1. Remote access Username and password, no VPN or MFA, for ~450 external users
    Two factors for any external access (order of 28 March 2022)
  2. Access rights A single account opens every patient's record
    Access limited to the care team, logged break-glass access
  3. Logs EDR, SOC and logs in place, but EHR logs never analysed
    Automatic alerts on massive or unusual access
  4. Vendor Permanent access to the data for the EHR vendor
    Access closed by default, opened with prior authorisation
  5. Crisis Shared temporary password; 202,246 trusted persons not informed
    Individual secrets; inform everyone affected (Art. 34)

Deadlines set by the CNIL: 3 to 15 months depending on the measure

02

Lesson 1: no remote access to the EHR without VPN and MFA

About 450 external users (independent practitioners, medical secretaries, some of the vendor's staff) connected to the EHR over the internet with nothing more than a username and password. Only around forty employees went through a VPN. Yet the French electronic identification framework approved by the order of 28 March 2022 requires two factors of different types for this kind of access. The software already supported two-factor authentication: the hospital was waiting for a group-wide solution, rolled out in September 2025, after the attack.

The right reflex: list every external access to clinical applications, including those of private practices and suppliers, and close any that do not go through a channel protected by two factors. France's CaRE programme for hospital cybersecurity points the same way: the instruction of 22 January 2025 asks healthcare organisations for a roadmap to secure the electronic identification of professionals. For their part, CERT-FR and CERT Santé report remote maintenance tools still exposed on the Internet, sometimes with no password at all.

03

Lesson 2: patient record security means each clinician sees only their patients

The second finding is probably the most fundamental: a single account gave access to the records of all the hospital's patients. Rights were split by job, department and module, but not by care team. The CNIL ties this requirement to the French public health code: a professional accesses the data of the patients they care for, with, where needed, a traced and monitored emergency "break-glass" access.

The detail that should give everyone pause: the data protection impact assessment (DPIA) carried out in 2021 had identified this as the main risk, with maximum severity. Known and documented, it was still untreated four years later. It is also the measure for which the hospital has the longest deadline: fifteen months to overhaul its access rights, according to Caducée.

The problem goes beyond this hospital. In their lessons-learned report CERTFR-2026-CTI-007, CERT-FR and CERT Santé describe access control failures that are "currently being exploited", especially in SaaS products: the attacker compromises a professional account, then gradually widens their reach. At VitalAire, a home healthcare provider hit on 19 September 2026, the hacker claims to have used a search function that did not limit results to each prescriber's own patients; the company has not confirmed this method.

04

Lesson 3: collecting logs is not enough, someone has to read them

The Hôpital privé de la Loire was not unequipped: it had an EDR, a security operations centre (SOC) and application logs. But nothing automatically analysed the EHR logs to spot abnormal behaviour. For almost a week, the attacker kept sending queries without triggering a single alert. In the CNIL's view, this lack of detection helped make the breach worse.

Seventy-three records a minute is more than one per second, day and night. A simple rule on the number of records opened per account per hour could have raised the alarm within the first few hours. CERT Santé specifically recommends that healthcare organisations detect unusual or massive access to sensitive data. In practice:

  • define a few anomaly scenarios: number of lookups, time of day, origin, a dormant account that wakes up;
  • send EHR logs to the SOC or SIEM, not just network and endpoint logs;
  • decide in advance who blocks a suspicious account, and how fast.
05

Lesson 4: the software vendor and suppliers are part of the risk

The EHR vendor had permanent access to the data, for maintenance purposes. The hospital pointed to its administration bastion. The CNIL's answer, as reported by Caducée: a bastion secures the route, it does not replace the hospital's prior authorisation. Vendor access must be closed by default, opened case by case and logged; the hospital has three months to comply.

Cyberattacks and health data: what autumn 2026 shows

Recent news shows how much that link matters. On 24 September 2026, AP-HP, the Paris public hospital group, learned that patient data was for sale on a forum. The leak did not come from its main system, but from the online service of the SRD meal-ordering software, published by Dedalus and used in 23 of its hospitals: 1,015 patients affected (identity, birth details, internal ID). In the United States, an intrusion into the cloud infrastructure of Aesto Health, a healthcare data archiving provider, affected 9,540,683 people, patients of many client organisations.

The CERT-FR and CERT Santé report reaches the same conclusion about software. According to a survey by France's digital health agency that it cites, 74% of healthcare organisations surveyed have dealt with a vendor that was slow or refused to fix a flaw, and 90% have no formal channel to report one. In one case, a fix was scheduled five years after the report. The Cyber Resilience Act now requires manufacturers to report actively exploited vulnerabilities (since 11 September 2026), but medical devices are excluded. Three reflexes, without waiting:

  • list the accounts and access of every vendor and supplier that touches patient data;
  • write two-factor authentication, a fix deadline, a reporting channel and incident notification into the contract;
  • reassess these suppliers regularly, not just when the contract is signed.
Autumn 2026: six warning signs for healthcare organisations
  1. Early Sept.United States Aesto Health 9.5M people Healthcare data archiving provider compromised Lesson 4
  2. 3 Sept.France Hôpital privé de la Loire €500,000 CNIL fine Penalty published for missing basic security measures Lesson 1-5
  3. 4 Sept.United States Luminis Health 2 hospitals Phones disrupted for weeks, patient portal offline Lesson 5
  4. 19 Sept.France VitalAire · Orkyn 2 providers Home care: patient extranets suspended, social security numbers exposed Lesson 2
  5. 24 Sept.France AP-HP · Dedalus 1,015 patients Leak through the online meal-ordering module Lesson 4
  6. 2 Oct.France CERT-FR · CERT Santé 74% of organisations have seen a vendor delay or refuse a fix Lesson 4
06

Lesson 5: prepare for the crisis before a health data breach

The last two findings concern the aftermath. To get accounts back in order, the hospital gave the same temporary password to every external practitioner, passed on through the chair of the medical committee. A shared secret is no longer a secret: the CNIL saw it as a failure to keep authentication credentials confidential. In a crisis, each user must receive an individual secret through a secure channel.

Next, the hospital did inform its patients, but not the 202,246 trusted persons whose data had also been stolen. Yet Article 34 of the GDPR requires informing data subjects when a breach poses a high risk to them. Identifiable and often reachable, they were exposed to phishing and identity theft. Before any crisis, you therefore need to know which categories of people appear in each processing activity: patients, relatives, professionals.

Continuity of care and the CaRE programme

A data leak is not the only hospital cyberattack scenario. On 4 September 2026, Luminis Health (Maryland) suffered a cyberattack affecting two of its hospitals. According to public radio station WYPR, phone service was disrupted for weeks and the patient portal was still offline on 22 September. The French CaRE programme plans for this: the January 2025 instruction requires one cyber crisis exercise a year involving decision-makers, a business impact analysis of critical services by the end of June 2026, then a continuity and recovery plan by the end of June 2027.

07

How to prepare: from risk analysis to action plan

After a hospital cyberattack, people tend to look for the technical flaw. Yet the failures found at the Hôpital privé de la Loire have one thing in common: they were known or foreseeable. The risk of overly broad access was in the DPIA as early as 2021, the authentication framework dated from 2022 and the vendor's access was a deliberate choice. What was missing was a process that turns these findings into tracked actions, each with an owner and a deadline.

A risk analysis using the EBIOS RM method puts these scenarios in writing: theft of a practitioner's credentials, compromise of a vendor, the EHR going down. Its workshop on the ecosystem requires mapping the suppliers that touch patient data. Phinasoft supports this approach with risk analysis software whose EBIOS RM module is labelled by ANSSI, a vendor risk management module and a GDPR module that links the record of processing, DPIAs and the action plan. To go further, read our articles on this autumn's data leaks and on ransomware that gets in through VPNs and firewalls.

08

Frequently asked questions

Why did the CNIL fine the Hôpital privé de la Loire?

For breaches of Articles 32 and 34 of the GDPR: remote access without VPN or two-factor authentication, access rights that ignored the care team, no detection of suspicious activity and failure to inform 202,246 trusted persons. According to reports on the deliberation, the vendor's permanent access and the shared temporary password were also noted. The fine amounts to €500,000.

What should a hospital do after a cyberattack with a data leak?

Contain first: cut off the compromised access and reset accounts with individual secrets. Then notify the data protection authority within 72 hours (Article 33 GDPR) and inform the people concerned if the risk is high, including relatives whose data appears in the record. AP-HP, for example, also alerted the national cybersecurity support unit for healthcare organisations and filed a complaint.

Is HDS certification enough to protect patient records?

No. France's HDS certification covers the hosting of health data. Access rights in the EHR, user authentication and monitoring of record lookups remain the hospital's responsibility, and these are exactly the points the CNIL penalised.

What is the CaRE programme?

CaRE (Cybersécurité accélération et Résilience des Établissements) is the French health ministry's hospital cybersecurity programme, led by the Digital Health Delegation with the Digital Health Agency. It sets priority actions: an annual crisis exercise, a maturity self-assessment, Active Directory audits, continuity plans and stronger identification of professionals.

How can you spot the exfiltration of patient records?

By monitoring the EHR logs, not just the network: number of records opened per account, time of day, where connections come from. In the case that was penalised, a pace of 73 records per minute for five days should have triggered an automatic alert.

Summary

01

Basic failures

No two-factor authentication, overly broad access rights, logs never reviewed: the CNIL only penalised well-known measures that the hospital had not put in place.

02

Third parties as the way in

Permanent vendor access, AP-HP's meal-ordering module, a US archiving provider: this autumn's healthcare breaches often came through a supplier.

03

A known risk must be treated

The main risk was already in the 2021 DPIA. A risk analysis only protects you if it turns into an action plan that someone follows up.

A platform and service that adapt to you

Our platform is designed for fine-tuned configuration and broad adaptability to your needs.