Skip to main content
Imprimer

Decision of the Restricted Committee of the French Data Protection Authority No. SAN-2026-009 of July 21, 2026

Healthcare institutions have for several years been a prime target for cyberattacks, even though their information systems contain large volumes of particularly sensitive data. In a decision of July 21, 2026, the restricted committee of the French Data Protection Authority (“CNIL”) fined a private hospital €500,000 following a cyberattack that led to the exfiltration of the data of more than 500,000 patients.

This decision is noteworthy on two counts: it restates a number of basic measures that must be implemented to secure information systems containing health data, and it stands out for the level of detail of the restricted committee’s analysis. It offers useful guidance for controllers in shaping their own practices.

Exfiltration of 524,867 Patient Records

The private hospital uses a computerized patient record system (“DPI”) that traces patients’ care pathways and coordinates the work of the various professionals involved in their treatment. In 2025, the DPI contained the data of approximately 530,000 patients. The information recorded included, in particular, civil status data, social security numbers, patients’ contact details, and their family and employment circumstances, as well as health data and, in some cases, copies of the front of national identity cards.

In June 2025, an attacker gained access to the DPI using the credentials of an account belonging to a self-employed physician affiliated with the hospital. After a reconnaissance phase that enabled the attacker to understand how the application worked, the attacker exfiltrated 524,867 patient records between June 26 and July 1, 2025. Of those, 202,246 contained data relating to trusted third parties designated by the patients (relatives).

The hospital notified the breach to the CNIL on July 4, 2025. In parallel, the authority received nine complaints from data subjects affected by the breach, and then carried out an on-site inspection at the institution’s premises.

The authority found several failures to comply with the security requirements laid down by the GDPR. It specifies, however, that the penalty imposed does not target the data breach as such, but rather the inadequacy of the security measures implemented beforehand, which allowed the incident to occur.

Inadequate Security of Remote Access

The first violation concerns the conditions of remote access to the DPI.

At the time of the attack, approximately 450 users external to the hospital — including self-employed practitioners, their administrative staff, and certain employees of the software publisher — were able to connect to the DPI directly over the internet using nothing more than a username and password. Neither a VPN nor any two-factor authentication mechanism was required.

The CNIL points out that the reference framework on the electronic identification of users of digital health services (made binding by a 2022 order) requires two-factor authentication for this type of remote access. The version of the software used by the institution did in fact allow such a measure to be implemented, but it had not been activated.

The CNIL notes that, had multi-factor authentication been implemented, knowledge of the compromised password alone would not have granted access to the DPI.

Overly Permissive Access Rights Policy

The restricted committee then turns to the access rights policy implemented within the DPI.

It recalls in this respect that an access rights policy must limit access to only the data each user needs to carry out their duties. In the healthcare sector, that policy must also take into account the concept of the “care team” set out in the French Public Health Code: by default, only those professionals actually involved in a patient’s care should be able to access information covered by medical confidentiality.

In this case, the hospital had put in place a matrix distinguishing between different job categories and determining which DPI modules each of them could access. The software, however, did not allow patient records to be partitioned. Medical and paramedical professionals could therefore consult the data of all of the institution’s patients within the modules to which they had access, including where they were not involved in those patients’ care.

That shortcoming also directly contributed to the scale of the breach: having compromised a single physician’s account, the attacker was able to access the data of all of the hospital’s patients. The restricted committee emphasizes that, had partitioning been implemented, the leak would have been limited to the records of the patients actually treated by the physician whose credentials had been stolen.

Insufficient Traceability Measures

The decision also provides valuable guidance on obligations relating to access logging. The CNIL recalls that implementing a logging mechanism contributes to compliance with the security obligation laid down by the GDPR, but above all that such security must be “essentially active.” The information recorded must therefore be capable of being used in real time or in the short term in order to detect abnormal operations and enable a rapid response to an incident.

Here, the hospital did have various security tools as well as a system for retaining records of the actions performed by DPI users. Those application logs, however, were not subject to any automated analysis or regular review and were examined only on request, in particular where an anomaly was suspected.

That shortcoming also materialized during the attack. After a reconnaissance phase of approximately twelve hours comprising 665 requests, the attacker carried out, over five days, an automated extraction of 524,867 patient records, an average of 73 records accessed per minute. The restricted committee considers that a logging system including automated analysis of application logs could have made it possible to detect promptly this volume of queries, incompatible with human activity, and to bring the exfiltration to an end sooner.

Other Vulnerabilities and Violations Identified by the CNIL

In addition to the three main vulnerabilities that caused or facilitated the data breach, the CNIL identified two further security shortcomings in the course of its inspection:

  • The first concerns the password reset procedure implemented following the attack: the hospital assigned an identical temporary password to all external practitioners and sent it to the chair of the institution’s medical committee, who was to pass it on to them. That process plainly could not ensure the confidentiality of DPI credentials.
  • The second concerns the software publisher’s employees, who had permanent access to the DPI and could connect to it at their own initiative, without prior authorization from the hospital.

The CNIL lastly finds a violation of Article 34 of the GDPR: while the hospital had informed the patients affected by the breach, no individual notice had been sent to the 202,246 individuals designated as trusted persons, whose data had also been exfiltrated. The restricted committee considers that the information concerned was likely to expose them to a high risk, in particular of phishing or identity theft attempts.

€500,000 Fine and Compliance Order

In light of all of these factors, the restricted committee imposes an administrative fine of €500,000 for the violations of Articles 32 and 34 of the GDPR. To determine the amount of that fine, the CNIL applies the concept of “undertaking” within the meaning of the GDPR and recalls that it must be understood as an economic unit, which may be made up of several legal entities. Here, it takes the view that the hospital and the group to which it belongs form part of a single economic unit. In order for the fine to be effective, proportionate, and dissuasive and to reflect the actual economic capacity of its addressee, its amount is therefore assessed by taking the parent company’s turnover into account.

It also issues a single order to bring the processing into compliance with Article 32 of the GDPR. That order covers three measures:

  • implementing a logging system with proactive log analysis capable of detecting abnormal behavior;
  • updating the access rights policy so that, by default, only those persons with a need to know can access the data, while providing for a “break-glass” mechanism for emergency situations; and
  • implementing technical measures so that the software publisher can access the DPI only with the hospital’s prior authorization.

These measures must be implemented within three, fifteen, and three months respectively, and each is subject to a penalty payment of €1,000 for each day of delay.

The value of this decision lies in particular in the method followed by the CNIL in assessing that obligation. For each vulnerability, the authority starts from the concrete risks presented by the processing, identifies the measures that should have been implemented in light of the legal framework and the state of the art, then verifies whether they were actually deployed and, for the main shortcomings, what role they played in bringing about or amplifying the attack. This should give controllers, particularly in the healthcare sector, a concrete illustration of how compliance with Article 32 of the GDPR is to be assessed.

Imprimer