Privacy Law Updates EDPB news

Health data breach: the CNIL fined Hôpital Privé de la Loire 500 000 EUR

The headline and the excerpt are the source’s own words.

Read it at cnil.fr · via EDPB

Source
European Data Protection Board
Published by the source
Type
Enforcement action
The source's category
Cybersecurity, Personal data breaches, Health and research

Status: not tracked by DeSpy · checked 2026-09-28 · the source's record

In EDPB’s words

In summer 2025, an attacker managed to connect to the Computerised Patient Summary (DPI) of the Hôpital Privé de la Loire (Loire’s private hospital), which centralises all the data of the individuals under care. It thus accessed the data of 524 867 patients (some of them health data) and 202 246 persons designated as “trusted third parties”. As a result of this data breach, the French Data Protection Authority (CNIL) carried out a check that identified several failures of the Hôpital Privé de la Loire to comply with the obligations laid down in the General Data Protection Regulation (GDPR).

Source: European Data Protection Board, edpb.europa.eu — excerpted; the headline is reproduced without alteration

Documents the source links

Source: European Data Protection Board, edpb.europa.eu — excerpted; the headline is reproduced without alteration. EDPB reuse notice (acknowledge the source; do not distort it).

Source record Collected from European Data Protection Board · First read at the source 2026-09-28 (automated)

Spotted a mistake in how this entry is shown? Email privacy@despy.app and quote edpb-20260909-561699.