top of page
Search

€500,000 GDPR fine for a hospital

Writer: Katarzyna  Celińska
Katarzyna Celińska
2 days ago
2 min read

The French CNIL fined HÔPITAL PRIVÉ DE LA LOIRE €500,000 after a 2025 breach exposed data relating to 524,867 patients and 202,246 people designated as trusted third parties. For some patients, the compromised information included sensitive Health Data.

 

External users, including private practitioners, could access the hospital’s patient-record system without sufficiently robust authentication. There was no VPN and no MFA. Access management was another problem. Permissions were not sufficiently limited to professionals actually involved in treating a particular patient. As a result, credentials from a single account enabled the attacker to access data across the hospital’s patient population.

 

Photo: DC Studio - Magnific


Additionally, the hospital lacked adequate mechanisms to identify suspicious activity in real or near-real time. The attacker was therefore able to explore the system for several days and extract a large volume of data without triggering an effective response.

 

Patients were informed, but 202,246 trusted third parties whose data had also been compromised were not directly notified.

 

Incidents like this do not happen only in Poland. Unfortunately, Poland is not the only country where parts of the healthcare sector still lack basic security mechanisms or simply management awareness that Cybersecurity requires continuous investment if maturity is expected to improve. By investment, I do not mean producing more policies, procedures or compliance documentation. I also do not mean buying an expensive firewall that nobody can properly configure and whose alerts nobody later monitors.

 

I mean the foundations.

Strong identity and access management.

MFA.

Asset and vulnerability management.

Patching.

Logging.

Monitoring.

Backups.

Segmentation.

Incident response.

Security awareness.

 

This is particularly important because healthcare combines several uncomfortable factors at once. It is frequently targeted by attackers, processes highly sensitive medical information, and, unlike many other sectors, a serious cyber incident may affect the health and safety of patients. Additionally, attack automation is increasing, and offensive use of AI can further reduce the cost and time required to identify vulnerabilities, prepare phishing campaigns, automate reconnaissance, or scale attacks.

 

We really need to address this problem more seriously, because the threat landscape is moving faster than the maturity of many healthcare organizations



 
 
 

Comments


Stay in touch

META FOR MENA Information Technology Consultants Est.

City Avenue, 7th floor, office 706-0114

2 27 Street, Port Saeed, Deira, Dubai, United Arab Emirates
P.O. BOX: 40138
Licence N.O.: 1049080

​

Privacy policy

  • Facebook
  • Twitter
  • LinkedIn
  • Instagram
bottom of page