France fines Saint-Étienne hospital €500,000 over breach hitting 727,000 people
A teenage hacker got into a doctor's account and roamed the patient record system for days. Regulators say the hospital's security controls were nowhere near enough.

Key points
- France's data protection regulator CNIL fined Hôpital privé de la Loire €500,000 (about $580,000) for security failings tied to a 2025 breach.
- The attack exposed data on 524,867 patients and 202,246 relatives or trusted contacts, a total of more than 727,000 people.
- A teenager using the name "Marak" broke in through a single doctor's account and spent days extracting records undetected.
- CNIL found no multi-factor authentication for external users, weak access limits, and no real-time monitoring.
- The hacker tried to sell the data for €2,000 to €5,000 but, by later reports, never found a buyer.
France's data protection authority, CNIL, has fined Hôpital privé de la Loire €500,000 for failing to protect patient records that ended up in the hands of a teenage hacker.
The hospital, known as HPL, sits in Saint-Étienne and belongs to the Ramsay Santé group. It handles surgery, maternity, cancer care, intensive care and emergencies, and sees around 60,000 patients a year across 333 beds.
In the summer of 2025, an attacker got into HPL's electronic patient record system and pulled out sensitive data on 524,867 patients. Another 202,246 people listed as "trusted third parties", usually relatives or emergency contacts, were also caught up in it. That is more than 727,000 individuals in total.
How did the hacker get in?
Through one doctor's account. A teenager using the alias "Marak" told French newspaper Le Progrès over Telegram that the whole intrusion started with a single compromised login, which then opened the door to the hospital's entire internal system.
Once inside, the intruder was not stopped by any of the barriers you would expect. External users, including doctors in private practice logging in from outside, could reach the system without a VPN, a private encrypted connection normally used to shield remote access. There was also no multi-factor authentication, the extra one-time code or app prompt that stops a stolen password from being enough on its own.
Access controls inside the system were loose too. The one compromised account could see records for every patient in the hospital, not just the ones that doctor treated.
And nobody was watching. CNIL said HPL had no real-time or near-real-time monitoring, so the hacker could wander the system and haul out data over several days without triggering an alert.
What did the regulator actually punish?
Breaches of the EU's General Data Protection Regulation, or GDPR, the bloc's main privacy law. Specifically, CNIL cited Article 32, which requires organisations to keep personal data secure, and Article 34, which forces them to tell affected people when something goes wrong.
HPL informed patients after the breach. It did not directly notify the 202,246 trusted third parties whose data was also taken, which the regulator flagged as a separate failure.
CNIL noted that the hospital tightened its security during the proceedings, which is likely why the fine landed where it did rather than higher.
| Detail | Figure |
|---|---|
| CNIL fine | €500,000 (about $580,000) |
| Patients exposed | 524,867 |
| Trusted third parties exposed | 202,246 |
| Total people affected | 727,000+ |
| Asking price for the stolen data | €2,000 to €5,000 |
Should patients be worried?
The data was reportedly never sold or published, according to follow-up reporting by BleepingComputer. "Marak" tried to offload it to a single buyer for between €2,000 and €5,000 and, by later accounts, found no takers.
That is not a guarantee it will stay buried. Anyone treated at HPL, or listed as a relative or emergency contact for someone who was, should be wary of unexpected phone calls, letters or emails that reference their hospital visit, and treat any request for bank details or ID numbers as suspicious. Health data is prized by fraudsters because it lends credibility to scams.
For hospitals watching from elsewhere in Europe, the message from CNIL is blunt: one weak login should not be enough to unlock every patient in the building.



