惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Apple Machine Learning Research
Apple Machine Learning Research
aimingoo的专栏
aimingoo的专栏
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - 聂微东
Engineering at Meta
Engineering at Meta
N
Netflix TechBlog - Medium
Blog — PlanetScale
Blog — PlanetScale
大猫的无限游戏
大猫的无限游戏
Vercel News
Vercel News
D
DataBreaches.Net
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
WordPress大学
WordPress大学
L
LangChain Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
F
Fortinet All Blogs
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
J
Java Code Geeks
Recent Announcements
Recent Announcements
Jina AI
Jina AI
G
Google Developers Blog
腾讯CDC
博客园_首页
博客园 - 【当耐特】

EDPB News

Failure to respect the rights of individuals: The CNIL fined EXTIA 300 000 EUR Data Protection Commission announces Final Decision following Inquiry into the Health Service Executive (HSE) Stakeholder event on guidelines on the interplay between data protection and competition law: overview of topics available Stakeholder event on guidelines on the interplay between data protection and competition law: save the date EDPB calls for legal basis for cross-regulatory information sharing EDPB requires Belgian DPA to handle the merits of NOYB cookie banner complaint EDPB sheds light on anonymisation and web scraping for generative AI and adopts final version of guidelines on blockchain EDPB and AMLA to develop Joint Guidelines on partnerships for information sharing One-Stop-Shop case digest on right to object and right to erasure updated Supporting GDPR consistency: EDPB launches dedicated form EDPB gets a new look: discover the new website and brand identity Coordinated Supervision Committee extends scope to include Eurodac Coordinated Supervision Committee extends scope to include Eurodac EDPB meets with EU Commissioner McGrath and adopts common data breach notification template EDPB meets with EU Commissioner McGrath and adopts common data breach notification template The Italian SA imposed a 40 000 EUR fine on a company for violating the confidentiality of a employee's email account after the end of his employment The Italian SA fined Poste Vita for data breach Imposition of fine on a telecommunications company for violations of data subject’s rights The Italian Supervisory Authority fined a company 120 000 EUR for tracking five employees who drove company cars Italian SA fines a company for post-sick leave questionnaires The Italian Supervisory Authority has fined Verisure Italia for unlawful processing of personal data for direct marketing purposes EDPB and EDPS support strengthening EU’s cybersecurity and easing compliance while protecting individuals’ personal data Europe Day 2026: let’s celebrate together Marking 10 years of the GDPR: the evolution of the European data protection landscape Stakeholder event on competition and data protection: save the date Stakeholder event on competition and data protection EDPB brings clarity to data processing for scientific research, speeds up the finalisation of the anonymisation guidelines and approves first European data protection seal as a tool for transfers Enhancing compliance and consistency: EDPB adopts DPIA template EDPB annual report 2025: supporting stakeholders through guidance and dialogue EDPB conference on cross-regulatory cooperation: what we learned
Health data breach: the CNIL fined Hôpital Privé de la Lo...
EDPB · 2026-09-09 · via EDPB News

Summary of the Decision

Origin of the case

In summer 2025, an attacker managed to connect to the Computerised Patient Summary (DPI) of the Hôpital Privé de la Loire (Loire’s private hospital), which centralises all the data of the individuals under care. It thus accessed the data of 524 867 patients (some of them health data) and 202 246 persons designated as “trusted third parties”. As a result of this data breach, the French Data Protection Authority (CNIL) carried out a check that identified several failures of the Hôpital Privé de la Loire to comply with the obligations laid down in the General Data Protection Regulation (GDPR).

Key findings

  • Failure to ensure the security of personal data (Article 32 GDPR)
    The authentication procedure to connect to the hospital’s e-Health Patient Summary, used by users outside the hospital, in particular doctors not affiliated with the hospital, was not sufficiently robust, due to the lack of VPNs and multifactor authentication means. The attacker took advantage of this vulnerability to access the data. Moreover, the access control policy was inadequate: it did not take account of the concept of care team, so that only professionals actually involved in the care of a patient had access to the information covered by medical confidentiality. This lack of access limitation allowed the attacker, using the credentials of a single user account, to access the data of all hospital patients. Finally, the hospital had not taken measures to detect suspicious activity within the e-Health Patient Summary in real time or in the very short term, and to trigger an alert mechanism if necessary. In those circumstances, the attacker was able to explore the hospital’s e-Health Patient Summary for several days and extract a very large volume of data, without that abnormal activity being detected. This vulnerability has contributed to exacerbating the scale of the data breach.
  • Failure to inform data subjects about the data breach (Article 34 GDPR)
    Finally, the restricted committee found that only the patients of the Hôpital Privé de la Loire concerned by the data breach had been informed, but that no direct information had been provided to the 202 246 individuals designated by patients as trusted third parties, even though their personal data had also been stolen by the attacker.

Decision

The restricted committee – the body of the CNIL responsible for issuing sanctions – imposed a fine of 500 000 EUR on the Hôpital Privé de la Loire, taking into account, inter alia, the lack of awareness of essential security principles, the number of persons concerned, the nature of the data compromised and its financial capacities.

Further information: