CNIL (Commission Nationale de l'Informatique et des Libertés) has fined Hôpital privé de la Loire €500,000 (about $580,000) over the security failures behind a summer 2025 breach. The attacker reached the records of 524,867 patients. They also reached the records of 202,246 people designated by patients as trusted third parties, and the hospital notified the patients while never directly informing that second group. The regulator made its decision public on September 3, 2026, under deliberation SAN-2026-009.
CNIL cited that omission under Article 34 of the GDPR (General Data Protection Regulation). The more useful question for anyone running a health data environment is how a notification process reaches half a million people and misses two hundred thousand more sitting in the same system.
Who the Second Group Was
Under Article L1111-6 of the French Code de la santé publique, any adult may designate a ‘personne de confiance’ (trusted person); a relative, a close friend, or their treating physician. Hospital staff consult them if the patient becomes unable to express their own wishes. The patient makes the designation in writing, and hospitals must offer every admitted patient the opportunity to make one. The resulting record holds a name, contact details, and a stated relationship to the patient.
None of those 202,246 people were patients. They never registered, never received care, and in many cases never knew a hospital held a file describing them. CNIL found that the omission deprived them of the information needed to understand the attack, judge its likely consequences, and take steps against misuse of their data.
Every hospital carries versions of this population: emergency contacts, escorts who accompanied a patient, next of kin recorded during an admission, referring physicians named in a discharge letter, and legal guardians. Their records rarely live in the systems an inventory exercise starts with.
Where Uncatalogued Personal Data Accumulates
Healthcare organizations build their data protection policies around health data. Detection rules look for diagnostic codes, medical record numbers, insurance identifiers, and treatment details, because that is what the regulations name and what auditors ask about.
A trusted third-party record contains none of that. It holds a name, a phone number, an address, and a relationship. Measured against a policy tuned for clinical content, the file scores clean. It contains regulated personal data in full, and nobody asked the rule set to look for it.
That gap explains how a hospital can run a competent notification process and still produce an Article 34 finding. The process worked on the population the organization had catalogued. The uncatalogued population was invisible to it, both during normal operations and after the breach.

Reading Contents Instead of Trusting Labels
Proactive DLP™ Technology inspects what is inside a file rather than what its name, extension, or classification label claims. It covers 125+ file types, including text, images, and embedded documents, and inspects recursively, so it examines archives and nested layers rather than skipping them.
Three capabilities matter for finding personal data nobody catalogued:
- Detection built for personal identifiers alongside clinical ones. Detectors powered by AI cover personal names, dates of birth, phone numbers, and national identification, passport, and driver's license numbers, alongside clinical detectors for diagnostic codes, common medical conditions, and blood type. For a French environment, one detail matters: the AI PII detection supports French alongside English, Spanish, German, Italian, and Portuguese

- OCR for documents that are images. Proactive DLP™ reads scanned forms, photographed paperwork, and non-searchable PDFs the same way it reads text documents. A designation form or DICOM scan that exists only as a scan stops being a blind spot

- Classification and tagging that produce a record. Proactive DLP™ classifies detected content against predefined sensitivity levels and embeds classification tags into the processed file. Those tags feed a SIEM platform or document management system, which turns individual detections into an accumulating picture of where regulated data lives. Document identification adds category-level classification for identity and financial documents

Content inspection at transfer points sees files as they move: uploads, downloads, email attachments, removable media, and managed transfers. It builds a map from real traffic rather than crawling storage at rest, which means the picture develops as data flows and needs pairing with a discovery exercise for archives that never move.
Proactive DLP runs inside MetaDefender Core, MetaDefender ICAP Server, MetaDefender Email Security, MetaDefender Kiosk, and MetaDefender Managed File Transfer.
The Practical Step
A breach notification list is an inventory problem solved under time pressure. Building it mid-incident means reconstructing which categories of people appear in which files, and the categories nobody documented are the ones that get missed.
IBM's 2026 Cost of a Data Breach Report puts the average healthcare breach at $6.64 million, the highest of any industry for the thirteenth consecutive year. Mean time to identify and contain reached 247 days, and removable media and supply chain compromise took longest at 258 days. A content inspection point covers both paths.
Start from the other direction. Point Proactive DLP™ Technology at the file flows already moving through your environment and classify what comes back. The tags accumulate into a record of the personal data you hold about people who are not your patients.

