Learn More about Benny Czarny's Book Cybersecurity Upside Down

Learn More
We utilize artificial intelligence for site translations, and while we strive for accuracy, they may not always be 100% precise. Your understanding is appreciated.

A French Hospital Was Fined €500,000 for Data It Failed to Protect, and for People It Never Told

CNIL fined a hospital €500,000 after a breach exposed 202,246 trusted contacts it never notified
By Joseph Nguyen, Product Marketing Manager
Share this Post

CNIL (Commission Nationale de l'Informatique et des Libertés) has fined Hôpital privé de la Loire €500,000 (about $580,000) over the security failures behind a summer 2025 breach. The attacker reached the records of 524,867 patients. They also reached the records of 202,246 people designated by patients as trusted third parties, and the hospital notified the patients while never directly informing that second group. The regulator made its decision public on September 3, 2026, under deliberation SAN-2026-009.

CNIL cited that omission under Article 34 of the GDPR (General Data Protection Regulation). The more useful question for anyone running a health data environment is how a notification process reaches half a million people and misses two hundred thousand more sitting in the same system.

Who the Second Group Was

Under Article L1111-6 of the French Code de la santé publique, any adult may designate a ‘personne de confiance’ (trusted person); a relative, a close friend, or their treating physician. Hospital staff consult them if the patient becomes unable to express their own wishes. The patient makes the designation in writing, and hospitals must offer every admitted patient the opportunity to make one. The resulting record holds a name, contact details, and a stated relationship to the patient.

None of those 202,246 people were patients. They never registered, never received care, and in many cases never knew a hospital held a file describing them. CNIL found that the omission deprived them of the information needed to understand the attack, judge its likely consequences, and take steps against misuse of their data.

Every hospital carries versions of this population: emergency contacts, escorts who accompanied a patient, next of kin recorded during an admission, referring physicians named in a discharge letter, and legal guardians. Their records rarely live in the systems an inventory exercise starts with.

Where Uncatalogued Personal Data Accumulates

Healthcare organizations build their data protection policies around health data. Detection rules look for diagnostic codes, medical record numbers, insurance identifiers, and treatment details, because that is what the regulations name and what auditors ask about.

A trusted third-party record contains none of that. It holds a name, a phone number, an address, and a relationship. Measured against a policy tuned for clinical content, the file scores clean. It contains regulated personal data in full, and nobody asked the rule set to look for it.

That gap explains how a hospital can run a competent notification process and still produce an Article 34 finding. The process worked on the population the organization had catalogued. The uncatalogued population was invisible to it, both during normal operations and after the breach.

Records about non-patients tend to sit in the least structured parts of a health environment: a database column can be inventoried, a scanned form in a shared folder cannot, until something reads its contents.

Reading Contents Instead of Trusting Labels

Proactive DLP™ Technology inspects what is inside a file rather than what its name, extension, or classification label claims. It covers 125+ file types, including text, images, and embedded documents, and inspects recursively, so it examines archives and nested layers rather than skipping them.

Three capabilities matter for finding personal data nobody catalogued:

Synthetic patient information redacted by Proactive DLP
  • OCR for documents that are images. Proactive DLP™ reads scanned forms, photographed paperwork, and non-searchable PDFs the same way it reads text documents. A designation form or DICOM scan that exists only as a scan stops being a blind spot
Synthetic DICOM scan anonymized by Proactive DLP
  • Classification and tagging that produce a record. Proactive DLP™ classifies detected content against predefined sensitivity levels and embeds classification tags into the processed file. Those tags feed a SIEM platform or document management system, which turns individual detections into an accumulating picture of where regulated data lives. Document identification adds category-level classification for identity and financial documents
Proactive DLP's tags enabled on document scan results

Content inspection at transfer points sees files as they move: uploads, downloads, email attachments, removable media, and managed transfers. It builds a map from real traffic rather than crawling storage at rest, which means the picture develops as data flows and needs pairing with a discovery exercise for archives that never move.

Proactive DLP runs inside MetaDefender Core, MetaDefender ICAP Server, MetaDefender Email Security, MetaDefender Kiosk, and MetaDefender Managed File Transfer.

The Practical Step

A breach notification list is an inventory problem solved under time pressure. Building it mid-incident means reconstructing which categories of people appear in which files, and the categories nobody documented are the ones that get missed.

IBM's 2026 Cost of a Data Breach Report puts the average healthcare breach at $6.64 million, the highest of any industry for the thirteenth consecutive year. Mean time to identify and contain reached 247 days, and removable media and supply chain compromise took longest at 258 days. A content inspection point covers both paths.

Start from the other direction. Point Proactive DLP™ Technology at the file flows already moving through your environment and classify what comes back. The tags accumulate into a record of the personal data you hold about people who are not your patients.

Stay Up-to-Date With OPSWAT!

Sign up today to receive the latest company updates, stories, event info, and more.