PrivacySignal
Breach

Health data breach: the CNIL fined Hôpital Privé de la Loire 500 000 EUR

EDPB · · EU · Data Breaches

France's data protection authority, the CNIL, fined Hôpital Privé de la Loire €500,000 after an attacker gained unauthorized access to its centralized patient records system in summer 2025. The hospital was found in violation of GDPR rules on security of processing and breach notification to affected individuals.

Why this matters: Health records are the most sensitive data most people will ever hand over. A hospital's patient system holds diagnoses, treatments, medications, and personal history — the kind of information that can affect insurance, employment, and personal relationships. When that system is left open enough for an attacker to walk in, the people harmed are patients who had no real choice but to share that data. The fine here is meaningful. Half a million euros from a single regulator sends a clear message that poor security in healthcare is not just a technical failure — it is a legal one.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · Healthcare professionals · General readers · Policy

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Breach
The Record · · International

Electronic health record company says customer data stolen in breach

Veradigm, an electronic health record company, disclosed that customer data was stolen in a breach affecting a specific interface. The company stated the incident did not spread to its broader infrastructure and caused no operational disruptions.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →
Breach
BleepingComputer · · International

Veradigm warns of patient data breach after ransomware gang claims attack

Veradigm, a healthcare technology company, has disclosed a data breach affecting patient personal data following a cyberattack on one of its third-party vendors. A ransomware group has claimed responsibility for the incident.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance · General readers · Policy

#breach#healthcare#privacy#security Read original →
Breach
WIRED — AI · · International

A Stealth Startup Thinks It Just Hacked the Memory Shortage

Kepler Computing, a stealth-stage chip startup, says it has developed a new design approach and a proprietary material that could ease the memory supply shortages driving up prices across the semiconductor industry.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
DataBreaches.net · · International

“Network outage” disrupts Westfield Public Schools in New Jersey as ransomware group posts samples

Joseph Topping reports: Westfield Public Schools in New Jersey kept classrooms open during a districtwide network outage that disrupted communications and digital instruction throughout the first week of school. The district initially attributed the outage to equipment failure. “We have confirmed that a networking hardware failure caused the disruption across all district schools and offices,”... Source

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
FTC Consumer Protection · · US Federal

FTC Withdraws Obsolete Policy Statement

The FTC has rescinded its 2021 Policy Statement on health app data breach notification, saying the statement became redundant after the agency updated its Health Breach Notification Rule in 2024 to formally cover health apps and connected devices. The withdrawal aligns with a Trump executive order directing agencies to remove unnecessary regulatory guidance.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance · Lawyers

#breach#healthcare#regulation Read original →