France’s data protection authority, CNIL, has fined Hôpital privé de la Loire €500,000, or about $580,000, after a data breach exposed sensitive information tied to more than 727,000 people, according to BleepingComputer. BleepingComputer reports that the breach occurred in the summer of 2025 and affected 524,867 patients as well as 202,246 people designated as trusted third parties. The exposed population included people who had received care at the hospital, escorted patients there, or otherwise helped them. Hôpital privé de la Loire, or HPL, is a general hospital in Saint-Étienne and part of the Ramsay Santé healthcare group, according to the report. The hospital provides medical, surgical, maternity, cancer, intensive-care, and emergency services. BleepingComputer says HPL has 650 staff, including 180 doctors, and 333 beds across five clinical divisions, with a reported 60,000 patients each year. CNIL’s investigation found several failures to comply with the hospital’s obligations under the General Data Protection Regulation, BleepingComputer reports. The violations cited related to GDPR Article 32, which concerns security of processing, and Article 34, which concerns communication of a personal-data breach to affected data subjects. The regulator also noted that HPL took measures to strengthen security during the proceedings. The reported intrusion centered on the hospital’s electronic patient-record system. BleepingComputer says an attacker accessed that system and extracted sensitive data belonging to people connected with HPL. A teen hacker using the alias “Marak” claimed responsibility at the time, according to the report. BleepingComputer says the hacker contacted French outlet Le Progrès over Telegram and claimed the attack began with the compromise of a single doctor’s account, which then allowed access to HPL’s internal system. The same report says the hacker tried to sell the stolen data to a single buyer for between €2,000 and €5,000. It was later reported that the data was neither sold nor published. The enforcement action is a reminder that healthcare breaches are not judged only by whether data eventually circulates publicly. In this case, according to BleepingComputer’s account of CNIL’s findings, the regulator focused on security failures and breach obligations after attackers obtained access to sensitive health-related records. Who benefits: Security teams focused on identity controls, electronic health record protection, and breach-response processes gain a concrete enforcement example to use in budget and risk discussions. Regulators also reinforce the expectation that healthcare providers protect both patient and related third-party data. Who's exposed: Hospitals and healthcare groups with broad internal access from individual user accounts are exposed to similar breach paths. Organizations handling patient records also face regulatory risk if GDPR security and notification obligations are found lacking.