preloader

· · digital-privacy digital-security gdpr healthcare data-breach europe compliance mfa

France’s Privacy Regulator Just Fined a Hospital 500,000 Euros for Skipping MFA

Source: CNIL

Half a million patient records, one missing security control, and a regulator that noticed. France’s data protection authority has just put a euro figure on what multi-factor authentication is worth.

No MFA, no VPN, one password for every practitioner

CNIL’s decision, dated July 21, 2026 and made public on September 3, fined Hopital Prive de la Loire 500,000 euros over a breach that began in summer 2025. An attacker used compromised credentials to access the hospital’s computerised patient record system and browsed it undetected, no multi-factor authentication and no VPN stood between a stolen password and the records themselves.

CNIL’s investigation found the hospital had issued practitioners an identical temporary password, and kept doing so even after the breach was discovered. Combined with the absence of MFA, that meant one leaked credential was effectively a master key. The regulator cited Article 32 of GDPR, the requirement to implement security measures appropriate to the risk, and found the hospital fell well short of it.

524,867 patients, and 202,246 people who were never told

The exposure covered the records of 524,867 patients, including health data in some cases, plus a further 202,246 “trusted third parties” associated with those records. CNIL’s second finding is arguably the more instructive one for any organisation handling personal data: while patients were eventually notified, the 202,246 trusted third parties were not. That is a separate violation, this time of Article 34, the duty to communicate a breach directly to the individuals affected. Knowing a breach happened is not enough; every affected party has to be told, not just the most obvious group.

Alongside the fine, CNIL ordered compliance measures with deadlines of three to fifteen months, and will name the hospital publicly for two years.

The lesson travels well beyond hospitals

MFA on remote access to systems holding sensitive data is not an optional hardening step, it is close to a baseline expectation now, and regulators are pricing its absence into fines. The second finding, on incomplete breach notification, is just as relevant: an incident response plan that only accounts for the “obvious” affected group will miss exactly the kind of secondary population CNIL flagged here.

If your organisation handles health data, financial data or any other sensitive personal information under GDPR, contact Excello Digital for a review of your access controls and breach response process. Closing gaps like these before a regulator finds them is considerably cheaper than the alternative.

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!