French hospital fined €500k after data breach
🔒 France’s data protection authority (CNIL) fined Hôpital privé de la Loire €500,000 after a 2025 breach exposed sensitive records for 727,113 people, including 524,867 patients and 202,246 trusted third parties. The investigation found failures including lack of VPN/MFA for external users, weak access controls, and absent real-time monitoring, enabling extensive data exfiltration. The hospital informed affected patients but did not directly notify all third parties; a teen hacker claiming responsibility sold the data attempt reportedly failed.