Amendă record de 500.000 de euro pentru o clinică privată din Franța pentru neprotejarea adecvată a datelor pacienților

A private clinic in Saint-Étienne, France, was fined €500,000 by the CNIL for inadequate patient data protection following a cyberattack in 2025. The breach affected over 500,000 patients and 200,000 authorized third parties. The CNIL criticized the clinic for failing to secure access to medical records and for not detecting suspicious IT activities. The clinic's president stated they are considering appealing the decision. The CNIL identified two violations of data protection regulations and mandated security measures to be implemented within 3 to 15 months, with some already underway.