O clinică privată a fost amendată cu 500.000 de euro după furtul de date ale pacienților

A private clinic in Saint-Étienne, France, was fined €500,000 by the CNIL for inadequate patient data protection following a cyberattack in 2025. The breach affected over 500,000 patients and 200,000 authorized third parties. The CNIL criticized the clinic for insufficient security measures and failure to detect suspicious IT activities. The clinic's president stated they are considering appealing the decision. The CNIL identified two violations of data protection regulations and mandated security improvements within a specified timeframe, some of which have already been initiated.