CNIL fines a hospital €500,000 for no MFA, no VPN: the RGPD security checklist that applies to your SMB too
On September 3, 2026, the CNIL published a €500,000 fine against the Hôpital Privé de la Loire for failing to secure the records of 524,867 patients — no VPN, no multi-factor authentication, and a shared temporary password for every practitioner. The legal basis, RGPD Article 32, applies identically to a ten-person SMB.
On September 3, 2026, the CNIL published a €500,000 fine against the Hôpital Privé de la Loire, part of the Ramsay Santé group, following a data breach between June 26 and July 1, 2025. An attacker roamed the hospital’s patient-record system undetected for days, extracting data on 524,867 patients — including health data for some — and 202,246 people listed as trusted contacts. The decision, adopted July 21, 2026 (deliberation SAN-2026-009), is not about a sophisticated attack. It is about the absence of a virtual private network for remote access, no multi-factor authentication anywhere in the system, and — after the breach was discovered — an identical temporary password issued to every practitioner. Those are not hospital-specific failures. They are the same three items on the security checklist of any company that holds a customer file, and the legal basis the CNIL applied, RGPD Article 32, reads the same for a ten-person SMB as for a hospital group.
What the CNIL actually sanctioned
- →A €500,000 fine for breaching RGPD Articles 32 (security of processing) and 34 (notifying data subjects), plus a compliance injunction and two years of public naming on the CNIL’s own site.
- →No VPN protecting remote access to the patient-record system.
- →No multi-factor authentication anywhere in the chain — a single password was enough to reach hundreds of thousands of records.
- →No monitoring of suspicious activity: the attacker browsed the database for several days before anyone noticed.
- →After the breach, the emergency fix was itself a security failure — one identical temporary password handed to every practitioner.
A gap that is far from exceptional
None of this is unusual — that is precisely the point. A 2025 systematic mapping study covering 73 peer-reviewed articles on SMB cybersecurity found that weak password practices, poor access control and the absence of multi-factor authentication remain among the most common gaps in small and medium firms, precisely because MFA and monitoring tooling are still treated as optional rather than baseline (Mujtaba & Alam, 2025). The detection gap is the other half of the story: a 2021 study of nearly 700 publicly reported breaches found that intrusions involving privilege misuse — an attacker who simply has valid-looking access and no one is watching for anomalies — take roughly 2.5 times longer to detect than the average breach (Roumani, 2021). That is exactly what happened at the Hôpital Privé de la Loire: nothing flagged the unusual access pattern, so the attacker had days instead of minutes.
What it changes for your SMB
RGPD Article 32 does not scale down for smaller companies — it requires security “appropriate to the risk,” and the CNIL has just shown, in a public and citable decision, what it considers the floor: encrypted remote access, MFA, and no shared credentials. Any SMB running a CRM, an accounting system or a customer portal with personal data inside it is bound by the same article. The detection piece matters just as much as the access controls: a customer-support agent, a supplier portal or an internal tool with no one — human or automated — watching login patterns and access volume will not notice an intrusion until a client, a journalist or the CNIL does. This is exactly the role of what we build as an “agent vigie” for clients: a process that watches authentication logs and access volume continuously, and flags an unusual login pattern or a spike in failed authentication attempts before it becomes an incident, rather than after.
Four moves before your next audit
- →Turn on multi-factor authentication on every system that holds personal data — CRM, accounting software, cloud storage, email — not just the ones flagged as “sensitive.”
- →Require encrypted, authenticated remote access (VPN or an equivalent) for any tool reachable from outside the office network.
- →Ban shared or identical passwords, including “temporary” ones issued during an incident response — that is the exact failure the CNIL cited.
- →Put continuous monitoring in place for unusual access patterns, even a lightweight one — the cost of a missed anomaly is measured in weeks of undetected exposure, not minutes.
The Hôpital Privé de la Loire fine will be visible on the CNIL’s site for two years, cited in every compliance training deck that follows. The more useful reading for an SMB owner is not “that could never happen to us because we are not a hospital” — it is that the CNIL has just priced, at €500,000, a security gap that a VPN, an MFA rollout and a basic monitoring habit would have closed.
Frequently asked questions
Does this CNIL sanction apply to non-healthcare SMBs?+
The fine was issued to a hospital, but the legal basis — RGPD Article 32, security appropriate to the risk — applies to any company processing personal data, regardless of sector or size. A CRM, an accounting system or a customer portal falls under the same requirement.
What security failures did the CNIL specifically cite?+
No VPN for remote access, no multi-factor authentication anywhere in the system, no monitoring of suspicious activity that let an attacker browse records undetected for days, and — after the breach — an identical temporary password issued to every practitioner.
What is the minimum an SMB should do after reading this decision?+
Enable MFA on every system holding personal data, require encrypted remote access, eliminate shared or default passwords, and put some form of continuous monitoring on login and access activity so an anomaly is caught in minutes rather than days.
Free resource
The self-assessment grid: 20 tasks AI can automate
Sales, admin, support, operations: the 20 tasks AI agents already handle in SMEs — with, for each one, the tell-tale sign that your team is concerned.
Read next
Business & compliance
E-invoicing goes live and business owners fear a hack — Bercy imposes an emergency cyber audit on approved platforms
2 September 2026·5 min read
Business & compliance
E-invoicing takes effect today, September 1, 2026 — and 42% of French businesses are not ready
1 September 2026·5 min read
Business & compliance
Google Workspace can now suspend AI agents and their Drive access — what SMBs should check before September 1
30 August 2026·5 min read