Healthcare Data Breach France: 15 Million Medical Records Exposed

Healthcare Data Breach France: 15 Million Medical Records Exposed

France is facing a healthcare data breach crisis of unprecedented scale. Since January 2026, more than ten distinct security incidents have struck the French healthcare sector, exposing millions of patient records across medical practices, online pharmacies, health insurers and regional health authorities. This is not a series of coincidences. It is the portrait of a sector structurally exposed, where digitalisation outpaced security investment by years.

data breach

The French Healthcare Data Breach That Changed the Scale

On 27 February 2026, specialist sources revealed the compromise of Cegedim Santé, a patient record management software provider used by 1,500 medical practices and 500 healthcare centres. Between 11 and 15 million patient records were exposed: chronic conditions, surgical history, sexual orientation, religious beliefs and handwritten notes from treating physicians. Data shared in the privacy of the consultation room, protected under European law at the highest level. To date, no official communication has been sent to the patients concerned.

What makes this incident structurally different from previous breaches is its attack vector. The attackers did not target medical practices one by one. They compromised their shared software provider and gained simultaneous access to data held across every organisation that trusted it. One intrusion, mass impact. This is the logic of software supply chain compromise (T1195, MITRE ATT&CK), a technique increasingly and deliberately used against healthcare organisations.

The method echoes the Itelis case. In November 2025, this healthcare reimbursement network reported unauthorised access linked to the impersonation of a partner optician. Data belonging to clients of Axa and Malakoff Humanis was exposed for reimbursement claims processed between 2020 and 2022.

A Wave of Healthcare Data Breaches Across France

Since January 2026, security incidents have followed one another across the full landscape of French digital healthcare.

On 12 January, monlogicielmedical.com suffered a breach exposing user data: names, dates of birth, addresses and social security information. On 27 January, the dermatology clinic NightSpire suffered a particularly invasive exfiltration: medical photographs of 10,000 patients were put up for sale on the dark web at three dollars each. On 28 January, Wemind, a health insurance provider distributed through Allianz, was compromised, resulting in the exposure of policyholders’ full contact details. On 5 February, the Regional Health Agency lost the professional data of 15,108 staff members. On 9 February, PharmaShopi suffered a breach that included full credit card numbers, CVV codes included. In March, Médoucine and La Mutuelle Familiale were also hit.

Two signals deserve particular attention. Since 13 February, 500,000 medical records from a French COVID-19 database have been circulating on Breach Forums, including social security numbers, diagnoses and insurance data, with no notification to the individuals affected. In March 2026, a maternity database of 3.6 million entries was put up for sale: mothers’ names, contact details and children’s birth information. The breach is believed to date back to March 2025 and circulated undetected for a full year before being discovered.

Internationally, 55 incidents have been recorded since January 2026, affecting more than 40 million people, with nine ransomware groups particularly active in the sector.

How Attackers Operate Inside Healthcare Systems

Behind these incidents lies a four-stage sequence that the MITRE ATT&CK framework allows organisations to understand and anticipate.

Finding the entry point.

Attackers identify a vulnerability in an internet-facing service: a login portal, an API, an exposed administration interface. Automated tools probe thousands of entry points every day. No key needed, no inside accomplice required. For Cegedim Santé as for the COVID-19 database, this is most likely where everything began.

Collecting data without rushing.

Once inside, the attacker behaves like a visitor with a legitimate access badge, methodically copying the archives. The 500,000 COVID-19 records were extracted from internal databases and shared document spaces through queries that looked like normal system activity.

Exfiltrating data without triggering an alert.

Stolen data travels through legitimate web channels: encrypted HTTPS traffic, mainstream cloud services, activity that blends into ordinary network traffic. A basic monitoring system sees nothing. This is what allowed the maternity breach to remain invisible for a full year.

An impact that does not fade.

Unlike a bank card blocked within 48 hours, a stolen medical record retains its criminal value for years. A social security number linked to a medical history enables insurance fraud, identity theft or targeted phishing attacks against patients themselves: “Regarding your treatment for…” The 15 million Cegedim patients are not facing a passing scam. They are facing the long-term exploitation of their most intimate data.

Regulatory Signals and How to Prepare

The transposition of the NIS2 Directive into French law is not yet finalised. But ANSSI has published its security objectives, which give a clear indication of what the legislature is preparing to make legally enforceable. Three workstreams cannot wait.

Map what you do not directly control.

The Cegedim case is, above all, a story of unmanaged dependency. The question to ask of every critical IT supplier, whether a patient record software vendor, a hosting provider or a subcontractor with access to patient data, is straightforward: what is their security policy, are they HDS-certified (the French healthcare data hosting certification), and does your contract formally give you the right to verify it?

See what is happening inside your own systems.

The maternity database circulated for a year without detection. Centralising activity logs, analysing abnormal behaviour and actively monitoring for data leaks on underground markets are capabilities that cannot be improvised on the day of an incident. They are built in advance.

Respond within regulatory timeframes.

Once NIS2 transposition is finalised, essential healthcare entities will be required to notify ANSSI within 24 hours of detecting a significant incident. The GDPR already imposes notification to the CNIL within 72 hours for any personal data breach. The data exposed in the Cegedim case, including sexual orientation, religious beliefs and medical records, falls under the GDPR’s special categories, with a mandatory obligation to inform the individuals concerned.

What This Requires Now

The incidents of January to March 2026 reveal a sector whose attack surface grew with digitalisation while security investment failed to keep pace, and whose software providers have become, without realising it, the most profitable targets available.

Attackers have scaled up their approach. They go after software vendors, platforms and suppliers because that is where the leverage is greatest.

The real question for CISOs and executives in the sector is this one: do you have an operational process to detect, qualify and report an incident within regulatory timeframes, including when the compromise originates with one of your providers?

Stroople is an Expert Cyber certified firm and member of the Cybermalveillance.gouv.fr network. We support healthcare organisations in assessing their cyber risk exposure and preparing for NIS2 requirements.

Share:

X
LinkedIn
External Attack Surface Management & Data Leak Detection

External Attack Surface Management

See your exposure before attackers do. Know what's already compromised.

Learn more
0 %

of successful breaches start from publicly exposed assets.