France Health Data Breach: 15 Million Records Stolen in Cegedim Hack
French Healthcare Data Breach Exposes Records of 15.8 Million
A significant data breach affecting France’s healthcare system has compromised the administrative files of approximately 15.8 million individuals, including sensitive medical notes for around 169,000 patients. The incident, stemming from a late 2025 attack on Cegedim Santé, a software supplier to the French health ministry, highlights the growing vulnerability of healthcare data to cyberattacks. The breach includes names, addresses, phone numbers and dates of birth, with a subset containing more sensitive information like doctors’ notes potentially detailing conditions such as HIV/AIDS and sexual orientation.
How the Breach Unfolded
The attack targeted Cegedim Santé’s MonLogicielMedical (MLM) software, used by approximately 3,800 doctors across France, with 1,500 directly affected. MLM provides a platform for patients to access health records and communicate with physicians, even as offering administrative tools for doctors. Cegedim confirmed the compromised data resided within patients’ administrative files, with the most sensitive information contained in free-text doctor’s notes. The company filed a criminal complaint in October 2025 following the discovery of the breach and is cooperating with authorities. Cegedim’s official statement expresses regret and commitment to data security.
Scope of Compromised Data and Potential Impact
While the health ministry has not yet released a detailed statement, reports indicate that top politicians were among those affected. The nature of the compromised data raises serious privacy concerns. The inclusion of doctor’s notes, even in a limited number of cases, presents a particularly acute risk, as this information is often highly personal and sensitive. The potential for misuse, including discrimination or blackmail, is a significant worry for those affected. It’s important to note that, according to Cegedim, prescriptions and biological test results were not accessed during the breach.
Broader Context: Recent French Government Cyberattacks
This incident is not isolated. Just weeks prior, in February 2026, France’s finance ministry confirmed a separate data security incident involving the compromise of details from approximately 1.2 million bank accounts. The Register reported that attackers impersonated a civil servant to gain access to the national bank account file, obtaining account numbers, addresses, and tax identification numbers. This pattern of attacks targeting French government systems suggests a heightened level of cyber threat activity and potential vulnerabilities in national infrastructure. The earlier incident involved attackers leveraging “impersonation as a service”, a concerning trend in cybercrime.
The Growing Threat to Healthcare Data
Healthcare organizations are increasingly becoming prime targets for cyberattacks. The value of medical data on the black market is high, as it can be used for identity theft, insurance fraud, and other malicious purposes. Healthcare data often includes a wealth of personally identifiable information (PII) and protected health information (PHI), making it particularly attractive to attackers. Many healthcare organizations operate with legacy systems and limited cybersecurity resources, making them more vulnerable to attacks. Cybersecurity Ventures tracks data breaches and cyberattacks globally, highlighting the escalating threat landscape. A recent report from the organization indicates a significant increase in attacks targeting the healthcare sector.
Mitigation and Response
Cegedim Santé is supporting affected doctors and patients and cooperating with authorities. Individuals concerned about potential exposure should remain vigilant for phishing attempts and monitor their credit reports for any signs of fraudulent activity. While the French government has not yet issued specific guidance, standard recommendations following a data breach include changing passwords, enabling two-factor authentication where available, and being cautious of unsolicited communications. The incident underscores the importance of robust cybersecurity measures, including regular security audits, employee training, and data encryption.
What Comes Next: Investigation and Potential Reforms
The investigation into the Cegedim Santé breach is ongoing. Authorities will likely focus on identifying the attackers, determining the full extent of the damage, and implementing measures to prevent future incidents. This incident may prompt a review of data security practices within the French healthcare system and potentially lead to stricter regulations and increased investment in cybersecurity. Further scrutiny of software vendors supplying critical infrastructure to the healthcare sector is also likely. The French government will need to assess its overall cybersecurity posture and address vulnerabilities that have been exploited in recent attacks.