Fifteen Million French Patients Affected by a Medical Data Breach

Introduction

In October 2025, a serious cybersecurity incident emerged involving millions of French citizens. The target was Cegedim Santé, a company that provides management software to approximately 1,500 doctors in France. The episode serves as a reminder of how health data is today among the most sensitive and coveted information for those operating in the realm of digital crime.

What Happened

A cyberattack allowed unauthorized individuals to gain access to Cegedim Santé’s systems and steal personal data belonging to approximately 15 million patients. The stolen information includes administrative details such as names, phone numbers, and addresses. For a smaller number of individuals — around 169,000 patients — clinical notes written by doctors were also compromised, representing far more sensitive information directly related to health conditions. The attack has been claimed, but the identity of the perpetrators and the precise details of how the unauthorized access occurred remain unknown. It is important to state clearly that the investigation is still ongoing.

Why It Matters and What Impact It May Have

A data theft of this scale has concrete consequences on people’s lives. Administrative information, such as names and phone numbers, can be used for fraud attempts, phishing, or identity theft. Medical notes, on the other hand, contain details about individuals’ health that, if misused, can cause significant harm to the privacy, reputation, and even the professional or insurance opportunities of those affected. According to reports, public figures from French public life are among those involved, making the matter even more prominent on a political and institutional level. In any case, anyone who has visited a doctor using Cegedim Santé’s software could be among those affected.

What Companies and Users Can Do Now

Those who fear they may be involved should pay close attention to suspicious communications received via email, SMS, or phone, especially if they request personal data or account access. It is advisable not to click on unsolicited links and to always verify the identity of whoever makes contact. Companies that handle health data, for their part, are called upon to strengthen their protection systems, limit internal access to strictly necessary personnel only, and have clear incident response plans in place. Timely reporting to the relevant authorities remains a fundamental obligation in these cases.

Final Takeaways

Health data is among the most sensitive of all and requires protections proportionate to its value.

Even medium-sized organizations, such as medical software providers, can become targets of attacks with consequences affecting millions of people.

When you are the victim of a breach, staying informed through official channels and remaining vigilant about incoming communications is the first concrete step to take.

Sources:
https://www.aa.com.tr/en/europe/15m-french-citizens-affected-by-massive-data-breach-following-cyberattack-on-medical-software/3842345
https://www.brusselstimes.com/1995423/france-political-figures-among-millions-affected-by-massive-medical-data-leak
https://sharjah24.ae/en/Articles/2026/02/28/15-million-French-medical-records-exposed-in-hack

Source: DataBreaches