The CNIL investigation found that external users, including private-practice physicians, could access the hospital's electronic patient record system without a VPN or multi-factor authentication. Inadequate access controls allowed the compromised account to view records for all patients, and the hospital lacked real-time monitoring, enabling the attacker to extract a large volume of data over several days without detection. Additionally, the hospital did not directly notify the 202,246 trusted third parties whose data was also stolen.
A teenage hacker using the alias "Marak" claimed responsibility, telling French outlet Le Progrès that the breach began with a single doctor's account, which granted access to the entire internal system. The hacker attempted to sell the stolen data for between €2,000 and €5,000, but it was later reported that the data was neither sold nor published. HPL took several security strengthening measures during the proceedings, the CNIL noted.