Designed French
Impacted doctors
Sensitive annotations
Source: France 2, Franceinfo, AFP, Ministry of Health — February 2026
Cegedim Santé is a subsidiary of Cegedim, one of the leading French medical software publishers. Its MLM solution (MonSoftwareMedical.com) was equipped with 3,800 general practitioners and specialists, as well as some 25,000 medical offices and 500 health centres, according to CNI estimates.
Equipped doctors
Medical offices
Health centres
This is not a spectacular intrusion by gross force. The hackers exploited medical accounts to send abnormal queries to the MLM software database. This technique, discreet and targeted, made it possible to extract 19 million data lines — of which 4 million duplicates — representing a history ranging from 3 to 15 years depending on the firm.
The contract signed with the claimant must contain the following cyber security elements:
Medical annotations (169,000 cases) For 1% of patients, free comments from physicians were also presented. These annotations may contain very sensitive information: Sexual orientation, Situations of violence, Addictions, Personal intimate information
Combined, these data form a very detailed personal profile. Unlike a password leak, you cannot « change » its name, date of birth or telephone number. This information can be used indefinitely by cyber criminals.
Longer-term risks
• Identity assurpation
• Singing (for 169 000 with annotations)
• Resale data on the dark web
This incident reminds us that our medical data are valuable and vulnerable, even when entrusted to health professionals. As patients, we have the right to be informed promptly in case of a leak and to ask our doctors what data is entered in our records. — including in fields « free ».
Physicians are responsible for the data entered into their software. The CEGEDIM incident raises the crucial issue of educating practitioners about cybersecurity: what should be noted in a free commentary? These issues must now be part of the ongoing training of health professionals.
The cyber attack highlights the responsibilities of technology providers. Despite a CNIL fine in 2024, Cegedim Santé had not yet sufficiently secured its systems. The ministerial program has begun to move things, but city medicine remains a poor parent of cybersecurity.
We will reply as soon as possible
PayPal admits data exposure via PayPal Working Capital For almost six months, PayPal Working Capital's personal data, whose social security numbers have remained accessible to unauthorized third parties as a result of a simple software error. An incident that illustrates how much a technical flaw, even involuntary, can have very concrete consequences on the lives of the...