Data breach
Cegedim.fr
- Records
- 445,435
- Breach date
- 27 February 2026Estimated
- Added
- 3 March 2026
What was exposed
1 type of data · 7 more reported
- Email addresses445,435
- NamesReported, not counted
- GenderReported, not counted
- Dates of birthReported, not counted
- Phone numbersReported, not counted
- Home addressesReported, not counted
- Sexual orientationReported, not counted
- Medical diagnosesReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
Data belonging to patients of French doctors who use software made by the Cegedim group was stolen and offered for sale online, a case that became public when the France 2 television channel reported it on February 26, 2026. The affected product is Mon Logiciel Médical (MLM), a practice-management program that Cegedim Santé, the group's healthcare software subsidiary, says is used by about 3,800 doctors in France. Our investigation team indexed a dataset tied to this incident containing 445,435 rows, with an estimated attack date of February 27, 2026, and no actor publicly claiming the listing itself. French authorities have described a far larger underlying database: the health ministry said on February 27, 2026, that administrative files on about 15.8 million people were involved. The two figures are not directly comparable, and the true number of affected individuals remains unclear as of the most recent reporting in late February 2026.
Breach Timeline
October 2025: Cegedim Santé filed a criminal complaint over the hack, according to AFP reporting carried by France 24.
Early January 2026: Cegedim contacted all affected doctors, offering help with notifying the CNIL and informing patients.
February 26, 2026: France 2 broadcast a report on the leak, and Cegedim published a press release confirming that patient data from MLM accounts had been illegally accessed or extracted. The same day, a second account on a cybercrime forum claimed the attack in the name of the group Dumpsec.
February 27, 2026: The French health ministry said the breach involved administrative files on about 15.8 million people, with doctor's annotations for roughly 165,000 patients, and the Paris prosecutor's office confirmed an investigation had been opened.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses. The exact number of email addresses in the indexed dataset is unknown.
According to Cegedim's own press release, the stolen information came from patients' administrative files and included surname, first name, gender, date of birth, telephone number, postal address, email address, and free-text administrative comments written by doctors. The company said structured medical records remained intact and that no prescriptions or laboratory results were involved, per the health ministry.
The free-text comments are the most sensitive element. For a very small share of patients, doctors' notes contained personal details about sensitive matters. France 2's reporting and Le Monde found examples including a patient's sexual orientation or an HIV diagnosis. The ministry put the number of patients with such annotations at roughly 165,000 to 169,000.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Most of the stolen data is administrative, but it reveals which patients see which doctors. That enables targeted phishing emails and phone scams that impersonate a medical practice, a health insurer, or the CNIL, since a caller can cite real details like a name, address, and doctor. Exposure of email addresses also invites ordinary spam and credential-harvesting attempts, particularly if a recipient reuses passwords across accounts.
For the smaller group whose records included doctors' free-text annotations, the risks are more serious. Sensitive medical or personal information, once public, cannot be changed, and it could be used for extortion, discrimination, or harassment.
What Is Cegedim.fr Doing in Response?
Cegedim says it detected abnormal activity on doctor accounts at the end of 2025, secured access, and contained the incident. It notified the CNIL, filed a criminal complaint in October 2025, and says affected doctors were contacted in early January 2026 with support for notifying their patients under the GDPR. The company states it was never contacted by the attacker and is cooperating with the ongoing investigation. Health Minister Stéphanie Rist has asked Cegedim to account for the causes of the incident and the corrective measures taken.
What Should You Do If You Were Affected?
Be wary of unexpected calls, texts, or emails referencing your doctor, your health, or this breach. Verify by contacting the practice directly through a known number.
Do not click links in unsolicited messages about medical records or reimbursements.
Use unique passwords and enable two-factor authentication where offered, especially on email and health-related accounts.
If you believe your medical information was exposed, you can raise the issue with your doctor or lodge a complaint with the CNIL.
