This is one of the largest health data breaches ever recorded in France. The Cerballiance network, comprising over 700 medical biology laboratories across the country, confirmed on April 10, 2026, that it had been the victim of a cyberattack resulting in "unauthorized access" to patients' personal data. The attack, initially revealed by Ouest-France at the end of March, has taken on considerable scope: according to Le Moniteur des pharmacies, the compromised data potentially concerns millions of patients who have undergone analyses in one of the network's laboratories.

The exposed information is particularly sensitive. According to the specialized website Cyberattaque.org, the compromised data includes civil status information (last name, first name, date of birth), login credentials (email address and encrypted password), as well as health data—notably the name of the prescribing physician and the nature of the analyses performed. Cerballiance specified that the analysis results themselves are not among the stolen data, but cybersecurity experts point out that the combination of name + type of analysis already constitutes exploitable medical information for blackmail or identity theft purposes.

The attack targeted a third-party IT provider hosting part of the network's data, not Cerballiance's internal systems directly. This is now a classic pattern in cyberattacks targeting the health sector: technical subcontractors, often less well-protected than the main establishments, constitute the weak link in the chain. France has already been hit by similar incidents: in February 2024, a data leak at Viamedis and Almerys exposed the information of 33 million social security beneficiaries. The health sector has become the preferred target of cybercriminals, representing 10% of all cyberattacks in France according to ANSSI.

Cerballiance reported the incident to the CNIL (National Commission for Information Technology and Liberties) in accordance with GDPR, and began individually notifying affected patients by email as early as March 25, 2026. The group recommends that all its patients immediately change their password on the online results platform, enable two-factor authentication where possible, and monitor their bank and email accounts for any suspicious activity. A complaint has been filed and a judicial investigation is underway.

This incident reopens the debate on the security of health data in France. The Ségur du numérique en santé, launched in 2021, planned an investment of 2 billion euros to modernize hospital and health information systems. But experts point to a persistent gap between stated ambitions and the reality on the ground. "As long as cybersecurity is considered a cost rather than a vital investment, leaks will multiply," warns an ANSSI report published in March 2026. For the millions of affected patients, the risk of their medical data being exploited remains high for several years.