Security Guides
One vendor, 15 million patients — the Cegedim Santé (MLM) breach in France and why the free-text box mattered most
Cegedim Santé, maker of the MLM software for French doctors, disclosed on February 26, 2026 that patient data was accessed or extracted through 1,500 physician accounts. France's Ministry of Health put the number of patients at about 15 million. What patients and clinics using cloud medical software should do.
For: anyone in France who sees a doctor (including foreign residents), and clinics and doctors that use cloud-based practice software. This article is based on Cegedim's own press release (February 26, 2026), statements attributed to France's Ministry of Health (as reported and as quoted in a National Assembly written question), and CNIL guidance. It does not cover attack techniques.
What patients should do today
The notice comes from your doctor — be wary of anyone else claiming to write about it
According to Cegedim, affected doctors were contacted in early January and, if they wished, helped to notify the CNIL and inform their patients as data controllers under the GDPR. In other words, the formal notice to patients comes from your own doctor or practice. The CNIL says it cannot check whether your data is in a leaked file, and it does not recommend third-party sites that claim to. If you are worried, ask your doctor directly through the contact details you already use.
Do not click links in emails or texts claiming to be from a doctor, insurer or authority
With a name, date of birth, phone number, address and email, someone can write a convincing "This is Dr X's practice" or "You are due a health insurance refund" message. The CNIL's advice: do not open attachments, do not reply, do not click links, and type the official website address yourself. How to spot these messages is covered in What is phishing?.
If a message uses your health or private life to pressure you, do not engage; keep the evidence
Because a small share of patients had sensitive notes in the free-text field, a message that shows knowledge of your health or private life and pressures you to pay or act cannot be ruled out. Do not reply or pay, keep screenshots and emails as evidence, and, as the CNIL advises, file a complaint (plainte) with the police or gendarmerie. You have done nothing wrong.
If your identity is misused: police, bank and account check
If you suspect identity theft (usurpation d'identité), the CNIL advises checking cybermalveillance.gouv.fr for guidance, filing a complaint with the police or gendarmerie as soon as possible, alerting your bank(s), and checking whether accounts have been opened in your name, for example through FICOBA (via impots.gouv.fr).
Ask your doctor, in writing, what is recorded about you
Under the GDPR right of access (droit d'accès), you can ask the practice what information it holds about you. According to the CNIL, the organization must reply within one month at the latest (extendable in complex cases). Knowing what the free-text field says about you also helps you judge any message that later claims to know it.
1 software vendor (MLM)
Every user doctor's patient list, in the cloud
↓
3,800 doctors use MLM
Abnormal activity on 1,500 accounts (Cegedim)
↓
About 15 million patients
Administrative data: name, birth date, contact details (Ministry of Health)
↓
About 1% of them
Doctors' notes on sensitive information in the free-text field
The company says structured medical records remained intact
What happened (from Cegedim's release and the Ministry of Health)
Everything below is as stated in Cegedim's February 26, 2026 press release, or as attributed to France's Ministry of Health in news reports and in a National Assembly written question.
End of 2025
Cegedim Santé identified abnormal application request behaviour on the accounts of doctors using MLM (MonLogicielMedical.com). The company says it took all necessary measures as soon as the incident was detected and contained it. It notified the CNIL and filed a complaint with the public prosecutor.Early January 2026
All affected doctors were contacted; dedicated teams helped those who wished to notify the CNIL and inform their patients.February 26
After a television news report on data leaks, Cegedim published a press release setting out the facts.Late February – March
The Ministry of Health was reported to put the number of patients who may be concerned at about 15 million, with about 1% involving sensitive notes. In March, a member of the National Assembly cited the ministry's figures in a written question to the government.
- Who
- Cegedim Santé, the Cegedim Group subsidiary that publishes software for healthcare professionals in France. The product involved is the doctors' software MLM (MonLogicielMedical.com)
- How it was spotted
- At the end of 2025, abnormal application request behaviour on doctors' accounts
- Data involved
- From the patient's administrative file only: surname, first name, gender, date of birth, phone number, address, email address, and administrative comments written in free text at the doctor's discretion. For a very limited number of patients, these comments may have contained the doctor's personal notes about sensitive information
- Not affected
- Patients' structured medical records
- Reports
- Notification to the CNIL; complaint filed with the public prosecutor; cooperating with the investigation
- Other
- The company says it was never contacted by the party responsible
How to read the numbers: where 15 million and 1% come from
The 15 million figure is attributed to the Ministry of Health in news reports and is quoted as the ministry's figure in a National Assembly written question; Cegedim's February 26 release does not give a patient count. The number of patients with sensitive notes is reported as about 169,000 in news coverage and 164,000 in the ministry figure quoted by the written question, so this article uses about 1%. Figures attributed to the party that took the data are not used.
The label said "administrative comment"; the content was the consulting room
The detail most easily missed is which field the sensitive data came from. According to the company, the structured medical record (where diagnoses and prescriptions are recorded in a fixed format) was untouched. What leaked was the "administrative comment", the field that sounds the least sensitive. But a free-text box holds whatever the person typing thinks is worth noting.
Structured medical record
- Diagnoses, prescriptions and results in a fixed format
- The system knows what each field contains
- According to the company, intact in this incident
Administrative comment (free text)
- The doctor can write anything
- The label is light; the content depends on who wrote it
- Held sensitive notes for a small share of patients (per the company)
Data protection usually sets its strength by the name of the field: strict for "medical record", looser for "contact details" or "comments". A free-text field breaks that model, because its real sensitivity depends on what was typed into it. Protect a field by what it actually contains, not by what it is called. That is the most concrete lesson a practice can take from this case.
For practices using cloud medical software
Know that notifying patients is the practice's duty, not the vendor's
Cegedim says it helped affected doctors, as data controllers under the GDPR, notify the CNIL and inform their patients. According to the CNIL, a controller must notify it within 72 hours of becoming aware of a breach and, where the risk is high, inform the people concerned. A processor (the software vendor) must alert the controller immediately when it discovers a breach. Check your contract: within how many hours, and through which contact, will the vendor tell you?
Decide what goes into free-text fields
Anything about a patient's health or private life belongs in the appropriate part of the medical record, not in the administrative comment. Write a one-page rule for what may and may not go into comment fields, and share it with reception staff and locum doctors. You can start by rereading the comment fields of a few dozen of your own patients to see what is already there.
One account per person, with multi-factor authentication on
How the accounts came to be used has not been published, but the impact ran through individual doctors' accounts. Do not share one login between reception and doctors; turn on multi-factor authentication for everyone if the software offers it; disable a leaver's account the same day. For choosing a method, see Choosing multi-factor authentication.
Ask the vendor who watches for unusual activity on each account
What Cegedim detected was abnormal request behaviour on doctors' accounts. A small practice cannot run its own monitoring, so ask the vendor three questions: (1) Is there an alert when one account opens far more patient files than usual? (2) Is the practice told when it fires? (3) Can the practice see its own account's access history? For example, a doctor who sees a few dozen patients a day should never have an account reading thousands of patient records. A threshold set at a volume no human consultation could produce is a realistic first rule.
Know in advance where to report an incident
Besides notifying the CNIL, healthcare organizations can turn to CERT Santé, the health sector's security response team (reporting portal: signalement.social-sante.gouv.fr). A single page saying who reports what, where and within how many hours means no hesitation when the vendor calls.
This site's view: concentration makes defense easier and failure bigger
Cloud practice software is often easier to secure than a server in every clinic, and choosing it is not a mistake in itself. But once one vendor holds thousands of practices' patient lists, one weakness works against all of them at once. A practice sees only its own account; it cannot see what is happening on the thousands of other doctors' accounts on the same platform.
That is why the right question when choosing software is not "is it secure?" but "if something unusual happens on my account, who notices, how fast, and how do you tell me?" If the answer is not specific, that is the answer. The broader baseline is in The minimum security baseline for organizations.
For another French case disclosed in 2026, involving the national ID-document portal, see the ANTS (France Titres) breach. Hospitals whose care was disrupted by cyberattacks are compared in four 2026 hospital cyberattacks.
Sources (public record)
The facts in this article come from the public sources below. Claims by the party that took the data, media descriptions of the leaked content, and undisclosed causes are not used.
- Cegedim, Press Release "Statement regarding the report broadcast during France 2 TV's 8 p.m. news program on February 26, 2026" (English translation) — cegedim.com (PDF) / French original — cegedim.fr (PDF)
- French National Assembly, written question no. 13530 "Données médicales piratées : quelles garanties ?" (Journal officiel, March 10, 2026; quotes the ministry's figures of 15 million and 164,000) — assemblee-nationale.fr
- Anadolu Agency, "15M French citizens affected by massive data breach following cyberattack on medical software" (reports the ministry's figure of about 169,000) — aa.com.tr
- CNIL, "Fuite ou vol de données : comment savoir si cela vous concerne et que pouvez-vous faire ?" — cnil.fr
- CNIL, "Les violations de données personnelles" (72-hour notification, processor duties) — cnil.fr
- CNIL, "Le droit d'accès : connaître les données qu'un organisme détient sur vous" — cnil.fr
- CERT Santé (health sector security response team), "Fuite de données" — cyberveille.esante.gouv.fr
Update history
2026-09-30: First version, based on Cegedim's February 26, 2026 press release, the Ministry of Health's figures as quoted in a National Assembly written question and in news coverage, and CNIL and CERT Santé guidance. Technical details of the cause have not been published; this article will be updated if they are.
Read next
- Another French case this year: The ANTS (France Titres) breach
- Cyberattacks on healthcare: Four 2026 hospital cyberattacks and what patients and providers should do
- When a legitimate account is the way in: 2026 breaches ran on legitimate credentials
- Spotting follow-on scams: What is phishing? / Choosing multi-factor authentication
- Other 2026 incidents: list of breaches and cyberattacks (Japan and worldwide)
FAQ
QWhat data was exposed in the Cegedim Santé (MLM) breach?
According to Cegedim's February 26, 2026 press release, the data comes exclusively from the patient's administrative file: surname, first name, gender, date of birth, phone number, address, email address, and administrative comments written in free text at the doctor's discretion. For a very limited number of patients, those comments may have contained the doctor's personal notes about sensitive information. The company says structured medical records remained intact.
QHow many people were affected?
Cegedim says 1,500 of the 3,800 doctors using MLM were affected. France's Ministry of Health was reported to put the number of patients who may be concerned at about 15 million, a figure also cited as the ministry's in a written question in the National Assembly. About 1% are said to involve sensitive notes; the count is reported as about 169,000 in news coverage and 164,000 in the ministry figure quoted by the written question.
QHow do I find out whether I am affected?
Cegedim says it contacted all affected doctors in early January and, if they wished, helped them notify the CNIL and inform their patients as data controllers under the GDPR. So the formal notice to patients comes from your doctor or practice, not from the software company. The CNIL says it cannot tell you whether your data is in a leaked file, and does not recommend third-party sites that claim to check.
QWere medical records themselves exposed?
Cegedim says structured medical records remained intact. It acknowledges, however, that for a very limited number of patients the free-text administrative comments written by the doctor may have contained personal notes about sensitive information.
QWhat should patients do?
Following CNIL guidance: do not open attachments or click links in emails or texts claiming to be from a doctor, insurer or authority, and type the official website address yourself. If you suspect identity theft, file a complaint with the police or gendarmerie, alert your bank and check whether accounts have been opened in your name. You can also ask your doctor in writing, under the GDPR right of access, what data the practice holds about you.
QWhat caused the breach?
Cegedim says it identified abnormal application request behaviour on doctors' accounts at the end of 2025, took all necessary measures as soon as it was detected, and contained the incident. It notified the CNIL, filed a complaint with the public prosecutor and is cooperating with the investigation. Technical details, such as how the accounts came to be used, have not been published.