Company · Healthcare data and technology services · SaaS and data solutions provider · Global
French technology and data services company serving healthcare and business markets.
The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.
Cegedim Sante, the French medical-software subsidiary of the Cegedim group, suffered a major breach affecting roughly 15.8 million records, detected via unusual activity on its MonLogicielMedical (MLM) electronic patient-record product (used by ~3,800 French doctors). After a failed extortion attempt, threat actors marketed the data on dark-web forums and Telegram in early 2026. Exposed data included names, gender, dates of birth, phone numbers, home addresses, emails, French national identification numbers, and, for subsets, doctors' notes and sensitive health conditions such as HIV/AIDS status and sexual orientation (about 165,000 files contained doctors' notes). (NOTE: prior record listed 445,435 email addresses only; this materially understated a ~15.8M-record breach with SSN-equivalent, medical, and special-category data - corrected.)
Full threat analysis, exploitation vectors, and principal guidance below.
10 additional sections · verified field analysis · defensive doctrine
15.8M records analyzed
Cegedim, through its subsidiary Cegedim Sante, is a major French health-technology and data-services group that provides medical software to physicians (including the MonLogicielMedical/MLM electronic patient-record product used by thousands of French doctors) and healthcare data/SaaS services. As a health-data processor, it holds large volumes of patient and physician records on behalf of the French healthcare system.
Healthcare data and technology providers collect identity, contact, billing, provider, patient, prescription, and workflow data across SaaS, analytics, and healthcare-administration systems.
Cegedim Sante detected unusual activity on its MonLogicielMedical (MLM) product in late 2025 and filed a criminal complaint. After a failed extortion attempt, threat actors began marketing the stolen dataset on dark-web forums and Telegram in early 2026. French media and authorities reported one of the largest medical data leaks in French history; Cegedim had previously faced GDPR enforcement.
The breach exposed one of the largest volumes of French medical data on record, roughly 15.8 million records, including patient names, dates of birth, contact details, French national identification (Social Security) numbers, doctors' notes, and sensitive health information such as HIV/AIDS status and sexual orientation for some individuals. The combination of identity, national-ID, and special-category health data creates severe identity-theft, medical-fraud, discrimination, extortion, and outing risks at national scale, with major GDPR/regulatory consequences.
• Outing, blackmail, and targeted harm from exposure of HIV/AIDS status and sexual orientation | • Identity theft and fraud using French national ID (SSN), name, DOB, and address | • Medical identity fraud and insurance abuse using diagnoses and doctors' notes | • Large-scale targeted phishing/smishing across millions of French patients | • Discrimination risk from disclosure of sensitive health conditions | • Doxxing and physical targeting from exposed addresses
A healthcare-linked breach: exposure ties a named individual to a provider relationship and, where clinical or insurance data is present, to conditions and treatment. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.
Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.
Request Consultation