Cegedim Santé A.I CyberSecurity Scoring
Cegedim Santé
Company Information
Website:http://www.cegedim-sante.com
Employees number:447
Number of followers:11,583
NAICS:5112
Industry Type:Software Development
Homepage:cegedim-sante.com
Cegedim Santé Risk Score (AI oriented)
Between 550 and 599
Cegedim SantéSoftware Development
Updated:
22/03/2026
22/03/2026
552/1000
Very Poor
Ca
Cegedim Santé Global Score (TPRM)
xxxx
Cegedim SantéSoftware Development
Score locked

Cegedim SantéVery Poor
Current Score
552Ca (VERY POOR)
01000
3 incidents
-108 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
572
JULY 2026
570
JUNE 2026
566
MAY 2026
558
APRIL 2026
555
MARCH 2026
553
FEBRUARY 2026
585
Cyber Attack
27 Feb 2026 • Cegedim Santé
Cegedim Santé and French Health Ministry: Doctors’ records hit by cyberattack: up to 15 million patients in France affected
Massive Cyberattack Exposes Data of 15 Million French Patients
549
CRITICAL-36
CEGFRE1772468826
Massive Cyberattack Exposes Data of 15 Million French Patients
In late 2025, a cyberattack on a widely used medical database in France compromised the personal data of up to 15 million patients, including sensitive information on approximately 164,000 individuals. The breach, confirmed by the French Health Ministry, targeted a software system developed by Cegedim Santé, which is used by around 1,500 doctors across the country.
The stolen data includes administrative details such as names, phone numbers, and postal addresses, as well as highly sensitive information like doctors’ notes on patients’ sexual orientation, religious beliefs, infidelity cases, and sexual assault disclosures. While medical records themselves remained intact, the leak has raised serious privacy concerns. Among the affected individuals are politicians, including potential candidates for the 2027 presidential election, and celebrities.
The attack was first detected by Cegedim Santé in late 2025 after identifying unusual activity in doctor accounts. The company reported the incident to France’s data protection authority, the National Civil Liberties Commission (CNIL), in October 2025, and the Paris prosecutor’s office launched an investigation in November 2025. However, the full scale of the breach only became public on February 27, 2026, when Health Minister Stéphanie Rist disclosed the details.
An alleged hacker, speaking to France2, claimed that only a portion of the stolen data had been published on the dark web, though the broadcaster verified that some sensitive information was already accessible. The investigation remains ongoing, with authorities yet to identify the perpetrators.
The incident has sparked outrage among medical professionals, who argue that government pressure to digitize patient records has left them vulnerable. Agnès Giannotti, president of France’s main GP union (MG France), criticized the push for centralized data storage, warning that it undermines patient trust and safety.
This breach is part of a broader surge in cyberattacks targeting French institutions, including recent incidents affecting the national bank account registry. The fallout from the leak continues to unfold as authorities assess the full impact.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JANUARY 2026
582
DECEMBER 2025
755
Breach
01 Dec 2025 • Cegedim Santé
Cegedim Santé: Fuite massive de données après une cyberattaque contre un logiciel de Cegedim Santé : premières réactions
Massive Data Breach Exposes Personal Information of 15 Million French Citizens
575
CRITICAL-180
CEG1772307567
Massive Data Breach Exposes Personal Information of 15 Million French Citizens
A cyberattack targeting Cegedim Santé’s medical software, MLM (MonLogicielMédical.com), has resulted in the exposure of sensitive data belonging to 15 million French citizens on the dark web. The breach, first reported by France 2 on February 26, occurred in late 2025, though details only emerged this week.
The compromised data includes names, phone numbers, birth dates, email and postal addresses of patients whose information was entered by 1,500 general practitioners roughly 40% of the 3,800 physicians using the software. For 169,000 individuals, the leak extended to highly sensitive details, such as medical conditions, sexual orientation, religious affiliation, and records of physical or sexual violence.
The attack was claimed by an unidentified hacker, though it remains unclear whether they were directly responsible or merely disseminated the stolen files. The French Ministry of Health confirmed the breach but emphasized that the incident did not stem from a failure in state-run systems. While structured medical records such as prescriptions or lab results remained unaffected, the scale of the leak is staggering, averaging 10,000 patients per affected physician.
Cegedim Santé detected the breach in late 2025 after identifying abnormal query activity on physician accounts. The company stated it took immediate containment measures, notified authorities (CNIL, ANSSI, and CERT Santé), and filed a police report. Physicians were contacted in early January to assist with GDPR compliance, including patient notifications.
The incident has drawn sharp criticism from MG France, the general practitioners’ union, which argues that doctors should not bear responsibility for the breach. The union has filed a complaint with the CNIL, demanding clarity on liability and urging stronger safeguards before expanding digital health tools like the Dossier Médical Partagé (DMP).
This breach follows a wave of cyberattacks on French healthcare systems, including previous incidents involving third-party payment operators and the Weda software. Despite government initiatives like Care and Ségur numérique to bolster cybersecurity, the sector remains a prime target, raising concerns about patient trust in digital health services.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Breach
01 Dec 2025 • Cegedim Santé
Cegedim Santé: La cyberattaque Cegedim prouve que nos médecins notent et conservent le pire de notre vie intime
Massive Health Data Breach Exposes Sensitive Medical Records of Millions of French Patients
575
CRITICAL-180
CEG1772187887
Massive Health Data Breach Exposes Sensitive Medical Records of Millions of French Patients
A major cyberattack targeting MonLogicielMedical (MLM), a medical software developed by Cegedim Santé and used by nearly 3,800 French physicians, has exposed highly sensitive patient data. The breach, detected in late 2025, compromised the records of an estimated 11 to 15 million individuals, with 1,500 doctors directly affected.
The leaked database, discovered on the dark web, includes standard personal details such as names, birthdates, contact information, and addresses. However, the most alarming exposure lies in an unstructured "administrative comments" field, where physicians freely recorded deeply private information HIV status, sexual orientation, histories of violence (including rape), and even family medical backgrounds. Investigations by France 2 and ethical hacker Clément Domingo (SaxX) confirmed the authenticity of the data, with affected individuals verifying its accuracy.
The cybercriminal group dumpsec claimed responsibility, asserting they had stolen over 65 million records, though Cegedim disputed the figure, insisting only a subset of data was accessed. The company reported the incident to France’s data protection authority (CNIL) and filed a criminal complaint, while also assisting impacted doctors in notifying patients. Despite these measures, concerns persist over the lack of prior alerts France 2 revealed that a whistleblower had previously flagged vulnerabilities to Cegedim, but received no response.
The breach underscores critical gaps in securing unstructured medical data, where free-text fields become unintended repositories for highly confidential information. With no evidence that structured patient records were compromised, the fallout remains centered on the unregulated handling of sensitive notes now circulating beyond the control of medical professionals. The incident has reignited debates over digital health security and the protection of intimate patient details in an era of escalating cyber threats.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
NOVEMBER 2025
755
OCTOBER 2025
755
SEPTEMBER 2025
755
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Cegedim Santé ??
What was Cegedim Santé's A.I Rankiteo Cyber Score in July 2026 ??
What was Cegedim Santé's A.I Rankiteo Cyber Score in June 2026 ??
What was Cegedim Santé's A.I Rankiteo Cyber Score in May 2026 ??
What was Cegedim Santé's A.I Rankiteo Cyber Score in April 2026 ??
What was Cegedim Santé's A.I Rankiteo Cyber Score in March 2026 ??
What was Cegedim Santé's A.I Rankiteo Cyber Score in February 2026 ??
What was Cegedim Santé's A.I Rankiteo Cyber Score in January 2026 ??
What was Cegedim Santé's A.I Rankiteo Cyber Score in December 2025 ??
What was Cegedim Santé's A.I Rankiteo Cyber Score in November 2025 ??
What was Cegedim Santé's A.I Rankiteo Cyber Score in October 2025 ??
What was Cegedim Santé's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on Cegedim Santé's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Cegedim Santé ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Cegedim Santé's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?