Cybersecurity Incident Affects Lyon Hospitals Staff Data
Lyon, August 6, 2026 – The Lyon Civil Hospitals (HCL) announced on Thursday, August 6, 2026, that sensitive personal data of its staff and external collaborators was stolen during a cybersecurity incident. The HCL was informed on June 25, 2026, about the breach affecting one of its external service providers.
Historical Database Compromised
According to a statement from the HCL, the external provider indicated that a historical database, used during a technical migration operation in 2020, may have been compromised. This could have led to the theft of personal data from 2020 related to HCL professionals and external contributors.
The HCL emphasized that its own IT system was not affected, and no malfunctions have been observed within the institution’s establishments.
What Data Was Stolen?
The full extent of the data theft remains unknown, but the HCL specified that the compromised information includes “administrative personal data related to the identification of professionals and access management.” This includes:
- Name
- First name
- Photograph
- Professional identifier
- Function
- Assignment site
As of now, the HCL certifies that no fraudulent use of the data, no unauthorized access to establishments, and no safety incidents have been reported following the breach.
Measures Taken and Ongoing Investigation
In response to the incident, complementary security measures are being implemented, including the preventive renewal of access credentials for the affected professionals and external personnel. The individuals concerned are being informed individually about the measures being taken.
The company targeted by the cyberattack has decided to file a complaint, and an investigation is currently underway to determine the full scope and nature of the incident.
This incident highlights the growing importance of cybersecurity for healthcare institutions, which often handle highly sensitive personal data. While the HCL’s internal systems were not directly affected, the compromise of an external provider’s database underscores the vulnerabilities that can arise within complex IT ecosystems.
The HCL continues to monitor the situation closely and is working with the affected provider and relevant authorities to mitigate any potential risks and ensure the security of its data and personnel.