Egidio
Case file · August 21, 2026

Hospices Civils de Lyon: the leak was at a vendor, not the hospital

Hospices Civils de Lyon confirmed a cybersecurity incident at an external vendor: a 2020 administrative database covering staff and contractors was potentially stolen. No patient medical data is affected.

⚠️ Confirmed by HCL, incident at a vendor. Hospices Civils de Lyon acknowledged the incident and states its own systems were not affected. What remains unclear is the exact scale of the theft at the vendor — a follow-up unit and a complaint have been set up to assess it.

The numbers

2020
Year of the historical database concerned, used during a technical migration operation.
HCL statement, Lyon Capitale, August 6, 2026.
0
Patient medical data affected, according to HCL — the database is strictly administrative and covers staff.
Tonic Radio, HCL statement.
Jun 25
Date HCL was informed of the incident at the vendor, ahead of the public announcement.
Lyonmag, August 6, 2026.
?
Exact scale of the theft at the vendor: not publicly quantified at this stage, investigation ongoing.
Not publicly confirmed.

Timeline

CONFIRMED
June 25, 2026
Hospices Civils de Lyon is informed of a cybersecurity incident affecting one of its external vendors.
CONFIRMED
August 6, 2026
HCL publicly announces the incident. A historical database used in 2020 during a technical migration, containing administrative information on HCL staff and external contractors (names, photographs, professional identifiers, roles, work sites), was potentially stolen.
CONFIRMED
Follow-up
HCL states no fraudulent use has been observed to date, and that a follow-up unit and a complaint have been set up to assess the real extent of the theft.

🏥"The hacked hospital" isn't always the hospital

This case illustrates an essential nuance: the headline circulating ("cyberattack at the hospital") hides a more precise reality. The incident happened at a vendor, not inside the institution's systems, and the database concerns staff, not patients. The distinction matters for assessing the real risk — here, no medical record is at stake, but a risk of impersonated professional identity.

What it changes for you

If you are or were a healthcare professional or external contractor at HCL, your name, photo and role could be in a 2020 database. The main risk is professional-identity impersonation — a message or call posing as a colleague or HR department using this information. See From Leak to Scam.

🔒 If you receive an unusual professional solicitation citing your role or work site at HCL, verify its origin through an independent channel before responding.

Frequently asked questions

Was the hospital itself hacked?

No. The incident concerns an external vendor; HCL's own systems were not compromised.

Is patients' medical data affected?

No, according to HCL: the affected database is administrative and covers staff, not patients.

What data is potentially exposed?

Names, photographs, professional identifiers, roles and work sites, in a 2020 database.

📌 Last checked: August 21, 2026. Verifiable information to report: contact@egidio.app.

Related reading

Cite this page Egidio — The Threat Laboratory, "Hospices Civils de Lyon: the leak was at a vendor, not the hospital," egidio.app/en/laboratoire/hospices-civils-lyon-vendor-breach/. Licensed CC BY 4.0.

Free to reuse, including commercially, with attribution. Reuse terms.