Hospices Civils de Lyon: the leak was at a vendor, not the hospital
Hospices Civils de Lyon confirmed a cybersecurity incident at an external
vendor: a 2020 administrative database covering staff and contractors was
potentially stolen. No patient medical data is affected.
⚠️ Confirmed by HCL, incident at a vendor.
Hospices Civils de Lyon acknowledged the incident and states its own systems were not
affected. What remains unclear is the exact scale of the theft at the vendor — a follow-up
unit and a complaint have been set up to assess it.
The numbers
2020
Year of the historical database concerned, used during a technical
migration operation.
HCL statement, Lyon Capitale, August 6, 2026.
0
Patient medical data affected, according to HCL — the database is
strictly administrative and covers staff.
Tonic Radio, HCL statement.
Jun 25
Date HCL was informed of the incident at the vendor, ahead of the
public announcement.
Lyonmag, August 6, 2026.
?
Exact scale of the theft at the vendor: not publicly quantified at
this stage, investigation ongoing.
Not publicly confirmed.
Timeline
CONFIRMED
June 25, 2026
Hospices Civils de Lyon is informed of a cybersecurity incident
affecting one of its external vendors.
CONFIRMED
August 6, 2026
HCL publicly announces the incident. A historical database used
in 2020 during a technical migration, containing administrative information on HCL
staff and external contractors (names, photographs, professional identifiers, roles,
work sites), was potentially stolen.
CONFIRMED
Follow-up
HCL states no fraudulent use has been observed to date, and that
a follow-up unit and a complaint have been set up to assess the real extent of the
theft.
🏥"The hacked hospital" isn't always the hospital
This case illustrates an essential nuance: the headline circulating ("cyberattack at
the hospital") hides a more precise reality. The incident happened at a vendor, not
inside the institution's systems, and the database concerns staff, not patients. The
distinction matters for assessing the real risk — here, no medical record is at stake,
but a risk of impersonated professional identity.
What it changes for you
If you are or were a healthcare professional or external contractor at HCL, your name,
photo and role could be in a 2020 database. The main risk is professional-identity
impersonation — a message or call posing as a colleague or HR department using this
information. See From Leak to Scam.
🔒 If you receive an unusual professional solicitation citing your
role or work site at HCL, verify its origin through an independent channel before
responding.
Frequently asked questions
Was the hospital itself hacked?
No. The incident concerns an external vendor; HCL's own systems were not
compromised.
Is patients' medical data affected?
No, according to HCL: the affected database is administrative and covers staff, not
patients.
What data is potentially exposed?
Names, photographs, professional identifiers, roles and work sites, in a 2020
database.
📌 Last checked: August 21, 2026. Verifiable
information to report: contact@egidio.app.
Cite this pageEgidio — The Threat Laboratory, "Hospices Civils de Lyon: the leak was at a vendor, not the hospital," egidio.app/en/laboratoire/hospices-civils-lyon-vendor-breach/. Licensed CC BY 4.0.
Free to reuse, including commercially, with attribution. Reuse terms.