Data breach at MédecinDirect: when digital health forgets what matters most
The cyberattack that hit MédecinDirect, disclosed in early December, affects up to 323,000 patients. The number is already enormous. But that is not what should worry us the most.

The cyberattack that hit MédecinDirect, disclosed in early December, affects up to 323,000 patients. The number is already enormous. But that is not what should worry us the most.
The real problem is not that an attack happened.
It is what the attack reveals: a dangerous trivialisation of health data, treated as just another piece of digital information among many.
Yet it is nothing of the sort.
What happened at MédecinDirect?
MédecinDirect is a telemedicine platform used by several French mutual insurers and supplementary health providers. It lets members consult doctors remotely, exchange medical documents, and obtain prescriptions or advice.
The intrusion was detected on 28 November 2025 and, according to the operator, neutralised immediately. Affected individuals started being informed from 3 December. MédecinDirect mentions around 285,000 people notified; the cybercriminal group behind the attack, which calls itself Dumpsec, claims 323,069 patients on its side and has authenticated samples of the data.
Following that intrusion, personal and medical data were exposed: contact details, the reason for the teleconsultation, information entered in the preliminary medical questionnaire, written exchanges between patients and doctors, and a small number of social security numbers. Video consultations, for their part, are reportedly not affected.
And the insurers? And the authorities? Nothing, as usual. We are firmly in familiar territory.
- The company communicates "transparently" but says nothing specific.
- The mutual insurers, the platform's partners, play for time.
- The State says it is "taking the matter seriously".
On paper, the process is followed: MédecinDirect says it notified the CNIL and filed a complaint with the Paris public prosecutor. In practice, AFP reported as early as 5 December that the CNIL, for its part, said it had not yet received any notification at that stage. And in the meantime, the data are already circulating. Perhaps for sale on forums. Perhaps in use. Perhaps being exploited.
One question remains: how can a health platform be compromised to this degree in 2025?

Is a cyberattack always an accident?
Let us be clear: any organisation can be attacked.
No infrastructure is invulnerable.
But not all attacks are equal.
There is a fundamental difference between:
- a sophisticated attack against a well-protected system,
- and a compromise made possible by weak structural choices: poorly segmented access, insufficient monitoring, badly controlled technical dependencies.
This distinction is anything but theoretical. According to the CERT Santé observatory, 749 security incidents were reported by French health and medico-social facilities in 2024, 29% more than in 2023, and ransomware remains the heaviest threat. Health is no longer one target among many: it is a front-line target.
In this field, the distinction is essential.
Because the impact is not financial.
It is human, intimate, lasting.
You can replace a payment card.
You cannot replace a medical history.
Why are health data a target of their own kind?
Medical data are not merely sensitive.
They are persistent.
A diagnosis, a treatment, a past or present condition: this information can be exploited years later, cross-referenced with other breaches, used for fraud, blackmail, manipulation or discrimination.
And contrary to a common assumption, these data are not used only for spectacular targeted attacks.
Above all, they feed a quiet underground market, where aggregating data is worth more than the isolated hit.
That is precisely why health platforms should be among the most rigorous systems in the country.
The real problem: trust delegated without oversight
In this affair, many patients are discovering that they were using MédecinDirect... without really knowing it.
The platform was built into their mutual insurer, their contract, their care pathway.
That is where the crux of the problem lies.
We have built a system in which:
- members trust their mutual insurer,
- mutual insurers trust technical providers,
- providers stack up digital solutions,
- and no one keeps a clear view of the chain of responsibility.
MédecinDirect is not an isolated case, it is one more link in that chain. In February 2024, the cyberattack on the two third-party payment operators Viamedis and Almerys exposed the data of more than 33 million insured people, close to one French person in two; the CNIL opened an investigation to check whether their security measures were compliant. Two years later, in February 2026, a breach affecting the Cegedim MLM medical software was made public, concerning around 15 million people, including 164,000 with sensitive data according to the health minister. Every time, the same pattern: data entrusted to a third party, then to a third party of that third party.
When everything works, no one asks questions.
When it breaks, everyone communicates.
But trust, by then, is already damaged.
What can you actually do if you have used telemedicine?
This is not about panicking, nor about sinking into blanket distrust.
But it is time to adopt a few simple, realistic habits.
If you have used a telemedicine service:
- Check whether you have an active account and change your access credentials.
- Ask your mutual insurer the question directly: which providers do they use for digital health?
- Separate your uses: an email address dedicated to medical services helps limit your exposure.
- Be wary of unexpected messages mentioning reimbursements, medical documents or urgent updates.
These steps do not make the system perfect.
But they reduce your personal exposure.
What the players should do (and are slow to do)
For companies and institutions, the subject runs deeper.
Cybersecurity in health can no longer be treated as a secondary technical matter, handed off to a provider or an isolated team.
It must be:
- driven at the governance level,
- built into architecture choices,
- tested regularly,
- accepted as a non-negotiable cost.
Not as a "bonus", not as a marketing argument.
Regulatory compliance (GDPR, health data hosting, certifications) is necessary.
But it is not enough if it is treated as an administrative formality.
What this affair reminds us, at heart
Digital health is a step forward.
But it has value only if it protects what it promises to make easier.
In Être en cybersécurité, I say it often:
security is not a matter of fear, but of clear sight.
This attack is not an anomaly.
It is a signal.
A reminder that the digital world, when it touches the intimate, demands something other than speed and innovation.
It demands discernment, responsibility, and a genuine culture of risk.
Without that, we will keep discovering the consequences... after the fact.
Sources
- Scale of the MédecinDirect breach (up to 323,069 patients), timeline, data involved and the Dumpsec group's claim: Caducée.net, December 2025 (in French).
- Confirmation of the breach and its perimeter (around 285,000 people notified): L'Usine Digitale and Egora, December 2025 (in French).
- Cyberattack on the third-party payment operators Viamedis and Almerys, more than 33 million insured people affected and an investigation opened: CNIL, 7 February 2024 (in French).
- Breach of the Cegedim MLM medical software, around 15 million people including 164,000 with sensitive data according to the health minister: Caducée.net, February 2026 (in French).
- 2024 review of cybersecurity incidents in French health facilities (749 reports, up 29%): Agence du Numérique en Santé, June 2025 (in French).
Frequently asked questions
How many patients are affected by the MédecinDirect breach?
MédecinDirect says it notified around 285,000 people. The cybercriminal group behind the attack, which calls itself Dumpsec, claims 323,069 patients on its side.
When did the cyberattack take place?
The intrusion was detected on 28 November 2025 and, according to the operator, neutralised immediately. Affected individuals started being informed from 3 December 2025.
What data was exposed?
Personal and health data: contact details, the reason for the teleconsultation, information from the preliminary medical questionnaire, written exchanges between patients and doctors, and a small number of social security numbers. Video consultations are reportedly not affected.
Who claimed the attack against MédecinDirect?
A cybercriminal group calling itself Dumpsec claimed the attack and authenticated samples of the data.
Why are health data a target of their own kind?
Because they are persistent: a diagnosis or a condition can be exploited years later, cross-referenced with other breaches and used for fraud, blackmail, manipulation or discrimination.
What can a patient who has used a telemedicine service do?
Check and change their access credentials, ask their mutual insurer which digital health providers it uses, dedicate an email address to medical services, and be wary of unexpected messages mentioning reimbursements or medical documents.
Is GDPR compliance enough to protect health platforms?
No. Regulatory compliance is necessary, but it is not enough if it is treated as an administrative formality rather than built into governance and architecture choices.

Être en cybersécurité
A cyber roadmap in plain language, for everyone, not just the experts.
