French healthcare services provider Viamedis said it suffered a significant cyber security incident that compromised the sensitive data of policyholders and healthcare professionals.
Headquartered in Paris, Viamedis offers healthcare data analytics and risk management services to health insurance organisations and healthcare professionals. The company says it has over 20 million beneficiaries and 240,000 healthcare professionals as clients.
In a recent post on Linkedin, Viamedis said that it recently identified a data security incident and immediately took its third-party payment management platform offline to mitigate the impact of the incident.
Viamedis said that it has also launched an internal investigation, with assistance from third party cyber security experts, to understand the nature and scope of the incident. It has lodged a complaint with the public prosecutor’s office and sent a notification and declaration to the French Data Protection Agency (CNIL) and the French Cybersecurity Agency (ANSSI).
“For beneficiaries, the personal data exposed is limited and is as follows: marital status, date of birth and social security number, name of their health insurer and guarantees available to third-party payers.
“Regarding health data: only less than 50 beneficiary invoices have been breached and only concerns information on medical transport (taxi, ambulance). For healthcare professionals, a specific note is currently being prepared,” Viamedis said.
The company added that the cyber security incident did not affect systems that store banking information and threat actors did not access customers’ postal addresses, telephone numbers, or email addresses.
The company is yet to comment on the number of affected individuals, but considering it has 20 million beneficiaries and 240,000 healthcare professionals as customers, the impact of the incident could be significant.
“To date, we do not have the number of policyholders “impacted”, we are still under investigation,” general director of Viamedis Christophe Candé told AFP.
Candé confirmed that the company did not suffer a ransomware attack and that threat actors used spear-phishing to gain access to its third-party payment management platform. “A healthcare professional’s account was phished,” he said.
Viamedis added that beneficiaries will be able to use their carte vitale and third-party payment cards. The temporary disconnection from the Viamedis platform will only affect certain health professionals, mainly opticians and audio prosthetists.
One of Viamedis clients, Malakoff Humanis, a French provider of insurance products and services, said that it was affected by the data security incident at Viamedis.
According to Bitdefender, in a notice sent to customers, Malakoff Humanis said that Viamedis fell victim to a cyber attack that compromised sensitive personal information including names, date of birth, marital status, social security numbers and health insurer names of policyholders and their families.
“We inform you that Viamedis, the organisation to which we subcontract the management of third-party payment for complementary health insurance, has just suffered a cyberattack,” Malakoff Humanis said.
The company added that no banking information, medical data, postal addresses, telephone numbers or email addresses were compromised as such records were not stored on the affected platform.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543