Earlier quoted context omitted.
In the UK, the data regulator fined a small organisation £180,000 ($230,000) for exactly the same mistake on a list with 781 recipients. The organisation was a specialist sexual health clinic and the newsletter was for patients with HIV. Without knowing the details, I can't say whether a €2000 fine was disproportionately onerous or a slap on the wrist. https://www.businessinsider.com/nhs-trust-fined-for-leaking-...
With such sensitive information they should really avoid CC/BCC and do it manually, or write a script for sending 1 email at a time. Not because CC/BCC is bad, but because you want to be 100% sure to dodge this kind of problems.
It's almost like laws can work.