GDPR & health data
GDPR compliance for the processing of health data (sensitive data): legal bases, consent, information, data-subject rights, register, DPIA.
→ Health · Sub-expertise
E-health combines digital law, sensitive personal data and sector-specific health regulation. Teleconsultation, appointment-booking platforms, medical artificial intelligence, data hosting: each solution requires a tailored legal framework. We support publishers, service providers and institutions.
→ What we cover
GDPR compliance for the processing of health data (sensitive data): legal bases, consent, information, data-subject rights, register, DPIA.
Compliance with the Health Data Host (HDS) certification: choice of a certified host, specific contracts, alignment with security obligations.
Legal framework for teleconsultation and telemedicine: agreements, technical conditions, eligibility for reimbursement, alignment with professional ethics.
Legal framework for platforms (appointment booking, patient records, communication between professionals): compliance, user contracts, business model.
Legal framework for medical AI solutions: qualification (medical device or not), MDR compliance, GDPR, alignment with the forthcoming European AI regulation.
Legal framework for research using health data: CNIL authorisations, ethics committees (CPP, CESREES), alignment with the national health-data system (SNDS) and the Health Data Hub (HDH).
→ Our approach
01
Analysis of the planned e-health solution, identification of the data processed, the actors, the data flows and the applicable regulatory constraints.
02
Setting up the compliant framework: GDPR (register, DPIA, information), HDS, alignment with professional ethics, contracts with subcontractors.
03
Drafting of the terms of sale/use, privacy policies, processing and HDS contracts, and agreements with professionals.
04
Advice on the evolution of the solution, management of incidents (CNIL notification, communication to data subjects), support in the event of an audit.
→ Who we help
Complete legal framework for a teleconsultation platform: GDPR, HDS, agreements with physicians, alignment with reimbursement, compliance with professional ethics.
Framework for a diagnostic-support AI solution: medical-device qualification (and MDR compliance where applicable), GDPR, alignment with users (institutions, physicians).
Support for a research project using health data: authorisations, GDPR compliance, agreements with data producers, alignment with the Health Data Hub.
Management of a health-data breach: analysis, notification to the CNIL within 72 hours, communication to the data subjects concerned, corrective measures.
→ Q&A
Health data is classified as sensitive data by the GDPR: its processing is in principle prohibited, save on a specific legal basis (explicit consent, vital interest, preventive medicine, research). The security conditions are reinforced (HDS, technical and organisational measures).
Health Data Host (HDS) certification is mandatory for any hosting of identifying health data. It guarantees compliance with strict requirements (security, traceability, incident management). The use of an HDS host is an obligation for e-health publishers.
Teleconsultation is regulated: conditions for eligibility for reimbursement (care pathway, known treating physician), technical requirements (secure platform, identity), compliance with professional ethics (quality of the remote consultation, consent). The framework evolves regularly.
Notification to the CNIL within 72 hours for breaches likely to result in a risk to rights and freedoms. Communication to the data subjects concerned if there is a high risk. Immediate corrective measures. Rigorous documentation of the incident and its handling.
→ Go further
Let's talk. We respond within one business day to qualify your transaction and direct you to the firm's most suitable lawyer.
Get in touch→