Skip to main content
Certyneo
Security

Electronic Medical Record: Security Standards 2026

Electronic medical record security: HDS requirements, certified hosting, strong authentication and electronic signature of practitioners.

Certyneo Team7 min read

Updated on

Certyneo Team

Writer — Certyneo · About Certyneo

a row of metal lockers with numbers on them

Electronic medical records are governed by two regimes that do not overlap: the protection of personal data, which treats health information as a special category subject to a general prohibition, and the French Public Health Code, which imposes its own retention periods and its own access rights. Compliance with the first does not amount to compliance with the second, and most of the breaches identified stem from this confusion.

Hosting: mandatory certification

Anyone hosting personal health data on behalf of third parties, in connection with prevention, diagnosis or care activities, must be certified for this purpose.

This obligation is fundamental and is often discovered too late. It does not depend on the volume of data or the size of the organisation: a practice that entrusts its practice-management software to an online provider must ensure that the data hosting is carried out by a certified provider. Responsibility for this check lies with the data controller, i.e. the professional or the institution, not with the provider.

Two practical points follow from this: the outsourcing contract must explicitly mention this certification and its scope, and a change of provider or infrastructure requires this coverage to be re-checked.

The regime governing health data

Health-related data falls into a special category whose processing is, in principle, prohibited. Processing is lawful only if it falls within one of the strictly defined exceptions — in particular healthcare provision, preventive medicine, or the explicit consent of the individual.

This reversed structure has a direct consequence: for each processing operation, it must be possible to identify the exception on which it is based. A secondary use of the data — internal statistics, improving a tool, research — cannot be inferred from the lawfulness of care-related processing; it requires its own legal basis.

In addition, there are general obligations: a record of processing activities, information provided to individuals, defined retention periods, and an impact assessment where the processing poses a high risk — which is frequently the case for an electronic patient record.

Retention periods

These are governed by the French Public Health Code and not solely by the principle of storage limitation.

A medical record created within a healthcare institution must be kept for twenty years from the last stay or the last outpatient consultation. Two specific rules apply on top of this:

  • For a patient who was a minor at the time of care, retention is extended until their twenty-eighth birthday where that date falls later.
  • In the event of the patient's death less than ten years after the last visit, the record must be kept for at least ten years from the date of death.

These periods are suspended by any administrative appeal or legal proceedings seeking to establish the liability of the institution or of the professionals.

The link with limitation periods for liability claims is direct: the claim is time-barred after ten years from the stabilisation of the harm, and a record destroyed prematurely deprives the professional of their main means of defence — an issue covered in detail in our article on professional civil liability.

Traceability of access

This is the most operational requirement, and the one whose absence is hardest to remedy after the fact.

Every access to the record must be logged: who consulted it, which item, on what date. This logging serves two distinct and complementary purposes.

It prevents and detects improper access, which is one of the most common breaches within institutions — consulting a colleague's, a relative's or an acquaintance's record.

It protects the professional, by making it possible to show that an access complained of did not take place, or that a disputed access was indeed related to the patient's care. Without a log, a suspicion can neither be established nor ruled out.

Access rights must also be differentiated according to roles: being part of the care team does not grant access to the entire record, but only to the information necessary, as explained in our article on medical confidentiality.

The patient's right of access

The patient has direct access to all information concerning their health, without having to justify their request.

Disclosure takes place no earlier than after a reflection period and no later than within a period that is extended where the information is more than five years old. Any fees are limited to the cost of copying and postage.

Two limits apply to this right: information gathered from third parties not involved in the care is excluded, as is information concerning such third parties. After death, access by the deceased's heirs is subject to a separate regime, limited to the information necessary for the stated purpose.

Use-case scenarios

Changing practice-management software. Check the new provider's hosting certification, data portability, and export format. A migration without a recovery plan risks the loss of records whose retention periods are still running.

Group practice. Differentiate access rights by practitioner and by patient rather than opening the entire record to everyone. This is the most common control point, and it is as much a matter of organisation as of technology — a subject covered in our article on administrative compliance for a medical practice.

Patient access request. Verify identity, isolate excluded information, and comply with the applicable time limit based on the age of the information. Keep a record of the request and the response: compliance with the time limit must be provable.

Frequently asked questions

Do we need a certified hosting provider? Yes, as soon as health data is hosted on behalf of a third party in a context of prevention, diagnosis or care. The verification is the responsibility of the data controller, not the provider.

How long must a medical record be kept? Twenty years from the last visit to the institution, extended until the patient's twenty-eighth birthday if they were a minor, and at least ten years from death if death occurred within ten years.

Can a patient view their record? Yes, directly and without needing a reason, within the applicable time limits, which are extended for information more than five years old. Only copying and postage costs may be charged.

Is logging of access mandatory? Yes, and it protects the professional as much as the patient: without a log, a disputed access can neither be established nor ruled out.

Can a professional view any record within the organisation? No. Access is limited to the information necessary for their role in caring for the patient concerned. Access rights must be differentiated accordingly.

Can the data be used for statistical purposes? Not under the basis of care-related processing. Any secondary use requires its own legal basis, and where applicable, specific information provided to individuals.

Key takeaways

Two regimes overlap and must be handled separately. Data protection requires identifying, for each processing operation, the exception that makes it lawful — the purpose of care does not cover secondary uses. The French Public Health Code imposes its own retention periods, which are measured in decades and are suspended in the event of legal proceedings.

Between the two, one mechanism serves both regimes at once: logging of access, combined with differentiated access rights. This is what makes it possible to demonstrate that the limit of "necessary for the role" has been respected, and it is also what protects the professional when an access is called into question. The reasoning is the same as that applicable to obtaining consent: what is not logged can neither be proven nor disproven.

Try Certyneo for free

Send your first signature envelope in less than 5 minutes. 5 free envelopes per month, no credit card required.

Go deeper into this topic

Our comprehensive guides to master electronic signatures.

Certyneo Community

A question about electronic signatures?

Join the Certyneo community: ask your questions, share your answers and connect with thousands of users and our team.