Electronic Health Record: Security Standards 2026
Electronic health record security: HDS requirements, certified hosting, strong authentication and electronic signature of practitioners.
Updated on
Certyneo Team
Writer — Certyneo · About Certyneo

The electronic medical record combines two regimes that do not overlap: that of personal data protection, which treats health information as a special category subject to a presumption of prohibition, and that of the French Public Health Code, which imposes its own retention periods and its own access rights. Compliance with the first does not amount to compliance with the second, and most of the breaches observed stem from this confusion.
Hosting: mandatory certification
Any person hosting personal health data on behalf of third parties, in the course of prevention, diagnosis or care activities, must be certified for this purpose.
This obligation is fundamental and is often discovered too late. It does not depend on the volume of data or the size of the organisation: a practice that entrusts its business software to an online provider must ensure that the data hosting is carried out by a certified provider. Responsibility for this verification lies with the data controller, that is to say the professional or the establishment, and not with the provider.
Two practical points follow from this: the outsourcing contract must explicitly mention this certification and its scope, and a change of provider or infrastructure requires this coverage to be rechecked.
The regime governing health data
Health-related data falls under a special category whose processing is prohibited in principle. Processing is only lawful if it falls under one of the exhaustively listed exceptions — notably healthcare provision, preventive medicine, or the explicit consent of the person concerned.
This reversed architecture has a direct consequence: for every processing activity, it must be possible to identify the exception on which it is based. A secondary use of the data — internal statistics, improvement of a tool, research — cannot be inferred from the lawfulness of care-related processing; it requires its own legal basis.
General obligations also apply: a register of processing activities, information provided to individuals, defined retention periods, and an impact assessment where the processing presents a high risk — which is frequently the case for a computerised patient record.
Retention periods
These fall under the French Public Health Code and not solely under the principle of storage limitation.
The medical record created in a healthcare establishment is retained for twenty years from the last stay or the last outpatient consultation. Two specific rules apply in addition:
- For a patient who was a minor at the time of care, retention is extended until their twenty-eighth birthday when this date is later.
- In the event of the patient's death less than ten years after the last visit, the record is retained for at least ten years from the date of death.
These periods are suspended by any administrative appeal or legal action seeking to establish the liability of the establishment or its professionals.
The link with limitation periods for liability actions is direct: the action is time-barred after ten years from the date on which the damage is consolidated, and a record destroyed prematurely deprives the professional of their main means of defence — an issue detailed in our article on professional civil liability.
Traceability of access
This is the most operational requirement, and the one whose absence is hardest to remedy after the fact.
Every access to the record must be logged: who consulted it, which element, on what date. This logging serves two distinct and complementary functions.
It prevents and detects unauthorised access, which is one of the most frequent breaches in healthcare establishments — consulting the record of a colleague, a relative, or an acquaintance.
It protects the professional, by making it possible to demonstrate that an alleged access did not take place, or that a disputed access was indeed part of the patient's care. Without a log, a suspicion can neither be established nor ruled out.
Access rights must also be differentiated according to roles: belonging to the care team does not grant access to the entire record, but only to the information necessary, as explained in our article on medical confidentiality.
The patient's right of access
The patient has direct access to all information concerning their health, without having to justify their request.
Disclosure occurs no earlier than after a reflection period and no later than within a period that is extended when the information is more than five years old. Any fees are limited to the cost of reproduction and postage.
Two limits apply to this right: information collected from third parties not involved in the patient's care is excluded, as is information concerning such third parties. After death, access by the patient's heirs is governed by a separate regime, limited to the information necessary for the stated purpose.
Usage scenarios
Change of business software. Verify the new provider's hosting certification, data reversibility, and export format. A migration carried out without a recovery plan exposes the organisation to the loss of records whose retention periods are still running.
Group practice. Differentiate access rights by practitioner and by patient rather than opening the entire record to everyone. This is the most common point of control, and it is as much a matter of organisation as of technology — a topic covered in our article on administrative compliance for a medical practice.
Patient access request. Verify identity, isolate excluded information, and comply with the applicable time limit based on the age of the data. Log the request and the response: compliance with the deadline must be demonstrable.
Frequently asked questions
Is a certified hosting provider required? Yes, as soon as health data is hosted on behalf of a third party in the context of prevention, diagnosis or care. The verification is the responsibility of the data controller, not the provider.
How long must a medical record be retained? Twenty years from the last visit to the establishment, extended until the patient's twenty-eighth birthday if they were a minor, and a minimum of ten years from a death occurring within ten years.
Can a patient consult their own record? Yes, directly and without justification, within the applicable time limits, which are extended for information more than five years old. Only reproduction and postage costs may be charged.
Is logging of access mandatory? Yes, and it protects both the professional and the patient: without a log, a disputed access can neither be established nor ruled out.
Can a professional consult any record within the organisation? No. Access is limited to the information necessary for their role in the care of the patient concerned. Access rights must be differentiated accordingly.
Can the data be used for statistical purposes? Not under the heading of care-related processing. Any secondary use requires its own legal basis for lawfulness, and where applicable, specific information provided to the individuals concerned.
Key takeaways
Two regimes overlap and must be handled separately. Data protection requires that, for each processing activity, the exception that makes it lawful be identified — the purpose of care does not cover secondary uses. The French Public Health Code imposes its own retention periods, which run into decades and are suspended in the event of legal action.
Between the two, one mechanism serves both regimes at once: logging of access, combined with differentiated access rights. This is what makes it possible to demonstrate that the limit of "necessary for the role" has been respected, and it is also what protects the professional when an access is alleged against them. The reasoning is the same as that applicable to obtaining consent: what is not logged can neither be proven nor disproven.
Try Certyneo for free
Send your first signature envelope in less than 5 minutes. 5 free envelopes per month, no credit card required.
Dive deeper
Reference articles on this topic.
Dive deeper
Our comprehensive guides to master electronic signatures.
Continue reading about Security
Deepen your knowledge with these articles related to the topic.

ISO Certification for Electronic Signature: 2026 Guide
ISO 27001, eIDAS, ETSI… certifications from electronic signature service providers have become an essential selection criterion. Discover how to compare them effectively.

Electronic Signature: Traceability and Internal Audit in 2026
The traceability of an electronic signature has become a pillar of internal audit and legal compliance in business. Discover how to make the most of it.

Electronic Signature and ISO 27001 Standard: 2026 Guide
The ISO 27001 standard has become an essential benchmark for securing electronic signature processes in business. Discover key requirements, synergies with eIDAS, and best practices to adopt.