Skip to main content
Certyneo

Healthcare Data Protection and GDPR Compliance for Professionals

Healthcare data is the most sensitive personal data under GDPR. Discover all the obligations that apply to healthcare sector professionals in 2026.

Certyneo Editorial Team14 min read
Doctor shows patient medical scan on tablet

Healthcare data occupies a distinct place in the European regulatory landscape. Classified as special categories of sensitive data by the GDPR (Article 9), it is subject to enhanced protection rules that apply to all professionals who process it: healthcare facilities, mutual insurance societies, health software editors, laboratories, home care services, and actors in e-health and telemedicine. In 2026, the regulatory landscape has become even more complex — with the progressive entry into force of the European Health Data Space (EHDS), updated CNIL recommendations, and record penalties imposed across the EU, compliance is no longer optional. This article describes, point by point, the applicable obligations and best practices to adopt to secure your processing activities.

What is healthcare data under GDPR?

The GDPR (Regulation No. 2016/679, Article 4 §15) defines healthcare data as "personal data relating to the physical or mental health of a natural person, including the provision of healthcare services, which reveal information about the health status of that person".

A scope broader than it appears

This definition encompasses far more than traditional medical records. It includes:

  • Medical history, diagnoses, prescriptions and test results;
  • Data collected by connected devices (watches, glucose monitors, menstrual tracking applications);
  • Administrative data that allows inference of health status (reimbursement rates, frequency of consultations);
  • Social security numbers (NIR) when cross-referenced with medical information.

In France, the CNIL has clarified, notably in its landmark decision on health data warehouses (EDS), that the notion should be interpreted broadly. Thus, a simple photograph revealing a visible disability or biometric data (retinal fingerprint) falls within the scope.

Why enhanced protection?

The particular sensitivity of healthcare data stems from its potential for discrimination. Revealing someone's health status can affect their access to employment, insurance, credit, or expose their privacy. The CNIL estimates that violations involving healthcare data accounted for, in 2024, more than 36% of notifications it received — the leading category of compromised data.

Article 9 §1 of the GDPR establishes a prohibition on processing sensitive data, subject to exhaustively listed exceptions. For healthcare professionals, the applicable legal bases are primarily:

Consent must be free, specific, informed and unambiguous, expressed through a clear affirmative action. In the healthcare sector, this basis is often unsuitable for routine care (power imbalance between doctor and patient), but remains essential for treatments for research purposes, marketing, or use of consumer health applications.

Best practice 2026: use electronic signature in healthcare to collect patient consent in a traceable and timestamped manner, which facilitates proof in the event of regulatory inspection.

Care and preventive medicine (Art. 9 §2 h)

This is the main legal basis for healthcare professionals who process data in the context of a care relationship. It applies provided that the processing is carried out by — or under the responsibility of — a professional bound by medical confidentiality.

Public interest and research (Art. 9 §2 i and j)

Processing for public health purposes (epidemiological surveillance, pharmacovigilance) or scientific research may rely on these exceptions. In France, the Data Protection Act (Articles 65 to 68) and the decree regulating the National Health Data System (SNDS) define access conditions.

Concrete obligations of data controllers

Whether a medical practice or a digital health solution editor, obligations are structured around five pillars.

1. Record of processing (Art. 30)

Every data controller or processor must maintain a record documenting each processing activity: purpose, legal basis, data categories, retention periods, recipients, security measures. The CNIL requires that this record be kept up to date and presentable without delay during an inspection.

2. Data Protection Impact Assessment (DPIA / Art. 35)

Processing of healthcare data at large scale or for profiling purposes mandatorily requires a DPIA. The CNIL has published a list of processing activities requiring DPIA, including health data warehouses, health status monitoring mobile applications, and connected medical devices.

Regarding the legal value of electronic documents in this context, service providers must ensure that their collection mechanisms meet probative requirements.

3. Appointment of a Data Protection Officer (DPO)

Appointment of a DPO is mandatory for:

  • Healthcare professionals organised in groups (hospitals, nursing homes, care structures with more than 50 staff);
  • Mutual insurance societies and health insurers;
  • Health software editors processing data at large scale.

Since 2024, the CNIL has strengthened its controls on the effectiveness of the DPO role, verifying notably their actual independence and resources.

4. Security of information systems (Art. 32)

Technical and organisational measures must be proportionate to the risk. The CNIL notably recommends:

  • End-to-end encryption of stored and in-transit data;
  • Pseudonymisation wherever the purpose allows;
  • Implementation of strict access controls (multi-factor authentication);
  • Regular backups tested and disconnected from the main network;
  • A business continuity plan (BCP) specific to healthcare data.

Since the entry into application of the NIS 2 Directive (transposed into French law by the Act of 26 March 2025), the essential entities of the healthcare sector — including hospitals, medical device manufacturers and certain laboratories — are subject to even stricter cybersecurity requirements, with mandatory notification of major incidents to ANSSI within 24 hours.

5. Notification of data breaches (Art. 33 and 34)

Any breach of healthcare data must be notified to the CNIL within 72 hours of discovery. If the breach is likely to result in high risk to the rights and freedoms of individuals, affected patients must also be informed without undue delay.

In 2024, the CNIL imposed penalties for notification delays, reiterating that responsiveness is itself a compliance obligation.

Healthcare data hosting: a specifically French requirement

In France, the Act of 26 January 2016 (Article L. 1111-8 of the Public Health Code) requires that personal healthcare data be hosted with a certified HDS provider (Healthcare Data Hosting provider). This certification, issued by COFRAC-accredited bodies based on ISO 27001 standard and the ANS HDS framework, covers six distinct activities.

Who is affected by HDS certification?

All actors who host, administer or manage information systems containing healthcare data on behalf of third parties are affected: cloud providers, editors of health records (DMP), telemedicine platforms, and — since 2023 — editors of consumer health applications as long as they retain identifying data.

Use of a certified HDS provider does not relieve the controller of its own obligations: it must imperatively formalise a data processor contract compliant with Article 28 of the GDPR, detailing instructions given to the hosting provider, security guarantees and audit procedures.

The European Health Data Space (EHDS): what impacts in 2026?

The EHDS Regulation (adopted late 2025 and with initial provisions entering into application progressively until 2027) establishes the framework for cross-border access to healthcare data for research, innovation and public health. For French professionals, two immediate impacts:

  1. The obligation to respect enhanced portability rights (structured, machine-readable format) for patient records;
  2. The prohibition on processing primary healthcare data for advertising targeting purposes, even with consent — a stricter restriction than GDPR alone.

These developments make it essential to update privacy policies and processor contracts before end of 2026. For professionals using eIDAS-compliant electronic signature tools, traceability of consents and authorisations constitutes a significant advantage for demonstrating compliance during audit.

Patient rights and exercise of GDPR rights

Patients enjoy all GDPR rights (access, rectification, erasure, restriction, portability, objection), with some sector-specific adjustments.

The right of access to healthcare data

A patient may request access to their entire medical file (Article L. 1111-7 CSP). The professional has a deadline of 8 days (48 hours for recent data, recent hospitalisations) and 2 months for older data. The CNIL and the Ombudsperson have both sanctioned establishments that refused or delayed such requests.

The right to erasure and its limits

The "right to be forgotten" is limited by legal retention periods: 20 years for adult medical records, 28 years if the procedure was performed before adulthood. These legal periods override any request for early erasure — the controller must clearly explain this to the patient.

Management of requests through electronic channels

For establishments that have dematerialised their processes, requests to exercise rights may be transmitted and processed via secure forms. Qualified electronic timestamping of requests and responses constitutes best practice, allowing proof of compliance with regulatory deadlines during CNIL inspection.

The compliance of healthcare professionals and their technology partners relies on an articulation of European and national texts that must be understood.

GDPR — Regulation (EU) No. 2016/679 of 27 April 2016: the cornerstone of the framework, it classifies healthcare data as sensitive data (Art. 4 §15), prohibits its processing except for exhaustively listed exceptions (Art. 9 §2), mandates DPIA (Art. 35), DPO appointment (Art. 37), breach notification (Art. 33-34) and proportionate security measures (Art. 32). Penalties reach 20 million euros or 4% of annual global turnover — the higher amount applying.

Data Protection Act (Law No. 78-17 of 6 January 1978 as amended): transposing the GDPR into French law, it empowers the CNIL to adopt sector-specific referentials for healthcare and defines access modalities to the SNDS.

Public Health Code — Art. L. 1111-7 and L. 1111-8: establish the patient's right of access to their medical file and the obligation to host with a certified HDS provider.

HDS Framework (Healthcare Data Hosting provider): published by the French Health Digital Agency (ANS), it defines six certification activities covering physical infrastructure, platform and application software.

NIS 2 Directive — Directive (EU) 2022/2555, transposed into France by the Act of 26 March 2025: subjects essential entities in the healthcare sector (hospitals with more than 30,000 patients/year, medical device manufacturers class IIb and III, reference laboratories) to enhanced cybersecurity obligations, notably notification to ANSSI within 24 hours in case of significant incident, and implementation of annually tested incident response plans.

eIDAS Regulation No. 910/2014 and eIDAS 2.0 (Regulation (EU) 2024/1183): establish the legal value of electronic signatures used for consents, dematerialised medical acts and contracts with service providers. Advanced or qualified electronic signature is recommended for any act whose probative value may be contested.

EHDS Regulation (European Health Data Space Regulation, 2025): strengthens patient rights over their primary data and frames the use of secondary data for research, with the creation of health data access bodies in each Member State.

Concrete legal risks: beyond CNIL administrative penalties, controllers face civil liability actions (Art. 82 GDPR), criminal prosecution (Article 226-17 of the Criminal Code, maximum penalty of 5 years imprisonment and €300,000 fine for legal entities), and reputational damage whose economic impact often exceeds the penalty amount itself.

Use cases: GDPR compliance and healthcare data in practice

Scenario 1 — A group of private clinics managing approximately 1,200 beds

An intermediate-sized group of private clinics (approximately 1,200 beds across three sites) processed patient consents on paper forms, stored in poorly secured filing cabinets. During an internal audit in preparation for CNIL inspection, several gaps were identified: inability to quickly locate consent dating back more than two years, lack of traceability for consents relating to medical video surveillance and transmissions to third parties (insurers, referring physicians).

Management deployed a qualified electronic signature solution integrated into the hospital information system. Results measured at six months: the time to process access to medical file requests fell from 14 to 4 working days (71% reduction), the time to locate consent fell to less than 2 minutes versus 45 minutes average previously, and the group obtained HDS certification for the application layer.

Scenario 2 — An editor of telemedicine solution for specialist practitioners

A company editing a remote consultation platform for specialist practitioners (approximately 4,000 active user doctors) faced major risk: its servers were hosted with a US cloud provider without contractual clauses compliant with Article 28 of the GDPR, and without HDS certification. The platform nevertheless collected consultation reports, prescriptions and clinical photographs.

Following an impact assessment (DPIA) conducted with an external DPO, the company migrated to a HDS-certified hosting provider based in France, reviewed all its processor contracts, and integrated a timestamped informed consent mechanism before each consultation. It also implemented an internal incident notification procedure within 12 hours, enabling compliance with the 72-hour regulatory deadline to the CNIL. The cost of compliance implementation was estimated at €180,000 — compared to the €400,000 fine imposed by the CNIL against a comparable sector player the same year.

Scenario 3 — A network of independent pharmacies

A group of approximately forty independent pharmacies used centralised management software processing prescription histories and loyalty data (linked to implicit health profiles). Without a designated DPO and without an up-to-date processing record, the group was unable to respond to a patient's data subject access request within 30 days.

A compliance project spread over eight months enabled designation of a mutualistic DPO (a common and lawful solution for groups of SMEs), documentation of 23 distinct processing activities in the record, review of retention period policies (loyalty data was retained for 10 years without justification), and training of all pharmacy staff on correct procedures in the event of a patient request or inspection. The estimated ex-ante risk of penalties exceeded €150,000.

Frequently asked questions

Is healthcare data collected by a mobile application subject to GDPR?

Yes, as long as the application collects data allowing inference of someone's health status (heart rate, menstrual tracking, blood glucose, diet), this data constitutes healthcare data within the meaning of Article 4 §15 of the GDPR. The editor is a controller and must obtain explicit consent, host data with an HDS-certified provider and conduct a DPIA if processing is at large scale.

Must a solo healthcare practitioner appoint a DPO?

No, appointment of a DPO is not mandatory for a solo healthcare practitioner or a practice with a few practitioners, unless processing involves large-scale healthcare data. However, this practitioner remains a controller and must maintain a record of processing, apply the data minimisation principle and be able to respond to patient data subject requests within regulatory deadlines.

What penalties can the CNIL impose in case of healthcare data breach?

The CNIL has sanctioning authority reaching 20 million euros or 4% of annual global turnover, the higher amount applying. Beyond the fine, it may impose a compliance order with penalties for non-compliance, or make the decision public. On the criminal side, Article 226-17 of the Criminal Code provides for up to 5 years imprisonment and €300,000 fine for legal entities.

Is a processor (software, cloud) liable in case of healthcare data leak?

Yes. The GDPR (Articles 28 and 82) establishes joint liability of the controller and processor towards data subjects. The processor is directly liable if it acted outside the controller's instructions or failed to meet its own GDPR obligations. It is therefore essential to formalise a precise processor contract and ensure the hosting provider is HDS-certified for healthcare data.

Is HDS certification mandatory for all digital health actors?

HDS certification is mandatory for any provider that hosts, administers or manages information systems containing personal healthcare data on behalf of a third party. It therefore applies to cloud providers, medical SaaS editors and telemedicine platforms. However, a healthcare professional hosting their own data (without entrusting it to a third party) is not directly subject to this obligation, but remains bound by Article 32 GDPR security measures.

Conclusion

Healthcare data protection constitutes, in 2026, one of the most complex and closely monitored regulatory challenges in the digital sector. Between the GDPR, the Data Protection Act, the HDS hosting requirement, the NIS 2 Directive and the emergence of the European Health Data Space, professionals must maintain continuous monitoring and structure their compliance around five pillars: processing record, DPIA, DPO, technical security and patient rights management.

Certyneo supports healthcare actors in the secure dematerialisation of their processes: collection of timestamped consents, qualified electronic signature of contracts with service providers, probative traceability of each act. Discover how our solution can strengthen your GDPR compliance by visiting our dedicated space for healthcare professionals or by starting free on Certyneo.

Try Certyneo for free

Send your first signature envelope in less than 5 minutes. 5 free envelopes per month, no credit card required.

Dive deeper

Our comprehensive guides to master electronic signatures.

Certyneo Community

A question about electronic signatures?

Join the Certyneo community: ask your questions, share your answers and connect with thousands of users and our team.