Skip to main content
Certyneo
Security

Electronic Medical Record: Security Standards 2026

Electronic medical record security: HDS requirements, certified hosting, strong authentication and electronic signature of practitioners.

Certyneo Team7 min read

Updated on

Certyneo Team

Writer — Certyneo · About Certyneo

a row of metal lockers with numbers on them

The electronic medical record combines two regimes that do not overlap: that of personal data protection, which treats health information as a special category subject to a default prohibition, and that of the French Public Health Code, which imposes its own retention periods and its own access rights. Compliance with the first does not equate to compliance with the second, and most of the violations observed stem from this confusion.

Hosting: mandatory certification

Any person who hosts personal health data on behalf of third parties, in connection with prevention, diagnosis, or care activities, must be certified for this purpose.

This obligation is fundamental and is often discovered too late. It does not depend on the volume of data or the size of the organization: a practice that entrusts its business software to an online provider must ensure that the data hosting is provided by a certified operator. Responsibility for this verification lies with the data controller, meaning the professional or the institution, not the provider.

Two practical points follow from this: the subcontracting agreement must explicitly mention this certification and its scope, and a change of provider or infrastructure requires re-verifying this coverage.

The regime for health data

Data concerning health falls under a special category whose processing is prohibited in principle. Processing is only lawful if it falls under one of the exhaustively listed exceptions — notably healthcare provision, preventive medicine, or the explicit consent of the individual.

This inverted structure has a direct consequence: for each processing activity, one must be able to identify the exception on which it is based. A secondary use of the data — internal statistics, tool improvement, research — cannot be inferred from the lawfulness of care-related processing; it requires its own legal basis.

In addition, general obligations apply: a record of processing activities, information provided to individuals, defined retention periods, and an impact assessment when the processing presents a high risk — which is frequently the case for a computerized patient record.

Retention periods

These fall under the French Public Health Code and not merely the data minimization principle.

The medical record created within a healthcare institution must be retained for twenty years from the last stay or the last outpatient consultation. Two special rules overlap with this:

  • For a patient who was a minor at the time of care, retention extends until their twenty-eighth birthday when this date is later.
  • In the event of the patient's death less than ten years after the last visit, the record must be retained for at least ten years from the date of death.

These periods are suspended by any administrative appeal or legal proceeding seeking to establish the liability of the institution or its healthcare professionals.

The connection with liability action time limits is direct: the action is time-barred after ten years from the date the harm is consolidated, and a record destroyed prematurely deprives the professional of their main line of defense — an issue detailed in our article on professional civil liability.

Access traceability

This is the most operational requirement, and the one whose absence is hardest to remedy.

Every access to the record must be logged: who consulted it, which element, on what date. This logging serves two distinct and complementary purposes.

It prevents and detects unauthorized access, which is one of the most frequent violations within institutions — viewing the record of a colleague, a relative, or an acquaintance.

It protects the professional, by making it possible to demonstrate that an alleged access did not occur, or that a disputed access was indeed part of the patient's care. Without a log, a suspicion can be neither established nor dismissed.

Access permissions must also be differentiated according to roles: being part of the care team does not grant access to the entire record, but only to the information necessary, as explained in our article on medical confidentiality.

The patient's right of access

The patient has direct access to all information concerning their health, without having to justify the request.

The information is provided no earlier than after a reflection period, and no later than within a period that is extended when the information is more than five years old. Any applicable fees are limited to the cost of reproduction and mailing.

Two limits apply to this right: information collected from third parties not involved in the patient's care is excluded, as is information concerning such third parties. After death, access by the patient's heirs is governed by a separate regime, limited to the information necessary for the stated purpose.

Use case scenarios

Changing business software. Verify the new provider's hosting certification, data portability, and export format. A migration without a recovery plan risks the loss of records whose retention periods are still running.

Group practice. Differentiate access permissions by practitioner and by patient rather than granting access to the entire record to everyone. This is the most frequent control point, and it depends on organization as much as on technology — a topic covered in our article on administrative compliance for a medical practice.

Patient access request. Verify identity, isolate excluded information, and comply with the applicable time limit based on the age of the records. Log the request and the response: compliance with the time limit must be provable.

Frequently asked questions

Is a certified hosting provider required? Yes, as soon as health data is hosted on behalf of a third party in a context of prevention, diagnosis, or care. Verification is the responsibility of the data controller, not the provider.

How long must a medical record be retained? Twenty years from the last visit to the institution, extended until the patient's twenty-eighth birthday if they were a minor, and at least ten years from death if it occurred within ten years.

Can a patient consult their record? Yes, directly and without justification, within the applicable time limits, which are extended for information more than five years old. Only reproduction and mailing costs may be charged.

Is access logging mandatory? Yes, and it protects both the professional and the patient: without a log, a disputed access can be neither established nor dismissed.

Can a professional consult any record within the organization? No. Access is limited to the information necessary for their role in the care of the patient concerned. Access permissions must be differentiated accordingly.

Can the data be used for statistical purposes? Not under the care-related processing basis. Any secondary use requires its own lawful basis, and where applicable, specific information provided to the individuals concerned.

Key takeaways

Two regimes overlap and must be handled separately. Data protection requires identifying, for each processing activity, the exception that makes it lawful — the care purpose does not cover secondary uses. The French Public Health Code imposes its own retention periods, which are measured in decades and are suspended in the event of legal proceedings.

Between the two, one mechanism serves both regimes at once: access logging, combined with differentiated access permissions. This is what makes it possible to demonstrate that the limit of "necessary for the role" has been respected, and it is also what protects the professional when an access is disputed. The reasoning mirrors that applicable to obtaining consent: what is not logged can be neither proven nor disproven.

Try Certyneo for Free

Send your first signature envelope in less than 5 minutes. 5 free envelopes per month, no credit card required.

Dive Deeper

Our comprehensive guides to master electronic signatures.

Certyneo Community

A question about electronic signatures?

Join the Certyneo community: ask your questions, share your answers and connect with thousands of users and our team.