Electronic Medical Record: Security Standards 2026
Electronic medical record security: HDS requirements, certified hosting, strong authentication and electronic signature of practitioners.
Updated on
Certyneo Team
Writer — Certyneo · About Certyneo

The electronic medical record combines two regimes that do not overlap: that of personal data protection, which treats health information as a special category subject to a default prohibition, and that of the French Public Health Code, which imposes its own retention periods and its own access rights. Compliance with the first does not equate to compliance with the second, and most of the violations observed stem from this confusion.
Hosting: mandatory certification
Any person who hosts personal health data on behalf of third parties, in connection with prevention, diagnosis, or care activities, must be certified for this purpose.
This obligation is fundamental and is often discovered too late. It does not depend on the volume of data or the size of the organization: a practice that entrusts its business software to an online provider must ensure that the data hosting is provided by a certified operator. Responsibility for this verification lies with the data controller, meaning the professional or the institution, not the provider.
Two practical points follow from this: the subcontracting agreement must explicitly mention this certification and its scope, and a change of provider or infrastructure requires re-verifying this coverage.
The regime for health data
Data concerning health falls under a special category whose processing is prohibited in principle. Processing is only lawful if it falls under one of the exhaustively listed exceptions — notably healthcare provision, preventive medicine, or the explicit consent of the individual.
This inverted structure has a direct consequence: for each processing activity, one must be able to identify the exception on which it is based. A secondary use of the data — internal statistics, tool improvement, research — cannot be inferred from the lawfulness of care-related processing; it requires its own legal basis.
In addition, general obligations apply: a record of processing activities, information provided to individuals, defined retention periods, and an impact assessment when the processing presents a high risk — which is frequently the case for a computerized patient record.
Retention periods
These fall under the French Public Health Code and not merely the data minimization principle.
The medical record created within a healthcare institution must be retained for twenty years from the last stay or the last outpatient consultation. Two special rules overlap with this:
- For a patient who was a minor at the time of care, retention extends until their twenty-eighth birthday when this date is later.
- In the event of the patient's death less than ten years after the last visit, the record must be retained for at least ten years from the date of death.
These periods are suspended by any administrative appeal or legal proceeding seeking to establish the liability of the institution or its healthcare professionals.
The connection with liability action time limits is direct: the action is time-barred after ten years from the date the harm is consolidated, and a record destroyed prematurely deprives the professional of their main line of defense — an issue detailed in our article on professional civil liability.
Access traceability
This is the most operational requirement, and the one whose absence is hardest to remedy.
Every access to the record must be logged: who consulted it, which element, on what date. This logging serves two distinct and complementary purposes.
It prevents and detects unauthorized access, which is one of the most frequent violations within institutions — viewing the record of a colleague, a relative, or an acquaintance.
It protects the professional, by making it possible to demonstrate that an alleged access did not occur, or that a disputed access was indeed part of the patient's care. Without a log, a suspicion can be neither established nor dismissed.
Access permissions must also be differentiated according to roles: being part of the care team does not grant access to the entire record, but only to the information necessary, as explained in our article on medical confidentiality.
The patient's right of access
The patient has direct access to all information concerning their health, without having to justify the request.
The information is provided no earlier than after a reflection period, and no later than within a period that is extended when the information is more than five years old. Any applicable fees are limited to the cost of reproduction and mailing.
Two limits apply to this right: information collected from third parties not involved in the patient's care is excluded, as is information concerning such third parties. After death, access by the patient's heirs is governed by a separate regime, limited to the information necessary for the stated purpose.
Use case scenarios
Changing business software. Verify the new provider's hosting certification, data portability, and export format. A migration without a recovery plan risks the loss of records whose retention periods are still running.
Group practice. Differentiate access permissions by practitioner and by patient rather than granting access to the entire record to everyone. This is the most frequent control point, and it depends on organization as much as on technology — a topic covered in our article on administrative compliance for a medical practice.
Patient access request. Verify identity, isolate excluded information, and comply with the applicable time limit based on the age of the records. Log the request and the response: compliance with the time limit must be provable.
Frequently asked questions
Is a certified hosting provider required? Yes, as soon as health data is hosted on behalf of a third party in a context of prevention, diagnosis, or care. Verification is the responsibility of the data controller, not the provider.
How long must a medical record be retained? Twenty years from the last visit to the institution, extended until the patient's twenty-eighth birthday if they were a minor, and at least ten years from death if it occurred within ten years.
Can a patient consult their record? Yes, directly and without justification, within the applicable time limits, which are extended for information more than five years old. Only reproduction and mailing costs may be charged.
Is access logging mandatory? Yes, and it protects both the professional and the patient: without a log, a disputed access can be neither established nor dismissed.
Can a professional consult any record within the organization? No. Access is limited to the information necessary for their role in the care of the patient concerned. Access permissions must be differentiated accordingly.
Can the data be used for statistical purposes? Not under the care-related processing basis. Any secondary use requires its own lawful basis, and where applicable, specific information provided to the individuals concerned.
Key takeaways
Two regimes overlap and must be handled separately. Data protection requires identifying, for each processing activity, the exception that makes it lawful — the care purpose does not cover secondary uses. The French Public Health Code imposes its own retention periods, which are measured in decades and are suspended in the event of legal proceedings.
Between the two, one mechanism serves both regimes at once: access logging, combined with differentiated access permissions. This is what makes it possible to demonstrate that the limit of "necessary for the role" has been respected, and it is also what protects the professional when an access is disputed. The reasoning mirrors that applicable to obtaining consent: what is not logged can be neither proven nor disproven.
Try Certyneo for Free
Send your first signature envelope in less than 5 minutes. 5 free envelopes per month, no credit card required.
Dive Deeper
Reference articles on this topic.
Dive Deeper
Our comprehensive guides to master electronic signatures.
Continue reading about Security
Deepen your knowledge with these related articles.

ISO Certification for Electronic Signature: 2026 Guide
ISO 27001, eIDAS, ETSI… certifications for electronic signature providers have become an essential selection criterion. Discover how to compare them effectively.

Electronic Signature: Traceability and Internal Audit in 2026
The traceability of an electronic signature has become a cornerstone of internal audit and legal compliance in business. Discover how to fully leverage it.

Electronic Signature and ISO 27001 Standard: 2026 Guide
The ISO 27001 standard has become an essential benchmark for securing electronic signature processes in business. Discover the key requirements, synergies with eIDAS, and best practices to adopt.