Skip to main content
Certyneo

Healthcare Data Protection and GDPR Compliance for Professionals

Healthcare data is the most sensitive personal data under GDPR. Discover all the obligations that apply to healthcare sector professionals in 2026.

Certyneo Editorial Team14 min read
Doctor shows patient medical scan on tablet

Healthcare data occupies a special place in the European regulatory landscape. Qualified as special category sensitive data by the GDPR (Article 9), it is subject to enhanced protection that applies to all professionals who process it: healthcare facilities, health insurance funds, health software editors, laboratories, home care services, digital health and telemedicine providers. In 2026, the regulatory landscape has become even more complex — between the progressive entry into force of the European Health Data Space (EHDS), updated CNIL recommendations, and record penalties imposed across the EU, compliance is no longer optional. This article describes, point by point, the applicable obligations and best practices to adopt to secure your processing activities.

What is healthcare data under GDPR?

The GDPR (Regulation No. 2016/679, Article 4 §15) defines healthcare data as "personal data relating to the physical or mental health of a natural person, including the provision of healthcare services, which reveal information concerning the health status of that person".

A scope broader than it initially appears

This definition encompasses far more than traditional medical files. It includes:

  • Medical history, diagnoses, prescriptions, and laboratory results;
  • Data collected by connected devices (smartwatches, glucose monitors, period-tracking applications);
  • Administrative data that can be used to infer a person's health status (reimbursement rates, consultation frequency);
  • Social Security identification numbers (NIR) when combined with medical information.

In France, the CNIL has clarified, particularly in its reference decision on health data repositories (EDS), that this concept should be interpreted broadly. Thus, a simple photo revealing a visible disability or biometric data (retinal fingerprint) falls within the scope.

Why enhanced protection?

The particular sensitivity of healthcare data stems from its potential for discrimination. Disclosing a person's health status can affect their access to employment, insurance, credit, or expose their private life. The CNIL estimated that violations involving healthcare data represented more than 36% of notifications it received in 2024 — the leading category of breached data.

Article 9 §1 of GDPR establishes a prohibition on processing sensitive data, with limited enumerated exceptions. For healthcare professionals, the usable legal bases are primarily:

Consent must be free, specific, informed, and unambiguous, expressed through a clear affirmative act. In the healthcare sector, this basis is often inadequate for routine care (power imbalance between doctor and patient), but remains essential for processing for research purposes, marketing, or use of consumer health applications.

Best practice for 2026: use electronic signatures in healthcare to collect patient consent in a traceable and time-stamped manner, which facilitates proof in case of regulatory inspection.

Care and preventive medicine (Art. 9 §2 h)

This is the main legal basis for healthcare professionals processing data as part of the care relationship. It applies provided that the processing is carried out by — or under the responsibility of — a professional bound by medical confidentiality.

Public interest and research (Art. 9 §2 i and j)

Processing for public health purposes (epidemiological monitoring, pharmacovigilance) or scientific research can rely on these exceptions. In France, the Data Protection Act (Articles 65 to 68) and the decree governing the National Health Data System (SNDS) define the conditions of access.

Concrete obligations for data controllers

Whether a medical practice or a digital health solution editor, obligations are structured around five pillars.

1. Processing activity register (Art. 30)

Every data controller or processor must maintain a register documenting each processing activity: purpose, legal basis, data categories, retention periods, recipients, security measures. The CNIL requires this register to be current and presentable without delay during an inspection.

2. Data Protection Impact Assessment (DPIA / Art. 35)

Healthcare data processing at large scale or for profiling purposes requires a mandatory DPIA. The CNIL has published a list of processing activities subject to mandatory DPIA, including health data repositories, mobile health tracking applications, and connected medical devices.

Regarding the legal value of electronic documents in this context, service providers must ensure that their collection mechanisms meet evidentiary requirements.

3. Appointment of a Data Protection Officer (DPO)

Appointment of a DPO is mandatory for:

  • Healthcare professionals organized as groups (hospitals, nursing homes, care facilities with more than 50 people);
  • Health insurance funds and insurers;
  • Health software editors processing data at large scale.

Since 2024, the CNIL has intensified its controls over the effectiveness of the DPO's role, verifying in particular their actual independence and resources.

4. Security of information systems (Art. 32)

Technical and organizational measures must be proportionate to the risk. The CNIL notably recommends:

  • End-to-end encryption of stored and transmitted data;
  • Pseudonymization whenever the purpose allows;
  • Implementation of strict access controls (multi-factor authentication);
  • Regular backups tested and disconnected from the main network;
  • A business continuity plan (BCP) specific to healthcare data.

Since the entry into force of NIS 2 Directive (transposed into French law by the law of March 26, 2025), essential entities in the healthcare sector — including hospitals, medical device manufacturers, and certain laboratories — are subject to even stricter cybersecurity requirements, with mandatory notification of major incidents to ANSSI within 24 hours.

5. Data breach notification (Art. 33 and 34)

Any healthcare data breach must be notified to the CNIL within 72 hours of discovery. If the breach is likely to result in a high risk to individuals' rights and freedoms, the affected patients must also be informed without undue delay.

In 2024, the CNIL imposed penalties for late notification, emphasizing that responsiveness is itself a compliance obligation.

Healthcare data hosting: a requirement specific to France

In France, the law of January 26, 2016 (Article L. 1111-8 of the Public Health Code) requires that personal healthcare data be hosted with a certified HDS provider (Healthcare Data Hosting Provider). This certification, issued by COFRAC-accredited organizations based on ISO 27001 standard and the ANS HDS repository, covers six distinct activities.

Who is subject to HDS certification?

All entities hosting, administering, or operating information systems containing healthcare data on behalf of third parties are covered: cloud providers, DMP (shared medical record) editors, telemedicine platforms, and — since 2023 — consumer health application editors insofar as they retain identifying data.

Using a certified HDS provider does not exempt the data controller from their own obligations: they must imperatively formalize a processor contract compliant with Article 28 of GDPR, detailing the instructions given to the provider, security guarantees, and audit procedures.

The European Health Data Space (EHDS): what impacts in 2026?

The EHDS regulation (adopted late 2025 with initial provisions entering into force progressively through 2027) establishes a framework for cross-border access to healthcare data for research, innovation, and public health. For French professionals, two immediate impacts:

  1. The obligation to respect enhanced portability rights (structured, machine-readable format) for patient records;
  2. The prohibition on processing primary healthcare data for advertising targeting purposes, even with consent — a stricter restriction than GDPR alone.

These developments make it essential to update privacy policies and processor contracts before the end of 2026. For professionals using eIDAS-compliant electronic signature tools, traceability of consents and authorizations constitutes a significant advantage for demonstrating compliance during an audit.

Patient rights and exercise of GDPR rights

Patients have all GDPR rights (access, rectification, erasure, restriction, portability, objection), with some sectoral adjustments.

The right of access to healthcare data

A patient may request access to their entire medical file (Article L. 1111-7 CSP). The professional has 8 days (48 hours for recent data, recent hospitalizations) and 2 months for older data. Both the CNIL and the Ombudsman have sanctioned facilities that refused or delayed such requests.

The right to erasure and its limitations

The "right to be forgotten" is governed by statutory retention periods: 20 years for adult medical files, 28 years if the procedure was performed before majority. These statutory periods take priority over any request for early erasure — the data controller must clearly explain this to the patient.

Managing requests through electronic channels

For facilities that have digitized their processes, requests to exercise rights may be transmitted and processed via secure forms. The qualified electronic time-stamping of requests and responses constitutes a best practice allowing proof of compliance with regulatory timelines during a CNIL inspection.

The compliance of healthcare professionals and their technology partners depends on understanding how European and national texts interact.

GDPR — Regulation (EU) No. 2016/679 of April 27, 2016: cornerstone of the framework, it qualifies healthcare data as sensitive data (Art. 4 §15), prohibits its processing except in limited, enumerated exceptions (Art. 9 §2), requires DPIA (Art. 35), DPO appointment (Art. 37), breach notification (Art. 33-34), and proportionate security measures (Art. 32). Penalties reach 20 million euros or 4% of annual global turnover — whichever is higher.

Data Protection Act (Act No. 78-17 of January 6, 1978 as amended): transposing GDPR into French law, it empowers the CNIL to adopt sectoral references specific to healthcare and defines the terms of access to SNDS.

Public Health Code — Articles L. 1111-7 and L. 1111-8: enshrine the patient's right of access to their medical file and the obligation to host data with a certified HDS provider.

HDS Repository (Healthcare Data Hosting Provider): published by the Digital Health Agency (ANS), it defines six certification activities covering physical infrastructure, platform, and application software.

NIS 2 Directive — Directive (EU) 2022/2555, transposed into France by the law of March 26, 2025: subjects essential healthcare entities (hospitals with more than 30,000 patients/year, Class IIb and III medical device manufacturers, reference laboratories) to enhanced cybersecurity obligations, notably notification to ANSSI within 24 hours in case of significant incident, and implementation of incident response plans tested annually.

eIDAS Regulation No. 910/2014 and eIDAS 2.0 (Regulation (EU) 2024/1183): govern the legal value of electronic signatures used for consents, digitized medical acts, and contracts with service providers. Advanced or qualified electronic signatures are recommended for any act whose evidentiary value might be challenged.

EHDS Regulation (European Regulation on the European Health Data Space, 2025): strengthens patients' rights over their primary data and governs the use of secondary data for research, with the creation of health data access bodies in each Member State.

Concrete legal risks: beyond CNIL administrative penalties, data controllers face civil liability actions (Art. 82 GDPR), criminal prosecution (Article 226-17 of the Penal Code, maximum penalty of 5 years imprisonment and €300,000 fine for legal entities), and reputational damage whose economic impact often exceeds the penalty amount itself.

Use case scenarios: GDPR compliance and healthcare data in practice

Scenario 1 — A group of private clinics managing approximately 1,200 beds

A group of intermediate-sized private clinics (approximately 1,200 beds across three sites) was handling patient consents on paper forms, stored in poorly secured filing cabinets. During an internal audit preparing for CNIL inspection, several gaps were identified: inability to quickly locate a consent dated more than two years prior, lack of traceability for consents concerning medical video surveillance and transmissions to third parties (insurers, referring physicians).

Management deployed a qualified electronic signature solution integrated into the hospital information system. Results measured at six months: the time to process file access requests fell from 14 to 4 business days (a 71% reduction), the average time to search for a consent dropped to under 2 minutes from 45 minutes previously, and the group obtained HDS certification for the application layer.

Scenario 2 — A telemedicine solution editor for independent specialists

A company editing a remote consultation platform for independent specialists (approximately 4,000 active physician users) faced major risk: its servers were hosted by an American cloud provider without a processor contract compliant with Article 28 of GDPR, and without HDS certification. The platform nevertheless collected consultation reports, prescriptions, and clinical photographs.

Following an impact assessment (DPIA) conducted with an external DPO, the company migrated to a France-based HDS-certified provider, reviewed all processor contracts, and integrated a time-stamped informed consent mechanism before each consultation. It also implemented an internal incident notification procedure within 12 hours, enabling compliance with the 72-hour regulatory timeline to CNIL. The cost of achieving compliance was estimated at €180,000 — compared to the €400,000 penalty imposed by CNIL against a comparable sector actor the same year.

Scenario 3 — A network of independent pharmacies

A group of approximately forty independent pharmacies used centralized management software processing prescription histories and loyalty data (linked to implicit health profiles). With no DPO appointed and no current processing register, the group could not respond to a data subject rights request within 30 days.

An eight-month compliance project enabled designation of a shared DPO (a common and lawful solution for SME groups), documentation of 23 distinct processing activities in the register, review of retention period policies (loyalty data had been retained for 10 years without justification), and training of all pharmacy staff on best practices when handling patient requests or inspections. The estimated ex-ante penalty risk exceeded €150,000.

Frequently asked questions

Is healthcare data collected by a mobile application subject to GDPR?

Yes, as soon as the application collects data allowing inference of a person's health status (heart rate, period tracking, glucose levels, nutrition), such data constitutes healthcare data under Article 4 §15 of GDPR. The editor is the data controller and must obtain explicit consent, host data with a certified HDS provider, and conduct a DPIA if processing occurs at large scale.

Must a solo practicing physician appoint a DPO?

No, DPO appointment is not mandatory for a solo practicing physician or small practice, unless processing concerns healthcare data at large scale. However, this physician remains responsible as a data controller and must maintain a processing register, apply the principle of data minimization, and be able to respond to patients' rights requests within regulatory timelines.

What penalties can the CNIL impose for healthcare data breach?

The CNIL has administrative penalty authority reaching 20 million euros or 4% of annual global turnover, whichever is higher. Beyond the fine, it may issue a compliance enforcement order with periodic penalties, or make the decision public. On the criminal side, Article 226-17 of the Penal Code provides up to 5 years imprisonment and €300,000 fine for legal entities.

Is a processor (software, cloud) liable in case of healthcare data leak?

Yes. The GDPR (Art. 28 and 82) establishes joint liability of the data controller and processor toward data subjects. The processor is directly liable if it acted outside the controller's instructions or failed to meet its own GDPR obligations. It is therefore essential to formalize a precise processor contract and ensure the hosting provider is HDS-certified for healthcare data.

Is HDS certification mandatory for all digital healthcare actors?

HDS certification is mandatory for any provider hosting, administering, or operating information systems containing personal healthcare data on behalf of a third party. It thus applies to cloud providers, medical SaaS editors, and telemedicine platforms. Conversely, a healthcare professional hosting their own data (without entrusting it to a third party) is not directly subject to this requirement, but remains bound by the security measures of Article 32 of GDPR.

Conclusion

Healthcare data protection constitutes, in 2026, one of the most complex and closely monitored regulatory challenges in the digital sector. Between GDPR, the Data Protection Act, the HDS hosting obligation, NIS 2 Directive, and the emergence of the European Health Data Space, professionals must maintain continuous monitoring and structure their compliance around five pillars: processing register, DPIA, DPO, technical security, and management of patient rights.

Certyneo assists healthcare stakeholders in the secure digitization of their processes: collection of time-stamped consents, qualified electronic signature of provider contracts, evidentiary traceability of every act. Discover how our solution can strengthen your GDPR compliance by visiting our dedicated space for healthcare professionals or by starting free on Certyneo.

Try Certyneo for Free

Send your first signature envelope in less than 5 minutes. 5 free envelopes per month, no credit card required.

Dive Deeper

Our comprehensive guides to master electronic signatures.

Certyneo Community

A question about electronic signatures?

Join the Certyneo community: ask your questions, share your answers and connect with thousands of users and our team.