Go to main content
Certyneo
Security

Electronic Medical File: 2026 Security Standards

Certyneo Editorial Team7 min read

Updated on

Digitalisation des processus administratifs — équipe en réunion de travail

The electronic medical record combines two regimes that do not overlap: the protection of personal data, which treats health information as a special category subject to a default prohibition, and the French Public Health Code, which imposes its own retention periods and its own access rights. Compliance with the first does not amount to compliance with the second, and most of the breaches observed stem from this confusion.

Hosting: mandatory certification

Any person who hosts personal health data on behalf of third parties, in connection with prevention, diagnosis or care activities, must be certified for this purpose.

This obligation is structural and is often discovered too late. It does not depend on the volume of data or the size of the organization: a practice that entrusts its practice-management software to an online provider must ensure that the data hosting is provided by a certified operator. Responsibility for this verification lies with the data controller, i.e. the professional or the institution, not the provider.

Two practical points follow from this: the subcontracting agreement must explicitly mention this certification and its scope, and a change of provider or infrastructure requires re-verifying this coverage.

The regime governing health data

Data concerning health fall within a special category whose processing is prohibited in principle. Processing is lawful only if it falls under one of the exhaustively listed exceptions — notably healthcare provision, preventive medicine, or the explicit consent of the individual.

This inverted architecture has a direct consequence: for each processing activity, it must be possible to identify the exception on which it is based. A secondary use of the data — internal statistics, improving a tool, research — cannot be inferred from the lawfulness of the care-related processing; it requires its own legal basis.

General obligations also apply: a record of processing activities, informing individuals, defined retention periods, and an impact assessment where the processing poses a high risk — which is frequently the case for a computerized patient record.

Retention periods

These fall under the French Public Health Code and not solely under the data-minimization principle.

A medical record created within a healthcare institution must be kept for twenty years from the last stay or the last outpatient consultation. Two specific rules overlay this:

  • For a patient who was a minor at the time of care, retention is extended until their twenty-eighth birthday where that date is later.
  • In the event of the patient's death less than ten years after the last visit, the record must be kept for at least ten years from the date of death.

These periods are suspended by any administrative or legal claim seeking to establish the liability of the institution or of the professionals.

The link with time limits for liability claims is direct: the claim is time-barred after ten years from the stabilization of the harm, and a record destroyed prematurely deprives the professional of their main means of defense — an issue examined in detail in our article on professional civil liability.

Traceability of access

This is the most operational requirement, and the one whose absence is hardest to remedy afterward.

Every access to the record must be logged: who consulted it, which item, on what date. This logging serves two distinct and complementary purposes.

It prevents and detects improper access, which is one of the most frequent breaches within institutions — viewing the record of a colleague, a relative, or an acquaintance.

It protects the professional, by making it possible to demonstrate that an alleged access did not take place, or that a disputed access was indeed part of the patient's care. Without a log, a suspicion can neither be established nor dismissed.

Access rights must also be differentiated according to role: belonging to the care team does not grant access to the entire record, but only to the information necessary, as explained in our article on medical confidentiality.

The patient's right of access

The patient has direct access to all information concerning their health, without having to justify the request.

Disclosure occurs no earlier than after a reflection period and no later than within a period that is extended when the information is more than five years old. Any fees are limited to the cost of copying and postage.

Two limits apply to this right: information collected from third parties not involved in the care is excluded, as is information concerning such third parties. After death, access by heirs is governed by a separate regime, limited to the information necessary for the stated purpose.

Usage scenarios

Changing practice-management software. Verify the hosting certification of the new provider, data reversibility, and the export format. A migration without a recovery plan risks the loss of records whose retention periods are still running.

Group practice. Differentiate access rights by practitioner and by patient rather than opening the entire record to everyone. This is the most frequently checked point, and it is a matter of organization as much as of technology — a topic covered in our article on administrative compliance for a medical practice.

Patient access request. Verify identity, exclude excluded information, and comply with the applicable time limit depending on the age of the data. Log the request and the response: compliance with the time limit must be provable.

Frequently asked questions

Is a certified host required? Yes, as soon as health data is hosted on behalf of a third party in a context of prevention, diagnosis or care. Verification is the responsibility of the data controller, not the provider.

How long must a medical record be kept? Twenty years from the last visit to the institution, extended until the patient turns twenty-eight if they were a minor, and at least ten years from death occurring within ten years.

Can a patient view their record? Yes, directly and without giving a reason, within the applicable time limits, which are extended for information older than five years. Only copying and postage costs may be charged.

Is logging of access mandatory? Yes, and it protects the professional as much as the patient: without a log, a disputed access can neither be established nor dismissed.

Can a professional view any record within the organization? No. Access is limited to the information necessary for their role in the care of the patient concerned. Access rights must be differentiated accordingly.

Can the data be used for statistical purposes? Not under the care-related processing basis. Any secondary use requires its own lawful basis, and where applicable, specific information provided to the individuals concerned.

Key takeaways

Two regimes overlap and must be handled separately. Data protection requires identifying, for each processing activity, the exception that makes it lawful — the care purpose does not cover secondary uses. The French Public Health Code imposes its own retention periods, which are measured in decades and are suspended in the event of a claim.

Between the two, one mechanism serves both regimes at once: logging of access, combined with differentiated access rights. This is what makes it possible to demonstrate that the limit of what is "necessary for the role" has been respected, and it is also what protects the professional when an access is challenged. The reasoning mirrors that applicable to obtaining consent: what is not logged can neither be proven nor disproven.

Try Certyneo for free

Send your first signature envelope in under 5 minutes. 5 envelopes/mo for 14 days, then 2/mo, no credit card required.

Go deeper on the topic

Our comprehensive guides to master electronic signatures.

Certyneo Community

A question about electronic signatures?

Join the Certyneo community: ask your questions, share your answers and connect with thousands of users and our team.