<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>health data - RiskInsight</title>
	<atom:link href="https://www.riskinsight-wavestone.com/en/tag/health-data/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.riskinsight-wavestone.com/en/tag/health-data/</link>
	<description>The cybersecurity &#38; digital trust blog by Wavestone&#039;s consultants</description>
	<lastBuildDate>Wed, 14 May 2025 12:19:43 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/Blogs-2024_RI-39x39.png</url>
	<title>health data - RiskInsight</title>
	<link>https://www.riskinsight-wavestone.com/en/tag/health-data/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Evolution of the HDS Framework &#8211; Towards Enhanced Security and Sovereignty </title>
		<link>https://www.riskinsight-wavestone.com/en/2025/05/evolution-of-the-hds-framework-towards-enhanced-security-and-sovereignty/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2025/05/evolution-of-the-hds-framework-towards-enhanced-security-and-sovereignty/#respond</comments>
		
		<dc:creator><![CDATA[Perrine Viard]]></dc:creator>
		<pubDate>Wed, 14 May 2025 12:19:40 +0000</pubDate>
				<category><![CDATA[Digital Compliance]]></category>
		<category><![CDATA[Focus]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[Digital compliance]]></category>
		<category><![CDATA[HDS]]></category>
		<category><![CDATA[health data]]></category>
		<category><![CDATA[règlementation]]></category>
		<category><![CDATA[regulation]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=25983</guid>

					<description><![CDATA[<p>The Health Data Host (HDS) certification is a French regulatory framework that governs the hosting of personal health data. Established by Decree No. 2018-137 of February 26, 2018, it is mandatory for any entity hosting health data to comply with...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2025/05/evolution-of-the-hds-framework-towards-enhanced-security-and-sovereignty/">Evolution of the HDS Framework &#8211; Towards Enhanced Security and Sovereignty </a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p style="text-align: justify;"><span data-contrast="auto">The Health Data Host (HDS) certification is a French regulatory framework that governs the hosting of personal health data. Established by Decree No. 2018-137 of February 26, 2018, it is mandatory for any entity hosting health data </span><span data-contrast="none">to comply with the certification</span><span data-contrast="auto">. It aims to ensure a high level of protection for this particularly sensitive data by imposing strict requirements regarding security, availability, and confidentiality.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559731&quot;:169}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">In the context where the digital transformation of the healthcare sector is accelerating, the protection of health data is an increasingly critical issue. In 2021, our article &#8220;Health Data Host Certification: Two Years Already!&#8221; by Laurent Guille and Alexandra Cuillerdier, provided a promising initial assessment of the HDS framework. Faced with growing concerns related to data sovereignty and cybersecurity, a redesign was necessary. This evolution towards HDS v2, which came into effect in 2024, marks a turning point in the approach to health data hosting in France, strengthening the protection and sovereignty of health data in an ever-evolving digital context.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559731&quot;:169}"> </span></p>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559731&quot;:169}"> </span></p>
<h2 style="text-align: justify;"><span data-contrast="none">HDS v1: a first structuring but perfectible framework</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></h2>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"><span data-contrast="auto">Since its introduction in 2018, the HDS framework has helped structure and professionalize the health data hosting sector. However, this first version of the framework had certain limitations. In particular, the initial framework presented gray areas regarding data sovereignty, especially concerning the location and control of health data. Additionally, the rapid evolution of cyber threats and technologies required a substantial update of security requirements to maintain a level of protection adapted to current risks.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559731&quot;:169}"> </span></p>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h2 style="text-align: justify;"><span data-contrast="none">Overhaul of the Technical and Security Framework</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></h2>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"><span data-contrast="auto">On the technical side, the new requirements of the ISO 27001:2023 standard are adopted within the new version of HDS. This update integrates security risk management adapted to new digital contexts, as well as new controls related to cybersecurity. The other normative references are rationalized. References to ISO 20000-1, ISO27017, and ISO27018 standards disappear in the HDS v2 framework, while 31 specific requirements are directly integrated into the framework, which also relies on the ISO/IEC-17021-1:2015 standard to govern conformity assessment. This new version also clarifies the articulation with the requirements of the SecNumCloud framework to facilitate obtaining HDS certification for hosts already qualified with SecNumCloud.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559731&quot;:169}"> </span></p>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559731&quot;:169}"> </span></p>
<h2 style="text-align: justify;"><span data-contrast="none">A Major Strengthening of Digital Sovereignty</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></h2>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"><span data-contrast="auto">One of the most significant developments in HDS v2 concerns the strengthening of digital sovereignty. The new framework now requires that the physical hosting of health data be carried out exclusively within the territory of the European Economic Area (EEA). This requirement reinforces guarantees in terms of data protection and contributes to the emergence of an ecosystem of European players in the field of digital health.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559731&quot;:169}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">This is complemented by enhanced transparency, which also becomes a central issue of the framework, with two major obligations:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<ul style="text-align: justify;">
<li data-leveltext="" data-font="Symbol" data-listid="6" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Hosts must now publish on their website a map of any data transfers to countries outside the EEA, thus allowing data subjects and healthcare actors to have clear visibility on the journey of their data;</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
</ul>
<ul style="text-align: justify;">
<li data-leveltext="" data-font="Symbol" data-listid="6" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" aria-setsize="-1" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">In the case of remote access to data from a third country or submission to non-European legislation that does not ensure an adequate level of protection within the meaning of Article 45 of the GDPR, the host must inform its clients in the contract. In particular, it must specify the associated risks and detail the technical and legal measures implemented to limit them.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
</ul>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h2 style="text-align: justify;"><span data-contrast="none">Strengthening of Contractual Requirements</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></h2>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"><span data-contrast="auto">Subcontracting supervision receives particular attention in HDS v2. The associated measures are reinforced, and hosts must now:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559731&quot;:169}"> </span></p>
<ul style="text-align: justify;">
<li data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Precisely detail the certified hosting activities in their contracts;</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
</ul>
<ul style="text-align: justify;">
<li data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" aria-setsize="-1" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">Maintain complete transparency regarding their subcontracting chain;</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
</ul>
<ul style="text-align: justify;">
<li data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" aria-setsize="-1" data-aria-posinset="3" data-aria-level="1"><span data-contrast="auto">Ensure that their subcontractors comply with the same requirements for data security and location;</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
</ul>
<ul style="text-align: justify;">
<li data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" aria-setsize="-1" data-aria-posinset="4" data-aria-level="1"><span data-contrast="auto">Implement mechanisms to control and audit their subcontractors.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
</ul>
<p style="text-align: justify;"><span data-contrast="auto">These new contractual obligations aim to ensure better control of the value chain and greater transparency for data controllers.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h2 style="text-align: justify;"><span data-contrast="none">Practical Consequences for the Ecosystem</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></h2>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"><span data-contrast="auto">For health data hosts, these evolutions of the framework imply an adaptation of their infrastructures to guarantee the location of data within the EEA. They also require an upgrade of their security measures to meet the requirements of the 2023 version of the ISO 27001 standard and the review of contracts, both with their clients and with their subcontractors.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559731&quot;:169}"> </span></p>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h2 style="text-align: justify;"><span data-contrast="none">Perspectives and Implementation</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></h2>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"><span data-contrast="auto">This new modernized version of the HDS framework addresses the growing challenges of security, sovereignty, and transparency. Its implementation is spread over approximately two years, with immediate application for new certifications from November 16, 2024, and a transition period until May 16, 2026, for hosts already certified under HDS v1.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559731&quot;:169}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">In the longer term, several questions arise regarding the evolution of the framework. At a time when the NIS 2 directive already includes healthcare providers and the pharmaceutical industry among its essential sectors of activity, while classifying the manufacturing of medical devices and in vitro diagnostics in its important sectors, the emergence of HDS 2 raises a question: could European cooperation lead to an even more integrated framework for health data protection and harmonize practices across the continent?</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559731&quot;:169}"> </span></p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2025/05/evolution-of-the-hds-framework-towards-enhanced-security-and-sovereignty/">Evolution of the HDS Framework &#8211; Towards Enhanced Security and Sovereignty </a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2025/05/evolution-of-the-hds-framework-towards-enhanced-security-and-sovereignty/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>“HEALTH DATA HOSTS&#8221;: HEALTH PROVIDES A SHOT IN THE ARM FOR THE FRENCH ISO 27001 CERTIFICATION MARKET</title>
		<link>https://www.riskinsight-wavestone.com/en/2018/08/health-data-hosts-iso-27001/</link>
		
		<dc:creator><![CDATA[Laurent GUILLE]]></dc:creator>
		<pubDate>Tue, 28 Aug 2018 15:24:57 +0000</pubDate>
				<category><![CDATA[Cyberrisk Management & Strategy]]></category>
		<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[data hosting]]></category>
		<category><![CDATA[données de santé]]></category>
		<category><![CDATA[Groupements Hospitaliers de Territoire]]></category>
		<category><![CDATA[health data]]></category>
		<category><![CDATA[hébergement des données]]></category>
		<category><![CDATA[ISO27001]]></category>
		<category><![CDATA[legal framework]]></category>
		<category><![CDATA[règlementation]]></category>
		<category><![CDATA[regulation]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/2018/04/hebergeur-donnees-sante-iso-27001/</guid>

					<description><![CDATA[<p>On April 1, 2018, the Health Data Host approval procedure, in force since January 2006, was replaced by a Health Data Host certification procedure . This new system includes ISO 27001 certification. While the number of ISO 27001 certifications seems...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2018/08/health-data-hosts-iso-27001/">“HEALTH DATA HOSTS&#8221;: HEALTH PROVIDES A SHOT IN THE ARM FOR THE FRENCH ISO 27001 CERTIFICATION MARKET</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><em>On April 1, 2018, the</em> <em><a href="https://www.riskinsight-wavestone.com/en/2016/07/nouvelle-loi-sante-trois-situations-hebergeurs-de-donnees-de-sante/">Health Data Host</a></em><em> approval procedure, in force</em> <em><a href="https://www.legifrance.gouv.fr/eli/decret/2006/1/4/SANX0500308D/jo/texte">since January 2006,</a></em> <em>was replaced by a Health Data Host certification procedure . This new system includes ISO 27001 certification. While the number of ISO 27001 certifications seems to be stagnating in France, this change makes it likely that there will be a shift to strong growth in the coming years.</em></p>
<h2>A NEW LEGAL FRAMEWORK IN 2018 FOR HEALTH DATA HOSTING</h2>
<p>The Health Data Hosting Decree was <a href="https://www.legifrance.gouv.fr/eli/decret/2018/2/26/SSAZ1733293D/jo/texte/fr">published in the French Official Journal on February 28, 2018</a>. This decree confirms the developments announced in <a href="https://www.legifrance.gouv.fr/eli/ordonnance/2017/1/12/AFSZ1626575R/jo">the Order of January 12, 2017, relating to the hosting of personal health data</a>, which is itself an instrument of <a href="https://www.legifrance.gouv.fr/eli/loi/2016/1/26/AFSX1418355L/jo">the act to modernize the health system of January 26, 2016</a>.</p>
<p>This new decree makes Health Data Host certification mandatory for any public or private organization that hosts &#8220;personal health data collected during prevention, diagnosis, care, and social or medical follow-up activities, on behalf of natural or legal persons who are the source of the production or collection of this data, or on behalf of patients themselves&#8221;.</p>
<p>Health Data Host certification must be overseen by an independent body, which has been accredited by the <a href="http://www.cofrac.fr/">French Accreditation Committee (COFRAC)</a> or one of its European equivalents. Achieving certification confirms the conformity of the service with all the relevant requirements. Health Data Host certification remains valid for three years but is subject to annual monitoring.</p>
<h2>APPROVAL OR CERTIFICATION: WHAT’S THE DIFFERENCE?</h2>
<p>As part of the approval process, the candidate organization had to compile a (large!) application file which included a set of completed forms and supporting documents, as well as a compliance audit report prepared by a company of its choosing.</p>
<p>Rather than starting from scratch every time, Health Data Hosting certification now relies almost exclusively on recognized international standards: ISO 27001 in its entirety—and parts of ISO 27017, ISO 27018, and ISO 20000-1. Some specific requirements are added too; these mainly focus on two aspects:</p>
<ul>
<li>The protection of health data: protection of outsourced backups, prohibition of the use of health data for purposes other than the provision of hosting services, the traceability (including names) of the use of generic accounts, and other provisions;</li>
<li>The transparency of the service: the option for the customer to carry out audits, a mandatory revocation policy, including the methods that will be used to return data, provision of the certification audit report at the client’s request, etc.</li>
</ul>
<p>Beyond the &#8220;usual&#8221; gains provided by ISO 27001 certification, which are discussed at length <a href="https://www.riskinsight-wavestone.com/en/tag/iso-27001-en/">in some of our previous articles</a>, these additional requirements aim to professionalize the hosting of services, improve transparency between the hosting provider and its customers, strengthen health-data security, and reaffirm the rights of those whose personal data is being processed in accordance with the General Data Protection Regulation (GDPR).</p>
<h2>HEALTH DATA CERTIFICATION REALLY MEANS TWO CERTIFICATES</h2>
<p>Health Data Host certification now includes two separate certificates, each tailored to a specific type of activity that the host may choose to carry out:</p>
<ul>
<li>A “Data Management Host&#8221; certificate;</li>
<li>A &#8220;Physical Infrastructure Host&#8221; certificate</li>
</ul>
<p>The diagram below, taken from <a href="http://esante.gouv.fr/sites/default/files/asset/document/hds_referentiel_daccreditation_asip_v1.0.0.pdf">requirements for Health Data Hosting</a>, provides the relevant detail on the certificate required for the type of health data hosting activity to be carried out.</p>
<figure id="post-11218 media-11218" class="align-none">
<figure id="post-11220 media-11220" class="align-none"><img fetchpriority="high" decoding="async" class="wp-image-11220 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2018/04/health-data.png" alt="" width="473" height="482" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2018/04/health-data.png 975w, https://www.riskinsight-wavestone.com/wp-content/uploads/2018/04/health-data-188x191.png 188w, https://www.riskinsight-wavestone.com/wp-content/uploads/2018/04/health-data-768x782.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2018/04/health-data-38x39.png 38w, https://www.riskinsight-wavestone.com/wp-content/uploads/2018/04/health-data-32x32.png 32w, https://www.riskinsight-wavestone.com/wp-content/uploads/2018/04/health-data-64x64.png 64w, https://www.riskinsight-wavestone.com/wp-content/uploads/2018/04/health-data-70x70.png 70w, https://www.riskinsight-wavestone.com/wp-content/uploads/2018/04/health-data-30x30.png 30w" sizes="(max-width: 473px) 100vw, 473px" /></figure>
</figure>
<figure id="post-10644 media-10644" class="align-none"></figure>
<p><em>Activities requiring Health Data Host certification (diagram from accreditation requirements reference material v1.0, accessed on 04/04/2018)</em></p>
<p>A certificate is required if at least one activity within the scope of the certification type is to be carried out. For example, a hosting provider offering the outsourced backup of health data (Activity 6) will need to have a &#8220;Data Management Host&#8221; certificate; it will therefore have to comply with for requirements of the Health Data Host certification for this form of certification. Similarly, a p  rovider supplying premises (Activity 1) must have a &#8220;Physical Infrastructure Host&#8221; certificate and comply with the requirements applying to that type of certification.</p>
<p>Every hosting provider will have to acquire one or both certificates, depending on the health data hosting services it plans to offer to its clients.</p>
<h2>FUTURE CERTIFICATION FOR APPROVED HEALTH DATA HOSTS&#8230;</h2>
<p>Health Data Hosting approvals remain valid until they expire (withdrawal or suspension notwithstanding, as was the case when this was the regime in force). The period of validity will be extended by six months for approvals due to expire before March 31, 2019. After this date, all Health Data Hosts will have to obtain Health Data Host certification.</p>
<p>The mandatory nature of certification will boost the French market for ISO 27001 certifications, which is currently sluggish, according to <a href="https://www.iso.org/fr/the-iso-survey.html?certificate=ISO%209001&amp;countrycode=FR#countrypick">ISO’s most recent study</a>: in 2016, only 209 valid ISO 27001 certificates were awarded, compared with 227 in 2015.</p>
<p>120 Health Data Hosts have already been approved and <a href="http://esante.gouv.fr/services/referentiels/securite/hebergeurs-agrees">logged on ASIP Santé’s (the French government’s digital health agency) website</a> . Although some are already ISO 27001 certified (and assuming that the scope of the Information Security Management System includes the hosting of health data), additional certification will be required to become a certified Health Data Host. For the rest, certification covering all requirements will be needed, and this development should, in itself, lead to growth in the market for ISO 27001 certifications in future years.</p>
<p>&nbsp;</p>
<h2>&#8230; AND SOME FACILITIES THAT ARE PART OF AREA HOSPITAL GROUPS (GHTs)</h2>
<p>Another consequence of the act to modernize the French health system is that public health facilities are currently coming together as Area Hospital Groups (GHTs) to share aspects of their work. Each of the <a href="http://solidarites-sante.gouv.fr/professionnels/gerer-un-etablissement-de-sante-medico-social/groupements-hospitaliers-de-territoire/article/les-ght-par-region">135 GHTs</a> is organized around a support facility, which provides a range of services to the GHT, including &#8220;Strategy, optimization, and joint management of a combined hospital information system&#8221; (<a href="https://www.legifrance.gouv.fr/affichTexteArticle.do;jsessionid=81E2ECCAB9BD22DD0E7856EF59FD159C.tplgfr31s_1?idArticle=JORFARTI000031913559&amp;cidTexte=JORFTEXT000031912641&amp;dateTexte=29990101&amp;categorieLien=id">Article 107 of the act</a>). This provision requires the implementation of unique applications for all GHT facilities and each functional area (computerized patient files, medication circuits, biology, imaging, etc.).</p>
<p>GHTs have two main (though not exclusive) options:</p>
<ul>
<li>Contract a certified third-party Health Data Host to host their data; or</li>
<li>Host their data within one of the GHT’s facilities (for example, the support facility).</li>
</ul>
<p>In the latter case, the host establishment will need to be a certified Health Data Host. While the majority of GHTs are still considering whether to outsource all, or part, of their combined information system, <a href="http://www.ticsante.com/story.php?story=3846">in late 2017, 57% of them were still planning to outsource hosting</a>. Nevertheless, large numbers of GHTs may well, in the end, choose to maintain their health information system within the GHT and certify the host facility, in order to maintain full control of the information system and health data. This choice is likely to be seen mainly among GHTs that have large support facilities (a large central hospital, for example). This, then, will also drive strong growth in the number of ISO 27001 certificates issued in France.</p>
<h2>FINANCIAL HELP TO SUPPORT THE TRANSFORMATION OF GHTs</h2>
<p>To support the creation of their combined ISs, <a href="http://www.ticsante.com/story.php?story=3747">GHTs can draw on various forms of financial support</a>. €20m has already been invested through Regional Health Agencies (ARSs), and a call for projects, with a scope of €25m, was announced at the end of 2017 by the French government agency, DGOS. The scope of the <a href="http://www.hospimedia.fr/actualite/articles/20170315-e-sante-hopital-numerique-et-territoire-de-soins">e-Hôp 2.0 Program</a> , the successor to the 2012-2017 Digital Hospitals Program, should have seen funding, to a level of €400m, to support the development of health-care facilities to 2021. Given that it has been recently replaced by the <a href="https://www.ticsante.com/la-suite-du-programme-Hopital-numerique-soutiendra-l-ouverture-des-etablissements-vers-la-ville-(DGOS)-NS_4002.html">Hop&#8217;EN Program</a>, the eventual level of funding remains unknown at present.</p>
<p>Part of this funding may be used by GHTs to configure their combined information systems, for example by financing an outsourcing program with a certified hosting provider, or by financing the Health Data Host certification of one of the GHT’s facilities.</p>
<p>By changing the regulations related to the health data hosting <a href="http://esante.gouv.fr/sites/default/files/asset/document/asip-sante_point_detape-convergence_si_ght_v04.pdf">at a time when the GHTs are configuring their combined ISs</a>, the government is seizing the opportunity to strengthen the data security of patients treated by the public health service. Indirectly, this provides a dual driver for growth in the French market for ISO 27001 certification, which will result in the standardization, and dissemination of good practice, in information-security management across the healthcare sector.</p>
<p>Although the result of long-awaited developments, this growth is likely to lead to an explosion of applications for ISO 27001 certification and health data hosting in the coming years: will COFRAC, and the companies that will be accredited to deliver Health Data Host certification, be able to meet demand? &#8230;There could be a bottleneck on the horizon.</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2018/08/health-data-hosts-iso-27001/">“HEALTH DATA HOSTS&#8221;: HEALTH PROVIDES A SHOT IN THE ARM FOR THE FRENCH ISO 27001 CERTIFICATION MARKET</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
