Making sense of digital-health compliance
Our articles and regulatory analyses — GDPR, HDS hosting, AI Act, NIS2, medical confidentiality — written by practising DPOs and checked against the official sources. Every article is available in English and in French.

A €500,000 fine: at Hôpital privé de la Loire, one account was all it took
An attacker used a doctor's credentials and exfiltrated 524,867 patient records. The alert came not from any system detecting the extraction, but from a practitioner who could no longer log in. The CNIL's decision shows what must protect the data once the first barrier gives way.
GDPR sanctions and health data: seven decisions that draw the red line
From a doctor fined €3,000 to a group ordered to pay €5 million: a sourced review of the landmark decisions and their operational lessons for the sector.
AI Act: August 2, 2026 was supposed to change everything — here is what actually applies
The AI Regulation was due to reach full application on August 2, 2026. But the Omnibus package voted by the European Parliament on June 16 reshuffled the deck for high-risk systems. An analysis for healthcare players.
Digital Omnibus: what the GDPR “simplification” changes (and does not change) for healthcare
A redefined notion of personal data, legitimate interest for AI training, cookies brought into the GDPR, a postponed AI Act: the Omnibus package is shaking up European digital law. Where things stand in summer 2026 for healthcare players.
EHDS: the European Health Data Space has entered into force — why to start preparing in 2026
The EHDS Regulation will apply in stages by the end of the decade: interoperable health records, patient access, regulated data reuse. Organizations that prepare now will gain a head start.
HDS v2: the May 16, 2026 deadline has passed — are your hosting providers still certified?
Since May 16, 2026, HDS certificates issued under the former v1.1 standard are no longer enough: every hosting provider had to migrate to the v2 standard. What every healthcare organization and software vendor must check, now.
Health data hosting (HDS): what you need to know in 2026
Who is subject to HDS certification, what obligations apply to software vendors and healthcare organizations, and how to frame a compliant hosting project.
The AI Act and healthcare: what obligations for your AI systems?
Most AI systems in healthcare fall into the “high-risk” category. An overview of the obligations and of the right reflexes to adopt from the design stage.
CNIL inspections: how to prepare with confidence
An inspection cannot be improvised. The documents to keep up to date and the reflexes that make the difference on the day.
The NIS2 Directive: what impact on the healthcare sector?
Healthcare is one of NIS2’s “highly critical” sectors. New cybersecurity and governance obligations to anticipate.
Medical confidentiality and the GDPR: two regimes to reconcile
Medical confidentiality and the GDPR pursue close but distinct objectives. How to reconcile them in day-to-day practice.
The record of processing activities: where to start?
The cornerstone of compliance, the record of processing activities is too often neglected. A method to build it and keep it alive.
Prefer to discuss it in English?
Book a call with our team: we work with international vendors, sponsors and healthcare organizations, and can walk you through any of these topics in English.
Response within 24 business hours · No obligation
