Les DPO de la Santé
Emergency

Health data breach: the first 72 hours decide everything

Ransomware, misdirected email, unauthorized access, lost equipment: qualify fast, notify accurately, document everything. Qualification the same day, clearly bounded scope, price known in advance.

The method

Five steps, in the order the GDPR imposes

Articles 33 and 34 of the GDPR set the framework; the difference lies in execution and documentation.

  1. 1

    Immediate qualification

    The same day: what happened, which data, which individuals, what risk? Not every breach requires a notification — but every breach requires a documented qualification.

  2. 2

    Assessing the risk to individuals

    Nature of the health data, volume, vulnerable individuals, possibility of re-identification: the assessment determines your obligations and is documented so it can be defended later.

  3. 3

    Notifying the CNIL within 72 hours

    Where required, we prepare and document the notification within the deadline set by Article 33 of the GDPR — complete, factual, with neither over-reporting nor under-reporting.

  4. 4

    Informing the individuals concerned

    Where there is a high risk, Article 34 requires informing the individuals. We prepare a clear, controlled communication, coordinated with your management.

  5. 5

    Documentation and lessons learned

    Every breach, notified or not, is recorded in the breach register with the facts, effects and measures taken — an obligation under Article 33(5), open to CNIL inspection at any time. That register is what proves your diligence.

Terms of engagement

From €3,500 excl. VAT — qualification the same day.

Excluding the technical investigation, carried out on a separate quote by our cybersecurity partner in coordination with us. Scope and deliverables set out in writing before any commitment.

Qualify my incident

Priority response — mention “breach” in your message, without including any patient data.

Frequently asked questions

What we’re asked in an emergency

Do we always have to notify the CNIL?

No. Notification is required unless the breach is unlikely to result in a risk to individuals — but that conclusion must be documented and defensible. With health data, caution is essential: that is precisely the purpose of the qualification we carry out the same day.

Who leads the technical investigation?

Our cybersecurity partner, on a separate quote, in coordination with us: analysis of the intrusion, compromised technical scope, containment measures. We handle the data-protection side: obligations, notifications, individuals concerned, documentation.

What if the breach comes from a processor?

The processor must inform you without undue delay, but the notification obligations rest with you as the controller. We coordinate gathering information from the processor and check what your contract provides.

Do you step in without us being a client first?

Yes — the offer is designed to be activated in an emergency, with no prior relationship. Clients on a DPO subscription benefit from the terms of their contract, with straightforward breach management included in their plans.

Received a letter from the CNIL? See the CNIL inspection assistance

Every hour of uncertainty increases the risk

Describe the incident in two sentences — without any patient data. We qualify the situation the same day and you know exactly what the GDPR expects of you.

Priority response — qualified the same day