Support designed around how you work
Every player in digital health has its own constraints. We adapt our method to your reality, your risks and your priorities.

Find your situation
For each type of organization: the situations that typically trigger the need for support, the classic mistake we see most often, and the offer that usually fits best.
Healthcare facilities
A hospital or clinic processes health data at a scale that makes appointing a DPO mandatory — and a public facility is required to do so as a public body. Patient records, access rights, imaging, laboratory, HR, CCTV: the scope is vast, projects keep coming, and the requirements keep stacking up — GDPR, HDS hosting, cybersecurity.
When the need typically arises
- A new hospital information system, a data warehouse or another structuring project
- A security incident or an alert from the CISO
- A certification visit or an announced inspection
- The departure of the in-house DPO or a vacancy in the role
The classic mistake
Treating compliance as the DPO's job alone. Without relays in the departments — IT, medical information, HR, quality — even the best DPO documents in a vacuum: it is governance, with identified owners in each department, that makes a facility compliant.
CPTS — territorial professional health communities
A CPTS coordinates independent health professionals around territorial missions: care pathways, prevention, unscheduled care. That coordination relies on information exchanges — directories, messaging, shared digital tools — which must be framed under the GDPR and professional secrecy.
When the need typically arises
- Rolling out a new coordination tool or a territorial platform
- A request from the regional health agency (ARS) or a funder about data governance
- New members joining and the sharing of directories or schedules
- A first incident: a misdirected message, lost equipment, uncontrolled access
The classic mistake
Assuming compliance is each member professional's own business. The CPTS itself operates processing activities — coordination, directories, territorial projects — and carries responsibilities of its own that no member covers on its behalf.
Recommended offer
Health Compliance Foundation
Full details and pricing on our pricing page.
Discuss my situationMulti-professional health centers (MSP)
Sharing the patient record among an MSP's professionals is at the heart of the care project — and can amount, depending on the patient base and how exchanges are organized, to large-scale processing of health data that engages the organization itself. Certified information system, access rights, patient information: compliance underpins serene coordinated practice.
When the need typically arises
- Installing or replacing the shared information system
- A new professional joining and the opening of their access rights
- A patient requesting access to their record
- A labeling process or an institutional visit
The classic mistake
Believing that the software vendor “handles the GDPR”. The vendor is a processor: the MSP remains responsible for the processing, for informing patients and for access rights — and it is the MSP the authority questions.
Recommended offer
Health Compliance Foundation
Full details and pricing on our pricing page.
Discuss my situationHealth centers
Salaried professionals, a shared patient record, third-party payment, prevention programs: a health center combines the processing activities of a practice with the responsibilities of an organization. Compliance is carried by the managing body — and when processing reaches large scale, health centers are among the structures concerned by the appointment of a DPO.
When the need typically arises
- Opening a new center or taking over an existing structure
- A change of practice software or billing provider
- A request from the managing body, a funder or a supervisory authority
- An incident, or an access request from a patient
The classic mistake
Transposing the reflexes of private practice. In a health center, the managing body — association, mutual insurer, local authority — is the data controller, with organizational obligations (access rights, processors, patient information) that individual practice never involves.
Recommended offer
Health Compliance Foundation
Full details and pricing on our pricing page.
Discuss my situationNursing homes (EHPAD) & the medico-social sector
A nursing home processes far more than administrative data: care records, daily-life data, family and social information, sometimes CCTV. Sensitive data about vulnerable people — an area the CNIL watches particularly closely.
When the need typically arises
- Installing CCTV or resident-monitoring devices
- An inspection, a visit or a request from the departmental council
- An incident affecting a resident's record or an exchange with families
- Renewing the core software or a key service provider
The classic mistake
Restricting compliance to the care record. Data about families, employees, external practitioners and technical devices (CCTV, remote assistance) belong to the same scope — and they are often the first to cause problems.
Recommended offer
Health DPO — Essential
Full details and pricing on our pricing page.
Discuss my situatione-Health vendors & startups
For a vendor of health software or applications, compliance is not a constraint: it is a decisive commercial argument in front of hospital clients and public buyers who demand it. Privacy by design, HDS hosting, processing agreements — and now the AI Act.
When the need typically arises
- A hospital buyer's security and data-protection questionnaire
- Investor due diligence or a fundraising round
- Adding an AI feature or a new data flow
- Signing your first healthcare-facility client
The classic mistake
Postponing compliance until “after the sale”. The buyer's questionnaire always lands at the worst moment of the sales cycle — and a file improvised in a few days shows. Prepared, compliance accelerates sales; improvised, it slows them down.
Recommended offer
e-Health Product Compliance
Full details and pricing on our pricing page.
Discuss my situationTelemedicine
Teleconsultation, remote patient monitoring, tele-expertise: telemedicine moves the act of care into the digital realm. Video flows, connected devices, platforms — every link in the chain processes health data and must be secured, from HDS hosting to patient consent.
When the need typically arises
- Launching or redesigning a teleconsultation platform
- A change of hosting provider or an HDS certification deadline
- Integrating an artificial-intelligence component into the care pathway
- A compliance requirement from a healthcare facility acting as principal
The classic mistake
Thinking HDS hosting is enough. The certification covers the hosting provider — not your uses: patient information, consent collection where required, access rights, retention periods and traceability remain your responsibility.
Recommended offer
e-Health Product Compliance
Full details and pricing on our pricing page.
Discuss my situationClinical research
Sponsors, CROs, investigators: research involving human subjects combines several frameworks — the GDPR, the French Jardé law, the CNIL's reference methodologies (MR-001 to MR-006), ethics-committee opinions. Our founder, a former member of a French research ethics committee (CPP), knows these requirements from the inside.
When the need typically arises
- Setting up a new protocol or a data-only study
- A sponsor audit or a requirement from an academic partner
- Building a data warehouse or reusing existing data
- A submission or publication requiring proof of compliance
The classic mistake
Confusing consent to participate in the research (Jardé law) with the GDPR legal basis for processing the data. They are two distinct regimes — and confusing them weakens both the protocol and its documentation.
Recommended offer
Research & Health Data
Full details and pricing on our pricing page.
Discuss my situationIndependent health professionals
A health professional practicing individually is, as a rule, not required to appoint a DPO. But every other obligation applies: record of processing activities, patient information, security, retention periods, breach notification. And the CNIL has already sanctioned independent physicians — €3,000 and €6,000 in 2020.
When the need typically arises
- Installing or changing practice software or an online scheduling tool
- Joining forces with other practitioners or hiring a secretariat
- A patient requesting access to their record
- An incident: lost equipment, a misdirected message, a compromised workstation
The classic mistake
Thinking “I'm too small to be concerned”. The two physicians sanctioned by the CNIL in 2020 practiced individually: size only exempts you, as a rule, from the obligation to appoint a DPO — not from the record of processing, not from security, not from breach notification.
Recommended offer
Health Compliance Diagnostic
Full details and pricing on our pricing page.
Discuss my situationNot sure which situation is yours?
A free, no-obligation first conversation to review your compliance, clarify your obligations and identify your priorities.
Response within 24 business hours · No obligation
