Les DPO de la Santé
Sector · MSP

Compliance for multi-professional health centers (MSP)

Sharing the patient record among an MSP’s professionals is at the heart of the care project — and can amount, depending on the patient base and how exchanges are organized, to large-scale processing of health data that engages the organization itself. Certified information system, access rights, patient information: compliance underpins serene coordinated practice.

Illustration — MSP
Your challenges

What is at stake for your organization

  • Frame the sharing of the patient record among professionals (scope of the care team, consent where applicable).
  • Secure the information system (e-health labeling, HDS hosting, access rights).
  • Appoint a DPO: an MSP processing health data on a large scale is in principle required to do so.
  • Formalize the record of processing, information notices and rights-handling procedures.
  • Prepare the organization for a CNIL inspection.

What triggers the need

  • Installing or replacing the shared information system
  • A new professional joining and the opening of their access rights
  • A patient requesting access to their record
  • A labeling process or an institutional visit

Sound familiar? Now is the right time to get the subject under control — before it takes control on its own.

The most common mistake

Believing that the software vendor “handles the GDPR”. The vendor is a processor: the MSP remains responsible for the processing, for informing patients and for access rights — and it is the MSP the authority questions.

Our support

What we put in place

  • Full compliance programme for health-information sharing
  • Shared outsourced DPO, designated with the CNIL for the organization
  • Audit of the information system and data hosting
  • Patient information templates and rights management
  • Training for the multi-professional team
Frequently asked questions

Your questions

Must an MSP appoint a DPO?

In most cases, yes: patient monitoring at the scale of an MSP generally amounts to large-scale processing of health data — a criterion which, when met, makes appointing a DPO mandatory. We qualify your situation during a first call; a shared outsourced DPO is often the best-suited solution.

Can the DPO be shared between several organizations?

Yes. The GDPR allows independent organizations to use the same external officer under a service contract (Article 37(6)), provided they remain reachable and effectively able to perform their tasks for each of them. That is precisely our model: a health-specialized DPO, designated for your organization.

Is the patient’s consent required to share their record?

Within a care team as defined by the French Public Health Code, sharing the information needed for care relies on informing the patient and on their absence of objection; outside the care team, their consent is required. We define these scopes precisely with you.

Let’s secure the compliance of your organization

A free first conversation to review your situation and identify your priorities.

Response within 24 business hours · No obligation