Compliance for multi-professional health centers (MSP)
Sharing the patient record among an MSP’s professionals is at the heart of the care project — and can amount, depending on the patient base and how exchanges are organized, to large-scale processing of health data that engages the organization itself. Certified information system, access rights, patient information: compliance underpins serene coordinated practice.

What is at stake for your organization
- Frame the sharing of the patient record among professionals (scope of the care team, consent where applicable).
- Secure the information system (e-health labeling, HDS hosting, access rights).
- Appoint a DPO: an MSP processing health data on a large scale is in principle required to do so.
- Formalize the record of processing, information notices and rights-handling procedures.
- Prepare the organization for a CNIL inspection.
What triggers the need
- Installing or replacing the shared information system
- A new professional joining and the opening of their access rights
- A patient requesting access to their record
- A labeling process or an institutional visit
Sound familiar? Now is the right time to get the subject under control — before it takes control on its own.
The most common mistake
Believing that the software vendor “handles the GDPR”. The vendor is a processor: the MSP remains responsible for the processing, for informing patients and for access rights — and it is the MSP the authority questions.
What we put in place
- Full compliance programme for health-information sharing
- Shared outsourced DPO, designated with the CNIL for the organization
- Audit of the information system and data hosting
- Patient information templates and rights management
- Training for the multi-professional team
Your questions
Must an MSP appoint a DPO?
In most cases, yes: patient monitoring at the scale of an MSP generally amounts to large-scale processing of health data — a criterion which, when met, makes appointing a DPO mandatory. We qualify your situation during a first call; a shared outsourced DPO is often the best-suited solution.
Can the DPO be shared between several organizations?
Yes. The GDPR allows independent organizations to use the same external officer under a service contract (Article 37(6)), provided they remain reachable and effectively able to perform their tasks for each of them. That is precisely our model: a health-specialized DPO, designated for your organization.
Is the patient’s consent required to share their record?
Within a care team as defined by the French Public Health Code, sharing the information needed for care relies on informing the patient and on their absence of objection; outside the care team, their consent is required. We define these scopes precisely with you.
Let’s secure the compliance of your organization
A free first conversation to review your situation and identify your priorities.
Response within 24 business hours · No obligation
