Les DPO de la Santé
Sector · Independent health professionals

The GDPR in your practice: the essentials, without the overkill

A health professional practicing individually is, as a rule, not required to appoint a DPO — the very example cited by the European guidelines themselves. But every other obligation applies: record of processing activities, patient information, security, retention periods, breach notification. And the CNIL has already sanctioned independent physicians — €3,000 and €6,000 in 2020, for medical images accessible online and an unnotified breach.

Illustration — Independent health professionals
Your challenges

What is at stake for your organization

  • Secure the workstation, the internet router and the software — the exact failure that earned the two physicians their sanctions.
  • Keep a record of processing activities proportionate to the practice’s activity.
  • Inform patients: a waiting-room notice, statements on documents.
  • Frame the secretariat, remote secretarial services and online scheduling (roles and contracts).
  • Know how to react to a breach: qualify, notify within 72 hours where required, document.

What triggers the need

  • Installing or changing practice software or an online scheduling tool
  • Joining forces with other practitioners or hiring a secretariat
  • A patient requesting access to their record
  • An incident: lost equipment, a misdirected message, a compromised workstation

Sound familiar? Now is the right time to get the subject under control — before it takes control on its own.

The most common mistake

Thinking “I’m too small to be concerned”. The two physicians sanctioned by the CNIL in 2020 practiced individually: size only exempts you, as a rule, from the obligation to appoint a DPO — not from the record of processing, not from security, not from breach notification.

Our support

What we put in place

  • An express diagnostic tailored to independent practice
  • A proportionate documentation kit: simplified record, notices, procedures
  • Review of the practice’s tools and providers
  • Awareness for the practitioner and the secretariat
  • One-off support in the event of an incident or a patient request
Frequently asked questions

Your questions

Must an independent physician appoint a DPO?

In principle no, for individual practice: the European guidelines expressly cite this case as not amounting to large scale. Things change in group practice — MSP, health center, a large group practice — where the analysis is made case by case. A voluntary appointment remains possible and sometimes relevant.

What does a practice really risk?

Real but proportionate sanctions: in 2020, two independent physicians were fined €3,000 and €6,000 for a security failure (images accessible online) and for failing to notify the breach. Beyond the fine, what is at stake is patients’ trust — and that cannot be bought back.

Where to start without spending weeks on it?

Three proportionate work streams: check basic security (passwords, updates, backups, router configuration), keep a simplified record of the practice’s processing activities, and display clear information for patients. Our express diagnostic covers these points and delivers a roadmap within ten days.

Let’s secure the compliance of your organization

A free first conversation to review your situation and identify your priorities.

Response within 24 business hours · No obligation