Les DPO de la Santé
Sector · Telemedicine

Compliance for telemedicine and remote patient monitoring

Teleconsultation, remote patient monitoring, tele-expertise: telemedicine moves the act of care into the digital realm. Video flows, connected devices, platforms — every link in the chain processes health data and must be secured, from HDS hosting to patient consent.

Illustration — Telemedicine
Your challenges

What is at stake for your organization

  • Verify the HDS hosting of the platforms and solutions used.
  • Inform the patient and collect the consents required for the act and the associated processing.
  • Frame vendors and providers as processors (Article 28 contracts).
  • Secure the flows (encryption, authentication, logging).
  • Frame remote monitoring and connected-device data.

What triggers the need

  • Launching or redesigning a teleconsultation platform
  • A change of hosting provider or an HDS certification deadline
  • Integrating an artificial-intelligence component into the care pathway
  • A compliance requirement from a healthcare facility acting as principal

Sound familiar? Now is the right time to get the subject under control — before it takes control on its own.

The most common mistake

Thinking HDS hosting is enough. The certification covers the hosting provider — not your uses: patient information, consent collection where required, access rights, retention periods and traceability remain your responsibility.

Our support

What we put in place

  • Compliance audit of your telemedicine pathway
  • Contractual framing with platforms and vendors
  • Information notices and patient consent journey
  • DPIAs for remote-monitoring systems
  • Outsourced DPO for telemedicine operators
Frequently asked questions

Your questions

Must my teleconsultation platform be HDS-certified?

If it hosts health data on behalf of third parties, yes: the hosting provider must be HDS-certified. The professional or facility choosing the tool must verify this — we audit your solutions and their contracts.

Is patient consent required for a teleconsultation?

The patient must consent to the telemedicine act after clear information. That consent to the act is distinct from the legal bases of the associated data processing. Both must be properly articulated in your pathway.

Who is liable if data leaks through the platform?

Responsibilities are shared between the data controller (the professional or facility) and the processor (the platform), depending on the contract and the failures involved. Hence the importance of solid contractual framing upstream.

Let’s secure the compliance of your organization

A free first conversation to review your situation and identify your priorities.

Response within 24 business hours · No obligation