Questions regarding health data have been particularly prominent since the government announced the Health Data Hub (HDH) project, which aims to ensure unified access to health data to improve the quality of care and patient support.
This has generated increased interest from external providers wishing to be referenced on the HDH and many questions about the position to adopt regarding health data.
What is health data?
The European General Data Protection Regulation (GDPR) provides a very broad definition of health data:
"Personal data concerning health are data relating to the physical or mental health, past, present or future, of a natural person (including the provision of health care services) which reveal information about the health status of that person."
Health data by nature (medical history, illnesses, healthcare services provided, examination results, treatments, disability, etc.)
Data that is so via a cross-referencing with other data making it possible to deduce an individual's health status (for example, a person's weight which could place them at risk of obesity)
Health data due to their intended medical purpose (for example, the transmission of a prescription)
We can therefore note that the concept of health data is very broad and must be assessed on a case-by-case basis : depending on the nature of the data, the cross-referencing carried out, and the conclusions that can be drawn.
What obligations must be observed for the hosting of this data?
A web or mobile application using health data must be hosted by providers holding the "Health Data Host" (HDS) certification.
The two most important international hosts are Amazon Web Service (AWS) and Microsoft Azure, as well as OVH at the French level. But there are many other hosting providers in France that hold the certification, such as Pictime Group, Ozytem, Cyllene, etc.
However, increased scrutiny is directed towards American hosts. In July 2021, the Court of Justice of the European Union (CJEU) rendered a historic decision invalidating the Privacy Shield :
"Agreement in the field of personal data protection law, which was negotiated between 2015 and 2016 between the European Union and the United States of America"
According to the Court, the limitations on the protection of personal data resulting from the domestic law of the United States concerning the access and use, by US public authorities, of data transferred from the European Union are not framed in a way that meets requirements substantially equivalent to those required under Union law.
How can this decision impact the choice of an HDS?
It could be inferred that, even if prohibitions do not come into force for the choice of an American host, increased attention will be paid to the management of flows of this sensitive data and we could possibly observe new regulations in the coming months.
What are the main elements to monitor?
If so, the legality of these transfers to third countries must be verified from a GDPR compliance perspective. This part should normally be analysed by the organisation carrying out the transfer, but attention must be paid to it when establishing the hosting contract.