Audit modelCompliance audit - Data warehouses in the healthcare sector
1. Who are these guidelines intended for?
The data warehouses covered by this standard are implemented to enable the data they contain to be re-used.
The guidelines do not apply to :
data warehouses implemented by a private company on the basis of its legitimate interest ;
the processing of personal data implemented solely for the purposes of preventive medicine, medical diagnosis, the administration of care or treatment, or the management of healthcare services and implemented by healthcare professionals and healthcare systems or services (e.g. dematerialised medical records). Such processing does not require prior formalities with the CNIL;
the processing of personal data when the individual has given his or her explicit consent for this purpose. Such processing does not require prior formalities with the CNIL;
data warehouses matched with the main database of the National Health Data System as defined in article L. 1461-1 of the French "code de la santé publique".
2. Purpose(s) of the data processing activity and governance
1. Purposes
Any use of the data in the warehouse by the data controller and for his exclusive use, is for the purposes of :
- production of indicators and strategic management of the activity, under the responsibility of the physician responsible for medical information;
- improving the quality of medical information or optimizing coding within the framework of the program for the medicalization of information systems (PMSI);
- operation of tools to assist in medical diagnosis or management;
- carrying out feasibility studies (pre-screening);
- carrying out research, studies and evaluations in the health field.
Apart from the uses mentioned above, the data controller must consider whether or not it is necessary to carry out specific formalities with the CNIL for any re-use of the data.
The data are not and will not be used :
- for the purpose of promoting the products mentioned in II of Article L. 5311-1 CSP to health professionals or health institutions;
- for the purpose of excluding guarantees from insurance contracts, nor for modifying the insurance contributions or premiums of an individual or a group of individuals presenting the same risk
2. Governance
3. Legal basis(s) of the processing
4. Personal data that can be included in the warehouse
5. Information access
6. Data retention periods
7. Information for individuals
1. Information to (re)admitted patients after the warehouse is established
2. Information from patients admitted before the warehouse is set up
3. Information for people involved in research projects
4. Information to the data subjects of each of the data re-uses
5. Information for professionals
8. Individual rights
9. Security
1. Network partitioning
2. Logical and cryptographic partitioning
3. Constitution and feeding of the warehouse
4. Pseudonymization of data
5. Physical access to data
6. Management of authorizations and logical access to data
7. Authentication for the consultation and administration of the warehouse
8. Workspace
9. Exporting data out of the warehouse and out of the workspaces
10. User awareness and workstation security
11. Logging
12. Re-identification procedures
13. Management of security incidents and personal data breaches
10. Subcontractors
11. Data transfers outside the European Union
12. Data Protection Impact Assessment (DPA)
Attribution / Pas d'utilisation commerciale
CC-BY-NC