Votre question concerne quel type d'offre ?
Votre question concerne quel couloir Ségur ?
Votre question concerne quel dispositif Ségur ?
Votre question concerne quel produit ou service produit?
Votre question concerne quelle thématique ?
All the rules are set out in the HDS certification – Accreditation reference system and the COFRAC’s "Exigences spécifiques pour l’accréditation des organismes procédant à la certification de systèmes de management dans le domaine des technologies de l’information" (Specific requirements for structures that certify management systems in the information technology sector), available in our Documentation section.
To find out more about the list of certified and accredited bodies, click on the links below.
Cette réponse vous a-t-elle été utile ?
There are 6 types of activities that make you eligible as a health data host:
- providing and monitoring the operations of a physical site that hosts the material infrastructure of the IS used to treat health data;
- providing and maintaining the structural material used by the IS to host health data;
- providing and maintaining a platform that hosts the IS applications;
- providing and maintaining a digital structure for the IS which hosts health data;
- the administration and exploitation of the IS which contains the health data;
- health data backup services.
The full list of HDS-certified activities is available here:
Cette réponse vous a-t-elle été utile ?
The evaluation is done in two phases. It is conducted by the certifying body, which must verify the compliance with the certification requirements set out in the HDS Certification document (available below).
The audit also verifies the specific requirements for health data hosting are being met.
Cette réponse vous a-t-elle été utile ?
It is compulsory to have an individual CPx-type card to log in to the INSi teleservice. Three types of cards are supported: CPS, CPE, CPF.
Cette réponse vous a-t-elle été utile ?
CPx cards issued before December 2020 have a contactless chip that prevents from overwriting its code.
The new CPS R3V3 cards that are now in circulation have a Mifare Desfire chip. These cards can stock crypto-secret keys that work with the Mifare Desfire protocol.
All the information about this feature is available in the Manual to deploy contactless CPx cards (available to download below). One must be cautious about the data inserted in the chip’s writing code.
We strongly advise against using this section of the chip to stock access rights. The ANS recommends you to use the ANSSI guidelines on using a "transparent" reader in connected mode. This does not involve a cryptographic protocol during a badge authentication – only the UTL (logic treatment unit) takes part in the cryptographic protocol.
ANSSI advises against setting up a “smart” badge allowing a double authentication breaking from the UTL.
All the recommendations on securing systems for physical access and video projection are available in the document below, "Recommendations on securing systems for physical and video projection access".
Cette réponse vous a-t-elle été utile ?
There are several levels of requirements for a module’s integration into the Hospital Information System.
The main requirements set out by the referential are:
- Interfacing, control, security guidelines;
- Prescription process requirements;
- National prescription thesaurus integration requirements;
- Requirements regarding medico-economic and decision processes;
- Guidelines for ergonomics, functions, and notification alerts;
- Settings function requirements.
In total, 139 requirements are used to reach the minimal level of security needed for a solution’s integration into the hospital information system.
Cette réponse vous a-t-elle été utile ?
The current referential (2017) was written with industry experts. It introduces the particular context of this mission and the goals to reach in order to improve safety measures in neonatology and paediatric reanimation. The referential walks you through the fundamental concepts you need to grasp to understand the several requirements and protocols involved with software development for this sector.
Cette réponse vous a-t-elle été utile ?
Neonatology is a high-risk practice for two main reasons:
- The patients are extremely fragile (premature babies)
- 50% of the drugs used in the sector have yet to receive a marketing authorisation.
A survey conducted in 2014 evidenced a risk in the prescription process across the sector. The digitalisation of prescription is among the 41 recommendations that the report issued in order to increase safety levels.
Cette réponse vous a-t-elle été utile ?
No, a person may only have one e-CPS card at a time.
Cette réponse vous a-t-elle été utile ?
The CPS card and e-CPS are two complementary means of authentication. A person may use both at the same time, or one or the other according to their preference.
Cette réponse vous a-t-elle été utile ?
This midware allows the interfacing between computer applications, such as the Vivoptim doctors portal and the CPS card.
Cette réponse vous a-t-elle été utile ?