Votre question concerne quel type d'offre ?
Votre question concerne quel couloir Ségur ?
Votre question concerne quel dispositif Ségur ?
Votre question concerne quel produit ou service produit?
Votre question concerne quelle thématique ?
All the rules are set out in the HDS certification – Accreditation reference system and the COFRAC’s "Exigences spécifiques pour l’accréditation des organismes procédant à la certification de systèmes de management dans le domaine des technologies de l’information" (Specific requirements for structures that certify management systems in the information technology sector), available in our Documentation section.
To find out more about the list of certified and accredited bodies, click on the links below.
Cette réponse vous a-t-elle été utile ?
There are 6 types of activities that make you eligible as a health data host:
- providing and monitoring the operations of a physical site that hosts the material infrastructure of the IS used to treat health data;
- providing and maintaining the structural material used by the IS to host health data;
- providing and maintaining a platform that hosts the IS applications;
- providing and maintaining a digital structure for the IS which hosts health data;
- the administration and exploitation of the IS which contains the health data;
- health data backup services.
The full list of HDS-certified activities is available here:
Cette réponse vous a-t-elle été utile ?
There are two steps to follow:
Step 1: Administrative phase
Should you wish to order test CPS cards or register authorisations for test software, you may:
- read our complete products offer ;
- place an order
To place an order, select your Profile and your Structure, then choose “Produits de développement. Commander des produits de développement : carte et/ou certificat logiciel de test" (Test products for products, cards and/or test software).
Step 2: Technical phase
Use the card you validated after step 1 in order to connect with the Trusted Platform IGC-Santé. You will be able to order, withdraw, monitor and revoke test certificates through the IHM or Webservice interface.
In order to do so, make sur you have inserted your test card in the card reader.
Read more about specific setup guidelines:
Cette réponse vous a-t-elle été utile ?
The evaluation is done in two phases. It is conducted by the certifying body, which must verify the compliance with the certification requirements set out in the HDS Certification document (available below).
The audit also verifies the specific requirements for health data hosting are being met.
Cette réponse vous a-t-elle été utile ?
The IGC-Santé is dedicated to the health sector and follows strict procedures in terms of data collection, professional identification, and works with certified authorities (RPPS register, etc.).
The certificates issued by the IGC guarantee the security of software or electronic cards, such as the CPS card.
The IGC also manages the publication of these certificates and can revoke them – this is signalled to the apps using certificates in revocation listings.
Cette réponse vous a-t-elle été utile ?
Generally speaking, the PGSSI-S needs to be applied as soon as personal health data are being handled. It is relevant to the public sector as well as the private sector, health professionals, workers of the social-health and social sectors, healthcare establishments and service providers.
As a patient, the PGSSI-S is a seal of guarantee on the accountability of digital health ecosystems.
Cette réponse vous a-t-elle été utile ?
Complying with the PGSSI-S frames of reference is either required by law (if the documents have been approved by a ministerial decree) or meant to be followed on a short-term basis until the documents are approved by the ministry.
Cette réponse vous a-t-elle été utile ?
There are two main reasons for the creation of IGC-Santé :
- guaranteeing the security of private keys and certificates issued by the ANS: the access to these private keys must be limited in order to prevent duplicates or their installation more than one device;
- maintaining a continuity in services: many health apps used to work on certificates issued by former CKI that ceased their activity in January 2021. These apps must be compatible with certificates issued by the IGC-Santé.
In addition, these certificates meet the security standards (risk analysis, safety policies), or “Certifying Policies” that comply with the PGSS-IS guidelines.
Cette réponse vous a-t-elle été utile ?