FRANCE Law and Practice Contributed by: Jérôme Philippe, Laéna Bouafy, Thomas Retière and Annabelle Hamelin, Freshfields
ment proposal is currently subject to parliamentary approval. Finally, in February 2026, ANSSI published a threat intelligence report (CERTFR-2026-CTI-001) on gen - erative AI facing cyber-attacks. The report notes that, while generative AI cannot yet autonomously exe - cute full attacks from end to end, it is increasingly integrated into attacker toolsets for victim profiling, social engineering and malware development, lower - ing the barrier to entry for less experienced actors. Furthermore, the report warns that generative AI sys - tems (such as LLMs) themselves are lucrative targets, highly susceptible to model poisoning, software sup - ply chain compromises and data exfiltration. 6.3 Cybersecurity in the Healthcare Sector The healthcare sector faces strict cybersecurity obli - gations to protect sensitive medical data across health sector entities, medical devices and electronic health record (EHR) systems. Health Sector Entities and EHR Systems Entities handling electronic health records must com - ply with the General Security Policy for Health Infor - mation Systems (PGSSI-S) established by the ANS. Furthermore, any entity hosting health data collected in the course of prevention, diagnosis, care or social and medical-social follow-up activities must hold the HDS certification. Technical operations considered to be part of the hosting activity notably include: • the provision and operational maintenance of the physical sites hosting the hardware infrastructure of the information system used to process health data or of the hardware infrastructure itself; • the administration and operation of the information system containing the health data; and • the retention of the health data.
The updated HDS Version 2.0 (mandatory by May 2026) introduces stringent data sovereignty rules, requiring all health data storage to reside exclusively within the EEA and mandating explicit transparency for any remote access from outside the EEA. The certification requires audits by independent bod - ies accredited by the French Accreditation Commit - tee (COFRAC). Failure to comply carries severe risks, including criminal penalties. Sector-Specific Incident Reporting France imposes stringent sector-specific incident- reporting obligations. As such, healthcare estab - lishments, bodies and professionals must immedi - ately report significant security incidents affecting their health information systems to the competent state authorities. This reporting is typically facilitated through the regional health agencies (ARS) and the dedicated CERT Santé. Medical Devices Connected medical devices must satisfy the General Safety and Performance Requirements (GSPR) under the EU Medical Device Regulation (MDR). To obtain CE marking and market access, manufacturers must integrate cybersecurity across the software life cycle, commonly utilising the universally recognised EN IEC 81001-5-1:2022 standard. Procurement-Related Security In public procurement, health data security is increas - ingly tied to national sovereignty. For instance, recent government tenders for major infrastructures such as the national Health Data Hub explicitly mandate that providers hold an ANSSI SecNumCloud qualification, effectively excluding standard foreign cloud offerings to immunise public health data against extraterritorial laws.
138 CHAMBERS.COM
Powered by FlippingBook