HEALTH · CLINICS · CABINETS

Health data.
Essential trust.

A health structure deals with intimate information whose exposure can permanently affect a person. Patient file, appointment, exams, prescriptions, billing, insurance, imaging, teleconsultation and exchanges between professionals create a set of flows that go far beyond the main medical software.

HEALTHPATIENT FILEHABITATATIONSINCIDENTS

Your activity,
its real flows.

The sensitivity of data requires linking professional confidentiality, authorizations, traceability, availability, backup, sharing and patient information. Technical service providers, laboratories, insurers, platforms and remote supports must be included in this analysis, particularly when data or access crosses a border.

RCM works on data protection governance, formalities, contracts, procedures and evidence. The mission does not constitute a medical audit, nor a safety certification, nor an exhaustive analysis of all the health regulations applicable to the establishment.

Scoping starts with the facts: systems, teams, people involved, data, customers, suppliers and countries. The obligations are then qualified separately with regard to the GDPR and Moroccan law 09-08. This method avoids applying a generic response to processing activities that have neither the same purpose nor the same level of risk.

WHEN TO COME

Triggers
most common.

A mission may begin before a launch, during a negotiation or after a gap appears.

01

New system

Patient file, laboratory, imaging, appointments, teleconsultation or accommodation.

02

External sharing

Laboratory, specialist, insurer, partner, support or recipient platform.

03

Incident or control

Undue access, sending error, loss, ransomware or need to demonstrate measures.

FROM THE FIELD TO EVIDENCE

A journey
in four stages.

Decisions and limits are made visible at each stage.

01

Map

Admission, care, examinations, sharing, billing, archiving and possible research.

02

To prioritize

Sensitive data, access, volumes, vulnerable audiences, availability and transfers.

03

Secure

Roles, contracts, procedures, authorizations, traceability and continuity.

04

Control

Access reviews, incidents, new services, suppliers and documentation.

SECTORAL RISKS

What the documents
Don't always show.

These situations are points of analysis, not automatic conclusions.

01

Internal curiosity

Technically possible access does not mean that it is necessary for support.

02

Misdirected sharing

Email, messaging or printing can expose a file to the wrong recipient.

03

Technical service provider

Maintenance, hosting or support may provide access to sensitive data.

04

Availability

Protection includes the ability to restore and continue activity, not just privacy.

05

Rights and third parties

A file may contain information about relatives or professionals to be protected.

06

Critical incident

Qualification must be rapid, documented and coordinated with the medical and technical teams.

OPERATIONAL CONTROLS

Measures that
teams can apply.

Each check must have a responsible person, frequency and proportionate proof.

01

Authorizations by function

Limit access based on role, department, support and administrative needs.

02

Traceability

Protected logs, targeted reviews and procedure for handling abnormal access.

03

Secure sharing

Channels, recipients, verification, appropriate encryption and printing rules.

04

Supervised suppliers

Contracts, confidentiality, support, processors, country and end of service.

05

Documented continuity

Backup, restoration, responsibilities and coordination with technical specialists.

06

Response to incidents

Sorting, limitation, retention of facts, risk analysis and notification decisions.

DELIVERY

What RCM
Leave it to your teams.

The final scope depends on maturity, risks and elements already available.

01

Health mapping

Patient journey, systems, exchanges, actors, data and countries.

02

Priority register

Sensitive treatment, purposes, bases, durations and measures.

03

Access Matrix

Clinical, administrative, technical and external profiles.

04

Incident procedure

Qualification, roles, escalation, evidence and communications.

05

Service provider review

Hosting, maintenance, laboratory, insurance and platforms.

06

Control plan

Access, sharing, accounts, backup, deletion and periodic testing.

TWO FRAMES

GDPR and law 09-08,
I didn't confuse them.

The same activity may fall within both frameworks for different reasons.

EU

GDPR

Roles, responsibilities, information, rights, security, subcontracting and transfers outside EEA.

MA

Law 09-08

Treatment in Morocco, rights, security and formalities of declaration or authorization.

International flows

Access, hosting, recipients, mechanism, context and additional measures.

Evidence

Contracts, registers, decisions, controls, training, incidents and actions followed.

INTERVENTION FORMATS

Start small.
Maintain if necessary.

The amounts are confirmed after scoping; no fictitious pricing is published.

DIAGNOSIS

Starting point

Targeted interviews, review of available elements, major risks and sectoral roadmap.

Fixed price · after scoping
TARGETED MISSION

Priority base

Agreed deliverables, corrections, review meeting and operational transfer to internal managers.

From — on estimate
ACCOMPANYING

Continuous management

Volume, deadlines, meetings, controls, new projects and contract overruns.

Subscription · on quote
RESPONSIBILITIES AND LIMITS

Advise, structure
and advance.

RCM provides GDPR advice, law 09-08 and operational assistance. The client organization retains its decisions, responsibilities, budgets, validations and technical actions. No mission guarantees absolute compliance, absence of sanction or a favorable decision from an authority.

  • Penetration tests, forensic investigations and certifications are carried out by competent experts.
  • Reserved legal consultations and litigation are directed to a lawyer.
  • Sectoral regulations excluding data protection remain outside the scope unless expressly stated.
FREQUENTLY ASKED QUESTIONS

Specific responses.
Contextualized decisions.

These answers present general principles. Processing, roles, countries and contracts should be reviewed before any conclusion.

Does health data still require CNDP authorization?

Health data belongs to sensitive categories and requires careful qualification of the applicable regime. The answer depends on the processing, its basis, who is responsible and any specific provisions. RCM prepares the analysis and the appropriate file without promising the CNDP’s decision.

Can all medical personnel check all files? +

Access must match the role and need for support or administration. Rights that are too broad increase the risk of unjustified consultation. An authorization matrix defines the profiles, while traceability and reviews make it possible to verify their use.

Does RCM certify the security of medical software? +

No. RCM examines privacy governance, available evidence, contracts, access and procedures. A certification, intrusion test, architectural review or in-depth technical analysis must be carried out by competent specialists.

How to respond to a request for access to the file? +

Proportionately verify identity, locate information, consider third party rights, prepare secure delivery and retain proof of response. The rules specific to medical access or care records must also be confirmed with competent legal and medical professionals.

What to do after a sending error containing medical data? +

The organization must act immediately: limit access if possible, identify recipients and data, preserve the facts, assess the consequences and determine communication or notification obligations. RCM coordinates the privacy analysis; technical investigations or medical decisions remain with the competent teams.

Does the offer cover all health regulations? +

No. It covers the protection of personal data and the coordination of GDPR/law 09-08 obligations within the agreed scope. The rules of medical practice, health records, insurance or sectoral authorization must be checked separately.

Your sector deserves A concrete scoping.

Present your tools, data, customers, suppliers, countries and deadlines. RCM will indicate the first useful perimeter.

Scoping the mission →
Talk to a DPO