New system
Patient file, laboratory, imaging, appointments, teleconsultation or accommodation.
RCM
A health structure deals with intimate information whose exposure can permanently affect a person. Patient file, appointment, exams, prescriptions, billing, insurance, imaging, teleconsultation and exchanges between professionals create a set of flows that go far beyond the main medical software.
The sensitivity of data requires linking professional confidentiality, authorizations, traceability, availability, backup, sharing and patient information. Technical service providers, laboratories, insurers, platforms and remote supports must be included in this analysis, particularly when data or access crosses a border.
RCM works on data protection governance, formalities, contracts, procedures and evidence. The mission does not constitute a medical audit, nor a safety certification, nor an exhaustive analysis of all the health regulations applicable to the establishment.
Scoping starts with the facts: systems, teams, people involved, data, customers, suppliers and countries. The obligations are then qualified separately with regard to the GDPR and Moroccan law 09-08. This method avoids applying a generic response to processing activities that have neither the same purpose nor the same level of risk.
A mission may begin before a launch, during a negotiation or after a gap appears.
Patient file, laboratory, imaging, appointments, teleconsultation or accommodation.
Laboratory, specialist, insurer, partner, support or recipient platform.
Undue access, sending error, loss, ransomware or need to demonstrate measures.
Decisions and limits are made visible at each stage.
Admission, care, examinations, sharing, billing, archiving and possible research.
Sensitive data, access, volumes, vulnerable audiences, availability and transfers.
Roles, contracts, procedures, authorizations, traceability and continuity.
Access reviews, incidents, new services, suppliers and documentation.
These situations are points of analysis, not automatic conclusions.
Technically possible access does not mean that it is necessary for support.
Email, messaging or printing can expose a file to the wrong recipient.
Maintenance, hosting or support may provide access to sensitive data.
Protection includes the ability to restore and continue activity, not just privacy.
A file may contain information about relatives or professionals to be protected.
Qualification must be rapid, documented and coordinated with the medical and technical teams.
Each check must have a responsible person, frequency and proportionate proof.
Limit access based on role, department, support and administrative needs.
Protected logs, targeted reviews and procedure for handling abnormal access.
Channels, recipients, verification, appropriate encryption and printing rules.
Contracts, confidentiality, support, processors, country and end of service.
Backup, restoration, responsibilities and coordination with technical specialists.
Sorting, limitation, retention of facts, risk analysis and notification decisions.
The final scope depends on maturity, risks and elements already available.
Patient journey, systems, exchanges, actors, data and countries.
Sensitive treatment, purposes, bases, durations and measures.
Clinical, administrative, technical and external profiles.
Qualification, roles, escalation, evidence and communications.
Hosting, maintenance, laboratory, insurance and platforms.
Access, sharing, accounts, backup, deletion and periodic testing.
The same activity may fall within both frameworks for different reasons.
Roles, responsibilities, information, rights, security, subcontracting and transfers outside EEA.
Treatment in Morocco, rights, security and formalities of declaration or authorization.
Access, hosting, recipients, mechanism, context and additional measures.
Contracts, registers, decisions, controls, training, incidents and actions followed.
The amounts are confirmed after scoping; no fictitious pricing is published.
Targeted interviews, review of available elements, major risks and sectoral roadmap.
Fixed price · after scopingAgreed deliverables, corrections, review meeting and operational transfer to internal managers.
From — on estimateVolume, deadlines, meetings, controls, new projects and contract overruns.
Subscription · on quoteRCM provides GDPR advice, law 09-08 and operational assistance. The client organization retains its decisions, responsibilities, budgets, validations and technical actions. No mission guarantees absolute compliance, absence of sanction or a favorable decision from an authority.
These answers present general principles. Processing, roles, countries and contracts should be reviewed before any conclusion.
Health data belongs to sensitive categories and requires careful qualification of the applicable regime. The answer depends on the processing, its basis, who is responsible and any specific provisions. RCM prepares the analysis and the appropriate file without promising the CNDP’s decision.
Access must match the role and need for support or administration. Rights that are too broad increase the risk of unjustified consultation. An authorization matrix defines the profiles, while traceability and reviews make it possible to verify their use.
No. RCM examines privacy governance, available evidence, contracts, access and procedures. A certification, intrusion test, architectural review or in-depth technical analysis must be carried out by competent specialists.
Proportionately verify identity, locate information, consider third party rights, prepare secure delivery and retain proof of response. The rules specific to medical access or care records must also be confirmed with competent legal and medical professionals.
The organization must act immediately: limit access if possible, identify recipients and data, preserve the facts, assess the consequences and determine communication or notification obligations. RCM coordinates the privacy analysis; technical investigations or medical decisions remain with the competent teams.
No. It covers the protection of personal data and the coordination of GDPR/law 09-08 obligations within the agreed scope. The rules of medical practice, health records, insurance or sectoral authorization must be checked separately.
Present your tools, data, customers, suppliers, countries and deadlines. RCM will indicate the first useful perimeter.
Scoping the mission →