Skip to main content
Les Assises 2026 · Monaco

Meet us at the Startup area, and at our workshop on Wednesday 7 October, 4:30 pm.

Book the workshop

BY INDUSTRY · HEALTHCARE

Continuity of care, with a posture one RSSI can actually hold.

One RSSI for a GHT of several hospitals, biomedical equipment nobody can patch, and a chain of obligations with different portals: CERT Santé, the CNIL, the HDS contract, NIS2. Mindlapse gives that one person a posture that holds between two crises.

NIS2 · HDS and PGSSI-S · CERT Santé · Derogations that expire

Value chain · clinical activities Illustrative data

Care functions · 4 Activities · 8 Risk links · 11 Supplier links · 6 Télémaintenance access on two critical activities · supplier not yet assessed

Emergency

Patient record (DPI) Critical

télémaintenance · 3 risks

Bed management Medium

1 risk

Imaging

PACS Critical

télémaintenance · 2 risks

Modality worklist Medium

1 supplier

Laboratory

Lab information system High

2 risks · 1 supplier

Analyser interface Medium

1 supplier

Pharmacy

Prescription High

2 risks

Dispensing robot Medium

1 supplier

CARE ↓
Support functions Health data hosting (your HDS-certified provider) Professional identity Biomedical maintenance Regional interoperability

A care pathway is the unit of risk; systems and suppliers hang off it. Governance records only: patient data never enters the platform.

THE SITUATION

Degraded mode is a plan on paper until it is tested.

  1. The device is owned by biomedical, not IT

    Embedded software older than your youngest nurse, on a flat network, under a maintenance contract that forbids touching it.

  2. One RSSI, six hospitals

    The same person answers the ARS, the CNIL and the auditor, and runs the crisis cell when it comes.

  3. Several portals, several clocks

    The CERT Santé declaration, the CNIL at 72 hours, the HDS contractual chain, and NIS2 to ANSSI once the French law applies: the same incident, several forms.

  4. The biomedical fleet with no owner in the register

    The analyser has a maintenance contract, a vendor VPN and no line in any risk register.

WHO IS IN SCOPE

Who is in scope in healthcare?

Healthcare providers are a NIS2 Annex I sector. In France, hospitals and hospital groups (GHT) are the entities most likely to be essential, smaller establishments important or out of scope by size, all of it once the French law applies. The sector also carries HDS certification for anyone hosting personal health data on behalf of a third party, the PGSSI-S referentials, the CaRE programme and mandatory incident reporting to CERT Santé. Medtech manufacturers answer to NIS2 Annex II and, for the devices it lists, to the AI Act.

Written for

  • Établissements de santé and GHT NIS2 essential, CaRE, CERT Santé
  • Private clinics and ESMS Important or out of scope by size, CaRE
  • HDS-certified hosts and health software editors Suppliers to entities in scope
  • Medtech manufacturers MDR, NIS2 Annex II, the AI Act

THE OBLIGATIONS MAP

What the sector asks, and what Mindlapse verifies.

EU rows first, the French specifics tagged; every "verifies" cell is a product claim at ledger level, no cell carries a date, and the sentence under the table is the site’s one dated source.

What the sector asks, and what Mindlapse verifies.
Regulation Obligation What Mindlapse verifies Surface
NIS2 Art. 20 · accountability of the directeur, the directoire and the GHT governance A verified posture in board-readable views: exposure by care activity against the appetite the directoire approved Cyber Cockpit
NIS2 Art. 21(2)(c) · continuity, backup and crisis management Continuity controls with dated evidence; what cannot be fixed yet as a derogation with compensating measures and an expiry Control Atlas
NIS2 Art. 23 · incident reporting One incident record, the cascade to the notification file, the log; your team files it Cyber Incidents
GDPR Art. 35 · DPIA where a clinical system is likely to entail a high risk Privacy scoping at initiative intake and GDPR-related control sets in the atlas; the DPIA itself stays where you keep it Security by Design
HDS FR Hosting of personal health data on behalf of a third party Your hosts and their sub-hosts assessed as critical suppliers, certificates as dated evidence, PGSSI-S mapped to the same control set; Mindlapse holds governance records only and claims no HDS status Supplier Hub
CERT Santé FR Mandatory declaration of significant incidents The declaration drafted by the cascade from the same incident record and logged; your team files it Cyber Incidents

NIS2 was due for transposition across the EU by 17 October 2024. As of September 2026 the French transposition law (the projet de loi résilience, which also recasts the OIV regime) is still before Parliament, and the European Commission referred France to the Court of Justice in July 2026.

A QUARTER, THEN THE DAY THE ARS ASKS

A normal quarter renews what cannot be fixed and rehearses degraded mode; the request finds one record, not a phone tree.

Four moments of an ordinary quarter in a hospital group, and what the platform had already done; then the day the ARS asks, in three steps. Governance records only: patient data never enters the platform.

A quarter in healthcare, then the request Illustrative data

A normal quarter

  1. WEEK 2

    The imaging workstation derogation comes up for renewal.

    Renewed with a new expiry once the segmentation it depends on was verified.

    Surface: Derogation lane

  2. alert: WEEK 5

    An advisory matched the laboratory system.

    The risk moved, a finding opened, and the editor’s re-assessment fired on its own.

    Surface: Risk Register

  3. verified: WEEK 8

    The directoire read exposure by care activity.

    Emergency, imaging, laboratory and pharmacy against appetite, each figure opening on its evidence.

    Surface: Cyber Cockpit

  4. WEEK 12

    Crisis exercise.

    The chain named which activities degrade first and which suppliers to call, before the scenario started.

    Surface: Business Impact Analysis

The day the ARS asks

  1. THE REQUEST

    After an incident, the ARS asks what was declared, when, and what has changed since.

    The incident record answered all three: its classification, its cascade log, the actions since.

    Surface: Cyber Incidents

  2. WHAT OPENS

    The incident record with its cascade log, the CERT Santé action, the derogations touching the affected pathway.

    Each derogation with its compensating measures and its expiry, on the pathway the incident hit.

    Surface: Derogation lane

  3. WHAT IS EXPORTED

    The incident record and the controls’ evidence.

    From Audit mode, scoped to the pathway and the period the ARS asked about.

    Surface: Audit mode

Illustrative quarter: the moments are fictional, the surfaces are the product’s. Governance records only: incident classification, evidence, suppliers.

FROM THE FIELD

Built with the people who keep the wards running.

CYBER COLLECTIVE LAB · Edition 5

Compliance: NIS2, DORA and CRA - round table and field feedback

What NIS2 changes for an entity that had never been regulated on cyber before: the round table on NIS2, DORA and CRA, read from the hospital’s side of the table.

−50–70%
time-to-risk-decision
15–30%
cyber-budget optimization
2–3×
risk visibility across the organization

Measured with our design-partner CISOs, figures under continuous validation.

FAQ

Healthcare asks

Does Mindlapse host health data under HDS?

No, and it does not need to: Mindlapse holds governance records, risks, controls, evidence, suppliers, incident classification, never patient data. Personal health data must not be uploaded; the HDS chain is a decision about your hosts, which the platform helps you assess.

Can it inventory our medical devices?

No, deliberately. The map holds the care activities and the systems that carry them, with their risks, suppliers and exceptions; a device register belongs to biomedical engineering and stays there.

How does it handle a device that cannot be patched?

As a derogation in its own lane: compensating measures with a scored coverage, an approver at the level the residual risk requires, and an expiry that reopens the decision instead of letting the exception outlive everyone who signed it.

Who declares to CERT Santé and the CNIL?

You do. The cascade qualifies the incident once and drafts the CERT Santé, CNIL and NIS2 notifications from the same record, with the log; your team files each one on its portal.

Does it fit a GHT with one shared RSSI?

Yes. Each establishment is an entity with its own scoped roles and register, the group reads the consolidated view, and the one RSSI works from a single action queue across all of them.

CARE, VERIFIED

Bring one clinical pathway. Leave with its systems, suppliers and exceptions on one map.

A live session on your establishment: activities, télémaintenance, derogations, the directoire view.

Refusing is exactly as easy as accepting, and nothing is pre-selected. Your choice is kept for 6 months and can be changed at any time from the footer.

Strictly necessary

Always on

Stores your cookie choice in this browser so we can honour it on your next visit. No tracking identifier, no third party. Cannot be disabled.