Continuity of care, with a posture one RSSI can actually hold.
One RSSI for a GHT of several hospitals, biomedical equipment nobody can patch, and a chain of obligations with different portals: CERT Santé, the CNIL, the HDS contract, NIS2. Mindlapse gives that one person a posture that holds between two crises.
NIS2 · HDS and PGSSI-S · CERT Santé · Derogations that expire
Value chain · clinical activities Illustrative data
Care functions · 4·Activities · 8·Risk links · 11·Supplier links · 6· Télémaintenance access on two critical activities · supplier not yet assessed
Emergency
Patient record (DPI) Critical
télémaintenance · 3 risks
Bed management Medium
1 risk
Imaging
PACS Critical
télémaintenance · 2 risks
Modality worklist Medium
1 supplier
Laboratory
Lab information system High
2 risks · 1 supplier
Analyser interface Medium
1 supplier
Pharmacy
Prescription High
2 risks
Dispensing robot Medium
1 supplier
CARE ↓
Support functions Health data hosting (your HDS-certified provider) Professional identity Biomedical maintenance Regional interoperability
A care pathway is the unit of risk; systems and suppliers hang off it. Governance records only: patient data never enters the platform.
THE SITUATION
Degraded mode is a plan on paper until it is tested.
01
The device is owned by biomedical, not IT
Embedded software older than your youngest nurse, on a flat network, under a maintenance contract that forbids touching it.
02
One RSSI, six hospitals
The same person answers the ARS, the CNIL and the auditor, and runs the crisis cell when it comes.
03
Several portals, several clocks
The CERT Santé declaration, the CNIL at 72 hours, the HDS contractual chain, and NIS2 to ANSSI once the French law applies: the same incident, several forms.
04
The biomedical fleet with no owner in the register
The analyser has a maintenance contract, a vendor VPN and no line in any risk register.
WHO IS IN SCOPE
Who is in scope in healthcare?
Healthcare providers are a NIS2 Annex I sector. In France, hospitals and hospital groups (GHT) are the entities most likely to be essential, smaller establishments important or out of scope by size, all of it once the French law applies. The sector also carries HDS certification for anyone hosting personal health data on behalf of a third party, the PGSSI-S referentials, the CaRE programme and mandatory incident reporting to CERT Santé. Medtech manufacturers answer to NIS2 Annex II and, for the devices it lists, to the AI Act.
Written for
Établissements de santé and GHTNIS2 essential, CaRE, CERT Santé
Private clinics and ESMSImportant or out of scope by size, CaRE
HDS-certified hosts and health software editorsSuppliers to entities in scope
Medtech manufacturersMDR, NIS2 Annex II, the AI Act
WHAT MINDLAPSE CHANGES
One map for the pathway, its systems, its suppliers and its exceptions.
What the sector asks, and what Mindlapse verifies.
EU rows first, the French specifics tagged; every "verifies" cell is a product claim at ledger level, no cell carries a date, and the sentence under the table is the site’s one dated source.
What the sector asks, and what Mindlapse verifies.
One incident record, the cascade to the notification file, the log; your team files it
Cyber Incidents
GDPR
Art. 35 · DPIA where a clinical system is likely to entail a high risk
Privacy scoping at initiative intake and GDPR-related control sets in the atlas; the DPIA itself stays where you keep it
Security by Design
HDS FR
Hosting of personal health data on behalf of a third party
Your hosts and their sub-hosts assessed as critical suppliers, certificates as dated evidence, PGSSI-S mapped to the same control set; Mindlapse holds governance records only and claims no HDS status
Supplier Hub
CERT Santé FR
Mandatory declaration of significant incidents
The declaration drafted by the cascade from the same incident record and logged; your team files it
Cyber Incidents
NIS2 was due for transposition across the EU by 17 October 2024. As of September 2026 the French transposition law (the projet de loi résilience, which also recasts the OIV regime) is still before Parliament, and the European Commission referred France to the Court of Justice in July 2026.
A QUARTER, THEN THE DAY THE ARS ASKS
A normal quarter renews what cannot be fixed and rehearses degraded mode; the request finds one record, not a phone tree.
Four moments of an ordinary quarter in a hospital group, and what the platform had already done; then the day the ARS asks, in three steps. Governance records only: patient data never enters the platform.
A quarter in healthcare, then the request Illustrative data
A normal quarter
WEEK 2
The imaging workstation derogation comes up for renewal.
Renewed with a new expiry once the segmentation it depends on was verified.
Surface: Derogation lane
alert: WEEK 5
An advisory matched the laboratory system.
The risk moved, a finding opened, and the editor’s re-assessment fired on its own.
Surface: Risk Register
verified: WEEK 8
The directoire read exposure by care activity.
Emergency, imaging, laboratory and pharmacy against appetite, each figure opening on its evidence.
Surface: Cyber Cockpit
WEEK 12
Crisis exercise.
The chain named which activities degrade first and which suppliers to call, before the scenario started.
Surface: Business Impact Analysis
The day the ARS asks
THE REQUEST
After an incident, the ARS asks what was declared, when, and what has changed since.
The incident record answered all three: its classification, its cascade log, the actions since.
Surface: Cyber Incidents
WHAT OPENS
The incident record with its cascade log, the CERT Santé action, the derogations touching the affected pathway.
Each derogation with its compensating measures and its expiry, on the pathway the incident hit.
Surface: Derogation lane
WHAT IS EXPORTED
The incident record and the controls’ evidence.
From Audit mode, scoped to the pathway and the period the ARS asked about.
Surface: Audit mode
Illustrative quarter: the moments are fictional, the surfaces are the product’s. Governance records only: incident classification, evidence, suppliers.
FROM THE FIELD
Built with the people who keep the wards running.
CYBER COLLECTIVE LAB · Edition 5
Compliance: NIS2, DORA and CRA - round table and field feedback
What NIS2 changes for an entity that had never been regulated on cyber before: the round table on NIS2, DORA and CRA, read from the hospital’s side of the table.
−50–70%
time-to-risk-decision
15–30%
cyber-budget optimization
2–3×
risk visibility across the organization
Measured with our design-partner CISOs, figures under continuous validation.
No, and it does not need to: Mindlapse holds governance records, risks, controls, evidence, suppliers, incident classification, never patient data. Personal health data must not be uploaded; the HDS chain is a decision about your hosts, which the platform helps you assess.
Can it inventory our medical devices?
No, deliberately. The map holds the care activities and the systems that carry them, with their risks, suppliers and exceptions; a device register belongs to biomedical engineering and stays there.
How does it handle a device that cannot be patched?
As a derogation in its own lane: compensating measures with a scored coverage, an approver at the level the residual risk requires, and an expiry that reopens the decision instead of letting the exception outlive everyone who signed it.
Who declares to CERT Santé and the CNIL?
You do. The cascade qualifies the incident once and drafts the CERT Santé, CNIL and NIS2 notifications from the same record, with the log; your team files each one on its portal.
Does it fit a GHT with one shared RSSI?
Yes. Each establishment is an entity with its own scoped roles and register, the group reads the consolidated view, and the one RSSI works from a single action queue across all of them.
Our host’s audience measurement (Vercel) uses no cookies and is not covered by this choice. Google Analytics and marketing trackers stay off until you say otherwise. Read the cookie policy