CalenDoc Integration: Embed in Days for French Clinics, HDS & FHIR

2 October 2026
1790782314673_healthcare-integration-compliance-review-at-clinic

 

Yes, CalenDoc can be embedded or connected to practice management systems in France, through a white-label widget or through API connectors. The embed route works within days for most single-site practices, while an API or SAS integration requires more planning and IT involvement. Clinics should confirm HDS and GDPR compliance before launch, and check whether FHIR-based SAS interoperability applies to their situation.


TL;DR:

  • Embedding CalenDoc via iframe takes a few days, making it ideal for single-site practices with straightforward scheduling needs.
  • API integrations require several weeks for technical setup, field mapping, and validation, suitable for multi-site or shared-calendar setups.
  • Practices in France must ensure hosting on HDS-certified infrastructure and formalize a processor contract to comply with GDPR, CNIL, and SAS/FHIR standards.
  • Using an outsourced secretariat allows staff to manage scheduling and access without technical development, easing compliance and operational workload.
  • Running SAS validation tests before going live prevents common errors like missing identifiers or incorrect status values, reducing rework.

Clicfone
clicfone.com
Simplify CalenDoc Appointment Management
 
Clicfone’s medical answering service manages calls and appointments through CalenDoc, with support tailored to healthcare professionals.

Discover Clicfone’s services

Table of Contents

Integration options at a glance: iframe, API, or secretary access

Three routes cover most integration needs, and the right one depends on how much technical work a practice wants to take on.

  • Iframe or widget embedding places a white-label booking calendar directly on the clinic’s own website, with no visible mention of the underlying platform, and it supports full booking and modification flows including on mobile devices.
  • API or connector integration allows appointment creation, updates, and availability synchronization between CalenDoc and another practice management or CRM system, along with patient identifier fields when two systems need to stay aligned.
  • Secretary or outsourced access gives staff or an external team a direct login to manage the calendar without any development work at all.

The iframe route typically takes a few days from request to a working embed, since it mostly involves branding and testing, as seen in the custom WordPress website with bespoke animations for medical software that showcases secure presentation options. API integration takes longer, often several weeks, because it requires field mapping, authentication setup, and testing against CalenDoc’s technical documentation. Secretary access can be operational within a day, since it depends on account setup and staff training rather than code. Practices with a single location and simple scheduling needs generally do well with the embed, while multi-site groups or those needing to share slots with national platforms tend to need the API path.

Technical and compliance essentials for France: HDS, GDPR, CNIL, and SAS/FHIR

Before any integration goes live, a French practice needs to confirm a short list of legal and technical points, since health data carries specific hosting and processing obligations that ordinary business software does not.

Hosting health data in France requires HDS certification, and the Agence du Numérique en Santé confirms that hosts must be certified by COFRAC-accredited bodies, with references available for verification. CalenDoc’s own documentation states that it hosts personal health data on HDS-compliant infrastructure through AWS Paris and declares GDPR compliance, with a designated data protection contact.

Health data compliance pathway illustration

On the contractual side, the CNIL’s practical guide for health professionals states that the relationship between a practitioner and a scheduling provider must be formalized in a processor contract, one that specifies processing strictly on instruction, confidentiality obligations for personnel, and technical security measures. This contract, sometimes paired with a data protection impact assessment for larger or riskier setups, is not optional paperwork: it is the legal basis for outsourcing any part of appointment management.

For practices connecting to the Service d’Accès aux Soins, the SAS INT_R03 specification sets out the required FHIR Appointment interactions and AppointmentStatus values, meaning any national-level slot sharing must follow this defined format rather than a custom one.

  • Confirm HDS certification status directly with the hosting provider before signing.
  • Insist on a signed processor contract covering instruction-based processing and security measures.
  • Check whether SAS/FHIR compliance is required for your region or care pathway.
  • Ask for encrypted hosting, role-based access controls, and audit logs as standard security features.

Step-by-step implementation: planning, embed, API, and secretary setup

A structured rollout avoids most of the friction that comes from skipping steps, particularly around compliance sign-off.

  1. Appoint a point of contact for data protection questions, gather proof of HDS certification from CalenDoc, and draft or review the processor contract before any technical work begins.
  2. Define the scope: a single-site embed is a much smaller project than a multi-site API integration feeding a shared calendar across several practices.
  3. For an iframe embed, request the widget code, test it on a staging page, apply white-label branding, and run through booking and modification flows on both desktop and mobile before publishing.
  4. For an API or SAS integration, obtain the technical documentation, map Appointment fields including identifiers and status values, configure secure authentication such as mTLS or OpenID Connect, and validate the setup against the SAS FHIR validator before moving from staging to production.
  5. For secretary access, assign roles, train staff on call-handling rules, and define escalation paths for urgent requests.

Pro Tip: Run the SAS validator against a handful of test appointments before touching production data: missing identifier fields are the most common reason an integration stalls at this stage.

Common pitfalls, testing checklist, and troubleshooting

Most integration problems fall into a handful of recurring categories, and catching them early saves a good deal of rework later.

  • Double bookings often trace back to a sync delay between two calendars rather than a configuration error.
  • Missing RPPS or ADELI identifiers on appointment records can block SAS validation entirely.
  • Incorrect AppointmentStatus values cause slots to appear available when they are not, or vice versa.
  • Timezone mismatches between systems create phantom gaps or overlaps in the schedule.

Before going live, run a full end-to-end test covering appointment creation, modification, and cancellation, confirm the setup passes SAS validation where relevant, and check that access logs correctly reflect each user’s role. Keep a record of any errors during testing so they can be shared quickly with CalenDoc’s support team or an integrator if a ticket becomes necessary. During the cutover period itself, a temporary phone triage process and a few buffer slots reduce the risk of a booking falling through the cracks.

How an outsourced medical secretariat eases CalenDoc integration

For practices that prefer not to manage the technical side directly, an outsourced secretariat offers a practical middle ground. An outsourced secretariat can offer specialized medical and paramedical phone reception and appointment management, with potential integration support for platforms like CalenDoc, Doctolib, LibreRDV, and Maiia.

  • Staff can typically gain calendar access after a setup period, without requiring development work.
  • The secretariat team can handle initial booking, patient call triage, and first-tier troubleshooting on day-to-day scheduling questions.
  • Compliance paperwork, including processor contract considerations, may be handled alongside operational setup.

Complex FHIR or SAS development still requires an IT resource or integrator. A secretariat handles the operational and compliance layer, not the underlying code.

Practical perspective: choose embed now, integrate later

The simplest path wins for most practices: embed first, and only build toward API or SAS integration once there is a clear need to share slots nationally or across multiple sites. A small clinic rarely needs FHIR compliance on day one, while a Maison de Santé coordinating several practitioners often does. When staffing is the bottleneck rather than the technology, bringing in an outsourced secretariat or an integrator solves the problem faster than more software ever will.

— Rudolph

How ClicFone can help with CalenDoc onboarding and ongoing operations

Setting up CalenDoc doesn’t have to mean pulling a practitioner away from patients to manage logins, branding, and staff training. Some providers handle that operational layer directly, offering services designed for medical and paramedical practices.

Clicfone

  • CalenDoc secretary access setup and day-to-day management, handled by trained staff familiar with medical scheduling.
  • Call and appointment management that keeps the calendar accurate while reducing administrative load on the front desk.
  • GDPR and HDS-aware handling of patient data throughout the booking process.

Practices that want to see how this works in their own setting can start with a short pilot. Visit the CalenDoc secretary access page to see how the service fits into an existing calendar setup.

Sources

FAQ

Does CalenDoc work with Google Calendar and Outlook?

CalenDoc is built around its own scheduling calendar rather than a two-way sync with Google Calendar or Outlook by default. Practices needing that kind of cross-platform sync should check current connector options directly with CalenDoc or an integrator, since capabilities can change.

Is CalenDoc GDPR compliant for French medical practices?

CalenDoc states in its knowledge base that it has been GDPR compliant since May 25, 2018. Practices still need their own signed processor contract, as required by CNIL guidance for health professionals.

How long does a CalenDoc integration take to set up?

An iframe widget embed can be tested and live within a matter of days, since it mainly involves branding and QA testing. A full API or SAS integration takes longer, often several weeks, due to field mapping, authentication setup, and validation steps.

What is HDS certification and why does it matter for CalenDoc?

HDS certification is the French requirement for hosting health data, verified through COFRAC-accredited bodies as explained by the Agence du Numérique en Santé. CalenDoc states its data is hosted on HDS-compliant infrastructure through AWS Paris.

Can an outsourced secretariat manage CalenDoc without IT help?

Day-to-day tasks like booking, call triage, and calendar access can be handled by an outsourced secretariat without development work, as with ClicFone’s CalenDoc secretary access service. Complex FHIR or SAS integration work still requires an IT resource or integrator.

author avatar
LibreRDV-ClicFone Télésecrétariat
ClicFone Télésecrétariat depuis 2010 au service des professionnels de la santé. Permanence téléphonique 7h/20h. Secrétariat téléphonique à distance pour médecins, paramédicaux ou autres praticiens de la santé. Secrétariat humain, empathique et formé aux agendas Doctolib, Maiia, CalenDoc ou LibreRDV mais aussi synchronisé avec Google Agenda, Calendly et Cal.com
Voir tous les articles