Any medical practice outsourcing phone reception or secretarial work must sign a written data processing agreement under Article 28 of the GDPR, add individual confidentiality commitments for each operator handling patient calls, and confirm HDS hosting compliance whenever health data touch the provider’s systems. Without these three elements, the practice, not the provider, carries the legal exposure.
TL;DR:
- Contracts must include detailed clauses on call processing purposes, data categories, instructions, security measures, sub-processing, and data deletion, with three supporting annexes.
- Each operator handling patient data should sign an individual confidentiality and secret professional attestation to ensure enforceable personal obligations.
- The provider must hold HDS certification for digital health data hosting when storing or transmitting health information within systems.
- Security annexes should specify concrete measures such as TLS 1.3 encryption, AES-256 at rest, multi-factor authentication, role-based access, and verified backups.
- Regular audits, breach reporting within 24 to 48 hours, and explicit data return or deletion procedures are essential for ongoing compliance management.
Table of Contents
- What Belongs in a Confidentiality Agreement for a Medical Secretary?
- Who Signs What: Roles Under Secret Professionnel
- What Security Measures Should the Contract Require?
- Clause Language You Can Adapt Right Now
- Managing the Contract After Signature
- Turning the Checklist Into an Onboarding Process
- Where Practice Managers Get This Wrong
- Working With Clicfone on Confidentiality-Ready Contracts
- Sources
- FAQ
What Belongs in a Confidentiality Agreement for a Medical Secretary?
A confidentiality agreement for an outsourced medical secretary is not a single document. It’s a data processing agreement (DPA) built around Article 28 of the GDPR, reinforced with individual confidentiality clauses and, where relevant, a hosting compliance annex tied to France’s HDS framework. Practice managers searching for a “confidentiality agreement” often expect one short form to sign. In reality, the contract needs to function as a compliance package, because any external processing of personal data creates a subcontracting relationship requiring a written contract under Article 28, with specific clauses the regulation makes mandatory, not optional.
Here’s the checklist to verify or draft a compliant contract for a telephone secretary or medical answering service:
- Subject, duration, and purpose: the contract states exactly what processing occurs (call handling, appointment booking, patient triage) and for how long.
- Nature and categories of data: patient names, phone numbers, appointment reasons, and any health information disclosed during calls must be listed explicitly.
- Controller instructions: the secretary or provider processes data strictly on the practice’s documented instructions, never on its own initiative.
- Security measures under Article 32: encryption, access controls, and incident response procedures need to appear in an annex, not a vague reference.
- Sub-processing rules: any tool or subcontractor the provider uses (a cloud host, an AI transcription service) requires prior authorization and disclosure.
- Deletion or return of data: what happens to call logs and patient records when the contract ends.
- HDS hosting proof: when health data are stored digitally, the hosting party must hold HDS certification under Article L.1111-8 of the Public Health Code, which sets stricter standards than general GDPR hosting.
- Business continuity plan: a PRA/PCA (disaster recovery and continuity plan) documented in the security annex, not promised verbally.
Demand three annexes with the signed contract: a description of the processing, a security measures document, and a current list of sub-processors. A model DPA built around these eight mandatory Article 28 items packed into three annexes is the structure most compliance-minded providers already use.
Who Signs What: Roles Under Secret Professionnel
The practice is the data controller. The secretary or outsourcing provider is the processor. That distinction matters legally: if a breach occurs, CNIL and any injured patient will look first at the controller, meaning the physician or practice manager who chose the provider and defined the processing terms.
French law adds a layer general GDPR guidance doesn’t cover. Professional secrecy under Article 226-13 of the penal code and Article L.1110-4 of the Public Health Code extends to collaborators, including secretaries who never touch a stethoscope but hear diagnoses, treatment plans, and appointment reasons every day. The physician is responsible for instructing staff and verifying they understand and respect that obligation.
A signed DPA alone doesn’t satisfy this. Best practice, and increasingly standard among careful providers, is requiring each individual operator to sign a personal confidentiality and secret professionnel attestation:
- It creates a direct personal legal link between the operator and the obligation, enforceable independently of the master contract.
- It survives staff turnover at the provider’s end without requiring contract renegotiation.
- It gives the practice a paper trail if an incident ever reaches a disciplinary board or court.
Ask for these attestations by name during contract negotiation, not as an afterthought.
What Security Measures Should the Contract Require?
Article 32 of the GDPR requires “appropriate” technical and organizational measures, but that word invites vague language in weaker contracts. Push for specifics instead. A properly built DPA for health data lists encryption standards, access logging, and continuity planning as named, verifiable items, not general assurances.
Concrete measures worth writing into the security annex:
- TLS 1.3 encryption for data in transit and AES-256 or equivalent for data at rest.
- Multi-factor authentication for any operator accessing patient records or call systems.
- Role-based access control limiting who sees what, by function.
- Access logs retained and reviewable on request.
- A tested PRA/PCA covering system outages and staff unavailability.
- Regular, verified backups with documented restoration tests.
Some providers already document these in practice. Example implementations show DPAs listing TLS 1.3 and AES-256 encryption alongside audit logs and breach procedures as standard contract content, which gives a useful benchmark when comparing proposals.
Pro Tip: Don’t accept “state-of-the-art security” as a standalone phrase. Ask for the pen-test report, the HDS certificate, or the annual audit attestation behind it. Operational proof convinces more than generic language, and it’s the difference between a contract that protects you and one that just sounds like it does.
If any data or call recordings are processed outside the EU, even briefly through a cloud tool, the contract needs Standard Contractual Clauses or an equivalent transfer mechanism, documented and dated. Don’t let this slide because the provider is French. A subcontractor further down the chain may not be.
Clause Language You Can Adapt Right Now
Handing counsel a blank page wastes time. Give them a starting point instead. These snippets reflect the structure CNIL recommends in its own model clauses for subcontracting agreements.
- Confidentiality clause: “The processor undertakes that only persons expressly authorized and bound by an individual confidentiality commitment will access patient data, and only to the extent necessary for the performance of the contract.”
- Breach notification clause: “The processor shall notify the controller of any personal data breach within 24 to 48 hours of becoming aware of it, providing sufficient detail to allow the controller to meet its 72-hour notification obligation to CNIL.” That tighter internal window exists because a 24 to 48 hour provider notification target leaves the practice enough runway to investigate before its own regulatory clock runs out.
- Sub-processor clause: “The processor shall maintain an up-to-date list of sub-processors, obtain prior written authorization from the controller before engaging any new sub-processor, and remain fully liable for their compliance.”
- End-of-contract clause: “Upon termination, the processor shall, at the controller’s choice, return or securely delete all patient data within 30 days and provide a signed certificate of deletion.”
Send these to your legal advisor as a starting draft, not a final answer. Every practice’s call volume, data flow, and platform integrations differ enough to warrant a real review.
Managing the Contract After Signature
Signing the DPA is the easy part. Managing it for the life of the relationship is where most practices lose track.
- Audit rights: the contract should specify a notice period (commonly 30 days), an audit frequency (at least annually), and confidentiality safeguards protecting both parties during the review.
- Breach workflow: the provider notifies the practice within 48 hours of any suspected incident, with a named contact responsible for the escalation.
- Data return and retention: define exactly what “deletion” means technically, and require written attestation, not just an email confirming it’s done.
- Liability allocation: negotiate which obligations, particularly confidentiality and security failures, remain uncapped rather than subject to a general liability ceiling.
None of this needs to be adversarial. A provider confident in its own compliance will usually welcome an annual audit request; it’s the ones who hesitate that deserve closer scrutiny before signing anything.
Turning the Checklist Into an Onboarding Process
Contract language means little without a verification step before go-live. Build this into onboarding:
- Request the DPA, the security annex, and the HDS attestation as a package, not three separate emails spread over weeks.
- Ask for the full list of named operators who will handle your line, along with proof each has signed an individual confidentiality commitment.
- Request a sample audit report or pen-test summary rather than a compliance statement alone.
- Confirm platform integrations (Doctolib, LibreRDV, Maiia, CalenDoc) route data through the documented processing terms, not a separate undisclosed workflow.
- Schedule a first access review and incident drill within 90 days of launch, then annually after that.
Pro Tip: Ask a potential provider how long its average client relationship lasts. A provider with a significant portion of clients retained long-term, as Clicfone reports for its own client base, has usually been through several audit cycles already and knows what a serious compliance review looks like.
Where Practice Managers Get This Wrong

The gaps I see most often aren’t dramatic. They’re small omissions that compound: a DPA missing one or two Article 28 items, a security annex that says “appropriate measures” without naming a single one, and zero individual confidentiality commitments from the actual people answering the phone. Each gap looks minor in isolation. Together they leave the practice, not the provider, holding the liability when something goes wrong.
Three requests close most of it: a DPA with all three annexes, written HDS proof if hosting is involved, and signed individual secrecy commitments from every operator. If a provider hesitates on any of these, that hesitation is the answer. For anything beyond this checklist, a data protection officer or a lawyer familiar with health-sector contracts earns their fee fast.
— Rudolph
Working With Clicfone on Confidentiality-Ready Contracts
A specialized provider in outsourced medical and paramedical telephone reception often has extensive experience with compliance conversations. The practical advantage for a practice manager: instead of chasing down a generic call center for documents it doesn’t have, you’re negotiating with a provider built specifically around the medical sector’s confidentiality demands from the start.

Clicfone’s remote medical secretary service integrates directly with Doctolib, LibreRDV, Maiia, and CalenDoc, and pairs trained human operators with clear data-handling terms rather than a one-size-fits-all script, benefiting from specialized Healthcare SEO Services to increase patient appointments and visibility. A provider with many years in the medical sector and a long-standing client base tends to have experience with multiple audit cycles. For practices also managing high call volumes or urgent triage needs, the urgent appointment triage and medical phone triage services run under the same contractual framework.
Before signing anything, request Clicfone’s DPA and security annex directly during contract discussions, and ask about a short pilot period to see the confidentiality safeguards in practice before committing long-term.

This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.
Sources
- Article 4 – Secret professionnel
- Contrat de sous-traitance RGPD : guide complet 2026 | DiliTrust
- Sous-traitance : exemple de clauses | CNIL
FAQ
Is a Verbal Confidentiality Agreement Enough for a Medical Secretary?
No. GDPR Article 28 requires a written contract whenever a third party processes personal data on a practice’s behalf, and a verbal agreement provides no enforceable evidence of the terms. French professional secrecy rules also expect documented instruction and commitment from staff, which a verbal understanding can’t demonstrate to CNIL or a court.
Does HDS Certification Apply to Every Outsourced Secretary?
HDS certification applies specifically to entities hosting health data digitally, so it becomes relevant whenever the provider stores, transmits, or processes patient information through its own systems. If the secretary only relays messages without storing data on separate infrastructure, the requirement may not apply the same way, but the contract should still document exactly where and how data are hosted.
What Happens if a Secretary Breaches Confidentiality?
A breach can trigger penal consequences under Article 226-13, professional sanctions for the physician who failed to properly instruct staff, and CNIL enforcement action against the practice as data controller. The physician’s responsibility to ensure staff understand and follow secret professionnel obligations makes this a shared liability, not just the individual secretary’s problem.
How Fast Must a Provider Report a Data Breach?
Contracts should require the provider to notify the practice within 24 to 48 hours of discovering an incident, which gives the practice enough time to investigate before its own 72-hour CNIL notification deadline expires. Waiting longer than that risks the practice missing its own regulatory window through no fault of its own.
Does Clicfone Provide a Signed DPA for Its Medical Secretary Services?
Clicfone structures its outsourced secretary services around the compliance documentation medical practices need, including data processing terms discussed directly during contract setup. Current pricing and contract details for services like remote secretary access are available by contacting Clicfone directly, since packages vary by practice size and call volume.