Pass CNIL & ANS: Secure Messaging After Calls for French Secretariats

29 September 2026
1790476331605_secretary-reviewing-secure-healthcare-message

 

MSSanté remains the preferred secure channel for exchanging patient information after a phone call, with delivery to Mon espace santé when the patient holds an active profile. When neither is available, an encrypted attachment with the password sent through a separate channel, or an authenticated SFTP or HTTPS transfer, meets the expected standard. Every message should carry only the fields strictly needed, and the exchange should be logged.


TL;DR:

  • MSSanté remains the primary secure channel for professional exchanges and delivery to active Mon espace santé profiles, with fallback options like encrypted attachments or secure transfers.
  • Staff must verify recipient identities and channel availability, matching against appointment records before sending any messages to ensure compliance.
  • Post-call messages should include only essential information, such as appointment details and a contact route, avoiding clinical data unless justified and documented.
  • When MSSanté or Mon espace santé are unavailable, encrypt files and send passwords through separate channels using SFTP or HTTPS with verified identities and minimal content.
  • Proper operational controls, role-based access, signed agreements, and timely transfer of message content into patient records are crucial for maintaining compliance and confidentiality.

Clicfone
Support Secure Medical Communications
Clicfone provides specialised medical phone secretariat services, appointment management and personalised support for healthcare professionals.

Table of Contents

Which channels to use and when

MSSanté was built as a supervised national secure messaging space reserved for healthcare professionals. It relies on verified professional identities, a network of trusted operators, and hosting that meets HDS requirements, which together give a level of assurance that ordinary email cannot match. Because every mailbox belongs to a checked professional, a secretary sending a message through MSSanté already knows the recipient is who they claim to be. That trust model, described in the official ANS guidance on MSSanté, is the reason it sits at the top of the channel hierarchy for post-call exchanges.

Mon espace santé extends that same secure space to patients, but only under specific conditions. A message can reach a patient there only if the patient has an active profile with a valid national health identifier, and delivery behavior differs from professional-to-professional exchange: the patient receives a notification rather than an open inbox, and reply options are limited compared with a professional mailbox. Sending to an inactive or nonexistent profile will simply fail, according to ANS operational guidance on MSSanté and Mon espace santé exchanges, so confirming eligibility before sending is not optional.

Before any post-call message goes out, staff should run through a short check:

  • Confirm the recipient’s professional MSSanté address or the patient’s active Mon espace santé status.
  • Match the identity against the appointment record, not just a name spoken on the phone.
  • Choose the fallback path immediately if either channel is unavailable, rather than defaulting to email.

What belongs in a post-call message

An appointment confirmation or operational note needs far less detail than most staff assume. CNIL’s referential for medical and paramedical practices sets out a necessity and proportionality principle: a message should carry only what the recipient needs to act on it, nothing that satisfies curiosity or convenience.

For a typical post-call exchange, that means:

  1. A limited patient identifier sufficient for matching, such as a last name and date of birth, never a full clinical file reference.
  2. The appointment date and time.
  3. The location, room, or a scheduling link.
  4. A contact route for questions, such as a callback number.

Diagnoses, test results, or other clinical details have no place in a routine appointment message unless a documented clinical reason requires it, and even then the justification should be recorded. Practices should write these permitted fields into a short internal procedure and reflect the same limits in patient-facing information materials, so both staff and patients know what to expect in a message.

Pro Tip: Keep a one-page “allowed fields” reference near every phone station so new staff never have to guess what counts as too much detail.

Secure fallback methods when MSSanté or Mon espace santé are not available

Ordinary email and consumer chat apps were not built for health data, and CNIL treats them as a proportionate risk only when the message content is trivial. For anything involving patient identity or health information, CNIL’s practical guide on protecting personal data recommends encrypting the attachment, sending the decryption password through a separate channel such as SMS or a phone call. Choose transfer protocols that authenticate the server, such as SFTP or HTTPS.

A workable fallback sequence looks like this:

  • Encrypt the file, then send the password by a channel different from the one carrying the document.
  • Use an SFTP or HTTPS provider that authenticates its server and, where the provider stores health data, holds valid HDS certification.
  • Verify the recipient’s identity before sending, the same way MSSanté would.
  • Keep the content minimal and the retention period short, deleting the transient copy once it has served its purpose.

Avoid any provider that cannot guarantee protection equivalent to European standards, since that guarantee is part of what CNIL expects from any fallback method.

Operational controls for outsourced or in-house secretariat teams

Choosing the right channel solves only part of the problem. CNIL’s guidance on health-data formalities makes clear that a secure channel does not, by itself, make excessive disclosure compliant: the surrounding controls matter just as much.

A practice working with administrative staff or an outsourced secretariat should have:

  • Role-based access so each operator sees only the records needed for their task, never the full patient file by default.
  • A signed processor agreement (DPA) with any outsourced provider, plus a check of the HDS certification scope for any host used, since HDS certification covers specific hosting activities and must match what is actually being hosted.
  • Strong authentication, such as a professional card (CPS) or multi-factor login, paired with audit logging so every message can be traced later.
  • Regular training and a short script for handling call-to-message handovers, so operators follow the same steps every time.

Pro Tip: Ask any outsourced provider to show, not just describe, their access logs during onboarding, before signing anything.

Filing and retention: from secure message to permanent patient record

A secure message is a delivery step, not a storage solution. Once the recipient has received the appointment detail or operational note, the final content belongs in the patient management system, transcribed or imported by the staff member who owns that record, ideally the same day.

MSSanté mailboxes were never designed as a permanent archive; guidance from ANS is explicit that exchanged documents should move into the practice’s own software, and the transient message should then be deleted or marked resolved according to the operational instructions for MSSanté and Mon espace santé. A short written retention rule, naming who imports the note, when, and how the transient copy is purged, gives the practice something concrete to point to during an audit.

Secure message moving into patient record

A specialist secretariat’s view on secure messaging after calls

The most common failure is not a weak encryption choice. It is a secretary sending more detail than the message required because it felt safer to over-explain the appointment than to sound abrupt. Minimisation has to be trained, not assumed.

The second common mistake is having no fallback plan at all: a team that only knows MSSanté freezes the moment a recipient’s mailbox is unreachable. The fix is a written, rehearsed fallback sequence, not an improvised one.

The third is access that outgrows its purpose, where an outsourced operator retains visibility into records long after the task that justified it. Reviewing access on a fixed schedule, rather than never, closes that gap. None of these fixes require new technology. They require a documented habit, checked regularly.

— Rudolph

How an outsourced medical phone secretariat supports compliant post-call messaging

An outsourced telephone secretariat service can handle call intake, appointment scheduling, and patient coordination for medical and paramedical professionals who need those tasks managed reliably.

Clicfone

Bringing in an outsourced secretariat does not replace the compliance steps described above. It gives a practice a team that already applies them as routine: role limits set in advance, procedures documented rather than improvised, and fallback methods tested before they are needed rather than during a crisis.

  • Integration with scheduling platforms including Doctolib, LibreRDV, Maiia, and CalenDoc, so appointment confirmations flow from the same system the practice already uses.
  • Human operators trained specifically for healthcare calls.
  • Flexible packages with transparent pricing.

Practices weighing whether to build this discipline in-house or hand it to a specialist team can review the outsourced telephone secretariat service to see how appointment handling and secure messaging fit together in practice.

This article is general information, not a substitute for advice from a qualified doctor. Consult a qualified healthcare professional about your own circumstances before acting on anything here.

Sources

FAQ

Is MSSanté required for every message sent after a patient call?

No. MSSanté is the preferred channel for professional-to-professional exchanges and for delivery to an active Mon espace santé profile, but a compliant fallback such as an encrypted attachment with a separately sent password is acceptable when it is unavailable.

What happens if a patient has no active Mon espace santé profile?

Sending a message to an inactive profile will fail, so staff need to confirm eligibility before attempting delivery and switch to an encrypted fallback method when needed.

Can an outsourced secretariat handle secure post-call messaging on a practice’s behalf?

Yes, provided the provider signs a processor agreement, applies role-based access, and follows the same channel and minimisation rules described here. ClicFone’s call and appointment handling service builds these controls into its standard workflow.

author avatar
LibreRDV-ClicFone Télésecrétariat
ClicFone Télésecrétariat depuis 2010 au service des professionnels de la santé. Permanence téléphonique 7h/20h. Secrétariat téléphonique à distance pour médecins, paramédicaux ou autres praticiens de la santé. Secrétariat humain, empathique et formé aux agendas Doctolib, Maiia, CalenDoc ou LibreRDV mais aussi synchronisé avec Google Agenda, Calendly et Cal.com
Voir tous les articles