Before signing any outsourced secretariat contract, a healthcare controller must have six non-negotiable items in place. These requirements address the core obligations of health data protection and confidential health data management under GDPR Art.28 and applicable health-data hosting rules:
- Art.28-compliant subcontracting contract covering scope, data categories, instruction-only processing, confidentiality, and sub-subcontracting restrictions
- HDS certification or national equivalent confirming the provider hosts health data on qualified infrastructure, with transfers outside the EU governed by appropriate safeguards
- Documented access controls and MFA (or CPS card where applicable) for all staff handling patient records
- Encrypted backups, stored offline, with tested restores and documented RTO/RPO targets
- Incident response SLA including a written notification timeline and data-restitution process at contract end
- Audit and inspection rights written into the contract, not merely referenced
Clicfone operates as a compliant outsourced medical secretariat option, integrating these requirements into its contractual and operational framework for healthcare practices across Central Europe.
Key Takeaways
Secure outsourcing of medical secretariat services requires an Art.28-compliant contract, verified HDS or equivalent hosting, tested offline backups, and active controller oversight maintained throughout the contract lifecycle.
| Point | Details | ||||
|---|---|---|---|---|---|
| An Art.28-compliant contract is mandatory | The contract must cover scope, confidentiality, sub-processor restrictions, audit rights, and a documented data-return clause. | ||||
Table of Contents
- What must the Art.28 contract include for outsourced health data?
- What technical security measures must an outsourced secretariat implement?
- How should controllers supervise an external secretariat?
- How should incident response and ransomware preparedness be structured?
- What operational rules must external secretaries follow daily?
- Vendor verification checklist for outsourced medical secretariat procurement
- How Clicfone approaches data security for outsourced medical secretariat services
- Why active oversight matters more than a signed contract
- Clicfone: a trusted partner for compliant medical secretariat outsourcing
- Sources
- FAQ
What must the Art.28 contract include for outsourced health data?
The contract is the legal foundation of secure medical record outsourcing, and its content is not discretionary. Under Art.28 GDPR, the agreement must specify the subject matter and duration of processing, the nature and purpose of the work, the categories of personal data involved (in this context: patient identifiers, appointment details, and any clinical notes relayed by phone), and the obligations and rights of the controller.
Beyond the standard Art.28 skeleton, health-data-specific clauses must address three additional areas. First, the HDS referential sets contractual and technical obligations for any provider hosting health data, including backup responsibilities and strengthened rules for transfers outside the EU. If the provider or its infrastructure sub-processes data outside the EU, the contract must name the transfer mechanism (Standard Contractual Clauses or an adequacy decision) and document it. Second, the contract must specify data return or secure deletion at contract end, with a verifiable record of that process. Third, sub-subcontracting must be either prohibited or subject to prior written authorization, with the same obligations flowing down.
CNIL recommends that controllers include explicit audit rights and require the subcontractor to provide security policies and evidence of guarantees, rather than relying on contract text alone.
Sample clause language to adapt:
- Scope: “The processor shall process personal health data solely on documented instructions from the controller, limited to appointment scheduling and patient call management.”
- Audit right: “The controller reserves the right to conduct or commission audits of the processor’s security measures, with reasonable notice, no more than once per calendar year unless an incident warrants additional review.”
- Sub-subcontracting: “The processor shall not engage a sub-processor without prior written authorization from the controller. Any authorized sub-processor is bound by the same data-protection obligations.”
- Data restitution: “Upon termination, the processor shall return all personal health data in a documented, machine-readable format within 30 days and certify secure deletion of all copies.”
Red flags to watch for: missing audit rights, vague language on transfers (“data may be processed internationally”), one-sided indemnity clauses, and no documented data-return process.
What technical security measures must an outsourced secretariat implement?
The minimum technical baseline for external health administrative security covers five control categories. CNIL’s subcontractor guide lists pseudonymization, encryption, resilience, and restore capability as required technical and organizational measures for subcontractors.
| Control category | What to demand | Evidence to request |
|---|---|---|
| Authentication | MFA for all staff; CPS card where applicable | Policy document, access log sample |
| Encryption | Encryption at rest and in transit | Technical specification, certificate scan |
| Backups | Offline copies, tested restores, documented RTO/RPO | Last restore-test report with date |
| Access logging | Full audit trail per user session | Sample log extract, retention policy |
| Network protection | Firewall, endpoint hardening, patching schedule | Vulnerability scan summary, patch log |
| Incident response | Written plan with notification timelines | Signed incident response plan |
The PGSSI security guide specifically recommends encrypted and offline-tested backups, continuity planning, and documented restore tests for healthcare practices. Availability, confidentiality, and integrity map directly to Art.32 obligations and HDS objectives.
Technical checklist for RFPs:
- Confirm encryption algorithms and key management procedures
- Request the most recent backup restore-test report (dated within 12 months)
- Verify that backup copies are not reachable from the production network
- Obtain a penetration-test summary or SOC report (ISO 27001 shows control maturity but does not replace HDS certification where HDS is required)
- Confirm patching cadence and endpoint management policy
Pro Tip: When verifying offline backups, ask the provider to demonstrate that the backup storage network segment has no live routing path to the production environment. A restore test report is necessary, but network segmentation evidence is what confirms ransomware cannot reach the backup copies.
How should controllers supervise an external secretariat?
A signed contract does not transfer the controller’s responsibility. As a practitioner-level guide confirms, the medical practitioner remains the controller, must maintain the processing register, and must verify that hosting providers hold HDS certification or an equivalent national credential.
The register of processing activities must include, for the outsourced secretariat function: the processing purpose (appointment management, patient call handling), the data categories processed, the retention periods, the identity and contact details of the processor, and any transfers outside the EU with their legal basis. Supplier mapping, meaning a documented list of all processors and sub-processors, sits alongside the register and must be updated whenever a provider changes its infrastructure or sub-processors.
A Data Protection Officer (DPO) designation is required for healthcare practices processing health data at scale; smaller practices may access a mutualized DPO through a professional association. Either way, the DPO must be consulted before signing a new outsourcing contract and when conducting a Data Protection Impact Assessment (DPIA). A DPIA is warranted when the outsourcing introduces large-scale processing of health data or systematic monitoring of patients.
Audit and oversight checklist:
- Annual security review of the provider (questionnaire plus document review)
- Ad-hoc audit following any security incident or major infrastructure change
- Quarterly review of access logs and staff training records
- Annual confirmation that HDS certification (or equivalent) remains current in the official directory
- Documented evidence file: audit reports, penetration-test summaries, backup-test records, training logs
How should incident response and ransomware preparedness be structured?
The provider must supply a written incident response plan before go-live, not after an incident occurs. That plan must specify RTO and RPO targets, notification timelines, and the agreed data-restitution process. The PGSSI guide requires continuity planning with documented restore tests and an end-of-service data return procedure.
| Phase | Responsible party | Maximum timeline |
|---|---|---|
| Detection and initial containment | Provider | Within 4 hours of discovery |
| Initial notification to controller | Provider | Within 24 hours of detection |
| GDPR breach notification to authority | Controller | Within 72 hours of awareness |
| Full forensic report | Provider | Within 15 days |
| Service restoration (RTO target) | Provider | Per agreed SLA (typically 4–24 hours) |
| Post-incident review | Both parties | Within 30 days |
For ransomware specifically, verify that backup copies use immutable snapshots, that restore procedures are tested at least annually, and that the contract includes a clause covering legal and forensic support costs. Patient notification obligations, where applicable under national health-code provisions, must also be addressed in the plan.
Pro Tip: Schedule a tabletop exercise within 90 days of contract signature and require the provider to supply written evidence of at least one full restore test per year. Providers who resist tabletop exercises are signaling that their plan has not been validated in practice.

What operational rules must external secretaries follow daily?
Day-to-day confidential health data management depends on staff discipline as much as technical controls. The PGSSI guide explicitly prohibits consumer-grade storage and standard email for identifiable medical documents, recommending MSSanté or an HDS-hosted secure messaging solution for all clinical exchanges.
Non-negotiable operational rules:
- Least-privilege access: each secretary accesses only the patient records and scheduling systems required for their assigned tasks
- No shared accounts: individual login credentials for every staff member, with session timeouts of no more than 10 minutes of inactivity
- Written confidentiality obligations: signed NDA or confidentiality clause for every staff member, renewed annually
- MSSanté or equivalent for all clinical message exchanges; no consumer email or generic cloud storage for identifiable patient data
- Printed documents containing patient data must be stored in locked cabinets and shredded when no longer needed
Quarterly training topics the provider must demonstrate:
- Medical confidentiality obligations and legal consequences of breach
- Phishing recognition and social engineering awareness
- Correct use of secure messaging (MSSanté or equivalent)
- Secure handling and disposal of printed patient documents
Vendor verification checklist for outsourced medical secretariat procurement
Use this checklist during procurement to verify a provider quickly. The PGSSI supplier questionnaire annex provides concrete questions to include when verifying HDS status, backup architecture, and transfer safeguards.
Minimum evidence to request:
- Current HDS certificate (or national equivalent) with listing in the official ANS directory — confirms qualified health-data hosting
- Recent ISO 27001 or SOC 2 audit report (within 24 months) — shows control maturity, does not replace HDS
- Last backup restore-test report with date — confirms tested recovery capability
- Named DPO or documented access to a mutualized DPO
- Signed Art.28 contract template for review before signature
- Documented transfer map showing any sub-processors and their locations
- Evidence of staff confidentiality agreements and training records
Onboarding timeline and sign-off milestones:
- Week 1–2: Contract review and signature; DPO consultation; register update
- Week 3–4: Technical onboarding; access provisioning; MSSanté or equivalent configuration
- Week 5: Test restore verification; tabletop exercise scheduling
- Week 6: Go-live with monitoring; first access-log review within 30 days
Red flags that warrant refusal or deeper review: no HDS certificate or refusal to share it, audit rights absent from the contract, no documented data-return process, shared staff accounts, or inability to produce a restore-test report.
How Clicfone approaches data security for outsourced medical secretariat services
Clicfone’s approach to health data protection aligns with the checklist above across contractual, technical, and operational dimensions. Practices working with Clicfone receive an Art.28-compliant contract covering scope, confidentiality, sub-processor restrictions, and data-restitution terms. Staff handling patient calls operate under individual accounts with session controls and signed confidentiality obligations, and scheduling integrations with platforms such as Doctolib, LibreRDV, Maiia, and CalenDoc are configured to minimize data exposure at each interface.
What Clicfone provides as standard:
- Art.28 contract with audit rights and documented data-return clause
- Staff trained on medical confidentiality, phishing, and secure messaging protocols
- Integration with Doctolib and equivalent scheduling platforms under access-controlled, need-to-know configurations
- Documented onboarding process with milestone sign-offs aligned to the timeline above
- Availability of security documentation (training records, access policies) for controller audits
Practices should verify Clicfone’s current certification status in the relevant official directory and request the security documentation pack, including the most recent backup-test evidence and staff training records, before go-live. For practices ready to evaluate fit, Clicfone’s medical telephone secretariat service page outlines the full offering and next steps for requesting a tailored compliance pack.
Why active oversight matters more than a signed contract
The most common gap in outsourced secretariat arrangements is not a missing clause. It is the absence of follow-through after the contract is signed.
Governance frameworks and regulatory guidance consistently show that controllers who treat the signed Art.28 agreement as the end of their compliance work are the ones who face the most exposure when an incident occurs. A contract that permits audits but where no audit has ever been conducted provides limited protection. A backup clause that has never been tested against a real restore scenario offers no operational assurance. The practices that navigate incidents with the least disruption are those that have run tabletop exercises, reviewed access logs quarterly, and confirmed annually that their provider’s HDS certification remains current.
The CNIL guidance on subcontracting makes this explicit: controllers must verify guarantees actively, not rely on contract text alone. That verification discipline, applied consistently, is what separates a defensible compliance posture from a paper one. Requesting Clicfone’s security pack or a governance checklist for procurement is a practical first step toward that posture.
Clicfone: a trusted partner for compliant medical secretariat outsourcing
Healthcare practices that have worked through the checklist above know exactly what a compliant outsourced secretariat must provide. Clicfone has delivered that standard for over 15 years, with more than half of its clients maintaining the partnership for over a decade.

The service covers telephone reception, appointment scheduling across Doctolib, LibreRDV, Maiia, and CalenDoc, patient call coordination, and emergency triage, all under a contract framework that includes Art.28 clauses, staff confidentiality obligations, and security documentation available on request. Flexible packages mean practices pay for the coverage they need without long-term lock-in, and the founding team remains directly accessible to every client.
Practices ready to verify fit can request a tailored security and compliance pack directly through Clicfone’s telesecretariat service page. For those evaluating the advantages of outsourcing before committing, that page provides a clear picture of what the service covers and what documentation is available for governance review.
This article is general information, not a substitute for advice from a qualified doctor. Consult a qualified healthcare professional about your own circumstances before acting on anything here.
Sources
The following official references provide the legal and technical detail underlying this article:
- Sécurité : Gérer la sous-traitance | CNIL
- Référentiel HDS — Exigences HDS v1.1 (France, HDS referential)
- RGPD et cabinet médical : guide pratique du praticien
Controllers should keep copies of all supplier audit evidence and check the ANS HDS directory annually to confirm that listed providers remain certified.
FAQ
What does Art.28 GDPR require in an outsourced secretariat contract?
The contract must specify the subject matter, duration, nature, and purpose of processing, the data categories involved, and the controller’s instructions. It must also include confidentiality obligations, sub-processor restrictions, audit rights, and provisions for data return or deletion at contract end.
Is HDS certification mandatory for an outsourced medical secretariat in Central Europe?
HDS certification is the French standard for health-data hosting and serves as the primary benchmark in Central Europe. Any provider hosting or processing identifiable health data must hold HDS certification or a recognized national equivalent, and controllers must verify that certification in the official ANS directory before contracting.
How often should a controller audit an outsourced secretariat provider?
An annual security review is the recommended minimum, covering the provider’s security policies, access logs, staff training records, and backup-test evidence. An additional ad-hoc audit is warranted after any security incident or major infrastructure change.
What messaging tools are permitted for clinical exchanges with an external secretariat?
MSSanté or an HDS-hosted equivalent is the required channel for clinical message exchanges. Consumer email services and generic cloud storage platforms are not permitted for identifiable patient data under PGSSI guidance.
Does Clicfone provide the documentation needed for a controller audit?
Clicfone makes security documentation available to controller practices on request, including staff training records, access policies, and onboarding milestone records. Practices should request this documentation pack before go-live and confirm its currency at each annual review.