Getting Care Without Undressing Digitally: Your Health Data — Who Really Sees It?

Back to the blog
29 August 202612 min read

Introduction: the appointment that never ends

You walk into a doctor's office. Twelve minutes later you walk out with a prescription. You feel you've had a private conversation, protected by a duty of confidentiality twenty-five centuries old.

During those twelve minutes, a booking platform recorded your name, your phone number, the speciality consulted and the time slot. A practice management application created a row in a database hosted who-knows-where. An electronic claim form went off to your health insurance fund, then to your top-up insurer. Your visit to the pharmacy wrote the name of the molecule into a pharmaceutical record. Your phone, still in your pocket, logged a location at that address — and if you'd searched for "symptoms" the night before in an ordinary browser, an ad network already knows something about it.

Man in a blue hoodie in front of a laptop in the dark

We've already written here about the traces left by your payments and by your communications. Health data forms a third layer, and by far the most sensitive one: the GDPR classifies it among the "special category" data of Article 9, alongside political opinions or sexual orientation. It doesn't expire, it can't be taken back, and it tells a story that no employer, no insurer and no relative should ever be able to read by accident.

This guide isn't an invitation to flee the healthcare system — that would be absurd and dangerous. It offers a way to know who sees what, what the law actually requires, and which simple steps shrink your exposure without harming your medical follow-up.


Mapping it out: the seven places your health ends up

1. The practitioner's file

This is the foundation. Doctors are required to keep a file; in practice it lives inside practice management software. These vendors increasingly host in the cloud, which in France requires HDS certification (Hébergeur de Données de Santé — certified health data host**)** issued under the supervision of the Agence du Numérique en Santé. It's a genuine technical guarantee — not a guarantee of absolute watertightness.

2. The national health insurance system

The electronic claim form sends your fund: identity, practitioner, coded procedures, date. Reimbursements appear in your Ameli account. This database is one of the richest in Europe; its pseudonymised data feeds the Système National des Données de Santé (SNDS), access to which for research purposes is governed by the CNIL and the Health Data Hub.

3. Your top-up or complementary insurer

This is the link most often underestimated. To reimburse you, a complementary insurer receives information of a medical nature. It must only know what is necessary to calculate the reimbursement, and the CNIL has repeatedly stressed that the collection of detailed pathology information by complementary insurers is strictly limited. In practice, the nature of the procedure (specialist consultation, medical device fitting, session with a psychologist) still says a great deal.

4. The pharmacy and the pharmaceutical record

Every dispensation can be recorded in the Dossier Pharmaceutique, managed by the Ordre national des pharmaciens, in order to detect drug interactions. Useful — and refusable: opening it requires your consent, and you can ask for it to be closed.

5. Mon espace santé

Opened by default since 2022 for all insured people, it centralises documents, discharge summaries and prescriptions. You can hide a document from certain professionals, refuse automatic feeding of the record, or close the service entirely. Few people know these three options exist.

6. Booking and teleconsultation platforms

They are not healthcare professionals but technical processors. They know who consults whom, when and for which speciality. Simply booking an appointment in addiction medicine, psychiatry or at a screening centre is in itself health data.

7. Your apps and connected devices

This is the black hole. A period-tracking app, a sleep tracker, a connected scale, a blood glucose log: most are not medical devices and have no obligation to use certified hosting. Their privacy policies often permit sharing with analytics "partners".


What medical confidentiality protects — and what it doesn't

Professional secrecy is defined by Article L.1110-4 of the French Public Health Code and is a criminal offence to breach (Article 226-13 of the Penal Code). It is general and absolute: it covers everything the professional has seen, heard or understood.

But it protects people, not infrastructure. Three blind spots are worth knowing:

Medical confidentiality prevents neither sharing between caregivers within the same care team, nor the transmission of administrative data to paying bodies, nor leaks resulting from an intrusion into a hospital IT system.

Sharing within the care team. Professionals involved in your care may exchange information that is "strictly necessary". You can object to this, item by item.

Cyberattacks. French hospitals have been targeted repeatedly in recent years, and ANSSI regularly publishes alarming assessments of the health sector. In 2021, the leak of laboratory test results concerning hundreds of thousands of people showed that published data never comes back.

Non-caregiving third parties. Employers, mortgage insurers, landlords, social administrations: none has any right to the diagnosis. Even the occupational health doctor only sends the employer a fitness opinion, never a reason.


Improper requests: the list of what you can refuse

Who's askingWhat they can legitimately obtainWhat you can refuse
EmployerA sick note without a stated reason, a fitness opinionThe diagnosis, the name of your GP, a detailed certificate
Mortgage insurerA health questionnaire (regulated, with a right to be forgotten)Direct access to your file or to Mon espace santé
Top-up insurerThe data necessary for reimbursementDetailed pathology information beyond what is necessary
LandlordNothing at allAbsolutely everything
Booking platformYour contact details and the reason for the appointmentThe creation of an advertising account, targeted marketing
Gym, personal trainerNothing medicalA detailed certificate, access to your connected device data

On mortgage insurance, it's worth recalling the loi Lemoine of 2022: the health questionnaire has been abolished for many home loans, subject to conditions on the amount and on your age at the end of repayment, and the oncological right to be forgotten has been shortened to five years. A major privacy advance that many borrowers still don't know about.


The weak link: your phone and your searches

Before seeing a doctor, we search. And that search comes before the diagnosis, sometimes by several weeks.

Woman typing on a laptop showing a team messaging app with online conversations

A query about an intimate symptom, typed into an ordinary browser, logged into an account, on an identifiable home network, is a dated and attributable event. Three habits change the picture radically:

  • Keep your health browser separate from everything else. A browser dedicated to sensitive searches, with no account signed in, using a search engine that doesn't keep history tied to an identifier. The principle of compartmentalisation we detail elsewhere on this site applies here in full.
  • Beware of public forums. Describing your symptoms under a pseudonym you reuse elsewhere amounts to publishing your medical file. A health pseudonym must be disposable and unique.
  • Verify before you believe. Reliable sources exist: Ameli, the Haute Autorité de Santé, Vidal, Santé publique France, and ANSES for food and environmental exposure. For readers who want an offline reference point, a family medical dictionary in paper form remains surprisingly effective and transmits strictly nothing to anyone.

Think about notifications too. A medication reminder appearing in plain text on your lock screen, in a meeting room, is a disclosure. The "hide sensitive notification content" setting exists on both major mobile systems; it takes thirty seconds.


Teleconsultation: the room, not just the platform

Teleconsultation has moved the doctor's office into your living room — along with the leaks that come with a living room.

  • The background talks. A blurred or neutral background avoids revealing your home's interior, the presence of children, or your standard of living. A folding office partition or a plain backdrop is enough.
  • Sound travels. In a flat or an open-plan office, noise-cancelling headphones with a directional microphone protect your confidentiality as much as your neighbours'.
  • A laptop camera is always on somewhere. A stick-on webcam cover, for two euros, settles the question for good once the consultation is over.
  • The network matters. Avoiding public Wi-Fi for a medical consultation is common sense; your carrier's 4G/5G is generally preferable.

Finally, check that the platform used is indeed an HDS-certified host and that it displays a data protection officer. Serious platforms state it in black and white.


Health apps: the question to ask before installing

An app for tracking periods, fertility, mood or addiction collects data that, in certain foreign legal contexts, has already been used as evidence. The question is not theoretical.

Hands typing on a multicoloured backlit keyboard in a dark room

Three sorting criteria, in order:

  1. Does the data stay on the device? Apps offering 100% local storage, with no account and no sync, exist in almost every category. They are the reasonable default choice.
  2. Is there a visible business model? A free app, with no visible ads and no subscription, has to be funded somehow. Reselling aggregated data is the most common model.
  3. Is deletion actually effective? The GDPR gives you a right to erasure. Test it before you accumulate three years of history.

For many uses, the analogue alternative remains unbeatable. A paper blood pressure log next to an approved upper-arm blood pressure monitor produces exactly the same medical value as a connected app — with no account, no cloud and no terms of service. Your doctor reads a handwritten table perfectly well.


Your rights, in practice, and how to exercise them

The GDPR and the Public Health Code give you real levers. You still have to use them.

Accessing your medical file

You can request the full disclosure of your file from the practitioner or the institution, by registered letter, with a copy of an ID document. The legal deadline is eight days (two months for information more than five years old). No reason needs to be given.

Taking back control of Mon espace santé

Within the service, three key actions: hide a document from all professionals, block access for a specific professional, or close the profile. Closing it doesn't erase health insurance reimbursements, but it does remove the centralisation of documents.

Closing a pharmaceutical record

An oral or written request at the pharmacy. The pharmacist is required to act on it.

Objecting to sharing within the care team

State it explicitly, orally and then in writing in the file: "I object to the transmission of such-and-such information to such-and-such professional." The refusal must be recorded.

Filing a complaint with the CNIL

In the event of improper collection — a top-up insurer demanding a diagnosis, an employer requiring a detailed certificate, an app refusing erasure — the online complaint to the CNIL is free and leads to an investigation.


Paper too: the forgotten link

We protect servers and leave prescriptions lying around.

Test results received by post, imaging reports, reimbursement statements, medication leaflets: it all piles up in a drawer and then goes out with the rubbish, intact, in a transparent bag left on the pavement. Waste sorting has made document scavenging easier than it has ever been.

A cross-cut shredder settles the matter in a few seconds per sheet — and works just as well for bank statements and administrative post. For what needs to be kept (long-term condition files, long-term follow-ups, X-rays), a closing document wallet stored away from shared spaces is better than a pile on the living room sideboard.

Finally, a piece of advice rarely given: avoid writing a medical reason in the "reference" field of a bank transfer or payment. That line will survive ten years in a banking database we've already described elsewhere on this site.


A ten-point protocol

  1. A dedicated browser, with no account signed in, for every symptom search.
  2. A unique, disposable pseudonym for any forum or support group.
  3. Sensitive notifications hidden on the lock screen.
  4. Health apps: local storage by default, otherwise none at all.
  5. Mon espace santé: actively configured, not passively accepted.
  6. Pharmaceutical record: opened knowingly, closable.
  7. Teleconsultation: neutral background, headset, controlled network, HDS platform.
  8. Documented refusal of unfounded requests (employer, landlord, top-up insurer).
  9. Medical papers shredded, not binned.
  10. No medical reason in a bank reference, an email subject line or an unprotected text message.

Conclusion: confidentiality is part of care

A patient who fears that their confidences will leave the consulting room tells their doctor less. That is true of mental health, addiction, sexuality and domestic violence. Confidentiality is therefore not a peripheral concern for activists: it is a condition for quality care, recognised as such by lawmakers since the loi Kouchner of 2002.

The paradox of 2026 is that the tools that smooth the care journey — platforms, apps, shared records — are also the ones that scatter the information. The answer is neither blanket refusal nor resignation, but informed use: accepting what serves your care, refusing what serves only data collection, and knowing at all times where the copy is.

You don't have to choose between being well cared for and remaining the owner of your own story. On this particular ground, French and European law is on your side. You just have to use it.

Sources and references: French Public Health Code (art. L.1110-4, L.1111-7), Penal Code (art. 226-13), GDPR (art. 9), CNIL, Ameli, Haute Autorité de Santé, Agence du Numérique en Santé, Ordre national des pharmaciens, ANSSI, law no. 2022-270 known as the loi Lemoine.

#Vie privée#Confidentialité#RGPD#CNIL#Cadre légal#Sécurité#Anonymat

On the same topic

Renting a Home Without Undressing: What a Landlord Has No Right to Ask You

Renting a Home Without Undressing: What a Landlord Has No Right to Ask You

Rental application, guarantor, viewing: house-hunting has become one of the moments when we hand over the most personal data. Here is the legal list of documents that can be required, the practices that are banned, and the methods for applying without exposing everything.

13 min read

// Anonymous SMS · Hidden number · To France

Envoyez votre message, gardez l'anonymat

Votre numéro reste masqué, aucune inscription, aucune trace. Rédigez, confirmez, et votre SMS part de façon totalement anonyme.

Envoyer un SMS anonyme