Getting Care Without Scattering Your File: What Your Health Journey Leaves Behind

Back to the blog
27 September 202613 min read

Introduction: the file you've never opened

You saw a doctor three weeks ago about back pain. You handed over your carte Vitale, collected a prescription, stopped by the local pharmacy where they know your name, then booked an X-ray online. Meanwhile, your watch recorded your restless nights, and you typed "lower back pain morning" into a search engine at two in the morning.

None of these actions is suspicious. Each one was perfectly reasonable. Strung together, however, they compose a medical narrative of a precision you have never reviewed, spread across seven or eight different entities, some of which are not bound by medical confidentiality.

Wooden letters spelling the word "consent" laid out on a table, with blurred green plants in the background

Health data is, alongside political opinions and sexual orientation, one of the categories the GDPR labels "sensitive" (Article 9). Processing such data is prohibited in principle, save for exceptions — and healthcare is obviously one of them. That isn't where the problem lies. The problem is everything orbiting around care: appointment-booking platforms, wellness apps, pharmacy loyalty cards, insurance health questionnaires, connected devices that measure without qualifying as medical devices.

This guide will never tell you to skip a test or lie to your doctor. It explains who sees what within the French system, what you can legally refuse, and the concrete steps that shrink your exposure.


Part 1 — Mapping the players: who actually holds what

The three circles of health data

Not everyone has access to the same information, and that is the first thing to grasp if you want to avoid tilting at the wrong windmills.

CirclePlayersWhat they seeMedical confidentiality
Care circleGP, specialists, hospital, pharmacist, laboratoryDiagnosis, prescriptions, results, medical historyYes, criminally enforced
Reimbursement circleAssurance Maladie, supplementary insurer, provident insuranceBilled procedures, CIP medication codes, dates, practitionersPartial, via the medical adviser
Peripheral circleBooking platforms, wellness apps, connected devices, health information sitesReported symptoms, specialties consulted, habits, physiological metricsNo

The third circle is the problematic one. It isn't illegal — it simply sits outside the protective regime of professional confidentiality. A single sleepless night recorded by a wristband isn't a diagnosis, but a series of thousands of insomnia measurements looks a great deal like medical information.

What the French social security system really knows

Assurance Maladie doesn't receive your diagnosis at every consultation. It receives a coded procedure: "general practitioner consultation," "radiology technical procedure," the fee, the date, the professional. The diagnosis is only passed along in specific cases — long-term condition status (ALD), sick leave, prior authorisation requests — and it is then handled by the medical service, which is separate from the administrative service.

Your reimbursements can be viewed in your ameli account, and reviewing them is a good habit: the history there is detailed over several months and constitutes, without you ever intending it, a medical timeline that anyone gaining access to your account could exploit.

What your supplementary insurer knows — and shouldn't

This is the most common blind spot. When a supplementary insurer reimburses a claim, it receives the nature of the procedure and, for medication, the box's CIP code. That code identifies the product precisely. A complementary insurer can therefore, technically, infer a chronic treatment from a pattern of repeat reimbursements, without ever reading a prescription.

The CNIL regulates this point: complementary organisations must process only the data strictly necessary to settle benefits, and detailed medical data must remain under the responsibility of a healthcare professional. In practice, checks do exist but grey areas persist, particularly around the health questionnaires presented when taking out provident or borrower insurance contracts.

Worth remembering: since the 2022 Lemoine Act, the medical questionnaire has been abolished for mortgages where the insured portion is below €200,000 per borrower and where repayment ends before the insured party turns 60. It is one of the rare legislative rollbacks of health data collection in France. Always check whether your situation qualifies before filling in anything.


Part 2 — Mon espace santé: understand the tool before fearing it

Rolled out at scale since 2022, Mon espace santé is a digital health record opened automatically for every insured person unless they opt out. It is hosted in France by a certified health data host (HDS), and access is locked behind strengthened authentication.

What you actually control

Contrary to a widespread belief, the tool leaves you considerable room for manoeuvre:

  • Masking documents: you can make a document invisible to healthcare professionals, except for the one who uploaded it and your registered GP.
  • Named blocking: you can bar access for a specific professional or facility.
  • Reviewing the access log: every time your file is opened it is logged and viewable. Get into the habit of reading it twice a year.
  • Closing the profile: possible at any time, with data retained for ten years and then deleted.

The limits to know about

Masking protects from view, not from existence. A masked document remains stored. Furthermore, in life-threatening emergencies certain override accesses exist — which is medically a good thing, but should be known.

The honest trade-off is this: a well-maintained shared medical record improves the safety of your care (drug interactions, allergies, duplicate tests). Blanket refusal carries a real health cost. The right stance isn't abstention, it's active management: record the essentials, mask the contextual, review the access log.


Part 3 — The third circle: where the real leaks happen

Finger entering an unlock code on a smartphone touchscreen

Appointment-booking platforms

Booking an appointment with a dermatologist isn't a medical act, but the reason for consultation you select from a drop-down menu is a formidable approximation of one. These platforms know which specialty you're consulting, how often, in which city, and sometimes why.

Good practices:

  • Choose the most generic reason available ("consultation," "follow-up") rather than the detailed one whenever the field allows it.
  • Use an email address dedicated to health matters, separate from your main address and your shopping accounts.
  • Decline the "partner communications" boxes: they have nothing to do with your care.
  • Delete your account after a one-off use rather than leaving it dormant with a history attached.

Wellness and tracking apps

A period-tracking, calorie-counting, meditation or sleep-monitoring app is almost never a medical device. It is therefore not bound by the same obligations as hospital software. The CNIL has issued several warnings about this sector, and cases of apps transmitting menstrual cycle or mood data to advertising networks have been documented repeatedly by the specialist press and European authorities.

Three questions before installing:

  1. Where is the data hosted? An HDS-certified host within the European Union is a positive signal.
  2. Does the app work without an account and offline? If so, that's the option to favour.
  3. Is the business model clear? A free app with no visible advertising and no subscription should give you pause.

For many uses, the most discreet medium remains the simplest. A paper health-tracking notebook syncs with nothing, can't be hacked remotely and slips into a drawer. For blood pressure, an upper-arm monitor without Bluetooth does exactly the same clinical job as a connected model, without creating an account or an outbound data stream.

Wrist-worn connected devices

A watch that measures heart rate, oxygen saturation and heart rate variability produces a continuous physiological stream. This data isn't medical in the regulatory sense, but it enables inferences: stress, alcohol consumption, pregnancy, sleep apnoea.

Minimum settings to adjust the very first time you switch it on:

  • Disable data sharing "to improve the product" and "for research purposes."
  • Refuse background geolocation when it isn't needed for sports activity.
  • Check, in the linked account, the data download and deletion tab required by the GDPR.

Part 4 — The pharmacy, the place everyone forgets

Pharmacists are bound by professional confidentiality, and the pharmaceutical record — which lists medication dispensed over the past four months — is a genuine safety tool against dangerous interactions. Even so, you can:

  • Refuse to have the pharmaceutical record updated on a one-off basis, for a given dispensing. The pharmacist must take this into account.
  • Decline the pharmacy loyalty card: it links purchases of supplements, intimate hygiene products or smoking-cessation aids to your identity, entirely outside any framework of medical confidentiality.
  • Pay in cash for over-the-counter purchases you'd rather not see appear on a bank statement readable by your bank, your partner or any third party with access to your account.
  • Avoid online orders for the most revealing products: home delivery creates an address trail, a named parcel and a purchase history kept for years.

On that last point, one material detail matters: parcel labels remain legible in communal bins. A small cross-cut shredder placed next to the wastebasket solves in ten seconds a problem that is widely underestimated.


Part 5 — Teleconsultation, information searches, messages

Hand holding a smartphone in a textured black case in front of a venetian blind

Teleconsulting cleanly

Teleconsultation is a fully fledged medical act, regulated by Assurance Maladie. The practitioner is bound by confidentiality; the technical platform, for its part, must be hosted with an HDS-certified provider. A few precautions are worth taking:

  • Consult from a place where no one can overhear. The shared wifi of a coworking space or a hotel lobby is not a consulting room.
  • Prefer a wired headset over a speaker: the most common leak in teleconsultation is acoustic, not digital.
  • Check that your prescription is sent through a secure channel (Mon espace santé, secure health messaging) and not by ordinary email.
  • Be wary of platforms offering a very detailed preliminary questionnaire with no identified doctor behind it.

If you often work from shared spaces, a privacy screen filter prevents a test result from being displayed for the person at the next table. It's a mundane accessory that solves a very real blind spot.

Searching for information without being profiled

Typing a symptom into a search engine is one of the most monetised signals on the web. Ad networks derive "health" audience segments from it with uncomfortable granularity.

  • Use a search engine that doesn't keep a history tied to an account.
  • Turn first to institutional sources: Ameli, Santé publique France, la Haute Autorité de santé, Vidal for drug leaflets, l'ANSES for nutrition and environmental exposure. They don't resell your curiosity.
  • Avoid health forums where you're identifiable: a username reused elsewhere links an intimate account to your real identity.

Passing on sensitive information

Sometimes you need to convey health information to a relative, an employer or an organisation without exposing your identity or your phone number. Reporting an exposure to a contagious illness, warning a partner, flagging a worrying medical situation to a service: these are situations where sending an SMS with the sender hidden lets you say what needs saying without opening a permanent channel back to you. The principle is the same as everywhere else on this site: pass on the useful information, not the identifier that will follow it around for ten years.


Part 6 — Your rights, in practice

The GDPR and the French Public Health Code give you real levers — you just have to use them.

RightWhat you can doLegal deadline
Access to your medical fileRequest a full copy from the facility or practitioner8 days (2 months for data older than 5 years)
GDPR access to a health appDemand all data held about you1 month
ErasureRequest deletion from a non-care player (app, platform)1 month
ObjectionRefuse unnecessary processing (marketing, research)Immediate
ComplaintFile with the CNIL online in case of refusal or silence—

Always put it in writing, with a record: an email is enough, though registered electronic mail is better for contentious cases. Keep the replies. If you hear nothing once the deadline has passed, filing with the CNIL is free and takes just a few minutes.

To dig deeper into the legal mechanics, a pocket-format practical guide to the GDPR makes the subject far less opaque than reading the regulation raw, particularly on the distinction between data controller and processor, which determines who to address your requests to.


Part 7 — The routine in seven steps

Do these once, then review them once a year:

  1. Read the access log of Mon espace santé and block facilities you no longer have any connection with.
  2. Create a dedicated email address for health matters, never used anywhere else.
  3. Audit your installed apps: uninstall the ones you no longer use and request deletion of the associated accounts.
  4. Check the sharing settings on your connected watch or wristband.
  5. Refuse non-mandatory health questionnaires, first checking whether the Lemoine Act applies to your situation.
  6. Clear out paper prescriptions kept for no reason, and destroy those no longer needed.
  7. Lock physical access to the phone holding your health apps: a six-digit passcode at minimum, biometrics enabled, notifications hidden on the lock screen.

For documents you must keep — test reports, X-rays, insurance files — a securely fastened storage folder in a locked drawer beats a pile on the desk. Physical security remains the link we neglect, believing everything is decided online.


Conclusion: treating the body without exposing the person

Compared with many others, the French health system is rather protective: criminally enforced medical confidentiality, certified hosting, CNIL oversight, and an Assurance Maladie that doesn't see your diagnoses. That is not where the leak occurs.

It occurs at the margins: in the overly specific appointment reason, in the free app installed on a Sunday, in the pharmacy loyalty card, in the insurance questionnaire filled in without reading it, in the watch sending heart rhythms to a server whose address you don't know.

The good news is that this margin can be narrowed with no medical cost: none of the steps described here degrades the quality of your care. They simply restore a distinction that digitisation has erased — the one between what your doctor needs to know and what the rest of the world has no reason to learn.

#Vie privée#Confidentialité#RGPD#CNIL#Sécurité#Anonymat

On the same topic

// Anonymous SMS · Hidden number · To France

Envoyez votre message, gardez l'anonymat

Votre numéro reste masqué, aucune inscription, aucune trace. Rédigez, confirmez, et votre SMS part de façon totalement anonyme.

Envoyer un SMS anonyme