In brief: Article L. 1110-4 of the French Public Health Code requires every paramedical professional to maintain absolute secrecy regarding patient data, including assessments received via email or WhatsApp. As of 2026, this requirement is compounded by specific GDPR obligations and, for certain organizations, a requirement for HDS (Health Data Hosting) certification. Here is what this means in practical terms for a physiotherapist, osteopath, or psychologist in private practice.
Monday morning, your patient sends you her orthopedic surgeon’s assessment via WhatsApp. You save it on your iPhone, open it during the consultation, and discuss it with her. At the end of the session, the PDF remains in your camera roll, next to your weekend selfies. You close the office without giving it another thought.
I have seen this scene a thousand times while advising physiotherapists, osteopaths, and psychologists who wanted to modernize their practice. It seems harmless. However, it is a direct violation of Article L. 1110-4 of the Public Health Code, which imposes absolute secrecy on all health professionals—including paramedical staff—regarding information concerning their patients. And the ethical risk precedes the criminal risk.

What Article L. 1110-4 exactly states
The core of the text has not changed since it was written. It encompasses “any person receiving care from a health professional, an establishment or service, or a professional or organization contributing to prevention or care.” The wording is broad, intended by the legislator as such: it covers doctors, but also physiotherapists, osteopaths, podiatrists, psychologists, midwives, liberal nurses, and the entire paramedical chain.
« Any person receiving care from a health professional, an establishment or a service, or any professional or body involved in prevention or care whose terms of practice or activities are governed by this code (…) has the right to respect for their private life and the confidentiality of information concerning them. »
Article L. 1110-4 of the Public Health Code, 1st paragraph
Confidentiality covers all information « that has come to the knowledge of the health professional, any member of the staff of these establishments, services or bodies, and any other person in contact with these establishments or bodies by virtue of their activities ». In other words: a medical report received via WhatsApp does not exit the scope of confidentiality just because it was sent via messaging. It enters it.

What your everyday tools do with this confidentiality
WhatsApp is end-to-end encrypted for classic conversations. This is true, and it is useful. But this encryption protects the transmission. It says nothing about storage, professional/personal separation, backups, or the metadata that Meta retains on data flows. When your phone is backed up to iCloud or Google Drive, the medical report ends up with Apple or Google. Your patient data leaves the perimeter you control.
Gmail, Outlook, or Yahoo email inboxes are also unencrypted at rest, from the provider’s perspective. Google can technically read your emails — it has committed to no longer doing so for advertising purposes, but the architecture allows it. And Google remains an American company, thus subject to the Cloud Act.
As for Drive, Dropbox, and other OneDrive services: they have the same problems as email providers, only worse. A folder shared with “anyone with the link” becomes a security hole. I have seen psychological practices share patient reports on a Drive accessible to an assistant who had not been under contract with them for six months.
GDPR Article 9: the extra layer that is often forgotten
Beyond French professional secrecy, the European General Data Protection Regulation (GDPR), in its Article 9, classifies health data among the “special categories” for which processing is prohibited by default. Exceptions exist—including explicit consent and the necessity of medical care—but these exceptions require a level of technical security that most consumer-grade tools do not provide.
In concrete terms: if you process your patients’ health data via Drive, WhatsApp, or Gmail, you cannot justify a Data Protection Impact Assessment in the event of a CNIL audit or a patient complaint. You also cannot prove that transfers outside the European Union are properly regulated. The risk is no longer just ethical; it becomes administrative and financial.
HDS: for whom, really?
The health data hosting standard, supervised by the Agence du Numérique en Santé, is often presented as a mandatory horizon. This is not entirely accurate for all paramedical professionals. The HDS certification is required for establishments and services that host health data on behalf of others. For a freelance physiotherapist hosting their own data with a service provider, the obligation lies with the chosen host, not with the individual.
In concrete terms: if you install a digital vault on your own WordPress site, and that WordPress site is hosted by an HDS-certified provider — OVHcloud Healthcare and Outscale are the two main French players — you are within the scope. If you host it with a standard shared hosting provider, you are taking a risk that I cannot recommend for patient records.
The cost of continuing as before
The direct cost of a breach of article L. 1110-4 of the Public Health Code is rarely an immediate criminal penalty. Professional secrecy is protected by article 226-13 of the French Penal Code, which provides for one year of imprisonment and a fifteen thousand euro fine. This sanction is infrequent in practice — but it is possible, particularly when a patient files a complaint after discovering that information concerning them has been disclosed.
The indirect cost is much more regular. A CNIL complaint can lead to a formal notice, an administrative fine, or even the publication of the sanction. For a freelance practice, this is equivalent to brand devaluation. And questions like “is my osteopath sending my records securely?” now come from patients to professionals, not the other way around.

Criteria for a compliant solution, independent of the provider
Before considering Client Vault or any other tool, here is the evaluation grid to apply to any candidate solution. Hosting with a provider certified HDS (Health Data Hosting) for health data. Encryption at rest for patient files. Space partitioned by patient — not a global shared folder. Defensible traceability of access and modifications. Ability to permanently delete data at the patient’s request. Full data ownership by the professional, without dependence on a third-party vendor that could block access.
This grid allows you to evaluate Doctolib Pro, Maiia, SimplePractice, or any other solution. Doctolib Pro is solid for appointment scheduling but does not cover structured collection of medical reports. SimplePractice is designed for the US market, under HIPAA regulations, which does not automatically qualify it for GDPR Article 9 or French HDS. Maiia positions itself in the medical segment but does not specifically handle the physical therapy/osteopathy/psychology chain in private practice.
How Client Vault responds — and where it stops
Client Vault is a WordPress plugin that creates a private space per patient on your own site. You request a report, the patient uploads it, the file is validated and timestamped. Each access is tracked. Every action — receipt, validation, refusal, deletion — leaves a defensible footprint. The patient can, upon request, obtain the permanent erasure of their data.
The key point is that all of this lives on your own systems. The server is the one you choose. If you host your patient data, you use an HDS-certified host — OVHcloud Healthcare or Outscale in France. If you want to change hosts tomorrow, you can do so without asking for permission from a software vendor. If Client Vault disappears tomorrow, your practice continues to run on the same WordPress, with the same data, under your control.
For WordPress agencies that equip paramedical practices: the true value-added service you provide is technical mediation. Choosing an HDS host, configuring the SSL certificate, WordPress hardening, encrypted backups, and training the practitioner on collection practices. It is a reproducible deployment, which is billed as initial setup and annual support.

Honest limits
Client Vault is not HDS-certified as a software vendor. This certification applies to the hosting provider, not the application code. You must therefore choose an HDS host yourself for health data — this combination is what makes your setup compliant. Client Vault does not handle appointment booking either: for that, Doctolib Pro remains excellent, and it integrates very well into WordPress via redirection or a widget. Finally, Client Vault does not replace a complete medical patient file in the sense of an Electronic Medical Record (EMR): it is a document vault, not clinical management software.
Let’s get to know each other
If you are a physiotherapist, osteopath, psychologist, podiatrist, or midwife, and you are concerned about the compliance of your patient record collection—or if your WordPress agency is asking these questions on your behalf—let’s discuss this via video call. Twenty to thirty minutes to understand your situation, review your current stack, and see if the sovereign pathway on WordPress with HDS hosting can meet your requirements.
Frequently asked questions
Does Article L. 1110-4 apply to physiotherapists and osteopaths?
Yes. The article encompasses “any person receiving care from a healthcare professional, establishment, or service, or a professional or organization contributing to prevention or care.” Physiotherapists, osteopaths, psychologists, podiatrists, and midwives are included.
Is receiving a patient report via WhatsApp illegal?
Not in itself, but it poses several problems. WhatsApp only covers transmission, not storage. iCloud or Google Drive backups take your data outside the HDS perimeter. Furthermore, separating professional and personal life becomes impossible if the phone is shared. It is a high-risk practice that no serious GDPR analysis can validate.
Must one be HDS certified to host a paramedical file?
The obligation lies with the hosting provider, not the professional. If you host your data with OVHcloud Healthcare or Outscale, which are HDS certified, you are within the perimeter. If you host them with a standard shared hosting provider, you are taking a risk that is difficult to justify in the event of an audit.
Is a Shared Drive acceptable for patient records?
No. A Shared Drive does not provide partitioning by patient, enforceable audit trails for access, or definitive deletion upon request. It also violates Article 9 of the GDPR regarding health data in the absence of technical guarantees equivalent to those of an HDS-certified hosting provider.
What is the risk for a physiotherapist storing records on their unencrypted computer?
In the event of theft or loss of the computer, professional secrecy is breached without intent. The CNIL can be notified by a patient. The criminal risk under Article 226-13 remains theoretical, but the administrative fine is very real.
Does Article 9 of the GDPR really prohibit non-European cloud storage?
It does not prohibit it in principle, but it strictly regulates it. For health data, transfers outside the European Union are possible only with additional guarantees—impact analysis, technical measures, and contractual clauses. In practice, hosting health data with a provider subject to the CLOUD Act is very difficult to justify.
Is Doctolib Pro sufficient for paramedical compliance?
Doctolib Pro is robust for appointment scheduling and teleconsultation, and it integrates well into a paramedical practice. It does not cover the structured collection of patient reports sent by the patients themselves. It is this final component that a sovereign digital vault completes.
{ “@context”: “https://schema.org”, “@type”: “Article”, “headline”: “Secret médical numérique : ce que dit l’art. L. 1110-4 en 2026”, “author”: {“@type”: “Person”, “name”: “Dragan Stamenkovic”, “url”: “https://clientvault.pro/auteur/dragan-stamenkovic”}, “datePublished”: “2026-05-10”, “dateModified”: “2026-05-10”, “publisher”: {“@type”: “Organization”, “name”: “Client Vault”}, “mainEntityOfPage”: “https://clientvault.pro/blog/secret-medical-art-l-1110-4-numerique” }{ “@context”: “https://schema.org”, “@type”: “FAQPage”, “mainEntity”: [ {“@type”: “Question”, “name”: “L’article L. 1110-4 s’applique-t-il aux kinés et ostéos ?”, “acceptedAnswer”: {“@type”: “Answer”, “text”: “Oui. L’article englobe toute personne prise en charge par un professionnel de santé, ce qui inclut les kinésithérapeutes, ostéopathes, psychologues, podologues et sages-femmes.”}}, {“@type”: “Question”, “name”: “Recevoir un bilan patient par WhatsApp est-il illégal ?”, “acceptedAnswer”: {“@type”: “Answer”, “text”: “Pas en soi, mais ça pose plusieurs problèmes : WhatsApp ne couvre que la transmission, la sauvegarde iCloud sort vos données du périmètre HDS, la séparation pro-perso devient impossible.”}}, {“@type”: “Question”, “name”: “Faut-il être certifié HDS pour héberger un dossier paramédical ?”, “acceptedAnswer”: {“@type”: “Answer”, “text”: “L’obligation pèse sur l’hébergeur. Si vous hébergez chez OVHcloud Healthcare ou Outscale, certifiés HDS, vous êtes dans le périmètre.”}}, {“@type”: “Question”, “name”: “Drive partagé est-il acceptable pour des bilans patient ?”, “acceptedAnswer”: {“@type”: “Answer”, “text”: “Non. Un Drive partagé ne fournit ni le cloisonnement par patient, ni la traçabilité opposable, ni la suppression définitive.”}}, {“@type”: “Question”, “name”: “Que risque un kiné qui stocke des bilans sur son ordi non chiffré ?”, “acceptedAnswer”: {“@type”: “Answer”, “text”: “En cas de vol ou perte, le secret est rompu sans intention. Risque CNIL et risque pénal théorique au titre de l’article 226-13.”}}, {“@type”: “Question”, “name”: “Le RGPD article 9 interdit-il vraiment le stockage cloud non-européen ?”, “acceptedAnswer”: {“@type”: “Answer”, “text”: “Il l’encadre. Pour les données de santé, les transferts hors UE imposent analyse d’impact et garanties techniques.”}}, {“@type”: “Question”, “name”: “Doctolib Pro est-il suffisant pour la conformité paramédicale ?”, “acceptedAnswer”: {“@type”: “Answer”, “text”: “Doctolib Pro couvre la prise de rendez-vous mais pas la collecte structurée de bilans envoyés par les patients.”}} ] }



