For digital health service providers :
A decree has been published setting out the practical arrangements for imposing financial penalties on digital health service providers that fail to comply with interoperability, security or ethical standards, or that do not hold the required certificate of compliance.
The decree therefore completes the legal framework designed to ensure effective compliance with requirements applicable to digital health technologies.
It defines the inspection procedure entrusted to the French Digital Health Agency (Agence du Numérique en Santé – ANS), which is already responsible for receiving reports of suspected non-compliance by digital health services with applicable requirements relating to interoperability, security, ethics and certification.
➡️ The ANS may carry out inspections and audits, including on-site visits, and may request demonstrations of the relevant tools and access to their specifications.
➡️ Failure to achieve compliance following a formal order to remedy the situation may trigger a penalty procedure. The decision is taken by the French Minister for Health, based on a proposal from the ANS.
➡️ The ANS proposal will include an assessment of the seriousness of the identified breach and the corresponding financial penalty. The penalty may amount to up to 1% of the service provider’s turnover excluding tax generated in France during the latest financial year, capped at €1 million. It may also be accompanied by a proposed periodic penalty payment.
➡️ The ANS must assess the seriousness of the breach by taking into account, in particular, the specific requirements of the framework that has not been complied with, the number and nature of the instances of non-compliance, the potential impact on patient care, the risks to public health and the financial consequences for the French Health Insurance system.
➡️ Decree No. 2026-153 of 3 March 2026 relating to the penalties referred to in Article L. 1470-6 III of the French Public Health Code