For you digital health service publishers:
Publication today of the decree establishing the practical application methods for financial sanctions against digital health service publishers not complying with interoperability, security, or ethical compliance obligations, or lacking the required compliance certificate.
This decree thus complements the legal framework to ensure the effectiveness of compliance obligations in the field of digital health technologies.
The text defines the inspection procedure entrusted to the National Agency for Digital Health (ANS), already responsible for collecting reports of alleged non-compliance with the obligations of a digital health service (interoperability, security, ethics, certification).
➡️ The ANS can therefore proceed with checks and audits: on-site visits, requests for demonstrations of the relevant tools and their specifications.
➡️ The failure to comply after being instructed to remedy may trigger a sanction procedure, with the decision being made by the Minister of Health, upon the proposal of the ANS.
➡️ The ANS’s proposal will include an assessment of the severity of the detected breach, the corresponding penalty amount (within the already provided limits of 1% of the revenue excluding taxes generated in France by the publisher during the last closed financial year, up to a limit of one million euros), possibly accompanied by a proposal for a fine.
➡️ The ANS must assess the severity of the breach particularly with regard to the specifics of the standard that has not been respected, the number and nature of non-conformities, the potential impact of the breach on patient care, risks to public health, and financial consequences for health insurance.
➡️ Decree No. 2026-153 of March 3, 2026, concerning the sanctions mentioned in III of Article L. 1470-6 of the Public Health Code