Acronym of the case: MSSanté
Web address of the case: https://www.mssante.fr/ - http://esante.gouv.fr/mssante
Country of the case: France
Summary
MSSanté is the global system set up by the French government with the involvement of health professionals to develop secure health messaging. This tool enables health professionals to share information quickly via email while keeping the personal health data of their patients secure, in compliance with French regulations. MSSanté has a common and certified directory of all health professionals. Any health professional messaging system can become "MSSanté-compatible".
Policy Context
Health professionals need to exchange and share health records while maintaining patient privacy. But when they share patients’ electronic information, they usually use traditional messaging and email systems that are not secure enough or do not fulfil all French privacy requirements. Mailing or phone calls are also a common method for sharing health records among health professionals.
An electronic system like MSSanté is not mandatory. But every health professional must respect the legal framework regarding the exchange of personal data (L1110-4 article of the law on public health). Personal health information is considered to be critical data, protected by law. The processing of this information should comply with the principles of personal data protection, as covered by the French Data Protection Act (Loi Informatique et Liberté).
Operators must also comply with articles R1110-1 to 3 that impose the requirement for implementing strong authentication controls through the CPS (CPS - Carte de professionnel de santé - Health professional card) or another equivalent technology certified by ASIP Santé, to guarantee the confidentiality of the information exchanged.
To join the MSSanté trusted environment, operators must comply with CNIL (Commission nationale de l’informatique et des libertés - National Commission on Informatics and Liberty) recommendations, be certified, get HDS (Hébergeur de données de santé - Health data hosting company) approval, and offer an MSSanté-compatible email service.
Case Abstract
What is MSsanté
MSSanté (Messagerie de Santé Securisée - secure health email system) was developed by ASIP Santé, the governmental agency in charge of the deployment of eHealth policy in France, helped by medical councils, hospitals and professional organisations. The MSSanté system is based on three principles:
- a development framework to create secure email systems;
- a global trusted environment in which health professionals can exchange and share health records and documents;
- a national directory that lists all health professionals, identified by their specialties (doctors, dentists, pharmacists, midwives, pedicurists, nurses and physiotherapists).
A decentralised model to improve security
The trusted environment of MSSanté is based on a decentralized model in which operators, software vendors, hospitals or groups of hospital can operate the secure messaging system. Health record hosting companies, or those who operate these systems for hospitals, need to receive approval and be certified to host health data. They are then white-listed, ensuring that they can be trusted to operate the email messaging system. Software vendors can develop or adapt their email systems and make them compatible with MSSanté.
Software vendors and operators wishing to enter this secure environment and make their tools compatible with MSSanté must meet the specifications (DSFT) defined by ASIP Santé. This summer, ASIP Santé published specifications for MSSanté-compatible email clients (http://esante.gouv.fr/services/mssante/breves/dst-clients-de-messagerie…). Specifications are also available for operators (http://esante.gouv.fr/services/mssante/editeurs-operateurs/operateurs). To ensure interoperability and the security of MSSanté-compatible solutions, messaging operators must sign an integration contract, and vendors - a certification contract.
Basically, the email systems are not centralized in a data-centre or hosted on the infrastructure of a unique operator. Instead, ASIP Santé has encouraged the creation of a trusted flexible virtual environment by securing every step in the process and involving all stakeholders in the French health system. This environment is considered to be hermetic.
A common national directory
ASIP Santé has developed a national directory, connected to MSSanté systems, that is common to all professionals. This directory makes it possible to browse and search for health professionals by name, speciality, practice location or occupation. This directory is to be integrated in the address book of all MSSanté-Compatible software. It lists all the secure email addresses opened by health professionals.
www.mssante.fr : the first secure webmail
ASIP Santé has developed a primary service that implements the MSSanté secure system. This first iteration of MSSanté is based on the open source Zimbra messaging system. It helps professionals to open their own secure email address and start using the messaging system. This service (https://www.mssante.fr) can be used as a webmail, directly in the browser, or on a traditional messaging client that is MSSanté compatible. ASIP Santé has also developed the first email client that is compatible with a secure environment. It is based on the open source messaging client Thunderbird (https://www.mssante.fr/telechargements/Thunderbird).
The service offers the same level of functions as every email service but its storage capacity is limited to 2 GB. Attachments are limited to 10 Mb.
Users can log in with their professional card (CPS - Carte de professionnel de santé), or via a two-stage authentication process, based on ID/password and an SMS confirmation.
In 2014, ASIP Santé issued a mobile app (iOS and Android) to access the service. It will provide the same level of data protection and security but within a mobile device. One or several smartphones can be paired to the service.
MSSante.fr offers basic functions. But ASIP Santé says that other private or public operators will develop more advanced systems in the future.
Benefits for health professionals:
- Health professionals are easy to locate in a unique, centralized directory;
- Patient health information automatically sent to your email system (medical and hospital reports, radiology reports, etc.)
- Fewer printed reports, less mailing of scans or reports;
- A simple and efficient method of sharing information between professionals;
- Patients’ data are secure and protected.
Benefits for hospitals and public health authorities:
- Break silos between doctors in town and hospitals and strengthen coordinated care;
- Guarantee that data are secure and confidentiality is maintained;
- Modernizing business processes and facilitating more efficient use of resources.
Case Description
- Domain: eHealth
- Start Date: 2012 (ongoing)
- Date Operational: March 2013
- Target Users: Health professionals / public health bodies / private and public operators
- Scope: National
- Language: French
Implementation and Management Approach
Since April 2013, 15 health care institutions (hospitals, university health centres) are testing the MSSanté system. These are:
- CHU Clermont-Ferrand (Auvergne)
- CHU Lille (Nord Pas de Calais)
- CHU Rouen (Haute Normandie)
- CHU Montpellier (Languedoc Roussillon)
- CLCC Rouen (Haute Normandie)
- CHLVO Challans (Pays de la Loire)
- CH Saint Denis (Ile de France)
- CH Eaubonne Montmorency (Ile de France)
- GH Paris Saint Joseph (Ile de France)
- CH de Sélestat (Alsace)
- CH Lens (Nord Pas de Calais)
- CH de Montluçon (Auvergne)
- CH Compiègne-Noyon (Picardie)
- Clinique du Cèdre (Haute Normandie)
- Clinique Pasteur – Evreux (Haute Normandie)
These beta-testers will provide feedback and will help improve the global system. ASIP Santé helps institution to migrate to MSSanté at their own pace. The pilot is then extended to other health institutions.
Health institutions and hospitals must appoint a representative that will be in charge of communicating with ASIP Santé. This representative will manage the project with the agency (technically end economically). ASIP Santé will provide them with information, specifications, a project description and a call number (3657) from which they can obtain information about MSSanté.
Multimedia content
None available