Blog

Why protect employee health data?

Employee health data is defined by the GDPR as sensitive special category data, subject to a reinforced protection regime. Protecting this information is not an option: it is a legal obligation governed by article 9 of the GDPR, the Public Health Code and the recommendations of the CNIL. For HR managers and compliance directors, understand why protecting employee health data directly affects the validity of disciplinary procedures, the reputation of the company and exposure to financial sanctions. The cyber incidents of 2026 have made this emergency even more concrete.

Why protect employee health data: the legal framework

The regulations applicable to corporate health data are based on three pillars: the GDPR, the Public Health Code and the case law of the Court of Cassation. These texts form a coherent whole which imposes precise obligations on the employer.

What the GDPR actually imposes

Article 9(1) of the GDPR prohibits in principle the processing of health data. Exceptions exist, but they are strictly regulated. The CNIL requires that any processing of medical data be based on an explicit legal basis, a documented purpose and proportionate security measures. Non-compliance with the GDPR exposes the company to sanctions of up to €20 million or 4% of global turnover. This double financial exposure explains why GDPR compliance has become a governance priority, and not a simple administrative formality.

Medical confidentiality: an absolute frontier

Medical confidentiality is absolute: only the occupational physician can be the employer's contact for any questions relating to an employee's health. The attending physician must refuse any communication, even administrative, to the employer. This rule also applies to prolonged sick leave.

The essential legal obligations are summarized as follows:

  • Prohibition of access to diagnosis: the employer cannot know either the pathology or the prescribed treatment.
  • Single channel: discussions on fitness for work go exclusively through the occupational physician.
  • Limitation of collection: only information strictly necessary for the management of the employment contract can be collected.
  • Defined retention periods: medical data cannot be kept beyond the legal period applicable to each type of document.

“The employer cannot access the diagnosis, treatment, or nature of an employee's pathology, under penalty of nullity of the dismissal. » This rule, confirmed by recent case law, transforms a violation of medical confidentiality into a direct risk to the validity of HR decisions.

The Court of Cassation has repeatedly recalled that any dismissal based on medical information obtained in violation of medical confidentiality is void. This case law gives the rights of employees over their health data a concrete and immediate impact on HR procedures.

What are the risks of insufficient protection of health data?

Discover in pictures the main steps to ensure the security of health data.

The consequences of a breach in the security of personal health data are multiple. They simultaneously affect the legal, financial and social aspects of the company.

Specialist in secure health data management within a reliable professional environment

Recent incidents with massive consequences

More than 355,000 employees saw their occupational health history exposed during a cyberattack against the SSTRN in June 2026. The same attack compromised 632,000 appointments and 309,000 HR files. These figures illustrate the extent of the damage that a single technical fault can cause.

The Almerys cyberattack, which occurred the same year, confirmed that administrative data related to health - name, address, mutual insurance number - are as valuable to cybercriminals as medical data stricto sensu. This information is used directly for identity fraud and targeted phishing campaigns.

The main risks identified are:

  • CNIL sanctions: administrative fines, compliance orders, publication of decisions.
  • Invalidity of dismissals: any HR decision based on illicitly obtained medical data is legally fragile.
  • Reputation damage: a leak of health data generates a lasting loss of trust among employees and partners.
  • Identity theft: exposed employees become targets for financial fraud exploiting their administrative data.
  • Criminal liability: the deliberate violation of medical confidentiality may incur the personal liability of the manager.

The technical flaw causing the SSTRN incident is of the IDOR (Insecure Direct Object Reference) type. This type of flaw allows access to protected data by simply modifying an identifier in a URL. Authentication alone is not enough to protect against this.

These incidents show that employee health data security challenges are not just a matter of regulatory theory. They materialize in concrete, measurable and publicized losses.

What technical and organizational measures are essential?

The CNIL defines minimum technical and organizational measures for any processing of sensitive data. These requirements apply directly to HR systems that manage medical or paramedical information.

Implement an information systems security policy

An information systems security policy (PSSI) approved by management is the basis of any compliance approach. It formalizes access rules, incident management procedures and the responsibilities of each actor. Without documented PSSI, the company cannot demonstrate its compliance during a CNIL audit.

The technical steps to deploy

1. Strict access controls: each employee only accesses the data necessary for their role. Authorizations are reviewed at each change of position.

2. Data encryption: data at rest is encrypted in AES-256; data in transit uses TLS 1.3 at a minimum. The absence of encryption of backups constitutes a breach punishable by the CNIL, even without a leak noted.

3. Access logging: each consultation or modification of a health record is traced with timestamp and user identifier.

4. Backup management: backups are encrypted, tested regularly and stored on media separate from the main system.

5. Incident notification procedure: in the event of a violation, the GDPR requires notification to the CNIL within 72 hours. The procedure must be written and known to all stakeholders concerned.

Pro Tip: Perform a test restore of backups at least quarterly. The CNIL considers that an untested backup does not offer sufficient guarantee under the security obligation.

The IT security policy must be subject to an annual review and regular awareness raising among HR and IT teams. Human errors remain the leading cause of data leaks in businesses. Training employees to recognize a phishing email or report abnormal access significantly reduces actual exposure.

How to reconcile data protection and HR management on a daily basis?

The daily management of absences, incapacities and job adjustments requires HR teams to handle information close to the medical field. The boundary between what is allowed and what is not deserves to be known precisely.

The principle of minimization applied to HR

The collection of data must remain proportionate to the purpose pursued. To manage sick leave, the employer needs the duration and start date, not the diagnosis. To organize a workstation adjustment, he needs the functional restrictions communicated by the occupational physician, not the pathological origin of these restrictions.

An arbitration from March 2026 clarified that the employer cannot require generalized access to medical information even for absences exceeding 17 weeks. This principle of minimal invasion of privacy applies regardless of the duration of the absence.

Good HR practices to implement are:

  • Centralize medical exchanges via the occupational physician, without ever directly contacting the attending physician.
  • Inform employees of their rights: right of access, right of rectification, right to erasure within legal limits.
  • Document each processing in the register of processing activities provided for by the GDPR.
  • Limit the retention period: medical certificates must not be kept beyond their administrative usefulness.

Pro tip: Include a confidentiality clause specific to health data in contracts with external HR providers. A subcontractor who accesses this data engages the responsibility of the ordering company in the same way as internal processing.

GDPR compliance in HR is a lever of trust that promotes a healthy social climate. Rapid and transparent communication during an incident limits reputational damage and strengthens management's credibility with employees. Companies that treat compliance as a proactive approach, and not as a reactive constraint, build a real advantage in terms of talent attractiveness and retention.

Key points

The protection of employee health data is based on three simultaneous obligations: respecting medical confidentiality, securing information systems and minimizing the data collected.

PointDetails
Absolute medical secrecyOnly the occupational physician can communicate medical information to the employer.
Severe GDPR sanctionsA violation can result in a fine of up to €20 million or 4% of global turnover.
Mandatory encryptionUnencrypted backups are punishable by the CNIL even without a proven leak.
Data minimizationThe employer only collects what is strictly necessary for the management of the employment contract.
Compliance as a leverA proactive compliance approach builds employee confidence and reduces exposure to risk.

What fifteen years in the field taught me about health data protection

Most of the incidents I have observed are not the result of sophisticated attacks. They come from a trivial flaw: an HR manager who transfers a medical certificate by unencrypted email, an external service provider who accesses a file without formal authorization, or an absence tracking table stored on a network share open to the entire company. These errors are avoidable. They persist because training is insufficient and procedures remain theoretical.

What strikes me more is that the protection of health data is often presented as a legal risk to be managed. This is too narrow a vision. An employee who knows that his employer treats his medical information rigorously has more trust in his organization. This trust translates into better commitment, less withholding of information during medical visits and more frank cooperation during job adjustments.

The rise of Shadow AI adds a new dimension to these challenges. Employees use unsecured artificial intelligence tools to process sensitive HR documents, without realizing that this data passes through third-party servers. Pseudonymizing documents before any processing by an external AI is today the most pragmatic response to this risk. See HR compliance guide 2026 for an overview of current requirements.

Monitoring cybercriminal developments is not reserved for IT teams. A compliance manager who understands what an IDOR breach or spearphishing attack is makes better budgetary and organizational decisions. Minimum technical competence has become a job requirement.

- Jacques

Safe-doc for HR compliance on sensitive data

https://safe-doc.ai

HR teams handle documents on a daily basis that contain health data, incapacity information and sensitive administrative elements. When these documents are analyzed with artificial intelligence tools, the risk of leak becomes real if no layer of protection is in place. Safe-doc addresses this problem by automatic pseudonymization documents before any processing by an external AI. Personal data is hidden in real time, no documents are stored, and GDPR compliance is maintained without changing the teams' working habits. For HR managers and DPOs looking to secure their employee files with AI, Safe-doc offers a concrete, audited response that complies with the AI ​​Act.

Frequently asked questions

Why is employee health data considered sensitive?

The GDPR classifies health data in a special category because its disclosure can lead to discrimination, invasion of privacy and direct professional harm. Their processing is prohibited in principle, except in legally regulated exceptions.

What sanctions are incurred by an employer who violates medical confidentiality?

A dismissal based on medical information obtained unlawfully is void. Administratively, the CNIL can impose a fine of up to 20 million euros or 4% of annual global turnover.

Who can access the medical data of an employee in the company?

Only the occupational physician is authorized to receive and transmit medical information in the professional context. The employer only has access to the conclusions of aptitude or incapacity, never to diagnosis or treatment.

How to protect health data when using AI tools?

Pseudonymization of documents before processing by an external AI is the recommended method. It hides personally identifiable data while allowing content analysis, without storing sensitive information on third-party servers.

What rights do employees exercise over their health data?

Employees have the right to access, rectify and delete their health data, within the limits of legal retention periods. They can also object to certain processing and request portability of their data under the conditions provided for by the GDPR.

Recommendation