This article is the second in a series on cybersecurity on the Evolucare website.
Identification requirements and standards for healthcare systems
In a context where cyberattacks are increasing exponentially, and where the healthcare sector, in the midst of a digital transformation, is particularly hard hit, wave 2 of the french “SEGUR Numérique” national digital healthcare project requires establishments to implement, by 12/31/2025 at the latest, two-factor authentication and substantial means of electronic identification within the meaning of the eIDAS reference framework.
But what does this mean in concrete terms?
“eIDAS”, is the European standard for electronic IDentification Authentication and trust Services. It has been in existence since 2014 and defines a set of standards on the subjects of electronic identification and trust services on electronic transactions.
In particular, it defines a confidence level scale for Electronic Means of Identification (EMI).
If we continue the parallel with the physical world, compare your voter’s card (paper, bearing your first and last name), your driving license (paper or plastic, bearing a photo, your first and last name) and your identity card (plastic, renewed every 15 years, bearing a recent photo, your first and last name).
It is possible to identify/”authenticate” yourself with all three, but in certain, more sensitive cases, you will be asked for the most secure means of identification of the three. For example, in communes with more than 1,000 inhabitants, you can vote only with your identity card, but not only with your voter’s card.
In the same way, electronic identifiers can be classified according to the way in which they are generated, handed over to their owner, managed, taken over and authenticated: low, substantial, high.
The aim of SEGUR wave 2, in order to strengthen the security of healthcare information systems, is therefore to lead players towards substantial, rather than weak, means of identification.
To summarize the “substantial” EMI, a diagram is better than a long speech:
The substantial EMIs in the eIDAS sense available today are :
- CPx cards (healthcare professionals french chip cards) which also have the advantage of being free of charge
- French national agency ANSSI-certified EMI (FIDO keys, like some YubiKeys)
- EMIs independently certified via the ANSSI certification process (costly in terms of time and effort)
- Authentication via ProSantéConnect (French healthcare professional network)
A progressive yet ambitious timetable
In the official timetable, it is possible to envisage a gradual transition, with “reinforced” weak EMIs as an intermediate stage before moving on to substantial EMIs.
Authorized electronic authentication methods for players in the healthcare, social and social care sectors
However, as articles 3 and 4 in this series will show, the project to implement substantial EMIs is a real facility project, requiring human, technical and monetary investment, and our recommendation is to decide now on a strategy for switching to substantial EMIs and two-factor authentication without any intermediate steps.
Stay tuned!
Previously : https://www.evolucare.com/en/cybersecurity-episode-1-identification-authentification-autorization/
Sources (in french)
- Exigences SEGUR vague 2
- DSR-HOP-DPI-Va2-Prepublication – §3.2.5, 3.2.6
- REM-HOP-DPI-Va2-Prepublication
- Référentiel d’identification électronique, rendu opposable par l’arrêté du 28/03/2022 – §2.9, 2.10, 4.1.1, 4.4, 4.5
- Référentiel ProSanté Connect, rendu opposable par arrêté du 4/04/2022
- Implémentation de ProSanté Connect obligatoire depuis le 01/01/2023 pour les services numériques sensibles
- Enregistrement au RPPS de tous les professionnels ayant besoin d’accéder aux SNS (via PSC) – Arrêté du 23/09/2022
- Référentiel de sécurité et d’interopérabilité relatif à l’accès des professionnels au DMP, rendu opposable par l’arrêté du 26/10/2023 – §1.6.2
- Recommandations relatives à l’authentification multifacteur et aux mots de passe | ANSSI (cyber.gouv.fr)
- ANS_Référentiel_Identifiant_National_de_Santé_V2.0.pdf (esante.gouv.fr)
- Le règlement “eIDAS” n°910/2014
- Produits et Services Qualifiés par l’ANSSI (cyber.gouv.fr)
- L’homologation de sécurité | ANSSI (cyber.gouv.fr)
- PGSSI-S_Guide_Pratique-Homologation MIE-V1.0 (esante.gouv.fr)