I.-The reporting of serious information system security incidents as provided for in Article L. 1111-8-2 is intended to :
1° Provide the competent State authorities with the information they need to decide on preventive measures in terms of information system security or to ensure the continuity of healthcare provision ;
2° Helping health establishments, organisations and services involved in preventive, diagnostic or care activities to take any useful measures to prevent the occurrence of significant or serious information system security incidents or to limit their effects.
II -Significant or serious information system security incidents are considered to be events which generate an exceptional situation within an establishment, organisation or service, and in particular :
-incidents with potential or proven consequences for the safety of healthcare ;
incidents with consequences for the confidentiality or integrity of health data; – incidents affecting the normal operation of a facility, organisation or service
-incidents affecting the normal operation of the establishment, organisation or service;
-incidents with a potential or proven impact on the departmental, regional or national organisation of the healthcare system;
-incidents likely to affect other establishments, organisations or services.
III -Serious information system security incidents are deemed to be significant if they have a potential or proven impact on the departmental, regional or national organisation of the healthcare system and if they are likely to affect other institutions, organisations or services.