I.-Reports of significant or serious information system security incidents, without prejudice to other mandatory reports, are made without delay by the director of the health establishment, the organisation or service providing preventive, diagnostic or care activities, or the medico-social establishment, or the person delegated for this purpose, to the public interest group mentioned in article L. 1111-24.
The public interest grouping is responsible for :
-analysing significant or serious information system security incidents and proposing measures to be taken to deal with the incident;
-supporting the structure reporting the incident. It may make recommendations and in particular propose emergency measures to limit the impact of the incident, remediation measures and measures to improve the security of the information system(s) concerned;
-relation with the French National Information Systems Security Agency, in particular in the event of an incident involving an essential service operator or which could have an impact of national scope;
-incident prevention, by organising feedback at national level, and proposing measures to assist in the handling of incidents;
-managing and implementing the processing of personal data relating to alerts, the characteristics of which are specified by an order of the Minister for Health.
The public interest grouping shall immediately inform the department of the senior defence and security official of the social ministries of any alert analysed. It shall also immediately inform the relevant departments of the Directorate-General for Health and the regional health agencies concerned of any alert likely to have a direct or indirect impact on health, particularly in the event of a malfunction in the provision of healthcare.
The public interest grouping is informed without delay of the resolution of incidents by one of the persons mentioned in the first paragraph of this I.
On the basis of the information provided by the establishments and organisations concerned, it draws up an annual statistical report on anonymised reports of information system security incidents. This report is made public.
II – Subject to the provisions relating to the protection of the confidentiality of national defence, the report of a significant or serious security incident mentioned in Article L. 1111-8-2 is made via the website mentioned in Article D. 1413-58.
The person making the report must provide all the information available at the time the incident is discovered, and in particular the following information:
information enabling the structure concerned by the incident and the reporter to be identified;
-a description of the incident, in particular the date on which it was reported, the scope of the incident, the information systems and data concerned and the status of the response;
-a description of the impact of the incident on data, people, information systems and the structure;
-the causes of the incident, if identified.
The public interest group referred to in Article L. 1111-24 may ask the structure concerned by the incident for any additional information needed to classify the incident and implement an appropriate response.