Health establishments, organisations and services carrying out preventive, diagnostic or care activities and medico-social establishments shall report significant or serious information system security incidents without delay to the competent State authorities and to the public interest group mentioned in article L. 1111-24, under conditions set by decree.
Subject to compliance with the rules relating to the protection of national defence secrets, this article shall apply to the armed forces health service with regard to significant or serious information system security incidents concerning the prevention, diagnosis or care activities of armed forces hospitals.
A decree defines the categories of incidents concerned, the procedures for reporting the incidents mentioned in the first paragraph and the conditions under which they are dealt with.