I.-To ensure compliance with the provisions of Article L. 1461-4, the data present in the national health data system and those made available by the joint managers are linked to each person concerned by a pseudonym. This pseudonym is produced in accordance with the procedures set out in II of this article.
II – The rules for the secure management of the national health data system, defined in a security reference framework drawn up by the ministers responsible for health, social security and digital technology after consultation with the Commission nationale de l’informatique et des libertés, are established in accordance with the following principles:
1° Pseudonymisation :
a) The databases covered by the national health data system do not contain any directly identifying data: neither the surname nor the forename nor the address nor the registration number in the National Register for the Identification of Individuals. A pseudonym, consisting of a non-meaning code obtained by an irreversible cryptographic process from the registration number in the National Register for the Identification of Natural Persons, is associated with the data relating to each person. The data is made available by means of a different pseudonym for each of the databases made accessible to each of the data controllers;
b) The above-mentioned irreversible cryptographic procedure is used to create the databases covered by the national health data system and to match data extracted from the national health data system with data relating to health insurance beneficiaries contained in other systems. This procedure is organised in such a way that no-one can have both the identity of individuals, in particular their registration number in the National Register for the Identification of Natural Persons, and the pseudonym mentioned in I of this article. The persons involved in this procedure are bound by professional secrecy;
2° Traceability :
The procedures for storing and using the data enable the use of the data to be monitored and evidence to be provided in the event of unauthorised use.