At ClinSearch, safeguarding clinical data and upholding the highest standards of regulatory compliance are fundamental to our operations. As an ISO 27001 et Health Data Host (HDS) certified organisation, our activities are structured in accordance with internationally recognised standards for information security and health data protection. These certifications formalise robust data governance practices, reinforce secure digital environments for clinical data collection and management, and ensure alignment with evolving regulatory standards.
In this blog post, we explain why these certifications are essential, how we have anticipated regulatory changes, and the benefits they bring to our customers.
The insights that follow are drawn from an interview with Samia ABBOUTE, our Quality System Manager, conducted by LNE, our partner for ISO 27001 and HDS certifications.
ISO 27001 & HDS: a strong commitment to compliance and data protection
In 2022, the French Data Protection Authority (Commission Nationale de l’Informatique et des Libertés – CNIL) issued two sets of guidelines* regulating early access and compassionate use procedures (Accès précoce/Accès compassionnel – AP/AC). This marked a major step in reforming exceptional access to medicines, which had previously relied on temporary use authorizations (ATU) and temporary use recommendations (RTU). The guidelines aim to simplify and harmonize procedures, accelerate patient access to treatments, and ensure the financial sustainability of the system.
In this context, the French National Authority for Health (Haute Autorité de Santé – HAS) authorizes the implementation of an AP/AC and requires laboratories to collect data and submit regular reports to continuously monitor the efficacy of treatments. To carry out this data collection, laboratories may call on CROs, and ClinSearch is frequently called upon to assist with these processes.
The CNIL simultaneously published two security standards to regulate this process of collection of health data, which is now no longer considered research but part of healthcare. As a result, CROs must work with HDS-certified hosting to comply with these standards. Following a legal analysis of the regulatory framework, we identified the need to obtain HDS certification ourselves—at a minimum for the 5th activity, as defined in Article R.1111-9 of the French Public Health Code—to ensure full compliance, and anticipated that laboratories using our services would eventually require it.
We therefore made the strategic decision to proactively obtain HDS certification, for which ISO 27001 is a prerequisite. Beyond meeting the minimum regulatory requirement, this certification now covers the full scope of HDS activities (1 to 6), reflecting our commitment to a higher level of security and accountability. Today, information management within our data collection platform and all associated analyses are conducted in an HDS-certified environment, guaranteeing security, compliance, and reliability for our clients and for patients whose data we process.
*References: Resolution No. 2022-107 and Resolution No. 2022-106.
Certifications that enhance the reliability of our services
Obtaining ISO 27001 et HDS certifications was a crucial step in strengthening our security practices. While awareness of digital risks was already part of our internal culture, these initiatives have enabled us to further structure our processes and consolidate all of our systems.
Before certification, our Chief Information Security Officer had implemented several technical measures, supplemented by regular awareness campaigns among our teams. The certifications have brought additional benefits, including:
• a deeper understanding and assessment of risks,
• a more rigorous organization of actions to reduce or eliminate identified risks,
• systematic and planned monitoring, promoting continuous improvement in the effectiveness of the measures put in place.
Beyond the technical aspects, these certifications strengthen our customers’ confidence. A survey conducted in 2023 reveals that 77% of them consider ISO 27001 certification to be a decisive asset. They also highlight the significant, and often critical importance of partnering with a certified CRO, thus confirming the soundness of our strategy.
Finally, these certifications give us a major competitive advantage. They facilitate compliance with qualification questionnaire requirements and open the door to new business opportunities.
Learn more by reading the full interview from LNE with Samia ABBOUTE our Quality System Manager: Clinsearch testimonial
Or you can also watch this interview with Mariano GENERA, our Business Developer and Marketing Manager, where he talks about our certifications and all their advantages: ClinSearch – ISO 27001 certifications and Health Data Hosting Providers