Data processing agreement

How medi.tn processes your patients' data, on your instruction and on your behalf.

Annex to the terms of service — Version 1.0, effective [TO COMPLETE]

This is a courtesy translation. The French version is the authoritative text and prevails in the event of any divergence. See Contrat de sous-traitance.

This agreement governs medi.tn's processing of the personal data of the Practitioner's patients. It is entered into pursuant to organic law no. 2004-63 of 27 July 2004 and deliberation no. 4 of 5 September 2018 of the National Authority for the Protection of Personal Data (INPDP) on the processing of health-related personal data.

1. Capacity of the parties

The Practitioner is the data controller. They determine the purposes and means of the processing of their patients' data, and they alone complete the prior formalities with the INPDP — the prior declaration under article 7 of law no. 2004-63, and the authorisation under the second paragraph of article 63 before any communication of health data to persons or establishments.

medi.tn is the processor. It processes patients' data only on the Practitioner's behalf and on their instruction.

medi.tn is a controller only for the data described in the privacy policy — account, billing, support, security.

2. Subject matter, duration and scope
Subject matterHosting and operation of the medi.tn practice management software
DurationThat of the subscription, plus the reversibility period
Nature of processingCollection, recording, storage, consultation, modification, extraction, erasure
PurposeSolely the management of the Practitioner's practice: scheduling, patient records, cash desk, billing, preparation of CNAM documents
Categories of dataPatient identification and contact details, health data, coverage and billing data
Data subjectsThe Practitioner's patients
3. Documented instructions

medi.tn processes patients' data exclusively on the Practitioner's documented instruction. These terms and the use of the Service constitute that instruction.

medi.tn uses patients' data for no purpose of its own. In particular it does not exploit them for commercial, statistical or research purposes, nor to train automated systems, and transfers them to no third party.

If an instruction from the Practitioner appears to constitute a breach of the regulations, medi.tn will inform them.

4. Confidentiality and staff authorisation

Under the first paragraph of article 63 of law no. 2004-63, health data may be processed only by physicians or by persons bound, by virtue of their duties, by an obligation of professional secrecy.

Article 23 of the same law requires the controller, the processor and their agents to preserve the confidentiality of the data even after the processing ends or they lose that capacity. Article 20 requires the processor to act only within the limits authorised by the controller and to have the appropriate technical means.

Accordingly:

  • every member of the medi.tn team who may access the data is individually identified and signs a confidentiality undertaking;
  • the support team does not access clinical content. This restriction is applied server-side, by excluding the relevant columns from queries, and not by a display mask that could be switched off;
  • access by a member of our team to a practice's account requires a written reason and a support request reference;
  • authorisations are limited to the data strictly necessary for each function.
5. Security

medi.tn implements:

  • personal accounts, credential sharing being prohibited, and a unique identifier per user;
  • encryption of communications;
  • strict partitioning of data between practices, applied on every query;
  • logging of access and incidents, making it possible to identify fraudulent access or misuse and to react to a data breach;
  • regular backups and tested restores;
  • the periodic security audit required by law no. 2004-5 of 3 February 2004 and decree no. 2004-1250 of 25 May 2004.

[TO COMPLETE: add encryption at rest and the patching policy once settled.]

6. Data location

Patients' data is hosted exclusively on Tunisian territory.

medi.tn transfers no patient data outside Tunisia. Such a transfer could occur only after prior notice to and written agreement from the Practitioner, and after obtaining the INPDP authorisation required by articles 51 and 52 of law no. 2004-63.

7. Sub-processing

The list of processors used by medi.tn appears in the privacy policy.

medi.tn engages no sub-processor with access to health data without the Practitioner's prior written authorisation. Any proposed addition or replacement is notified with [TO COMPLETE: e.g. 30] days' notice, during which the Practitioner may object and, failing agreement, terminate free of charge.

medi.tn imposes on each sub-processor the same obligations as those of this agreement and remains fully liable for their performance.

8. Assistance to the Practitioner

medi.tn assists the Practitioner:

  • Data subject rights — by providing the functions needed to locate, rectify, extract or delete the data of a patient exercising their rights. A request received directly by medi.tn from a patient is forwarded to the Practitioner without being answered on the merits. Article 21 of law no. 2004-63 requires the controller and the processor alike to rectify or complete data they know to be inaccurate, and to notify the person concerned of any modification within two months.
  • Data breach — by notifying the Practitioner without delay after becoming aware of it, with the nature of the breach, the categories and approximate volume of data concerned, the likely consequences and the measures taken. Any notification to the INPDP and to patients is for the Practitioner, as controller.
  • Formalities and impact assessment — by providing the information about the Service needed for the Practitioner's INPDP file and impact assessment.
9. Fate of data at the end of the agreement

At the end of the subscription, the Practitioner has [TO COMPLETE: e.g. 90] days to obtain a full export of their practice's data in a usable format.

After that period, medi.tn deletes the data from active systems, then from backups according to their rotation cycle, and certifies this in writing on request.

Under article 64 of law no. 2004-63, processing may in no case exceed the period necessary to achieve the purpose for which it is carried out.

Should medi.tn contemplate permanently ceasing its activity, it would inform the INPDP three months before the cessation date, in accordance with article 24 of the same law, destruction of the data then being subject to the Authority's authorisation. The Practitioner would be informed within the same period so as to be able to export their data.

It is for the Practitioner to retain their patients' medical records in accordance with the obligations incumbent on them as a practitioner.

10. Verification

The Practitioner may request, once a year and with reasonable notice, evidence of compliance with this agreement, in particular the conclusions of the most recent security audit. An on-site audit may be conducted by the Practitioner or an independent third party bound by confidentiality, at their own cost, without compromising the security of other practices.

11. Contact

contact@medi.tn — [TO COMPLETE: DPO email address]