From the perspective of Arthur Dauphin

France Assos Santé: placing the patient's voice at the heart of cybersecurity

1. YOUR JOURNEY INTERSECTS PUBLIC HEALTH, HEALTH DEMOCRACY, AND DIGITAL TECHNOLOGY. HOW DO THESE THREE DIMENSIONS SHAPE YOUR PERSPECTIVE ON HEALTH DATA PROTECTION AND USER TRUST? 
The digital transition of our society means that the world of health is transforming a little more each day, exponentially. The digitization of data has opened up unprecedented fields of action for medical research and for approaching medical records differently. Obviously, we must not suffer this transition but leverage it for the health of everyone, while respecting the values of our society and in particular the values of our ethical, humanist, and supportive healthcare system. 

However, in a globalized world where different societal models clash, this digitalization can seem like a Pandora's box. Healthcare users already experience the daily difficulties of our healthcare system, regarding access to care, and the respect of some of their rights, even if it's just access to their medical records, which is often difficult. They therefore place many hopes in digital technology, but also fears, many of which crystallize around the distance it can symbolize and the issue of data security. 

2. IN AN EVENT DEDICATED TO CYBERSECURITY, WHAT CONCRETE ROLE CAN PATIENT ASSOCIATIONS PLAY: RAISING AWARENESS, CO-CONSTRUCTING, ALERTING, CONTROLLING? WHERE, IN YOUR OPINION, LIES THEIR TRUE ADDED VALUE? 
Associations have a role to play in raising awareness among users and patients. Often, they poorly understand the digital risks to which they may be exposed. Firstly, sick people fear that their data will fall into the wrong hands and be used maliciously against them by their employer, bank, or insurance company. It is the preservation of medical secrecy that worries them the most. But alongside this, they do not fully realize the exposures related to their personal data, those used for phishing attempts, identity theft, fraud, etc. And so, they don't know how to protect themselves or react if they become victims. 

However, this cannot rest solely on the shoulders of associative actors. User representatives, patient associations, must already contribute to sensitizing all stakeholders so that they take data security seriously, as well as the information that can be shared with individuals.

In healthcare facilities, following the explosion in the number of cyberattacks in recent years, user representatives participating in governance are becoming increasingly interested in the subject. Some facilities even involve these associative representatives in their work. Thanks to their cross-cutting knowledge of the facility and patient pathways, they can provide relevant input during crisis exercises, review chapters of business continuity and recovery plans, or help design communication addressed to users. 

3. DO PATIENTS REALLY KNOW HOW THEIR DATA IS COLLECTED, PROTECTED, AND SOMETIMES SHARED? HOW CAN TRANSPARENCY AND EDUCATION AROUND THESE USES BE STRENGTHENED WITHOUT CREATING MISTRUST?
Healthcare users have a very poor understanding of their health data. Last year, a survey within our associative network, which is nevertheless more informed than average, showed that nearly 40% thought their medical record was on their "carte vitale" (health insurance card). Consequently, lack of knowledge can create mistrust. Yet, patients are well aware of the benefit of collecting and sharing their data when it allows them to be treated or to improve future care, for research for example. 

Transparency and education must therefore primarily focus on the personal benefit they will derive and, in parallel, deconstruct certain negative misconceptions. Furthermore, before digital technology, paper was not an absolute guarantee of confidentiality, and medical records could easily be consulted in hospitals, for example. Digital technology allows for more sharing but also more control. We therefore see the importance of healthcare actors participating in this dialogue, to bring back to the center of individual reflections what can be expected from this data sharing through the healthcare experience. 

4. CYBERSECURITY IS OFTEN PERCEIVED AS A TECHNICAL CONSTRAINT. HOW, IN THIS CONTEXT, CAN THE HUMAN DIMENSION OF THE CARE RELATIONSHIP AND TRUST BETWEEN PATIENTS AND CAREGIVERS BE PRESERVED?
We must avoid making it a taboo, which would only exacerbate existing attitudes of mistrust. Patients have great trust in their healthcare professionals, and they are also aware that zero risk does not exist, in medicine as in IT. This is also why 360-degree information on the subject must be considered. As we said, with associations, professionals, and all actors interacting in the healthcare system. More than a technical or regulatory constraint, protecting data means preserving trust but also protecting individuals from all the vulnerabilities that result from it. Whether they are linked to well-known risks or potential risks that currently concern us little in France but could develop, such as blackmail related to health information for sensitive pathways of people living with HIV, psychiatric pathways, or addiction treatment, etc.

It must be remembered that even today, many users suffer medical discrimination or discrimination in their entourage, and sometimes travel dozens of kilometers to go to a pharmacy other than their usual one to preserve the confidentiality of their pathways. Their fears and choices are therefore legitimate! 

Above all, healthcare organizations must communicate more. Positively about all the efforts and actions deployed to improve cybersecurity and show patients that their data and security are not neglected. But also during a vulnerability, by clearly explaining the impact on care (unavailability of records, closure of emergency services, etc.) and the risks incurred by potentially affected patients, recalling their great lack of knowledge on the subject and facilitating the exercise of their rights (complaint letter, etc.). And continuously on the entire cyber response improvement process. 

5. AS A USER REPRESENTATIVE, WHAT DO YOU EXPECT FROM THIS 5TH EDITION OF CYBERCAMP SANTE? WHAT WOULD YOU LIKE TO SEE EMERGE SO THAT THE PATIENT'S VOICE IS BETTER INTEGRATED INTO THE GOVERNANCE OF DIGITAL HEALTH? 
One of the essential points for this 5th edition is that we take advantage of the maturity of the sector and healthcare actors on the subject not to rest on our laurels but precisely to address the different challenges in depth. Now that governance structures have been established, and organizations have been equipped with essential response elements that were still missing, we can enter a more reflective phase. And precisely, we want to show that the voice of users is a rich lever for improving the cyber response as a whole and even indispensable for overcoming the challenge of public opinion and transparency. 

6. AT CYBERCAMP SANTE, YOU WILL BE SPEAKING TO CISOS, CIOs, AND PUBLIC DECISION-MAKERS. WHAT MESSAGE DO YOU WISH TO CONVEY TO THEM SO THAT THEY FINALLY PLACE THE "PATIENT'S VOICE" AT THE HEART OF DIGITAL SECURITY?
Simply to tell them that we at France Assos Santé are making strong commitments to constructively add our perspective and expertise to the common pool of cyber response. With more than 6000 user representatives participating in the governance of healthcare facilities throughout the territory, these are as many allies they can count on. And this is as much for extending their action and imagining a cyber response that truly protects patients when the future of their data is uncertain, as for imagining positive communication in the service of trust and user rights.