How to Use Netsoins Domusvi Safely While Complying with GDPR

A caregiver logs into their Netsoins account on the tablet of the care cart, checks a resident’s file, and then forgets to lock the screen before entering the room. In nursing homes, this kind of situation happens several times a day.

The GDPR compliance of Netsoins Domusvi is not only about the software settings: it is also about the daily actions of the teams, the network configuration of the establishment, and the documentation that no one wants to write.

Strong Authentication on Netsoins: What Really Holds Up on the Ground

Netsoins can be paired with Pro Santé Connect and the CPS card to implement strong authentication. On paper, this is the recommendation from the CNIL for large-scale health databases. In practice, deployment often stalls over hardware details.

CPS card readers are not always available at every workstation. Care assistants, who do not have a CPS card, must use a standard identifier. And when the establishment’s Wi-Fi connection is unstable, verification via Pro Santé Connect fails or slows down the care process.

For strong authentication to work daily, it is recommended to test the CPS reader and Wi-Fi setup station by station before any widespread deployment. If the infrastructure does not support it, it is better to start by securing individual passwords (regular renewal, minimum eight characters with numbers and special characters) and blocking inactive sessions after a few minutes. The idea is to progress in stages rather than impose a system that teams will circumvent.

To better understand how to use Netsoins Domusvi securely, one must first accept that technical security is worthless without on-the-ground adherence.

IT technician checking access and GDPR compliance of a medical records system in a server room of a care establishment

GDPR Impact Assessment: The Document Every Nursing Home Must Produce

A nursing home using Netsoins processes health data on a large scale. Article 35 of the GDPR makes the data protection impact assessment (DPIA) practically mandatory. The CNIL confirms this in its recommendations for the medico-social sector.

This assessment is not a form to be filled out once and stored in a drawer. It must be updated with every significant change to the system: adding a telemedicine module, interfacing with a new tool, moving to mobile on a tablet, or even integrating an artificial intelligence component.

What the DPIA Must Specifically Cover

  • A precise description of the processing carried out in Netsoins (computerized user file, targeted transmissions, prescriptions, billing via Netfactu) and the categories of data involved.
  • Identification of risks for residents: unauthorized access, data loss, accidental disclosure during an ARS audit or transmission to an external professional.
  • The technical and organizational measures already in place (HDS hosting, access logging, differentiated authorizations by profile) and those that still need to be deployed.
  • The tested business continuity plan, required by the HDS certification of the host, with proof of the HDS certificate number to be kept in the compliance file.

Feedback varies on this point, but in most establishments, it is the IDEC or the director who carries this document, due to the lack of a dedicated DPO. Planning for an annual review remains the minimum.

Authorizations and Logging in Netsoins: Configuring According to Job Profiles

Netsoins operates with differentiated authorizations by user profile. A coordinating physician does not have the same rights as a care assistant or an administrative agent. The problem is that these profiles are often configured during the initial installation and then never revised.

However, the GDPR imposes a principle of minimization: each professional should only access the data strictly necessary for their mission. A receptionist does not need to read targeted transmissions. An external consultant in teleconsultation should only see the file of the resident concerned during the consultation.

Concrete Actions to Take on Access Rights

Start by exporting the list of active accounts and comparing it to the list of current staff. Accounts of departed employees must be deactivated within 48 hours of departure. This is a classic vulnerability that ARS audits consistently highlight.

Next, ensure that logging is active and usable. Netsoins records a complete history of actions (consultations, modifications, exports). This history serves as proof in case of a CNIL inspection or a complaint from a resident exercising their right of access. It is essential to ensure that logs are kept for a duration consistent with the establishment’s retention policy.

Two nursing staff in a nursing home using care tracking software on a tablet at the nursing station, in the context of secure and GDPR-compliant use

Security in Mobility: Tablets and Remote Access on D.netsoins

Mobile access via D.netsoins or a browser on a tablet facilitates bedside monitoring of the resident. However, mobility multiplies points of vulnerability, and protective measures are rarely applied uniformly.

The establishment’s Wi-Fi must be segmented between the care network and the visitor network. When both share the same access point without partitioning, a visitor terminal can theoretically intercept data flows. The browser used on the tablet must be kept up to date, which requires an automatic update policy managed by the IT department or the IT service provider.

Automatic session locking is the simplest and most neglected action. Netsoins automatically logs out after a period of inactivity, but this duration must be set to the shortest compatible with on-the-ground usage. Many establishments leave the default setting unchanged without ever adjusting it.

Each tablet used in mobility should also be encrypted and protected by a device-specific unlock code, distinct from the Netsoins password. In case of theft or loss, encryption prevents the extraction of cached data.

The GDPR compliance of a nursing home using Netsoins Domusvi relies less on the software itself than on three operational pillars: regularly revised authorizations, an up-to-date DPIA, and regulated mobility practices. The software provides the technical tools (logging, profiles, HDS hosting), but it is the internal organization that transforms these tools into real guarantees for residents.

How to Use Netsoins Domusvi Safely While Complying with GDPR