520.3.3. If a certificate is required to use the EDP assets of the health and social services network or the Régie de l’assurance maladie du Québec or to support the planning, organization and secure provision of health services and social services, it must be(1) issued by a public body within the meaning of section 3 of the Act respecting Access to documents held by public bodies and the Protection of personal information (chapter A-2.1) or by a professional order referred to in the Professional Code (chapter C-26) that has been designated by the Conseil du trésor, on the Minister’s recommendation, to offer certification services in the health and social services sector; (2) issued at the request of an access profile manager responsible for assigning access profiles and authorizations that enable the persons employed by that manager or under that manager’s direction to obtain and use certificates, unless otherwise provided by law with regard to those or other persons; and
(3) associated with cryptographic keys generated in the secured premises of an identity verification agent referred to in section 520.3.6 or 520.3.7, on a physical medium that must be under the control of the certificate holder at all times to ensure the key’s confidentiality and security.
The physical medium referred to in subparagraph 3 of the first paragraph must meet the standards prescribed by a regulation made by the Minister under section 520.4.