AuditXYZ

Compliance Framework

MEthode Harmonisée d'Analyse de RIsques (MEHARI) (MEHARI)

MEHARI is a comprehensive risk analysis method widely used in French healthcare. This guide covers the methodology, risk assessment approach, healthcare applications, and integration with ISO 27001.

$15,000–$100,0002–6 months2023
Issuing BodyCLUSIF (Club de la Sécurité de l'Information Français)
First Published1996-01-01
Latest Version2023
Typical Cost$15,000–$100,000
Typical Timeline2–6 months
Audit RequiredNo
Audit FrequencyNo mandatory audit. MEHARI is a risk analysis methodology that supports compliance with frameworks that do require audits.
Geographyfrance, european-union, africa

MEHARI: French Risk Analysis Method for Healthcare

MEHARI (MEthode Harmonisée d'Analyse de RIsques) is a comprehensive information security risk analysis methodology developed by CLUSIF, the French information security association. While applicable across industries, MEHARI is particularly widely adopted in French healthcare organizations and francophone countries as the preferred approach to assessing and managing health information security risks. For French hospitals, health data hosting providers (Hébergeurs de Données de Santé, or HDS), and health tech companies seeking to demonstrate risk management rigor to French regulators, MEHARI is a natural starting point.

What MEHARI Is and Who Issues It

MEHARI was first developed by CLUSIF (Club de la Sécurité de l'Information Français) in 1996, building on an earlier method called MARION. CLUSIF is a French association for information security professionals with members from across industry, government, and the technology sector. Unlike commercial frameworks, MEHARI is freely available — CLUSIF publishes the methodology, knowledge bases, and supporting tools without license fees, making it accessible to organizations of all sizes.

The current version (2023) incorporates updates reflecting the modern threat landscape, cloud computing risks, and alignment with international standards including ISO 27001, ISO 27005 (risk management), and GDPR. CLUSIF maintains the methodology through working groups that include healthcare sector specialists, ensuring that healthcare-specific risk scenarios and security services are well-represented in the knowledge base.

MEHARI is recognized by ANSSI (Agence Nationale de la Sécurité des Systèmes d'Information), the French national cybersecurity authority, as an appropriate risk analysis methodology for organizations implementing security management programs. ANSSI's own preferred methodology is EBIOS RM (Expression des Besoins et Identification des Objectifs de Sécurité Risk Manager), and the two methods are complementary — organizations often use both depending on context.

In healthcare specifically, MEHARI aligns with the requirements of the French HDS (Hébergement de Données de Santé) certification scheme, which requires health data hosting providers to demonstrate rigorous risk management of health information systems.

Who Uses MEHARI

MEHARI is most widely used by:

French healthcare organizations: Hospitals (établissements de santé), hospital information systems directors (DSI), and health data protection officers (DPOs) use MEHARI to conduct risk analyses required by French health data regulations, ISO 27001 certification projects, and GDPR compliance programs.

Hébergeurs de Données de Santé (HDS): Cloud providers and data centers seeking HDS certification — the French certification required for hosting health data from French healthcare providers — use MEHARI to satisfy the risk analysis requirements of the HDS framework.

French health tech companies: Software companies and digital health platforms deployed in the French healthcare market use MEHARI to demonstrate rigorous risk management to hospital customers and health authority regulators.

Francophone organizations in Africa and Europe: MEHARI has significant adoption in francophone African countries (including Morocco, Senegal, Tunisia, and Côte d'Ivoire) and in parts of Belgium, Switzerland, and Luxembourg, where French language and regulatory influence is strong.

ISO 27001 implementers: Organizations seeking ISO 27001 certification can use MEHARI to fulfill the standard's risk assessment requirements, as MEHARI is aligned to ISO 27005 and ISO 31000.

The MEHARI Methodology Explained

MEHARI provides a structured approach to risk analysis through three complementary analytical modules:

Module 1: Risk Analysis (Analyse des Risques)

The risk analysis module starts from business assets — the information assets, processes, and functions that are valuable to the organization. For healthcare organizations, these might include patient medical records, clinical information systems, medical imaging archives, and health data exchange platforms.

For each asset, MEHARI identifies:

  • Threats: The circumstances or events that could adversely affect the asset (cyberattacks, human error, system failure, natural disaster)
  • Vulnerabilities: The weaknesses that could be exploited by threats to cause harm
  • Risk scenarios: Specific combinations of threat actors, threat types, and affected assets that represent credible paths to harm

Risk scenarios are described in terms of the potential impact on the organization — consequences for patient care continuity, patient data confidentiality, financial integrity, and regulatory compliance. Each scenario is assessed for its potential severity if realized.

Module 2: Security Service Evaluation (Évaluation des Services de Sécurité)

MEHARI's knowledge base contains a comprehensive catalogue of "security services" — categories of security controls organized by domain. Security service domains include:

  • Organizational security: Governance, policy, roles and responsibilities, compliance management
  • Physical security: Physical access controls, environmental controls, secure areas
  • Personnel security: Hiring, training, awareness, disciplinary procedures
  • Network and communications security: Perimeter controls, internal segmentation, remote access, cryptography
  • System security: Operating system hardening, patch management, endpoint protection
  • Application security: Secure development, application access controls, data validation
  • Data management: Backup, archiving, data classification, data lifecycle
  • Business continuity: Business continuity planning, disaster recovery, crisis management
  • Incident management: Detection, response, forensics, notification

For healthcare applications, MEHARI's knowledge base includes specific security services addressing patient data protection, clinical system integrity, medical device security, and health information exchange security.

Each security service is assessed using a quality scale — typically 0 to 4 — reflecting the maturity and effectiveness of the control. A score of 0 means the security service does not exist; a score of 4 means the service is fully implemented and effective. These scores form the basis for the risk situation analysis.

Module 3: Risk Situation Analysis (Analyse des Situations de Risque)

The risk situation analysis combines the threat scenarios from Module 1 with the security service quality scores from Module 2 to calculate risk levels. The calculation considers:

  • The intrinsic severity of the risk scenario (what would happen if controls were absent)
  • The effectiveness of existing security services in reducing likelihood or impact
  • The residual risk after accounting for current controls

The result is a risk heat map showing which risk scenarios have unacceptably high residual risk and require treatment, which are at acceptable levels with current controls, and which could be managed at lower cost.

Risk Treatment Planning

Based on the risk situation analysis, MEHARI guides organizations through risk treatment planning:

  • Risk reduction: Selecting and implementing additional security services to reduce unacceptable residual risks
  • Risk transfer: Insurance or contractual transfer of residual risk
  • Risk acceptance: Formally accepting residual risks below the organization's risk threshold with board or management approval
  • Risk avoidance: Eliminating the activity or asset that generates the unacceptable risk

Treatment plans are documented with responsible owners, target dates, and expected risk reduction outcomes. The MEHARI methodology supports iterative risk treatment — each treatment cycle improves the organization's security service quality scores, which in turn reduces risk levels across the scenarios that the improved services address.

Healthcare-Specific Applications

HDS Certification Risk Analysis

The French HDS certification (Certification Hébergeurs de Données de Santé) requires health data hosting providers to demonstrate rigorous information security management of the systems used to host health data. HDS certification is based on ISO 27001 with healthcare-specific overlay requirements from the French health authority (Agence du Numérique en Santé, ANS). MEHARI is well-suited for the risk analysis component of HDS certification, providing a structured approach aligned to both ISO 27001 and the French healthcare regulatory context.

GDPR Health Data Risk Assessments

MEHARI supports GDPR Data Protection Impact Assessments (DPIAs) for health data processing. The methodology's structured approach to identifying threats, assessing vulnerabilities, and quantifying risks maps directly onto DPIA requirements. French DPAs (particularly the CNIL) expect organizations processing health data to conduct rigorous risk assessments — MEHARI provides a documented, defensible approach.

Clinical Information System Risk Analysis

MEHARI's healthcare knowledge base includes specific risk scenarios relevant to clinical systems: unauthorized access to electronic health records, data corruption in clinical systems, medical device network intrusions, and availability failures affecting patient care. These scenarios enable healthcare organizations to conduct risk analyses tailored to their specific clinical technology environments.

Integration with ISO 27001 and Other Frameworks

MEHARI is designed to complement ISO 27001 rather than compete with it:

  • MEHARI fulfills ISO 27001 Clause 6.1.2 (information security risk assessment) and Clause 6.1.3 (information security risk treatment) requirements, providing the documented methodology that ISO 27001 mandates but does not prescribe
  • MEHARI's security service quality assessments help select and justify the Annex A controls implemented in the ISO 27001 Statement of Applicability (SoA)
  • ISO 27001 certification then provides the auditable management system that MEHARI's risk analysis feeds into

This integration means that French healthcare organizations often use MEHARI and ISO 27001 together: MEHARI provides the risk analysis rigor, and ISO 27001 provides the internationally recognized certification that demonstrates it to customers and regulators.

MEHARI also integrates with:

  • EBIOS RM: Organizations in France may use MEHARI for detailed technical risk analysis and EBIOS RM for strategic risk scenarios involving threat actors. The methodologies are complementary and can be used in parallel.
  • ISO 27005: MEHARI aligns closely with ISO 27005's risk management process, making it straightforward for ISO 27005-aligned organizations to adopt MEHARI as their implementation methodology.
  • GDPR: MEHARI's structured output supports DPIA documentation required by GDPR Article 35.

Costs and Timeline

Organization TypeTypical TimelineEstimated Cost Range
Small health tech company or clinic2–3 months$15,000–$30,000
Mid-sized hospital or HDS provider3–5 months$30,000–$60,000
Large health system4–6 months$60,000–$100,000

Tools: MEHARI is available as a free download including methodology guides, knowledge base spreadsheets, and analysis workbooks. Organizations may also purchase GRC platform licenses that support MEHARI natively. Consulting costs for healthcare-specific MEHARI implementations are the primary variable cost.

  • ISO 27001: 60% overlap. MEHARI fulfills ISO 27001's risk assessment and treatment requirements while ISO 27001 provides the certification framework. The two are most powerful when used together.
  • ISO 27005: 75% overlap. MEHARI directly implements the ISO 27005 risk management process, with healthcare-specific scenarios and security service categories.
  • EBIOS RM: 55% overlap. ANSSI's EBIOS RM is France's national strategic risk methodology, focused on threat scenario analysis from a cyber resilience perspective. MEHARI provides more granular security service assessment, while EBIOS RM addresses strategic threat actor scenarios. Many French organizations use both.
  • GDPR Health: MEHARI supports GDPR DPIA requirements for health data processing. See the GDPR Health guide.

How Automation Helps

While MEHARI is traditionally conducted using spreadsheet tools, GRC platforms that support MEHARI can significantly reduce the analytical burden:

  • Risk scenario libraries import CLUSIF's published risk scenarios directly into the analysis platform
  • Security service assessment templates guide evaluators through the quality scoring process with standardized criteria
  • Risk calculation engines automatically compute residual risk levels from scenario and security service inputs
  • Treatment plan tracking maintains control implementation status and recalculates risk levels as improvements are made

LowerPlane supports risk analysis frameworks including MEHARI-aligned risk assessment workflows alongside ISO 27001, GDPR, and 50-plus additional frameworks. At $4,000 per year with a free tier available, and rated 9.4/10 on AuditXYZ, LowerPlane enables French healthcare organizations to conduct MEHARI-based risk analyses within a unified compliance platform that also supports HDS certification and GDPR compliance. Compare platforms at /compare/best-compliance-automation-platforms.

Frequently Asked Questions

Is MEHARI mandatory for French healthcare organizations?

MEHARI is not legally mandated for any French organization. However, it is widely recognized by French regulators and is specifically adapted for healthcare risk analysis in France. Organizations seeking HDS certification, ISO 27001 certification in the French healthcare context, or GDPR compliance programs targeting health data will find MEHARI an appropriate and well-recognized methodology. French hospital information security officers (RSSI) and health tech DPOs frequently cite MEHARI as their risk analysis methodology of choice.

How does MEHARI compare to EBIOS RM?

EBIOS RM (published by ANSSI) is France's official strategic risk management methodology, oriented toward understanding threat actors, attack scenarios, and strategic risk decisions. MEHARI is more technically oriented, focusing on security service quality assessment and detailed risk scenarios at the operational level. In practice, many French organizations use EBIOS RM for strategic risk analysis (addressing the threat landscape and organizational risk appetite) and MEHARI for detailed technical risk analysis (assessing specific security controls and their effectiveness against threat scenarios). The CNIL recommends a risk-based approach for GDPR DPIAs and accepts both methodologies as appropriate.

Can MEHARI be used for medical device security risk analysis?

MEHARI can be used for medical device information security risk analysis — assessing risks to the information assets and network connectivity of medical devices. It should be distinguished from medical device safety risk analysis (performed under IEC 62304 and ISO 14971), which addresses device failure modes and patient safety. For connected medical devices, both types of risk analysis are typically required: the clinical/safety risk analysis under IEC standards, and an information security risk analysis (for which MEHARI is suitable) addressing cybersecurity threats to the device and associated data.

How often should a MEHARI risk analysis be updated?

MEHARI methodology recommends updating the risk analysis whenever significant changes occur in the organization's information assets, threat landscape, or security controls. Best practice in healthcare is an annual review of the full risk analysis with more frequent updates for specific scenarios when significant events occur (new system deployments, major security incidents, or significant changes to the healthcare environment). For HDS-certified hosting providers and ISO 27001-certified organizations, the management system review cycle — typically annual — drives the cadence of risk analysis updates. GDPR DPIAs should be reviewed when processing activities change or risks evolve.

Where can I find MEHARI's knowledge base and tools?

MEHARI's methodology documents, knowledge base, and analysis tools are available for free download from CLUSIF's website (clusif.fr). The knowledge base includes a comprehensive catalogue of risk scenarios and security services in French, with some materials available in English. CLUSIF also publishes healthcare-specific guidance documents and runs training events for practitioners. Several GRC platforms support MEHARI natively, allowing organizations to manage MEHARI risk analyses within a digital workflow rather than spreadsheets — useful for larger organizations managing multiple simultaneous risk analysis cycles.

Request a MEHARI consultation

Step 1 of 520%

Which framework do you need?

Framework Mappings

Overlap with other frameworks

ISO 27005Medium75%
ISO 27001Medium60%
EBIOS RMMedium55%

Get matched with a MEHARI auditor in 24 hours

Free, no-obligation — just tell us your email and we'll do the rest.

By submitting, you agree to our privacy policy.