CaRE Program: sustain control of your internet exposure
France's CaRE program made internet exposure control the #1 cybersecurity priority for healthcare facilities — with measurable results. The challenge now: making those gains last. Purplemet continuously monitors your facility's web attack surface, without intrusion and without mobilizing your teams.
CaRE at a glance
What CaRE changes for
healthcare facilities, in three points
- An unprecedented national effort Launched in late 2023 by the French Ministry of Health, the CaRE program (Cybersecurity Acceleration and Resilience of Facilities) mobilizes massive funding — an ambition of €750M by 2027 — to close the cybersecurity gap of health and medico-social facilities.
- Internet exposure, priority of "Domain 1" The first funding call targets control of internet exposure and technical directories — one of attackers' main entry vectors. Results are showing: the share of facilities with critical exposure vulnerabilities has dropped sharply. Domain 1 bis extends the scheme to new facilities in 2026.
- The coming challenge: lasting France's Court of Auditors stressed it: the effort must be sustained, and funding may become conditional on continuous improvement. A one-off audit and remediation are not enough if exposure is not monitored afterwards.
Where Purplemet fits
We extend the impact of your "Domain 1" remediation
"Domain 1" helped healthcare organizations identify and remediate critical risks affecting their internet exposure. Purplemet helps preserve those improvements over time, as new patient portals, telemedicine services, and applications continuously reshape the attack surface.
- Keeping the exposure map current Purplemet continuously discovers the facility's exposed web applications — including those deployed outside the IT department's radar (business services, providers, legacy). The map produced for Domain 1 stops being a snapshot: it stays current, automatically.
- Catching drift before it settles Every exposure change and every newly published vulnerability affecting your components is detected as it happens. The gains of the initial remediation are preserved — no silent backsliding between audits.
- Sparing teams already under pressure No installation, no configuration, no intrusive scanning that could disturb critical systems: Purplemet observes from the outside, the way an attacker would, and delivers prioritized, actionable results — built for hospital IT teams with no time to waste.
- Documenting continuous improvement If funding evolves toward measured progress over time, Purplemet's monitoring history objectifies your facility's trajectory: exposure reduced, vulnerabilities addressed, drift corrected.
Common questions about CaRE and Web ASM
Is Purplemet listed or funded by the CaRE program?
Purplemet is neither a CaRE-certified or labeled solution, nor an audit provider of the program. Expense eligibility for funding is determined by your regional health agency (ARS) and the French digital health agency (ANS). Purplemet does, however, address Domain 1's operational objective: continuous control of internet exposure.
Why monitor internet exposure after the Domain 1 audit?
Because an attack surface changes constantly: new telemedicine services, portals, applications deployed by providers, vulnerabilities published weekly on existing components. Without continuous monitoring, the gains of the initial remediation erode silently — and the program itself insists the effort must last.
Could Purplemet disrupt critical hospital systems?
No. Purplemet installs nothing, configures nothing and performs no intrusive scanning: it observes what is visible from the outside, exactly as an attacker would, without interacting with systems. It is an approach suited to sensitive environments such as healthcare facilities.

