HDS: understanding France's health data hosting certification
Who needs to be certified, for which activities, and what changes in 2026.
HDS stands for hébergeur de données de santé, France's mandatory health data hosting certification for any organisation that stores or operates personal health data on behalf of a third party. It is issued for three years by an accredited certification body, based on a framework from France's Digital Health Agency, and covers six activities, from the data centre to backup. Since 16 May 2026, only the HDS 2.0 framework applies.
HDS: definition and legal framework
The obligation comes from Article L.1111-8 of the French Public Health Code. It applies to anyone who hosts personal health data collected during prevention, diagnosis, care, or social and medico-social follow-up, on behalf of the person or organisation that produced or collected it, or on behalf of the patient. That host must be certified.
The system changed in 2018. Until then, hosts obtained a ministerial approval, reviewed case by case. Since 1 April 2018, approval has been replaced by a certification issued by independent, accredited bodies against a public framework. The process is now much closer to the ISO certifications that security teams already know.
Three parties share the roles:
- the Digital Health Agency (ANS) writes the certification and accreditation frameworks and publishes the list of certified hosts;
- certification bodies, accredited by COFRAC in France or an equivalent European body, audit hosts and issue certificates;
- hosts apply for certification for the activities they carry out and undergo the audits.
HDS does not replace the GDPR. Health data is a special category of personal data: the controller (the hospital, the practice or the software vendor, depending on the case) still needs a legal basis, a record of processing and, in most cases, a data protection impact assessment (DPIA). HDS governs the host; the GDPR governs the processing.
Who needs HDS certification?
Three conditions must all be met: personal health data, collected in a care context (prevention, diagnosis, care, social or medico-social follow-up), and hosted on behalf of a third party. If any one is missing, certification is not required, although other obligations remain. The tool below follows that reasoning.
Answer three questions to see where your organisation stands.
Is the data personal health data collected during prevention, diagnosis, care, or social and medico-social follow-up?
Examples: patient records, imaging reports, lab results, remote monitoring data.
Who stores the data or runs the system that holds it?
Do you yourself carry out at least one of the six hosting activities: physical site, hardware, virtual infrastructure, application platform, administration and operation of the system, backup?
No HDS certification for this data
A wellness app, or data unrelated to patient care, is not automatically in scope. If the data relates to a person's health, however, the GDPR treats it as a special category: a DPIA and stronger security measures still apply. If you are unsure how to classify the data, have the scope confirmed.
You do not need certification for this activity
An institution that keeps its own data on its own resources is not hosting on behalf of a third party. Security obligations still apply (GDPR, France's health information security policy, NIS 2 where relevant). As soon as you outsource part of the hosting, the provider must be certified.
Your provider must be HDS certified
Check the certificate before signing: legal entity, activities covered, sites, validity dates. The contract must include the clauses required by the French Public Health Code (location, subcontractors, reversibility, transfers outside the EU/EEA). You remain the data controller.
You must be HDS certified for your activities
Each player in the chain is certified for the activities it carries out itself. A SaaS vendor that administers and operates its clients' application usually falls under activity 5, even when it relies on infrastructure that is already certified. Hosting without a certificate carries criminal penalties.
Map your hosting chain in detail
If you truly carry out none of the six activities, your providers must be certified for each of them. This is rare: administrative access to the data is often enough to fall under activity 5. Validate the split, activity by activity, with your providers and your certification body.
SaaS software vendors
This is the case that raises the most questions. A vendor offering patient records, medical appointment booking or remote monitoring as SaaS hosts its clients' data. Relying on a cloud that is already certified does not exempt it: each party is certified for the activities it carries out itself. A vendor that administers the application and database usually falls under activity 5 (administration and operation of the information system).
Healthcare institutions and hospital groups
A hospital, clinic or care home that hosts its own data on its own resources does not need certification for that activity. Things change as soon as it hosts for others: a lead hospital hosting the information system of the other members of a regional hospital group, or a university hospital offering its infrastructure to partners, becomes a host under the law. Several institutions appear on the ANS list of certified hosts.
What is not automatically in scope
A wellness app, a step counter or a consumer service unrelated to care is not automatically subject to HDS. Caution is still needed: the boundary depends on how the data is used, and the GDPR applies in every case as soon as the data reveals something about a person's health.
The 6 health data hosting activities
Article R.1111-9 of the Public Health Code splits hosting into six activities, stacked like the layers of an infrastructure. A host can be certified for just one of them or for all six. The split is mainly used to allocate responsibilities in a chain that often involves a data centre, a cloud provider, a software vendor and sometimes a managed service provider.
- 06 Backup Backing up health data, including, since 2026, keeping it as part of electronic archiving.
- 05 Administration and operation Administering and operating the information system that holds the health data.
- 04 Application hosting platform Providing and maintaining operating systems, databases and middleware.
- 03 Virtual infrastructure Providing and maintaining virtual machines and the virtualisation layer.
- 02 Hardware infrastructure Providing and maintaining servers, storage and network.
- 01 Physical site Providing and maintaining the physical sites that house the hardware.
All six activities, from the server room up to running the system that holds the data.
According to the ANS, only sites located in the European Economic Area can be certified for activities 1, 2 and 6. Since the decree of 24 March 2026, activity 6 explicitly includes retention as part of electronic archiving: a third-party archiving provider that keeps health data must now be HDS certified for that activity.
The HDS 2.0 framework and the 2026 rules
The certification framework was completely overhauled in 2024, then supplemented in 2026 by a decree stemming from France's SREN law. Here is the timeline to remember, based on ANS presentations:
- 26 April 2024: order approving the HDS 2.0 framework, published in the Official Journal on 16 May 2024. New hosts are certified against this version.
- 16 November 2024: end of the transition for certification bodies, which now audit only against version 2.0.
- 24 March 2026: Decree No. 2026-209, implementing Article 32 of the SREN law of 21 May 2024, published in the Official Journal on 26 March.
- 16 May 2026: end of the transition for hosts. Certificates issued under the former version 1.1 are no longer valid.
- End of September 2026: the territoriality and transparency rules and the new contract clauses apply, six months after the decree's publication.
- Coming next: a framework 2.1 that writes the decree into the certification requirements. The ANS states that audits carried out three months after its publication in the Official Journal will follow that version.
Location: storage in the EU or EEA
Where data is stored, it must be stored exclusively in a European Union member state or a state party to the European Economic Area (new Article R.1111-9-1 of the Public Health Code). Data therefore does not have to stay in France. Access from a third country, including simple remote administration, counts as a transfer: it is only allowed on the basis of an adequacy decision or appropriate safeguards under Articles 45 and 46 of the GDPR.
Transparency about extraterritorial laws
This is the decree's most visible change. If the host or one of its subcontractors is subject to the law of a country outside the EU/EEA, the contract must name that law, state whether an adequacy decision exists and, if not, describe the mitigation measures and residual risks. The host must also publish and keep up to date a map of transfers and access from third countries. As Acteurs publics pointed out back in 2024, HDS does not require full immunity from foreign law: that is the key difference with SecNumCloud.
More complete contracts
The clause on data subjects' rights now covers access, rectification, erasure, restriction and objection, not just portability. According to the analysis by Vigier Avocats, these new clauses only take effect six months after the decree's publication in the Official Journal, on 27 September 2026: amendments to existing contracts need to be planned ahead.
Getting HDS certified: steps, bodies and timeline
The process follows the usual pattern of a management system certification:
- Define the scope: the activities (1 to 6) you actually carry out, the sites, the services, the subcontractors.
- Set up or extend an information security management system compliant with ISO 27001 over that scope (see our article on the ISMS), with a risk assessment, a statement of applicability and the related controls.
- Cover the HDS-specific requirements: contract clauses, location, handling of access from third countries, publication of the transfer map, patients' rights.
- Choose an accredited certification body from the list published by the ANS, then go through the initial audit (document review and on-site audit).
- Address any non-conformities, then obtain the certificate, valid for three years.
- Maintain it: annual surveillance audit, then a renewal audit after three years.
How long should you plan for? At its SantExpo workshop in May 2026, the ANS reported nine to twelve months of compliance work on average, then at least three to four months for the certification, plus three to six months if non-conformities are found. The agency counted 411 certified hosts at the time. Cost depends on scope and starting maturity: certification body fees, internal time, technical work and surveillance audits.
Not to be overlooked: under Article L.1115-1 of the Public Health Code, hosting without certification is punishable by three years' imprisonment and a €45,000 fine.
HDS, ISO 27001 and SecNumCloud: what are the differences?
These three schemes often come up together in healthcare tenders. They do not answer the same question, and none of them replaces the others.
| Criterion | HDS | ISO 27001 | SecNumCloud |
|---|---|---|---|
| Nature | Mandatory certification (French law) | Voluntary international standard | ANSSI qualification |
| Issued by | Accredited certification body | Accredited certification body | ANSSI, after evaluation by an approved centre |
| Subject | Hosting health data for a third party | Information security management system | A cloud service (IaaS, PaaS, SaaS) |
| Data location | Storage in the EU or EEA | No requirement | In the EU, with stricter requirements |
| Extraterritorial laws | Transparency and mitigation | Not addressed | Protection required |
| Validity | 3 years, annual audit | 3 years, annual audit | 3 years, surveillance audits |
ISO 27001 is the foundation: the HDS framework builds on it and adds its own requirements, so a host already certified to ISO 27001 has covered much of the ground. To manage that common base, a compliance assessment tool saves you from documenting the same controls twice. SecNumCloud goes further on sovereignty but does not replace HDS: a qualified cloud hosting health data must also be certified. According to the ANS, eight of the ten SecNumCloud-qualified providers listed in May 2026 were also HDS certified. We cover that framework in our article SecNumCloud: ANSSI's trusted cloud framework.
Choosing and monitoring an HDS-certified host
For a healthcare organisation or vendor entrusting its data to a host, the HDS certificate is a starting point, not a sufficient guarantee. Before signing, check at least:
- the legal entity on the certificate, which must be the one signing the contract;
- the activities and sites covered, against the service actually purchased;
- the validity dates and the framework version (2.0 since 16 May 2026);
- the list of subcontractors and their own certification;
- the map of transfers outside the EU/EEA published by the host;
- the reversibility clauses: return of data in a usable format and no copies kept.
These checks are part of third-party risk management: they happen at signature, then at each renewal. A well-designed vendor security questionnaire lets you collect this information consistently from every provider.
HDS, PGSSI-S and NIS 2: the other pieces of the puzzle
In a healthcare organisation, HDS is part of a wider whole. The health information systems security policy (PGSSI-S), published by the ANS, brings together the sector's security frameworks and guides, some of which are binding (electronic identification, accountability, and more). Healthcare is also one of the sectors covered by the NIS 2 directive. The same CISO therefore has to track several frameworks, often across several sites.
How Phinasoft helps
Phinasoft lets healthcare organisations run compliance assessments (HDS, ISO 27001, NIS 2, your security policy and more) and compliance campaigns by site or institution, assess their providers on a dedicated portal, and keep their DPIAs and record of processing up to date. It is listed with French healthcare purchasing bodies, including Resah and CAIH, and can be hosted as SaaS on a French sovereign cloud (OVH or Outscale) with a SecNumCloud option, as SaaS on AWS in Europe, or on-premise. To see how you can monitor your hosts' compliance, you can request a demo.
Summary
A legal obligation
Hosting personal health data on behalf of a third party in France requires HDS certification, activity by activity (Article L.1111-8 of the Public Health Code).
A tougher framework
Since 16 May 2026, only certificates under framework 2.0 are valid. The decree of 24 March 2026 anchors storage in the EU or EEA and requires transparency about access from third countries.
A chain to manage
The host's certificate is not enough: the healthcare organisation or software vendor must check the scope, contract clauses and subcontractors, then monitor their compliance over time.
Frequently asked questions
What is HDS certification?
HDS (health data hosting) certification is mandatory in France for anyone who hosts personal health data on behalf of a third party: a healthcare institution, a health professional, a software vendor or the patient. It is issued by an accredited certification body, based on a framework published by France's Digital Health Agency (ANS), and covers one or more of six hosting activities.
Who needs HDS certification?
Any person or organisation that hosts health data collected during prevention, diagnosis, care, or social and medico-social follow-up, on behalf of whoever produced it or of the patient. This typically includes data centres, cloud providers, managed service providers and healthcare SaaS vendors. An institution hosting its own data on its own resources is not concerned for that activity.
How long does HDS certification last?
An HDS certificate is valid for three years, with a surveillance audit every year, followed by a renewal audit. As for preparation, the ANS reports nine to twelve months of compliance work on average, then at least three to four months for the certification itself, longer if the audit finds non-conformities.
What is the difference between HDS and ISO 27001?
ISO 27001 is a voluntary international standard for information security management, with a scope chosen by the organisation. HDS certification is a French legal obligation specific to health data: it builds on ISO 27001 and adds specific requirements, notably on contracts, data location and transparency about access from third countries.
Does health data have to be hosted in France?
No. The decree of 24 March 2026 requires storage to take place exclusively in a European Union member state or a state party to the European Economic Area. Access from a third country, even remote access, is only allowed with an adequacy decision or appropriate safeguards under the GDPR, and must be disclosed to the client.
Where can I find the list of HDS-certified hosts?
The ANS publishes and updates on esante.gouv.fr the list of certified hosts, with their certification body and the activities covered, as well as the list of bodies accredited to issue the certification. Always check the certificate itself: legal entity, sites, activities and validity dates.
What are the risks of hosting health data without HDS certification?
The French Public Health Code provides for up to three years' imprisonment and a €45,000 fine for hosting health data without certification. On top of that come GDPR penalties imposed by the CNIL for security failures, and contractual risk towards clients.
Sources (10)
- Légifrance — French Public Health Code (Articles L.1111-8, L.1115-1, R.1111-8-8 et seq.)
- Légifrance — Decree No. 2026-209 of 24 March 2026 on health data hosting
- French Digital Health Agency (ANS) — HDS certification (frameworks, lists of hosts and accredited bodies)
- ANS — HDS certification webinar, 15 October 2025
- ANS — HDS webinar, 18 March 2026 (framework 2.1)
- ANS — SantExpo workshop “HDS certification”, 20 May 2026
- ANS — Health information systems security policy (PGSSI-S)
- Vigier Avocats — The decree of 24 March 2026 strengthens sovereignty, territoriality and transparency
- Acteurs publics — The State sets new rules to secure health data (May 2024)
- ANSSI — SecNumCloud qualification FAQ
A platform and service that adapt to you
Our platform is designed for fine-tuned configuration and broad adaptability to your needs.