Guide
HDS: what the certification covers, and what it doesn't
HDS certification is mandatory for hosting health data on behalf of third parties. What it guarantees, and what it ignores: the application layer and sovereignty. A practical read before signing with a host or a software vendor.
Published July 18, 2026
HDS certification (hébergeur de données de santé, France's health data hosting scheme) is mandatory for any organisation that hosts personal health data on behalf of third parties, under article L.1111-8 of the French public health code. It attests that the hosting meets a baseline of security requirements, nothing more: it does not cover the software processing your data, and it does not guarantee its sovereignty.
Those two blind spots make all the difference between reading a certificate and understanding what it protects. Here is exactly what the certification covers, and the questions it leaves open.
The obligation hinges on four words: "on behalf of third parties"
Article L.1111-8 covers health data collected in the course of prevention, diagnosis, care or social and medico-social follow-up. Whoever hosts that data for a third party - an institution, a practitioner, or the patient themselves - must hold a certificate of conformity, issued by an accredited body. The law adds two safeguards: the host may do nothing with the data beyond the hosting service itself, and must return it in full when the contract ends.
The mirror of that clause matters just as much: hosting your own data falls outside the scope. The Agence du Numérique en Santé says it plainly:
"Health establishments that run their own health information system do not need to be HDS-certified." (ANS FAQ, our translation)
A clinic running its information system on its own servers remains subject to the GDPR and to the sector's security frameworks, but HDS certification does not apply to it. Self-hosting sits outside the scheme by design, not by omission.
Six activities, two certificates: read the scope
There is no such thing as a generic HDS certificate. The framework splits hosting into six activities:
- physical sites (premises, datacenters);
- hardware infrastructure;
- virtual infrastructure;
- application hosting platform;
- administration and operation of the health information system;
- outsourced backup.
They map onto two profiles: the "physical infrastructure host" certificate covers activities 1 and 2, the "managed services host" (infogéreur) certificate covers activities 3 to 6. A given provider may hold only part of a profile's activities.
The practical consequence: "being HDS-certified" means nothing until you have read which activities the certificate covers. The most common case: a software vendor operates your application on a major cloud's certified infrastructure. The cloud's certificate covers the machines, not the operation. If the vendor administers the system carrying your health data, that is activity 5, and it requires the vendor's own certificate. A subcontractor's certificate does not travel up the chain.
V2: what the order of 26 April 2024 changed
The framework was revised by the order of 26 April 2024, and the entire certified market has been operating under this version 2 since May 2026. Two changes matter directly to customers:
- the physical hosting of the data must be located within the European Economic Area;
- the host must be transparent about its exposure to non-European law: you must be able to know whether a non-EU legal regime can reach your data through its ownership structure or its subcontractors.
More than 400 certified hosts appear on the official list published by the ANS. That list is authoritative.
What the certification does not cover
The application layer. HDS certifies the hosting: sites, infrastructure, operation, backup. It says nothing about the software running on top - its access controls, its outbound flows, the quality of its code. A tool that sends every request to an AI API outside that perimeter can perfectly well run on certified hosting: the certificate does not cover that flow.
Sovereignty. This is the most expensive confusion. American hyperscalers hold HDS certification: hosting within the EEA does not remove a provider from the extraterritorial laws of its home state. V2 addressed the issue through transparency, not immunity: the host declares its exposure, it does not have to eliminate it. The immunity requirement was pushed up to the European debate on the future EUCS cloud certification scheme, still unresolved to date. An HDS certificate tells you the hosting is secure; it does not tell you who can, as a matter of law, demand access to your data.
The three questions to ask before signing
For a practice, a clinic or a group evaluating software or AI in healthcare, reading the certificate comes down to three questions:
- Who hosts? The host's name, its certificate, the activities covered.
- Who operates? If the vendor administers your instance, it needs its own infogéreur certificate (activity 5): its host's certificate is not enough.
- Where does inference run? For an AI tool: which model do the requests go to, hosted where, under which jurisdiction? Certified hosting in France protects little if every question put to the AI leaves the perimeter.
Those three questions also describe our own architecture. Your agents run on your own instance: hosted within your walls, in which case the HDS obligation does not even apply, or hosted and operated on the HDS-certified infrastructure of one of our regional partners. The details for healthcare organisations are on our dedicated page.
Frequently asked questions
What is the difference between ISO 27001 and HDS?
ISO 27001 is the international information security management standard: generic, voluntary, applicable to any sector. HDS is a sector certification required by French law for hosting health data on behalf of third parties. The HDS framework builds on ISO 27001 and adds sector-specific requirements: EEA location, transparency on non-European law, contractual safeguards. One is the foundation, the other the legal obligation.
Who must be HDS-certified?
Any natural or legal person hosting, operating or backing up health data on behalf of third parties: infrastructure hosts, managed service providers, software vendors administering the system that carries the data. The certificate states which activities it covers; check that they match the service actually delivered.
What are the conditions for hosting health data?
A hosting contract compliant with article L.1111-8, a certificate covering the relevant activities, physical hosting within the EEA, customer information on exposure to non-European law, a ban on using the data beyond the service itself, and full return of the data at the end of the contract.
Does a medical practice need to be HDS-certified?
No. The obligation falls on whoever hosts on behalf of third parties: that is the business of your patient-record vendor and its host, not yours. And if the practice hosts its own data on its own servers, nobody needs the certificate: the practice remains responsible for its security under the GDPR, but the HDS scheme does not apply.