| Question | Short answer | What to remember |
|---|---|---|
| Can medical AI work with poor-quality data? | No, quality comes before the algorithm | A model trained on incomplete or unstructured data produces unreliable recommendations |
| Where must health data be hosted in France? | With an HDS-certified host | HDS certification, supervised by the French Digital Health Agency (ANS), is a legal obligation |
| Must data leave the hospital to train an AI? | No, decentralized learning trains models on-site | With Blockchain Swarm Learning®, data stays on hospital servers; only the learning travels |
| What does the EU AI Act change for hospitals? | Some clinical AI is classified "high-risk", depending on use | Documentation, traceability of training data and human oversight become mandatory |
| Who should validate health data structuring? | Caregivers themselves | Only clinicians can guarantee that data reflects clinical reality |
| What is the EHR's role in an AI project? | It is the primary source of clinical data | An EHR designed for AI avoids years of data cleaning before any use case |
| Does GDPR prevent AI in healthcare? | No, it frames it | Legal basis, minimisation and transparency are fully compatible with a well-governed project |
| Where to start in 2026? | Data quality audit, HDS check, governance | Foundations first, AI use cases second |
Artificial intelligence has become the number one selling point of healthcare software vendors. Yet in hospital IT departments, another reality prevails: promising AI projects that fail, not because of the algorithms, but because of the data that feeds them. Data scattered across departments, heterogeneous formats, inadequate hosting: the problem sits upstream.
The question is no longer "which AI should we choose?" but "is our health data ready?". This is precisely the conviction on which Galeon has been building its smart EHR since 2016, together with caregivers: the Electronic Health Record deployed in 19 hospitals, including 2 university hospitals, now structures more than 3 million patient records alongside 10,000+ caregivers.
A healthcare AI is only worth the data it was trained on. That sentence sums up what is at stake in 2026 for hospitals, as France's Ségur du numérique en santé programme, funded with 2 billion euros, pushes the whole sector towards interoperability and as the European AI Act gradually comes into force.
This article reviews what every hospital CIO and CEO must master: data quality, HDS certification, the new regulatory obligations, and the architectures that make it possible to train an AI without ever exposing patient records.
Because an AI model only learns from what it is shown: incomplete, redundant or badly coded data produces biased predictions, regardless of the power of the algorithm.
Healthcare is paradoxical: it generates close to 30% of the world's data volume according to RBC Capital Markets estimates, yet a large share of it remains unusable. Free-text reports, duplicates across software systems, misaligned terminologies (ICD-10, SNOMED, LOINC): the daily routine of a medical information department still too often consists of reconciling contradictory sources.
The consequence is direct for AI projects: data teams spend most of their time cleaning and structuring data before they can even train a model. To avoid this wall, Galeon made a radical architectural choice: structuring data at the source, validated by caregivers themselves at the moment of entry. Well-born data never needs to be repaired.
For a hospital, the criterion for choosing an EHR in 2026 is therefore no longer just functional: it is the software's ability to produce structured, coded data that is ready for research and AI. We cover this in detail in our article on predictive medicine in hospitals.
HDS certification (Hébergeur de Données de Santé, health data host) is the French legal framework governing the hosting of personal health data: as soon as this hosting is entrusted to a third party (software vendor, cloud host), that provider must be HDS-certified.
Issued by accredited bodies under the supervision of the French Digital Health Agency (ANS), the certification covers the physical security of infrastructures, service continuity, reversibility and protection against unauthorized access. The 2024 HDS framework, aligned with ISO 27001:2022, reinforced the requirements, notably on data location within the European Economic Area.
The link with AI is direct: training a model on patient records means processing health data. If your training pipeline copies data to a non-certified cloud, the whole project becomes non-compliant, whatever the clinical value of the result. Many hospital AI proofs-of-concept have stopped on exactly this point.
Three simple questions audit a project in minutes: where is the data hosted during training? Is the provider HDS-certified? Does the data leave the hospital's perimeter? If the answer to the last question is yes, there is now an alternative.
This is what decentralized learning makes possible: instead of centralising records in a single warehouse, the model is trained locally in each hospital, and only the learning parameters are shared.
Galeon has industrialised this approach with Blockchain Swarm Learning®: the hospitals in the network train AI models together, coordinated through a blockchain, without a single patient record ever leaving the institution's servers. Each hospital keeps control of its data, which stays on its own servers, while benefiting from a model enriched by the collective experience of the network.
This architecture eases the three classic frictions of multi-site AI projects: the legal one (fewer data transfers, hence simpler data-sharing agreements), the security one (limiting how records circulate reduces the exposure surface) and the political one (no institution has to "hand over" its data to a third party). These benefits do not remove the need for a case-by-case compliance review.
Beyond the technology, the aim is for the value created by AI to also benefit the hospitals that produce the data, rather than external players.
The essential fits in one sentence: compliance is no longer added at the end of an AI project, it is designed from the start.
On the GDPR side, the fundamentals are unchanged: a clear legal basis, data minimisation, patient information, and a data protection impact assessment (DPIA) for large-scale processing. Our guide on GDPR and health data for hospital CIOs details the concrete obligations institution by institution.
What is new in the 2025-2027 period is the gradual entry into force of the European AI Act (Regulation EU 2024/1689). Some clinical AI may be classified as "high-risk", depending on the use, the level of autonomy and the impact on patients. For these systems, this implies: complete technical documentation, governed and traceable training datasets, logging, effective human oversight and, for the medical devices concerned, CE marking.
For a CIO, the operational translation is the following: require from every AI vendor the traceability of its training data and its AI Act roadmap. A vendor unable to answer these two questions in 2026 exposes the institution to regulatory risk.
The main benefit is architectural: an EHR that structures data at the source limits the build-up of technical debt. Native interoperability (Ségur compatibility, exchanges with France's shared medical record Mon Espace Santé), HDS-certified hosting, and a data foundation ready for every new AI use case, without yet another migration project.
AI only makes sense if it gives medical time back. Structuring data at entry also means: less double data entry, reliable automatic summaries, up-to-date protocols available at the right moment. The goal is clear: to ease the mental load of care teams, a success criterion at least as important as algorithmic performance.
| Criterion | Traditional EHR (monolithic) | Galeon approach (AI + Blockchain) |
|---|---|---|
| Data structuring | Often after the fact, reprocessing free-text entries | At the source, validated by caregivers at the moment of entry |
| Data quality for AI | Long cleaning phase before every project, variable results | Data structured and coded at entry, ready sooner for training |
| Hosting | HDS-certified, with architectures that vary by vendor | HDS-certified, data kept on the hospital's servers |
| AI training | Data centralised in an external warehouse | Swarm Learning®: the model travels, never the data |
| Sovereignty | Strong dependency on the vendor and its cloud | The hospital remains owner and physical guardian of its data |
| AI Act compliance | Training-data traceability hard to reconstruct | Native traceability through blockchain coordination |
| Caregiver involvement | End users consulted late in the process | Co-built with caregivers since 2016, continuous clinical validation |
| Scalability | Every AI use case is a new data project | One foundation feeds all successive use cases |
| Proof at scale | Many references but peripheral AI | 19 hospitals including 2 university hospitals, 3 million structured records |
It would be dishonest to present hospital AI as an obstacle-free path. Here are the main limits to keep in mind in 2026.
Will AI replace doctors in hospitals?
No. Current clinical AI assists diagnosis, automates documentation tasks and flags risks, but the medical decision remains human, and the AI Act actually mandates effective human oversight for high-risk systems.
Can a hospital use a US public cloud for its health data?
Only if the offer is HDS-certified and compliant with the location requirements of the current framework. Beyond formal compliance, the question of sovereignty and exposure to extraterritorial laws must be raised at board level.
What is Swarm Learning® in concrete terms?
It is a decentralized training method: each hospital trains the model on its own servers, and only the learned parameters are shared and aggregated through blockchain coordination. Patient records never leave the institution.
How much does HDS compliance cost a hospital?
If the hospital hosts its own data, certification concerns its infrastructure; if it goes through a vendor or host, that provider must be certified. The institution's cost therefore shifts to contractual verification and subcontractor audits.
How do you measure the data quality of an EHR?
Four simple indicators: the share of structured fields (vs free text), the coding rate of diagnoses and procedures, the patient duplicate rate, and the delay between a procedure and its complete documentation. An initial audit on these four axes is enough to set a baseline.
In 2026, the success of a hospital AI project is decided at the foundations: data structured at the source and validated by caregivers, HDS-certified hosting, traceability compatible with GDPR and the AI Act, and an architecture that does not require patient records to leave the institution. Decentralized learning now makes possible what seemed contradictory: training models at the scale of a hospital network while keeping patient records within each institution. This is the path Galeon has been building since 2016: a smart EHR co-designed with caregivers, deployed in 19 hospitals including 2 university hospitals, structuring more than 3 million records, and a model where the value created by AI goes first to those who produce the data, the hospitals.
Want to know more about our smart EHR ?
Book a demoWant to go further ? Read our guide on HDS certification in 2026




