Blog

Health and AI

Summary
Health and AI

AI and Health Data: What Every Hospital Must Master in 2026

Data quality, HDS certification, GDPR and the AI Act, decentralized learning. The complete guide for hospital decision-makers.

The essentials in 30 seconds

Question Short answer What to remember
Can medical AI work with poor-quality data? No, quality comes before the algorithm A model trained on incomplete or unstructured data produces unreliable recommendations
Where must health data be hosted in France? With an HDS-certified host HDS certification, supervised by the French Digital Health Agency (ANS), is a legal obligation
Must data leave the hospital to train an AI? No, decentralized learning trains models on-site With Blockchain Swarm Learning®, data stays on hospital servers; only the learning travels
What does the EU AI Act change for hospitals? Some clinical AI is classified "high-risk", depending on use Documentation, traceability of training data and human oversight become mandatory
Who should validate health data structuring? Caregivers themselves Only clinicians can guarantee that data reflects clinical reality
What is the EHR's role in an AI project? It is the primary source of clinical data An EHR designed for AI avoids years of data cleaning before any use case
Does GDPR prevent AI in healthcare? No, it frames it Legal basis, minimisation and transparency are fully compatible with a well-governed project
Where to start in 2026? Data quality audit, HDS check, governance Foundations first, AI use cases second

Introduction

Artificial intelligence has become the number one selling point of healthcare software vendors. Yet in hospital IT departments, another reality prevails: promising AI projects that fail, not because of the algorithms, but because of the data that feeds them. Data scattered across departments, heterogeneous formats, inadequate hosting: the problem sits upstream.

The question is no longer "which AI should we choose?" but "is our health data ready?". This is precisely the conviction on which Galeon has been building its smart EHR since 2016, together with caregivers: the Electronic Health Record deployed in 19 hospitals, including 2 university hospitals, now structures more than 3 million patient records alongside 10,000+ caregivers.

A healthcare AI is only worth the data it was trained on. That sentence sums up what is at stake in 2026 for hospitals, as France's Ségur du numérique en santé programme, funded with 2 billion euros, pushes the whole sector towards interoperability and as the European AI Act gradually comes into force.

This article reviews what every hospital CIO and CEO must master: data quality, HDS certification, the new regulatory obligations, and the architectures that make it possible to train an AI without ever exposing patient records.

Why does healthcare AI depend on data quality first?

Because an AI model only learns from what it is shown: incomplete, redundant or badly coded data produces biased predictions, regardless of the power of the algorithm.

Healthcare is paradoxical: it generates close to 30% of the world's data volume according to RBC Capital Markets estimates, yet a large share of it remains unusable. Free-text reports, duplicates across software systems, misaligned terminologies (ICD-10, SNOMED, LOINC): the daily routine of a medical information department still too often consists of reconciling contradictory sources.

The consequence is direct for AI projects: data teams spend most of their time cleaning and structuring data before they can even train a model. To avoid this wall, Galeon made a radical architectural choice: structuring data at the source, validated by caregivers themselves at the moment of entry. Well-born data never needs to be repaired.

For a hospital, the criterion for choosing an EHR in 2026 is therefore no longer just functional: it is the software's ability to produce structured, coded data that is ready for research and AI. We cover this in detail in our article on predictive medicine in hospitals.

What is HDS certification and why does it concern your AI projects?

HDS certification (Hébergeur de Données de Santé, health data host) is the French legal framework governing the hosting of personal health data: as soon as this hosting is entrusted to a third party (software vendor, cloud host), that provider must be HDS-certified.

Issued by accredited bodies under the supervision of the French Digital Health Agency (ANS), the certification covers the physical security of infrastructures, service continuity, reversibility and protection against unauthorized access. The 2024 HDS framework, aligned with ISO 27001:2022, reinforced the requirements, notably on data location within the European Economic Area.

The link with AI is direct: training a model on patient records means processing health data. If your training pipeline copies data to a non-certified cloud, the whole project becomes non-compliant, whatever the clinical value of the result. Many hospital AI proofs-of-concept have stopped on exactly this point.

Three simple questions audit a project in minutes: where is the data hosted during training? Is the provider HDS-certified? Does the data leave the hospital's perimeter? If the answer to the last question is yes, there is now an alternative.

How can hospitals train medical AI without moving patient data?

This is what decentralized learning makes possible: instead of centralising records in a single warehouse, the model is trained locally in each hospital, and only the learning parameters are shared.

Galeon has industrialised this approach with Blockchain Swarm Learning®: the hospitals in the network train AI models together, coordinated through a blockchain, without a single patient record ever leaving the institution's servers. Each hospital keeps control of its data, which stays on its own servers, while benefiting from a model enriched by the collective experience of the network.

This architecture eases the three classic frictions of multi-site AI projects: the legal one (fewer data transfers, hence simpler data-sharing agreements), the security one (limiting how records circulate reduces the exposure surface) and the political one (no institution has to "hand over" its data to a third party). These benefits do not remove the need for a case-by-case compliance review.

Beyond the technology, the aim is for the value created by AI to also benefit the hospitals that produce the data, rather than external players.

What do GDPR and the AI Act change for hospital AI projects in 2026?

The essential fits in one sentence: compliance is no longer added at the end of an AI project, it is designed from the start.

On the GDPR side, the fundamentals are unchanged: a clear legal basis, data minimisation, patient information, and a data protection impact assessment (DPIA) for large-scale processing. Our guide on GDPR and health data for hospital CIOs details the concrete obligations institution by institution.

What is new in the 2025-2027 period is the gradual entry into force of the European AI Act (Regulation EU 2024/1689). Some clinical AI may be classified as "high-risk", depending on the use, the level of autonomy and the impact on patients. For these systems, this implies: complete technical documentation, governed and traceable training datasets, logging, effective human oversight and, for the medical devices concerned, CE marking.

For a CIO, the operational translation is the following: require from every AI vendor the traceability of its training data and its AI Act roadmap. A vendor unable to answer these two questions in 2026 exposes the institution to regulatory risk.

What are the concrete benefits for the CIO and for caregivers?

For the CIO

The main benefit is architectural: an EHR that structures data at the source limits the build-up of technical debt. Native interoperability (Ségur compatibility, exchanges with France's shared medical record Mon Espace Santé), HDS-certified hosting, and a data foundation ready for every new AI use case, without yet another migration project.

For caregivers

AI only makes sense if it gives medical time back. Structuring data at entry also means: less double data entry, reliable automatic summaries, up-to-date protocols available at the right moment. The goal is clear: to ease the mental load of care teams, a success criterion at least as important as algorithmic performance.

Comparison table: traditional EHR vs Galeon approach

Criterion Traditional EHR (monolithic) Galeon approach (AI + Blockchain)
Data structuring Often after the fact, reprocessing free-text entries At the source, validated by caregivers at the moment of entry
Data quality for AI Long cleaning phase before every project, variable results Data structured and coded at entry, ready sooner for training
Hosting HDS-certified, with architectures that vary by vendor HDS-certified, data kept on the hospital's servers
AI training Data centralised in an external warehouse Swarm Learning®: the model travels, never the data
Sovereignty Strong dependency on the vendor and its cloud The hospital remains owner and physical guardian of its data
AI Act compliance Training-data traceability hard to reconstruct Native traceability through blockchain coordination
Caregiver involvement End users consulted late in the process Co-built with caregivers since 2016, continuous clinical validation
Scalability Every AI use case is a new data project One foundation feeds all successive use cases
Proof at scale Many references but peripheral AI 19 hospitals including 2 university hospitals, 3 million structured records

Limits and challenges to be aware of

It would be dishonest to present hospital AI as an obstacle-free path. Here are the main limits to keep in mind in 2026.

  • The quality of historical data remains a major project. Structuring at the source fixes the future, not the past: years of free-text reports still require a recovery effort whose cost is often underestimated.
  • Decentralized learning does not remove governance. Even without data transfer, coding practices must be harmonised between institutions and training priorities arbitrated: this is human and medical work, not just technical.
  • The regulatory framework is still moving. The AI Act's implementing acts roll out until 2027, and some interpretations (notably the articulation with the Medical Device Regulation) are still being stabilised. Roadmaps must factor in this uncertainty.
  • Change management is the real limiting factor. A well-performing model poorly integrated into caregivers' workflows will simply not be used. Adoption is won department by department, with clinical champions, not by top-down rollout.
  • Data skills remain scarce in hospitals. Reinforced medical information departments, data managers, DPOs versed in AI: recruitment and training condition execution speed as much as technology does.

FAQ

Will AI replace doctors in hospitals?
No. Current clinical AI assists diagnosis, automates documentation tasks and flags risks, but the medical decision remains human, and the AI Act actually mandates effective human oversight for high-risk systems.

Can a hospital use a US public cloud for its health data?
Only if the offer is HDS-certified and compliant with the location requirements of the current framework. Beyond formal compliance, the question of sovereignty and exposure to extraterritorial laws must be raised at board level.

What is Swarm Learning® in concrete terms?
It is a decentralized training method: each hospital trains the model on its own servers, and only the learned parameters are shared and aggregated through blockchain coordination. Patient records never leave the institution.

How much does HDS compliance cost a hospital?
If the hospital hosts its own data, certification concerns its infrastructure; if it goes through a vendor or host, that provider must be certified. The institution's cost therefore shifts to contractual verification and subcontractor audits.

How do you measure the data quality of an EHR?
Four simple indicators: the share of structured fields (vs free text), the coding rate of diagnoses and procedures, the patient duplicate rate, and the delay between a procedure and its complete documentation. An initial audit on these four axes is enough to set a baseline.

In summary

In 2026, the success of a hospital AI project is decided at the foundations: data structured at the source and validated by caregivers, HDS-certified hosting, traceability compatible with GDPR and the AI Act, and an architecture that does not require patient records to leave the institution. Decentralized learning now makes possible what seemed contradictory: training models at the scale of a hospital network while keeping patient records within each institution. This is the path Galeon has been building since 2016: a smart EHR co-designed with caregivers, deployed in 19 hospitals including 2 university hospitals, structuring more than 3 million records, and a model where the value created by AI goes first to those who produce the data, the hospitals.

Want to know more about our smart EHR ?

Book a demo
Want to go further ? Read our guide on HDS certification in 2026

Sources

Ils nous font confiance

Logo du Centre Hospitalier Intercommunal Toulon La Seyne-sur-MerLogo du Centre Hospitalier Sud Francilien (CHSF)Logo blanc du GHNE (Groupement Hospitalier Nord Essonne) sur fond transparentLogo du CHU de RouenLogo du CHU Caen Normandie