| Question | Short answer | What to remember |
|---|---|---|
| What does HDS certification actually certify? | The hosting of health data entrusted to a third party | It covers the host's infrastructure and operations, not your software or your usage |
| Is HDS the same as GDPR compliance? | No, they are two distinct frameworks | HDS secures the hosting; the GDPR governs the lawful use of the data |
| Which framework applies in 2026? | The HDS 2024 referential | Aligned with ISO/IEC 27001:2022 and published by the French authorities |
| Does HDS cover the EHR software itself? | No | The application layer, its access controls and clinical logic are out of scope |
| Who issues and oversees the HDS certificate? | Accredited bodies, overseen by the ANS | Certifying bodies are accredited (COFRAC); the ANS supervises the scheme |
| Does HDS guarantee data stays in Europe? | Partly | The referential sets location requirements but does not neutralise extraterritorial laws on its own |
| What are the two HDS certificates? | Physical-infrastructure host and managed-services host | Six hosting activities split across two certificate types |
| If my host is HDS-certified, am I fully compliant? | No | You remain responsible for the software, access governance and the GDPR |
| Where to check a provider's HDS status? | The public list on esante.gouv.fr | Verify the exact activities covered, not just the label |
In hospital tenders, one line reassures everyone: the provider is HDS-certified. It is often read as a full guarantee that health data is safe and compliant. It is not. HDS certification proves one precise thing, the security of the hosting entrusted to a third party, and stays silent on much of the rest.
That gap between what the label promises and what it actually certifies is where compliance projects stumble. It matters even more as France's Ségur du numérique en santé programme, funded with 2 billion euros, pushes hospitals to modernise their data. Galeon has been building a smart EHR with caregivers since 2016, now deployed in 19 hospitals including 2 university hospitals, structuring more than 3 million patient records with 10,000+ caregivers, on HDS-certified hosting.
HDS certification is a hosting certification, not a certification of your software, your data usage or your GDPR compliance. Confusing the two is the most common, and the most expensive, mistake a hospital can make before signing.
This article maps precisely what the HDS 2024 framework covers, what it deliberately leaves out, and how it differs from the GDPR, so that CIOs and CEOs can read a certificate for what it really says.
HDS certification (Hébergeur de Données de Santé, health data host) certifies the security of hosting personal health data when that hosting is entrusted to a third party. It covers the host, not the client's software.
The framework, overseen by the French Digital Health Agency (ANS), defines six hosting activities, from providing physical sites and hardware to operating the information system and backing up the data. They are grouped into two certificates: a physical-infrastructure host and a managed-services host (hébergeur infogéreur).
Concretely, the certification audits physical and logical security, availability and business continuity, backup, controlled administration, protection against unauthorised access and data reversibility. Certifying bodies are themselves accredited, by COFRAC in France, which is what gives the label its weight.
In short, HDS answers one question well: is the roof over your health data solid? It does not tell you what happens inside the house.
Everything above the hosting layer. The EHR software, how data is entered and used, GDPR compliance in the broad sense, and any medical-device or AI Act obligations all sit outside the certification's scope.
This is the crucial nuance for a decision-maker: an HDS-certified host can perfectly well store data that a poorly designed application exposes, or that no one is legally allowed to process.
A certified host is a necessary foundation, never a complete compliance file.
HDS secures the hosting; the GDPR governs the lawful processing of the data. One is about infrastructure, the other about rights and purposes, and passing one says nothing about the other.
The GDPR (Regulation EU 2016/679) applies to the entire processing chain and gives the hospital, as data controller, obligations that no host can discharge for it: defining a legal basis, informing patients, honouring their rights and running a DPIA for large-scale health-data processing. Non-compliance can cost up to 20 million euros or 4% of worldwide annual turnover.
HDS certification, by contrast, is a French sector-specific requirement anchored in the Public Health Code: it makes sure that whoever physically holds the data meets a security bar. The two are complementary, not interchangeable. We detail the controller's duties in our guide on GDPR and health data.
You can host with a flawless HDS provider and still breach the GDPR on day one, if your usage is not governed.
The reference in force is the HDS 2024 referential, aligned with ISO/IEC 27001:2022. Any provider or document still pointing to an older version is out of date.
The updated referential modernises the requirements and maps them onto the current international security standards, notably ISO/IEC 27001:2022 for information-security management, alongside cloud-specific standards. It clarifies the six hosting activities and reinforces expectations on operations, subcontracting transparency and data location.
For a CIO, the practical test is simple: ask which version of the referential the certificate covers, and when the next audit is due. Certification is not permanent; it is maintained through periodic audits and renewals.
In 2026, the only correct answer to the question "which HDS version?" is the 2024 referential aligned with ISO/IEC 27001:2022.
Not on its own. The referential sets data-location requirements, but certification alone does not neutralise the extraterritorial laws a provider may be subject to.
Location and legal exposure are two different things. A provider can host data within the European Economic Area and still belong to a group subject to non-EU legislation. HDS certification does not settle that question; it must be analysed contract by contract, alongside reversibility and subcontracting clauses.
This is why sovereignty is assessed beyond the label. Galeon runs a single European, HDS-certified and ISO 27001 cloud, and, for AI, favours decentralized learning so that models can be trained while records stay on the hospital's servers, an approach that reduces, without ever eliminating, the questions raised by moving data. We compare providers on these criteria in our guide on how to choose your HDS provider.
Read the certificate for its exact scope, then map everything it does not cover to a named owner inside the project.
Verify the exact activities certified (physical infrastructure only, or managed services too), the referential version, the subcontractors, the data location and the reversibility terms. Cross-check the provider on the public list published on esante.gouv.fr. Then assess the application layer separately: access controls, audit trail and the structuring of the data itself.
Treat HDS as one line of a broader risk file, not as the whole answer. The institution remains the data controller: GDPR responsibility, professional-secrecy obligations and, where relevant, AI governance stay with the hospital. Ask your teams which risks the certificate does not cover, and who owns them.
A signature protects the hospital only if it is informed by what the certificate leaves out.
| Criterion | Reading the HDS label alone | Galeon layered approach |
|---|---|---|
| What the certificate proves | Read as a full compliance guarantee | Read as the hosting layer only, one control among several |
| Scope transparency | "HDS-certified" stated without detail | Exact activities, referential version and subcontractors documented |
| Application security | Outside HDS scope, rarely audited | Access controls, audit trail and traceability built into the software |
| Data structuring and usage | Free text, usage governance left to the client | Structured at the source, validated by caregivers |
| GDPR responsibility | Assumed covered by the host | Controller duties made explicit, DPIA support |
| Data location and exposure | EEA at best, extraterritorial exposure unaddressed | European hosting, exposure assessed contract by contract |
| AI training | Data copied to an external warehouse | Decentralized learning: models trained on-site, records stay in the hospital |
| Reversibility | Clause often overlooked | Reversibility and exit defined in the contract |
| Traceability of access | Hard to reconstruct after the fact | Access logging and audit trail native |
| Overall reading | The label ends the discussion | The label starts a structured due-diligence |
It would be dishonest to present HDS as a full answer to health-data risk. Here are the main limits to keep in mind in 2026.
Is HDS certification mandatory?
Yes, for anyone hosting personal health data collected during care. The obligation is anchored in France's Public Health Code, and the scheme is overseen by the French Digital Health Agency (ANS).
Does HDS certification mean my project is GDPR-compliant?
No. HDS secures the hosting; the GDPR governs the lawful processing of the data. They are complementary but distinct, and one never replaces the other.
What is the difference between the two HDS certificates?
One covers the physical-infrastructure host (providing sites and hardware), the other the managed-services host, which operates the information system and backs up the data. Together they span six hosting activities.
Is the current framework the 2023 or the 2024 version?
The reference in force is the HDS 2024 referential, aligned with ISO/IEC 27001:2022. A certificate or document referring to an earlier version should be updated.
Can an HDS-certified provider host data outside Europe?
The referential imposes location requirements within the European Economic Area. A provider owned by a non-EU group can still be certified, so extraterritorial exposure must be assessed separately, contract by contract.
Does HDS certify the EHR software?
No. It certifies the hosting activity only. The software's own security, access controls and clinical safety are outside its scope and must be evaluated on their own.
How do I verify a provider's HDS status?
Check the public list published on esante.gouv.fr, and confirm the exact activities certified and any subcontractors, rather than relying on the "HDS-certified" label alone.
In 2026, HDS certification proves exactly one thing: that the hosting of your health data, when entrusted to a third party, meets a defined security bar under the HDS 2024 referential aligned with ISO/IEC 27001:2022. It does not certify your EHR software, your data usage, your GDPR compliance or your medical-device and AI obligations, and it does not, by itself, resolve questions of sovereignty and extraterritorial exposure. Reading a certificate for its exact scope, then assigning every uncovered risk to a named owner, is what separates a reassuring line in a tender from a genuinely secure project. This is the approach Galeon builds on: a single European, HDS-certified and ISO 27001 cloud, an EHR whose data is structured at the source and validated by caregivers, and, for AI, decentralized learning designed so that models can be trained while patient records stay on the hospital's servers.
Want to know more about our smart EHR ?
Book a demoWant to go further ? Read our guide on what every hospital must check before signing an HDS contract




