Blog

Health and AI

Summary
Health and AI

HDS Certification: What It Really Covers in 2026 (and What It Doesn't)

HDS certification secures health data hosting, not your software, your usage or GDPR.

The essentials in 30 seconds

Question Short answer What to remember
What does HDS certification actually certify? The hosting of health data entrusted to a third party It covers the host's infrastructure and operations, not your software or your usage
Is HDS the same as GDPR compliance? No, they are two distinct frameworks HDS secures the hosting; the GDPR governs the lawful use of the data
Which framework applies in 2026? The HDS 2024 referential Aligned with ISO/IEC 27001:2022 and published by the French authorities
Does HDS cover the EHR software itself? No The application layer, its access controls and clinical logic are out of scope
Who issues and oversees the HDS certificate? Accredited bodies, overseen by the ANS Certifying bodies are accredited (COFRAC); the ANS supervises the scheme
Does HDS guarantee data stays in Europe? Partly The referential sets location requirements but does not neutralise extraterritorial laws on its own
What are the two HDS certificates? Physical-infrastructure host and managed-services host Six hosting activities split across two certificate types
If my host is HDS-certified, am I fully compliant? No You remain responsible for the software, access governance and the GDPR
Where to check a provider's HDS status? The public list on esante.gouv.fr Verify the exact activities covered, not just the label

Introduction

In hospital tenders, one line reassures everyone: the provider is HDS-certified. It is often read as a full guarantee that health data is safe and compliant. It is not. HDS certification proves one precise thing, the security of the hosting entrusted to a third party, and stays silent on much of the rest.

That gap between what the label promises and what it actually certifies is where compliance projects stumble. It matters even more as France's Ségur du numérique en santé programme, funded with 2 billion euros, pushes hospitals to modernise their data. Galeon has been building a smart EHR with caregivers since 2016, now deployed in 19 hospitals including 2 university hospitals, structuring more than 3 million patient records with 10,000+ caregivers, on HDS-certified hosting.

HDS certification is a hosting certification, not a certification of your software, your data usage or your GDPR compliance. Confusing the two is the most common, and the most expensive, mistake a hospital can make before signing.

This article maps precisely what the HDS 2024 framework covers, what it deliberately leaves out, and how it differs from the GDPR, so that CIOs and CEOs can read a certificate for what it really says.

What does HDS certification actually cover?

HDS certification (Hébergeur de Données de Santé, health data host) certifies the security of hosting personal health data when that hosting is entrusted to a third party. It covers the host, not the client's software.

The framework, overseen by the French Digital Health Agency (ANS), defines six hosting activities, from providing physical sites and hardware to operating the information system and backing up the data. They are grouped into two certificates: a physical-infrastructure host and a managed-services host (hébergeur infogéreur).

Concretely, the certification audits physical and logical security, availability and business continuity, backup, controlled administration, protection against unauthorised access and data reversibility. Certifying bodies are themselves accredited, by COFRAC in France, which is what gives the label its weight.

In short, HDS answers one question well: is the roof over your health data solid? It does not tell you what happens inside the house.

What does HDS certification NOT cover?

Everything above the hosting layer. The EHR software, how data is entered and used, GDPR compliance in the broad sense, and any medical-device or AI Act obligations all sit outside the certification's scope.

This is the crucial nuance for a decision-maker: an HDS-certified host can perfectly well store data that a poorly designed application exposes, or that no one is legally allowed to process.

  • The application layer. The EHR software itself, its access controls, its clinical logic and its own vulnerabilities are not audited by HDS.
  • Data usage. Who accesses a record, for which purpose and with which legal basis is a GDPR question, not an HDS one.
  • The GDPR at large. Patient information, data minimisation, data-subject rights and impact assessments (DPIA) remain the controller's responsibility.
  • Medical-device and AI qualification. Whether a feature is a medical device, or an AI system with specific obligations, depends on its purpose, not on where it is hosted.
  • Your own perimeter. Workstations, internal network and staff practices inside the hospital are outside the host's certificate.

A certified host is a necessary foundation, never a complete compliance file.

HDS certification vs GDPR: what is the real difference?

HDS secures the hosting; the GDPR governs the lawful processing of the data. One is about infrastructure, the other about rights and purposes, and passing one says nothing about the other.

The GDPR (Regulation EU 2016/679) applies to the entire processing chain and gives the hospital, as data controller, obligations that no host can discharge for it: defining a legal basis, informing patients, honouring their rights and running a DPIA for large-scale health-data processing. Non-compliance can cost up to 20 million euros or 4% of worldwide annual turnover.

HDS certification, by contrast, is a French sector-specific requirement anchored in the Public Health Code: it makes sure that whoever physically holds the data meets a security bar. The two are complementary, not interchangeable. We detail the controller's duties in our guide on GDPR and health data.

You can host with a flawless HDS provider and still breach the GDPR on day one, if your usage is not governed.

Which HDS framework applies in 2026: the HDS 2024 referential explained

The reference in force is the HDS 2024 referential, aligned with ISO/IEC 27001:2022. Any provider or document still pointing to an older version is out of date.

The updated referential modernises the requirements and maps them onto the current international security standards, notably ISO/IEC 27001:2022 for information-security management, alongside cloud-specific standards. It clarifies the six hosting activities and reinforces expectations on operations, subcontracting transparency and data location.

For a CIO, the practical test is simple: ask which version of the referential the certificate covers, and when the next audit is due. Certification is not permanent; it is maintained through periodic audits and renewals.

In 2026, the only correct answer to the question "which HDS version?" is the 2024 referential aligned with ISO/IEC 27001:2022.

Does HDS certification guarantee health data sovereignty?

Not on its own. The referential sets data-location requirements, but certification alone does not neutralise the extraterritorial laws a provider may be subject to.

Location and legal exposure are two different things. A provider can host data within the European Economic Area and still belong to a group subject to non-EU legislation. HDS certification does not settle that question; it must be analysed contract by contract, alongside reversibility and subcontracting clauses.

This is why sovereignty is assessed beyond the label. Galeon runs a single European, HDS-certified and ISO 27001 cloud, and, for AI, favours decentralized learning so that models can be trained while records stay on the hospital's servers, an approach that reduces, without ever eliminating, the questions raised by moving data. We compare providers on these criteria in our guide on how to choose your HDS provider.

What must a hospital CIO and CEO check before signing?

Read the certificate for its exact scope, then map everything it does not cover to a named owner inside the project.

For the CIO

Verify the exact activities certified (physical infrastructure only, or managed services too), the referential version, the subcontractors, the data location and the reversibility terms. Cross-check the provider on the public list published on esante.gouv.fr. Then assess the application layer separately: access controls, audit trail and the structuring of the data itself.

For the CEO

Treat HDS as one line of a broader risk file, not as the whole answer. The institution remains the data controller: GDPR responsibility, professional-secrecy obligations and, where relevant, AI governance stay with the hospital. Ask your teams which risks the certificate does not cover, and who owns them.

A signature protects the hospital only if it is informed by what the certificate leaves out.

Comparison table: reading the HDS label alone vs a layered approach

Criterion Reading the HDS label alone Galeon layered approach
What the certificate proves Read as a full compliance guarantee Read as the hosting layer only, one control among several
Scope transparency "HDS-certified" stated without detail Exact activities, referential version and subcontractors documented
Application security Outside HDS scope, rarely audited Access controls, audit trail and traceability built into the software
Data structuring and usage Free text, usage governance left to the client Structured at the source, validated by caregivers
GDPR responsibility Assumed covered by the host Controller duties made explicit, DPIA support
Data location and exposure EEA at best, extraterritorial exposure unaddressed European hosting, exposure assessed contract by contract
AI training Data copied to an external warehouse Decentralized learning: models trained on-site, records stay in the hospital
Reversibility Clause often overlooked Reversibility and exit defined in the contract
Traceability of access Hard to reconstruct after the fact Access logging and audit trail native
Overall reading The label ends the discussion The label starts a structured due-diligence

Limits and challenges to be aware of

It would be dishonest to present HDS as a full answer to health-data risk. Here are the main limits to keep in mind in 2026.

  • HDS is necessary but never sufficient. It says nothing about how well the software protects or uses the data; the most sensitive risks often live above the hosting layer.
  • The label hides its scope. Two certificate types and six activities mean a provider can be certified for physical infrastructure only, while subcontracting the operations you actually depend on.
  • HDS does not neutralise extraterritorial laws. The referential sets location requirements, but the legal exposure of a provider owned by a non-EU group is a separate analysis, to be conducted case by case.
  • Compliance is a moving target. The 2024 referential aligns with ISO/IEC 27001:2022, and certification is maintained through periodic audits and renewals, not granted once and for all.
  • The client keeps most of the responsibility. GDPR, access governance, professional secrecy and, where applicable, medical-device or AI Act obligations remain with the hospital and its software vendor.

FAQ

Is HDS certification mandatory?
Yes, for anyone hosting personal health data collected during care. The obligation is anchored in France's Public Health Code, and the scheme is overseen by the French Digital Health Agency (ANS).

Does HDS certification mean my project is GDPR-compliant?
No. HDS secures the hosting; the GDPR governs the lawful processing of the data. They are complementary but distinct, and one never replaces the other.

What is the difference between the two HDS certificates?
One covers the physical-infrastructure host (providing sites and hardware), the other the managed-services host, which operates the information system and backs up the data. Together they span six hosting activities.

Is the current framework the 2023 or the 2024 version?
The reference in force is the HDS 2024 referential, aligned with ISO/IEC 27001:2022. A certificate or document referring to an earlier version should be updated.

Can an HDS-certified provider host data outside Europe?
The referential imposes location requirements within the European Economic Area. A provider owned by a non-EU group can still be certified, so extraterritorial exposure must be assessed separately, contract by contract.

Does HDS certify the EHR software?
No. It certifies the hosting activity only. The software's own security, access controls and clinical safety are outside its scope and must be evaluated on their own.

How do I verify a provider's HDS status?
Check the public list published on esante.gouv.fr, and confirm the exact activities certified and any subcontractors, rather than relying on the "HDS-certified" label alone.

In summary

In 2026, HDS certification proves exactly one thing: that the hosting of your health data, when entrusted to a third party, meets a defined security bar under the HDS 2024 referential aligned with ISO/IEC 27001:2022. It does not certify your EHR software, your data usage, your GDPR compliance or your medical-device and AI obligations, and it does not, by itself, resolve questions of sovereignty and extraterritorial exposure. Reading a certificate for its exact scope, then assigning every uncovered risk to a named owner, is what separates a reassuring line in a tender from a genuinely secure project. This is the approach Galeon builds on: a single European, HDS-certified and ISO 27001 cloud, an EHR whose data is structured at the source and validated by caregivers, and, for AI, decentralized learning designed so that models can be trained while patient records stay on the hospital's servers.

Want to know more about our smart EHR ?

Book a demo
Want to go further ? Read our guide on what every hospital must check before signing an HDS contract

Sources

Ils nous font confiance

Logo du Centre Hospitalier Intercommunal Toulon La Seyne-sur-MerLogo du Centre Hospitalier Sud Francilien (CHSF)Logo blanc du GHNE (Groupement Hospitalier Nord Essonne) sur fond transparentLogo du CHU de RouenLogo du CHU Caen Normandie