Blog

Health and AI

Summary
Health and AI

Health Data Sovereignty in 2026: Cloud Act vs Sovereign Hosting

Health data sovereignty in 2026: how the US Cloud Act exposes hospital data and what sovereign hosting, SecNumCloud and HDS certification re

The essentials in 30 seconds

QuestionShort answerWhat to remember
What is health data sovereignty?The ability to keep effective control over where health data are stored, who can access them, and which law applies.Sovereignty is first a question of legal control, not only of server location.
What is the US Cloud Act?A 2018 US law that can compel a US-controlled provider to hand data to American authorities, even when it is stored in Europe.Storing data in the EU does not remove US legal reach if the provider is US-controlled.
Does HDS certification stop the Cloud Act?No. HDS certifies how health data are hosted securely, not immunity from foreign law.HDS is necessary but not sufficient for sovereignty.
What is a trusted cloud?A service qualified as resistant to extraterritorial law, in France through ANSSI's SecNumCloud qualification.A trusted cloud adds a legal-immunity criterion on top of strong security.
Is EU localization enough?Localization in the EU reduces exposure but does not, on its own, guarantee immunity.Localization, governance and provider control matter together.
What does GDPR say about foreign orders?GDPR Article 48 states that a foreign court order is not, by itself, a valid basis to transfer data.GDPR and the Cloud Act can conflict directly.
How does Galeon approach it?HDS-certified hosting, plus Swarm Learning that keeps AI training data on each hospital's servers.Reducing data movement lowers exposure, without ever removing it entirely.
What should a CIO check first?The provider's ownership, applicable law, sub-processors, key control and exit terms.Ask who could be legally compelled, not only where the servers sit.

Introduction

Health data sovereignty has moved from a legal footnote to a decisive line in hospital tenders. The question is no longer only where patient records are stored, but which law governs the company that can access them. For a DSI, the hospital's chief information officer, that distinction now shapes procurement, risk registers and board-level scrutiny.

The tension has a name: the US Cloud Act. Passed in 2018, it can compel a provider subject to US jurisdiction to disclose data it controls, even when that data sits in a European data centre. Combine this with the uncertainty left by the Court of Justice of the EU in its 2020 Schrems II ruling, and localization alone stops looking like a guarantee.

Galeon has built an AI-assisted electronic health record (EHR) with caregivers since 2016. It is used in 19 hospitals, including two university hospitals, covering more than 3 million patient records and over 10,000 caregivers. Sovereignty, in this context, is decided less by the country on the map than by the law that governs the company holding the keys.

This guide explains, in measured terms, what the Cloud Act really allows, why HDS certification and SecNumCloud answer different questions, and how a hospital can assess sovereign hosting without falling for the myth of total sovereignty.

What is health data sovereignty, and why is it a 2026 tender criterion?

Health data sovereignty is the ability to keep effective control over where health data are stored, who can access them, and under which jurisdiction. It has become a tender criterion because localization and legal exposure are now scored explicitly, not assumed.

Two ideas are often confused. Data residency is the physical location of the servers. Data sovereignty is the legal control over the data, which depends on the law that binds the operator. A European data centre run by a company subject to a foreign law does not automatically deliver sovereignty.

In practice, sovereignty is a spectrum of control, not a binary badge you either hold or lack. A realistic goal is to minimise and document exposure, not to claim it has disappeared.

What is the US Cloud Act, and how does it reach data hosted in Europe?

The Clarifying Lawful Overseas Use of Data Act (Cloud Act) is a 2018 US law that lets American authorities compel a US-based provider to produce data it controls, regardless of where that data is stored. A European data centre does not, on its own, place the data beyond that reach when the provider is subject to US jurisdiction.

The reach follows the company, not the map. It can apply to a US parent and, depending on the structure, to its European subsidiaries. This is why the identity and control of the provider matter as much as the address of the data centre.

European regulators have flagged the friction. The European Data Protection Board and the European Data Protection Supervisor issued a joint response in 2019 noting that the Cloud Act can conflict with EU data protection law. The Court of Justice's Schrems II ruling later reinforced how seriously EU law treats foreign access to European data.

Does HDS certification protect against the Cloud Act?

No. HDS certification proves how health data are hosted securely; it does not grant immunity from foreign extraterritorial law. A provider subject to US jurisdiction can hold HDS certification and still fall within the scope of the Cloud Act.

HDS (Hebergeur de Donnees de Sante) is the French certification required when the hosting of health data is entrusted to a third party. It is overseen by the ANS, the national digital health agency, and the current framework is the HDS 2024 referential, aligned with the ISO 27001:2022 security standard.

HDS answers the question is this data hosted securely; it does not answer who could be legally compelled to hand it over. That is why HDS and sovereignty are complementary but separate checks. For a deeper look, see our guide to HDS certification in 2026.

What is a trusted cloud, and what does SecNumCloud actually guarantee?

A trusted cloud, or cloud de confiance, is a service qualified as resistant to extraterritorial law. In France, that qualification is SecNumCloud, issued by ANSSI, the national cybersecurity agency.

SecNumCloud adds criteria that go beyond security: it requires that the provider not be exposed to non-EU extraterritorial law and sets conditions on the ownership and control of the operator. In its current version, it is one of the most demanding cloud qualifications in Europe.

It is not a universal label. Few services hold it, and it targets the most sensitive data and critical operators. The pragmatic reading is that SecNumCloud is a strong answer where the data class justifies it, not a box every project must tick.

What does sovereign hosting concretely mean for a hospital?

Sovereign hosting means the data, the encryption keys and the legal control stay within a European perimeter you can verify. Concretely, it combines EU localization, an EU-controlled operator, transparent sub-processing and workable reversibility.

For a RSSI, the information security manager, the practical question is not only geography. It is whether a foreign authority could lawfully compel disclosure, and whether the hospital keeps control of the keys and of an exit path.

European law provides a partial shield. Under GDPR, and specifically Article 48 of Regulation (EU) 2016/679, a foreign court order is not, by itself, a valid basis to transfer personal data. A genuine legal conflict can still remain, which is exactly why architecture and provider choice matter. See our overview of GDPR and health data.

How does Galeon approach data sovereignty in practice?

Galeon combines HDS-certified hosting in Europe with Swarm Learning, a decentralised AI-training method in which each hospital's data stay on its own servers. This reduces data movement, which lowers exposure, without claiming to remove every legal or technical risk.

Instead of pooling records into a single central dataset to train models, Swarm Learning trains where the data live and shares model updates rather than raw patient data. Less movement means a smaller footprint to expose, though governance and security still have to be managed carefully.

Galeon also structures health data with caregivers, which keeps records usable for care and, when authorised, research-ready. The honest framing is that this approach improves control; it is not a magic shield against every scenario.

CriterionTraditional / hyperscaler-based hostingGaleon's approach
Hosting securityOften HDS-certified through a major cloud providerHDS-certified hosting
Data locationCan use EU regionsData hosted in the EU
Provider legal controlMay be a US-controlled company or subsidiaryEuropean operator
Exposure to extraterritorial lawCan persist even with EU data centresReduced by minimising data movement, though not fully removed
AI training dataOften centralised or pooled to train modelsSwarm Learning keeps training data on each hospital's servers
Sub-processor chainCan be long and partly outside the EUDocumented and limited
Reversibility and exitSometimes complex and costlyContractual reversibility and portable structured data
Fit with the Segur du numeriqueVariableDesigned for Segur requirements
Data structuring for reuseDepends on integrationsStructured with caregivers, research-ready

What should a hospital director and CIO check before signing?

Before signing, a director (DG) and a CIO should verify who can be legally compelled to access the data, not only where it is stored. The most revealing questions are about ownership, applicable law and reversibility.


     

     

     

     

     

     


Limits and challenges to be aware of


     

     

     

     

     


FAQ

Is my data safe from the Cloud Act if it is stored in France?
Not automatically. If your provider is controlled by a US company, the storage location alone may not prevent a Cloud Act request.

Is HDS certification the same as sovereignty?
No. HDS covers the security of health-data hosting. It does not grant immunity from foreign law, and a US-controlled provider can be HDS-certified.

Do I need SecNumCloud for all health data?
Not necessarily. SecNumCloud targets the most sensitive data and critical operators. The right level should be assessed by data class rather than applied blindly everywhere.

Does GDPR block the Cloud Act?
GDPR Article 48 limits transfers based on foreign court orders, but a real legal conflict can remain. That is why provider choice and architecture matter alongside the law.

What is the EHDS, and does it change sovereignty?
The European Health Data Space, adopted in 2025, frames how health data are used and shared across the EU. It reinforces diligence on data governance, but it does not replace sovereignty checks.

Is total data sovereignty achievable?
No absolute guarantee exists. The realistic objective is to minimise and control exposure, then document the residual risk for governance.

In summary

Health data sovereignty in 2026 is decided by legal control as much as by geography. The US Cloud Act shows why: a European data centre does not shield data from a provider that is subject to foreign law. HDS certification answers a security question and remains essential, while SecNumCloud and the trusted-cloud doctrine answer a distinct question about immunity from extraterritorial law. Galeon's position is deliberately measured: HDS-certified hosting in Europe, an European operator, and Swarm Learning that keeps AI training data on each hospital's servers to reduce data movement and lower exposure. None of this promises total sovereignty, which no serious provider can guarantee. The practical goal, built with caregivers since 2016 across 19 hospitals and more than 3 million patient records, is to keep control verifiable, exposure minimal and choices reversible.

Want to know more about our smart EHR ?

Book a demo
Health data hosting: how to choose your HDS provider in 2026

Sources


     

     

     

     

     

     

     

     

     

     


Ils nous font confiance

Logo du Centre Hospitalier Intercommunal Toulon La Seyne-sur-MerLogo du Centre Hospitalier Sud Francilien (CHSF)Logo blanc du GHNE (Groupement Hospitalier Nord Essonne) sur fond transparentLogo du CHU de RouenLogo du CHU Caen Normandie