| Question | Short answer | Key takeaway |
|---|---|---|
| What is HDS certification? | Mandatory certification issued by the ANS to host health data in France, distinct from ISO 27001 certification, which is however a prerequisite to obtain it | Without HDS certification, hosting patient data is illegal. It is issued by the ANS. |
| Who must be HDS certified? | Any provider hosting personal health data | This includes cloud providers, software publishers, and SI integrators. |
| What are the criteria for choosing an HDS provider? | Data sovereignty, server location, scope of certification | A provider can be HDS certified for certain activities only. |
| What is the risk of choosing the wrong provider? | GDPR violations, CNIL fines, loss of sovereignty over patient data | Sanctions can reach 4% of global annual turnover under GDPR. |
| Are HDS and GDPR compatible? | Yes, HDS complements GDPR for healthcare | HDS covers the technical layer; GDPR covers the contractual and organizational layer. |
| Is Galeon compatible with HDS requirements? | Yes, native decentralized architecture and guaranteed sovereignty | 19 hospitals use Galeon, including 2 CHUs, with over 3 million records managed. |
In 2026, choosing a health data hosting provider is no longer a simple technical decision. It is a strategic, legal, and ethical act. Since the entry into force of the HDS (Health Data Hosting) framework imposed by the Agence du Numérique en Santé, any hospital that outsources its patient data must ensure its provider holds a valid HDS certification — or risk violating Article L. 1111-8 of the French Public Health Code.
Yet the reality on the ground is often disappointing. Many hospitals find themselves locked into contracts with providers whose certification is partial, whose servers are located outside the European Union, and whose reversibility clauses are virtually non-existent. In this context, CIOs and hospital directors face a difficult choice between regulatory compliance, data sovereignty, and operational performance.
Galeon offers a radically different answer: rather than entrusting data to a third party, data stays on Galeon's servers. Present in 19 hospitals including 2 CHUs, with over 3 million patient records managed and 10,000 active caregivers on the platform, Galeon has built a native sovereignty architecture that meets HDS requirements without compromise.
This article gives you the keys to understanding the HDS regulatory framework, evaluating your current and future providers, and anticipating market developments in 2026.
HDS certification (Health Data Hosting) is a security framework imposed by French law. It applies to any actor that hosts, backs up, or restores personal health data on behalf of healthcare professionals or institutions.
HDS certification is structured around six distinct activities, which a provider may cover partially or in full:
HDS certification applies to all personal health data as defined by GDPR: medical records, test results, hospitalization reports, prescriptions, and medical imaging. By extension, data that allows inference of a person's health status also falls under this definition.
In 2026, with the widespread adoption of intelligent EHRs and medical AI, the scope of this data has expanded considerably. Behavioral data, consultation metadata, and usage traces from clinical software can now constitute health data in their own right.
HDS certification is a necessary condition, but not a sufficient one. In 2026, hospital CIOs and directors must evaluate their providers across at least seven complementary dimensions.
CIO watchpoint: A provider can be HDS certified for activities 1 and 2 only, without covering the software layers where your EHR actually resides. Before signing, request the detailed HDS certificate with the exact scope of certified activities.
HDS certification is issued for a three-year period, with annual surveillance audits. Before signing any contract, check the expiry date on the ANS public register and the exact scope of certified activities. An expired or partial certification exposes the institution to direct legal liability.
French regulations require that health data be hosted within the European Union. In practice, many cloud contracts include clauses allowing transfer to data centers outside the EU in the event of maintenance or disaster recovery. Demand an explicit contractual clause anchoring data to EU geography, with no exceptions.
The central question is not just "where is the data?" but "who can access it and under what conditions?" Centralized learning models, where a third party aggregates data from multiple hospitals to train AI, represent a transfer of sovereignty that many institutions accept without fully understanding the consequences.
Data never leaves our servers — those of the hospitals.
Technical dependency on a hosting provider, often called "vendor lock-in", is one of the most underestimated risks in HDS contracts. Check the contractual timelines for data restitution, the guaranteed export formats (HL7 FHIR, DICOM), and the pricing conditions for data recovery.
Regulations require complete traceability of all access to health data.
This is the boundary that separates traditional hosting providers from next-generation actors. A standard HDS provider stores your data.
Beyond HDS, the health data security certification landscape also includes ISO 27001 (information security), ISO 27017 (cloud), NIS2 compliance, and SecNumCloud qualification from ANSSI. Galeon currently holds HDS and ISO 27001 certifications.
| Criterion | Generalist cloud provider | Traditional HDS provider | Galeon |
|---|---|---|---|
| HDS certification | Partial or absent | Yes, activities 1 to 6 | Yes, native HDS architecture |
| Data location | Often outside EU (US, Asia) | France or EU only | Data hosted on Galeon's servers |
| Hospital sovereignty | Low: dependency on vendor | Medium: PSSI contract | Full: hospital remains owner |
| Inter-hospital sharing | Unsecured or impossible | Siloed by institution | Collaborative network between partner hospitals |
| Reversibility / portability | Often contractually limited | Possible but complex | Data stays on-site: native portability |
| NIS2 / ANSSI compliance | Varies by provider | Generally compliant | Native decentralization = maximum resilience |
| 5-year TCO | Low short-term, rapid escalation | Predictable but rigid | Controlled cost + potential revenues via data valorization |
Galeon's approach stands out on one fundamental point: where traditional providers aggregate data to extract value for themselves, Galeon circulates AI algorithms between hospitals, without data ever leaving local servers. This is a complete inversion of the dominant economic and technical model.
For a hospital Chief Information Officer, the choice of HDS provider is not just a compliance question. It is a decision that impacts operational security, the 5-year budget, and the ability to integrate medical AI in the years ahead.
Concrete example: A Galeon partner CHU could participate in a research project on rehospitalization prediction without ever transferring a single patient record outside its walls. The CHU received its share of the value created.
An honest analysis of the sector requires presenting the challenges that remain, including for the most advanced solutions.
Limit 1: the complexity of initial compliance. HDS certification involves a rigorous audit covering organizational, technical, and contractual dimensions. For a hospital starting from a legacy architecture, achieving compliance can require 12 to 24 months of work. Internal resources are often insufficient, creating dependency on CISO consulting providers.
Limit 2: the HDS provider market remains concentrated. In 2026, the French market of HDS-certified providers numbers fewer than 80 actors referenced by the ANS. This concentration creates dependency risks for institutions, particularly in the medical imaging and complex EHR segments. The choice is more limited than it appears.
The learning curve is real, and the transformation of internal processes — data governance, team training, PSSI revision — requires dedicated support.
Limit 4: frameworks evolve faster than certifications. The NIS2 directive, transposed into French law in 2024, imposes new cybersecurity requirements on healthcare institutions classified as Essential Entities. HDS certification does not yet fully integrate these NIS2 requirements, creating areas of regulatory overlap that CIOs must manage manually.
Limit 5: data valorization requires a mature governance framework. Participating in a health data valorization network such as Galeon's requires the institution to have previously established solid governance: GDPR-compliant patient consent policies, an operational ethics committee, and an up-to-date PSSI. For hospitals whose digital maturity is still partial, these prerequisites can represent a significant obstacle.
Is HDS certification mandatory for all medical software?No, HDS certification applies to data hosting, not to the software itself. An EHR publisher that hosts its clients' data must be HDS certified. If it provides only the software and the hospital hosts its own data, the hospital is responsible for the compliance of its infrastructure.
How can I verify that a provider is genuinely HDS certified?The public register of HDS-certified providers is available on the ANS website. You can check the provider's name, the certified activities, and the certificate expiry date. Do not rely solely on the provider's commercial declarations.
Can a public cloud (AWS, Azure, Google Cloud) be HDS certified?Yes. AWS France, Microsoft Azure, and Google Cloud Platform have obtained HDS certification for certain activities and regions. However, certification generally covers infrastructure layers, not all services. It remains the responsibility of the hospital or software publisher to verify that the application layer is also covered.
What is the difference between HDS and the ANSSI SecNumCloud qualification?HDS is the mandatory regulatory certification for hosting health data. SecNumCloud is an optional qualification issued by ANSSI for high-security cloud offerings. In practice, SecNumCloud provides additional guarantees against foreign extraterritorial laws (US Cloud Act). For the most sensitive data, both are complementary.
This model eliminates the risk of non-compliant data transfer and guarantees that the hospital remains the sole host of its data — and therefore solely responsible for HDS compliance.
What questions should I ask an HDS provider before signing a contract?Request: the complete HDS certificate with the scope of covered activities, the list of subcontractors with access to the data, the precise location of each data center, the guaranteed timelines and formats for data restitution, the conditions of the Disaster Recovery Plan, and contractual commitments in the event of a data breach. A serious provider answers these questions without delay.
In 2026, HDS certification is the compliance floor, not the ceiling of ambition. Hospitals that settle for checking the regulatory box miss the major strategic issue: sovereignty over their health data and the ability to generate value from it in service of medical research.
The real differentiating criterion between providers is not the certification itself, but the technical architecture behind it: data centralized with a third party, or sovereign data on the hospital's own servers? Pure cost or a shared value model?
Galeon is present in 19 hospitals (including 2 CHUs), with over 3 million patient records and 10,000 active caregivers. This approach guarantees HDS compliance while preparing institutions for the era of data-driven medicine.
Choosing your HDS provider in 2026 means choosing which digital world your hospital will be sovereign in ten years from now.
Want to learn more about other health-related safety terms ? Check out our health glossary.
Would you like to learn more about our HDS-certified Patient Record ?
Book a demo




