Les DPO de la Santé
All articles
HDS hosting

Health data hosting (HDS): what you need to know in 2026

Les DPO de la SantéPublished Updated 4 min
Health data hosting (HDS): what you need to know in 2026

Who is subject to HDS certification, what obligations apply to software vendors and healthcare organizations, and how to frame a compliant hosting project.

Any organization that hosts personal health data on behalf of a third party must use an HDS-certified hosting provider. This obligation, derived from the French Public Health Code, now structures the entire digital-health ecosystem.

Who is concerned?

Healthcare facilities that outsource their infrastructure, but also software vendors that host their customers’ data, are directly concerned. The question arises from the moment the product is designed.

Determining whether you are a controller, a processor or a hosting provider is the first step — and the one that determines all the obligations that follow.

Framing a compliant project

A compliant hosting project rests on a risk analysis, a precise hosting contract and a clear allocation of responsibilities. Compliance support upstream avoids costly rework.

The framework: Article L.1111-8 of the French Public Health Code

Since 2018, the former approval regime has given way to a certification issued by bodies accredited by COFRAC (or by the national accreditation body of another EU Member State), on the basis of a standard published by the Agence du Numérique en Santé and built on ISO 27001 and ISO 20000. The certificate is valid for three years, with annual surveillance audits; since May 16, 2026, only version v2 of the standard (order of 26 April 2024, published on 16 May 2024) is authoritative.

The principle is simple to state: anyone who hosts health data collected in the course of prevention, diagnosis, care or social and medico-social follow-up activities, on behalf of a third party, must be certified. The whole difficulty lies in applying it: who hosts “on behalf of a third party”?

Are you a hosting provider without knowing it?

The SaaS vendor that stores the health data of its healthcare customers is a hosting provider — the most frequent case, and the one most often discovered late, sometimes on the back of a lost tender. The managed-services provider that administers an information system containing health data performs activity 5. Conversely, a facility that hosts its own data for its own account does not need to be certified — but the day it pools its infrastructure for the benefit of other organizations, the question arises again.

For a software vendor, two routes: get certified (a heavy investment, but a differentiator) or rely on a certified hosting provider while keeping a crystal-clear allocation of responsibilities. The choice is made at the product architecture stage — redoing it afterwards costs ten times more.

Selecting and contracting: the checklist

A valid v2 certificate, verified at the source; a scope of activities covering exactly the services purchased; data location and conditions of access from third countries; a documented subcontracting chain (is your software vendor’s own hosting provider certified?); testable reversibility and data-return clauses; a contract combining the requirements of Article 28 of the GDPR and those of the Public Health Code; and finally, the certificate reference recorded in your record of processing activities, with an annual review scheduled.

One frequently overlooked point: test and acceptance environments. Copying real patient data into them without the same hosting and security guarantees is one of the most common gaps we encounter in audits.

The questions we are asked most often

“Does my medical practice need to be certified?” No: a professional who hosts their own records for their own practice is not a hosting provider within the meaning of the law — but their SaaS software vendor must be. “Is a US cloud provider with HDS certification compliant?” The v2 certification requires it: hosting in the EEA and transparency about third-country access; formal compliance exists, the risk analysis still has to be done and documented. “What about backups?” Outsourced backup is certifiable activity no. 6: a backup provider that receives health data must be certified for that activity. “Does my provider’s certification exempt me from a contract?” Never: Article 28 of the GDPR and the requirements of the Public Health Code come on top of certification, they do not replace it.

A compliant hosting project, step by step

Step 1 — qualify: who is the controller, who is the processor, who hosts what. Step 2 — map the data and the flows, test environments included. Step 3 — select the hosting provider on documentary evidence: v2 certificate, scope of activities, location, subcontracting chain, reversibility. Step 4 — contract: Article 28 DPA, Public Health Code clauses, service levels, audit and data return. Step 5 — document: record of processing, risk analysis, DPIA where the processing warrants it. Step 6 — monitor: annual review of the certificate and of subprocessors, reversibility test. Allow several weeks for a simple project, several months when a data migration is involved — and always cheaper upstream than in remediation.

This article is provided for general information purposes and does not constitute personalized legal advice.

Turn your obligations into opportunities.

A free, no-obligation first conversation to review your compliance posture and identify your priorities — in English.

Response within 24 business hours · No obligation