AsteronAsteron

    HDS readiness for European healthtech in France

    Asteron helps healthtech companies and hosting providers determine whether French HDS certification applies, define the correct hosting scope and prepare the security, contractual and operational evidence required under HDS v2. We connect ISO 27001, cloud architecture, hosting activities, subcontractors, data location, third-country access risks and certification evidence within one practical readiness programme for the French healthcare market.

    View HDS pricing
    • HDS applicability assessed
    • Six hosting activities mapped
    • HDS v2 and ISO 27001 aligned
    • Certification evidence prepared

    What is HDS certification?

    HDS stands for Hébergeur de Données de Santé. It is the French certification framework for organisations that host personal health data collected through prevention, diagnosis, treatment or health and social-care activities on behalf of the organisation that collected the data or on behalf of the patient.

    HDS certification is a legal requirement for qualifying digital hosting activities. It is issued by an independent accredited certification body—not by Asteron or the Agence du Numérique en Santé.

    Since 16 May 2026, valid HDS certificates must conform to HDS v2. The revised framework aligns with ISO 27001:2022, clarifies hosting activities and strengthens requirements concerning data sovereignty, contracts, subcontractors and risks of access from outside the European Economic Area.

    Who may need HDS certification?

    A SaaS provider stores French patient data for a healthcare customer
    The provider may perform HDS activities and require its own certification.
    A healthtech company administers a platform containing hosted health data
    Activity 5 may apply even when the underlying cloud provider is HDS certified.
    A cloud or infrastructure provider hosts health data
    Certification must cover the infrastructure activities it performs.
    A company only uses an HDS-certified service without performing hosting activities
    It may not need its own certificate, but must verify the provider’s scope and retain its own GDPR and security responsibilities.
    A processor chain involves several cloud, platform and support providers
    Every hosting activity and responsible provider must be mapped across the chain.

    Using an HDS-certified cloud provider does not automatically make the complete service HDS compliant. The provider's certificate may cover infrastructure but not the application company's administration, operation, backups or other activities.

    Applicability depends on the actual service, data, contractual role and technical responsibility—not simply on whether the company describes itself as a hosting provider.

    The six HDS hosting activities

    1
    Provision and operational maintenance of physical sites hosting the hardware infrastructure
    2
    Provision and operational maintenance of hardware infrastructure
    3
    Provision and operational maintenance of virtual infrastructure
    4
    Provision and operational maintenance of the application-hosting platform
    5
    Administration and operation of the information system containing health data
    6
    External backup of health data

    The certificate must identify the activities actually performed. A company should not pursue all six activities by default, but it must not omit an activity that it controls in practice.

    Activity 5 requires particular attention for SaaS and managed-service companies because administration privileges, operational interventions, access reviews and responsibility for the application environment may place the company inside the HDS hosting chain.

    HDS v2, ISO 27001 and GDPR

    HDS v2
    French sector-specific certification for qualifying health-data hosting activities.
    ISO 27001
    The information-security management system on which HDS v2 builds.
    GDPR
    Legal responsibilities for processing personal data, including health data.
    SecNumCloud
    A separate French cloud-security qualification; it is not automatically required for every HDS engagement.

    An HDS candidate needs an ISO 27001-certified ISMS whose scope covers all relevant HDS activities. ISO 27001 alone is not HDS certification because HDS adds sector-specific contractual, hosting, sovereignty and transparency requirements.

    HDS certification also does not prove complete GDPR compliance. Controller and processor roles, lawful processing, transparency, data-subject rights and international transfers remain separate legal responsibilities.

    Data location and sovereignty

    HDS v2 strengthens transparency and control over where personal health data is stored and who may access it.

    Health data within the HDS hosting scope must be stored in an EU Member State or another country within the European Economic Area. The hosting model must also address:

    • Countries from which support or administration may occur
    • Subcontractors and their applicable jurisdictions
    • Risks of access under non-EEA laws
    • Technical, contractual and organisational safeguards
    • Required client disclosures
    • Rules for transfers, changes and incident notification

    The French decree published on 24 March 2026 reinforces these obligations and the information that must be included in hosting arrangements. Some provisions have a six-month implementation period, so new contracts and architectures should be prepared for the complete requirements now.

    Shared responsibility in a cloud service

    HDS-certified infrastructure provider

    • Operates the certified activities listed on its certificate
    • Protects the infrastructure included within its scope
    • Provides relevant security, location and subcontractor evidence
    • Maintains its own HDS and ISO 27001 certifications

    Healthtech or SaaS provider

    • Determines which activities it performs above the infrastructure layer
    • Secures and administers the application environment
    • Manages identities, privileged access, releases and incidents
    • Controls its own suppliers and contractual commitments
    • Demonstrates that the end-to-end service remains within the declared HDS model
    Certification gaps often occur at the boundary between these parties, where each assumes that the other owns an activity or control.

    HDS certification process

    1. Define applicability and activities

      Identify the health data, clients, services and hosting responsibilities that determine whether HDS applies and which activities are performed.

    2. Establish the certification scope

      Include the legal entities, sites, systems, suppliers and HDS activities that must be covered by the certificate.

    3. Align the ISMS

      Ensure that the ISO 27001 scope and controls cover the HDS service consistently across people, technology and suppliers.

    4. Implement HDS-specific requirements

      Address contracts, guarantees, subcontracting, data sovereignty, transparency obligations and service-specific evidence.

    5. Complete internal readiness

      Perform internal audit, management review and prioritised remediation before the external audit.

    6. Independent certification audit

      Complete the documentary and on-site assessment with an accredited certification body. Up to three months may be allowed to correct identified nonconformities. Certificates are normally valid for three years, with annual surveillance audits.

    How Asteron prepares the organisation

    • Assess HDS applicability and hosting roles
    • Map all six activities across the provider chain
    • Define the certification and ISO 27001 scope
    • Review cloud, subcontractor and support arrangements
    • Map HDS v2 requirements to existing controls and evidence
    • Prepare contractual and sovereignty evidence
    • Conduct the internal readiness review
    • Coordinate remediation and certification-body preparation

    Deliverables

    Scope and architecture

    • Documented HDS applicability assessment
    • Hosting-activity and responsibility matrix
    • Legal-entity, system and location scope
    • Cloud and subcontractor chain map
    • Data-location and third-country access assessment
    • HDS and ISO 27001 scope alignment

    Controls and audit evidence

    • HDS v2 gap assessment
    • Contract and supplier requirement map
    • Control and evidence register
    • Internal-audit and management-review preparation
    • Prioritised remediation roadmap
    • Certification audit-readiness pack

    HDS readiness pricing

    Scoped readiness project
    From €9,900

    Covers French health-data hosting readiness for one principal organisation, one defined hosting service and the agreed HDS activities.

    Final scope depends on the number of legal entities, hosting activities, cloud providers, locations, subcontractors, existing ISO 27001 maturity and complexity of the service architecture.

    The price does not include ISO 27001 or HDS certification-body fees.

    Typical milestones
    • 40% at signing
    • 40% after delivery of the scope and gap baseline
    • 20% after the contracted readiness deliverables

    Prices exclude VAT where applicable.

    Asteron guarantees completion and correction of its contracted deliverables within the agreed scope. It cannot guarantee certification, prevent an auditor from identifying nonconformities or control decisions made by certification and accreditation bodies.
    View full pricing

    Independent certification and external costs

    Asteron prepares the organisation but cannot issue the HDS certificate or perform the independent certification audit. Combining implementation and certification would create an independence conflict.

    The client selects, contracts and pays an appropriately accredited certification body directly.

    Separate costs may include:

    • HDS certification and surveillance audits
    • ISO 27001 certification or scope extension
    • Penetration testing
    • Technical remediation and cloud migration
    • French legal opinions
    • Contract renegotiation
    • SecNumCloud services or qualification
    • Additional entities, products or hosting environments

    Responsibilities

    Asteron

    • Determine and document the proposed scope
    • Translate HDS v2 requirements into practical controls
    • Review evidence, providers and contractual boundaries
    • Identify gaps and coordinate agreed remediation
    • Prepare the organisation for independent audit

    Your organisation

    • Confirm services, clients, data and hosting responsibilities
    • Maintain the ISO 27001 ISMS
    • Approve scope, risks, suppliers and contracts
    • Implement required technical and operational changes
    • Operate controls and retain evidence
    • Contract the independent certification body

    Frequently asked questions

    What is HDS certification?

    HDS (Hébergeur de Données de Santé) is the French certification framework for organisations that host personal health data collected through prevention, diagnosis, treatment or health and social-care activities. Since 16 May 2026, valid certificates must conform to HDS v2, which aligns with ISO 27001:2022.

    When is HDS certification mandatory?

    It is legally required when an organisation performs one or more of the six HDS hosting activities on personal health data for a customer or a patient. It applies to the activity performed, not to the general description of the company.

    Does a healthtech SaaS company need HDS?

    Frequently, yes. Even when the underlying cloud is HDS certified, the SaaS company often performs Activity 5 (administration and operation of the information system containing health data) and therefore falls inside the HDS hosting chain. Applicability must be assessed based on the actual service and responsibilities.

    Is an HDS-certified cloud provider enough?

    No. Using an HDS-certified cloud provider does not automatically make the complete service HDS compliant. The provider certificate typically covers infrastructure activities, not administration, operation, backups or other activities performed by the application company.

    Which six activities can appear on an HDS certificate?

    1) Physical sites hosting hardware, 2) hardware infrastructure, 3) virtual infrastructure, 4) application-hosting platform, 5) administration and operation of the information system containing health data, 6) external backup of health data. The certificate must reflect the activities actually performed.

    What changed in HDS v2?

    HDS v2 aligns with ISO 27001:2022, clarifies the definitions of hosting activities and strengthens requirements on data sovereignty, contracts, subcontractors and risks of access from outside the European Economic Area. Certificates issued from 16 May 2026 must conform to HDS v2.

    Must health data be stored in France?

    Health data within the HDS hosting scope must be stored in an EU Member State or another country within the European Economic Area. HDS v2 additionally requires transparency and safeguards for the countries from which support, administration or subcontracting may occur.

    How does HDS relate to ISO 27001?

    HDS v2 builds on ISO 27001. An HDS candidate needs an ISO 27001-certified ISMS whose scope covers all relevant HDS activities. ISO 27001 alone is not HDS certification, because HDS adds sector-specific hosting, contractual, sovereignty and transparency requirements.

    Does HDS prove GDPR compliance?

    No. HDS certification demonstrates that qualifying hosting activities meet the HDS requirements. Controller and processor roles, lawful processing, transparency, data-subject rights and international transfers remain separate legal responsibilities under the GDPR.

    How long is an HDS certificate valid?

    An HDS certificate is normally valid for three years, with annual surveillance audits by the certification body. Nonconformities identified during audit typically must be corrected within a defined period, often up to three months.

    Who performs the certification audit?

    An independent certification body accredited for HDS performs the audit and issues the certificate. Asteron prepares the organisation but does not issue the certificate; combining implementation and certification would create an independence conflict.

    How much does HDS readiness cost?

    A scoped HDS readiness engagement starts from €9,900. Final scope depends on the number of legal entities, hosting activities, cloud providers, locations, subcontractors, existing ISO 27001 maturity and the complexity of the service architecture. HDS and ISO 27001 certification-body fees are separate.

    Official references

    • – Article L.1111-8 of the French Public Health Code (Code de la santé publique)
    • – Decree 2026-209 of 24 March 2026 on health-data hosting
    • – HDS v2 certification framework (référentiel HDS)
    • – Agence du Numérique en Santé (ANS) — HDS information page

    Last reviewed: July 2026

    Asteron is not endorsed by or partnered with the Agence du Numérique en Santé, COFRAC, any certification body or any supervisory authority.

    Prepare your health-data hosting service for France

    Define whether HDS applies, establish the correct activity scope and build the ISO 27001, supplier, contractual and sovereignty evidence required for independent certification.

    View pricing