10 min read
Health data hosting : Understanding the HDS Certification
Can you host healthcare data in France without HDS certification? This guide explains what HDS certification covers, who needs it, and how to choose a secure, compliant hosting provider.

Hosting health data is not something you can improvise. These are highly sensitive records, governed by strict legal and technical requirements.
In France, this responsibility has a name: the HDS certification (Hébergement de Données de Santé, or Health Data Hosting). It ensures that technical service providers meet the highest standards of security, traceability, and regulatory compliance.
In this article, we’ll walk you through what HDS certified hosting is, who it applies to, why it matters, and how Scalingo has made the commitment to cover every regulatory scope defined by law, offering a reliable, sovereign, and fully compliant solution for healthcare organizations.
What is HDS (Health Data Hosting)?
HDS is a mandatory French certification that governs how personal health data can be legally hosted and managed.
Introduced by the French Agence du Numérique en Santé (ANS), It applies to providers that host personal health data falling within the HDS framework on behalf of another organization or individual, including cloud platforms, hosting providers, and other technical service providers performing the relevant hosting activities. We’ll define exactly what qualifies as health data in a moment.
The HDS framework ensures that providers like Scalingo adhere to the highest levels of security and confidentiality, on par with standards seen in critical sectors like banking or national defense.
Why is HDS Certification Necessary?
Health data is among the most sensitive information that exists. It directly concerns a person’s physical and mental well-being, and can sometimes reveal delicate social or family situations.
Now imagine the risks if that information were to circulate in a digital system without adequate protection.
If health data falls into the wrong hands, the consequences can be severe:
Privacy breaches – exposure of medical conditions, psychological issues, confidential treatments, or personal health history
Discrimination – in employment, insurance, or even housing
Blackmail or extortion – some ransomware attacks specifically target hospitals and clinics, exploiting the value of sensitive data to demand payment
Protecting health data isn’t only about preventing unauthorized access though. Availability and continuity of service matter too. An outage can prevent healthcare professionals from accessing information needed for patient care or temporarily make an essential service unavailable.
This is why HDS addresses not only security, confidentiality and traceability, but also service continuity and availability.
Important
HDS certification does not guarantee that an incident will never happen. What it does ensure is that the infrastructure is well-prepared, actively monitored, and ready to respond quickly. Most importantly, it confirms that the provider follows industry best practices, all of which are audited and certified.
What Counts as “Health Data”?
The reference definition of “health data” comes from the GDPR (General Data Protection Regulation) and the French Data Protection Authority (CNIL):
"Health data is any personal information related to the physical or mental health of an individual, past, present, or future. This includes, for example, diagnoses, test results, prescriptions, or even indirect data such as heart rate measured by a connected device, if it can be used to infer a person’s state of health."
In short: as soon as an application processes identifiable medical information, it falls under the category of health data, along with all the legal obligations that come with it.
Examples of information commonly considered health data include:
Blood test results or a COVID test result
A medical diagnosis (e.g., diabetes, depression)
Information from a prescription or medical certificate
Data collected from a connected device (e.g., heart rate, step count)
Records of a medical appointment or hospitalization
Genetic or biological data, even if anonymized, if it can be re-identified
Data is considered personal only if it is linked to or can be used to identify someone, either directly or indirectly. To qualify as health data, it must also reveal information, even indirectly, about a person’s physical or mental health.
Who needs HDS-certified hosting?
HDS certification becomes mandatory when an organization entrusts the hosting of this personal health data to a third-party provider.
For example, a hospital can store the patient data it collects on infrastructure it operates itself without needing HDS certification for that hosting. However, if it outsources the hosting to a cloud or other third-party provider, the relevant hosting activities must be covered by HDS certification.
In practice, HDS-certified hosting is commonly needed for:
Healthcare SaaS applications that host patient data for their customers
Telemedicine and remote-care platforms
Patient management and care coordination tools
Digital health applications that host personal health data for healthcare organizations
Healthcare organizations that outsource the hosting of patient data
Needing HDS-certified hosting doesn’t necessarily mean your organization needs to become HDS certified itself. What matters is that the providers responsible for hosting your health data are certified for the HDS activities they perform.
What Are the 6 HDS Certification Scopes?
Now that we’ve defined what qualifies as health data, another key question comes up: who is allowed to host it, and under what conditions?
This is exactly where HDS certification becomes relevant, especially when it comes to its different scopes.
A common misconception is that all HDS certifications are the same. In practice, an HDS certification refers to a set of clearly defined scopes, not a universal stamp of approval. It is a modular system that reflects the specific role a provider plays in handling health data.
👉 In simple terms, HDS certification can cover up to six distinct activities. Some companies are certified for just one, others for several. Very few cover all of them.
Here are the six official HDS hosting scopes:

1. Physical facility hosting
This scope ensures that the buildings housing the servers (such as data centers) comply with strict standards. These include controlled access, fire safety systems, backup power supply, and other physical safeguards.
2. Physical infrastructure hosting
This covers the actual hardware — servers, storage arrays, network equipment. The goal is to ensure that these components are installed, maintained, and monitored under optimal security and operational conditions.
3. Virtual infrastructure hosting
This covers the virtual infrastructure used to process health data, such as virtual machines. These environments must be securely operated, maintained, and monitored.
4. Application hosting platform
This involves everything that allows applications to run properly. It includes operating systems, databases, middleware, and other foundational software layers.
5. Administration and operation of the information system
This covers the day-to-day administration and operation of information systems containing health data. It can include managing access, monitoring systems, carrying out technical interventions, and maintaining their operation.
6. Health data backup
This covers externalized backups of health data, ensuring that a copy of the data can be recovered if the primary data is lost, corrupted, or unavailable.
These six scopes are defined by the Agence du Numérique en Santé (ANS) and outlined in the official HDS Certification Framework.
Important
Under HDS 2.0, the numbering of activities 3 and 4 has changed. Virtual infrastructure is now activity 3, while application hosting platforms are activity 4. You may still see the previous numbering in older resources, including the diagram below, which was created under the previous HDS framework 👇

HDS 2.0: What are the latest updates?
The current HDS certification framework is version 2.0, which came into force in 2024 and replaced the previous version 1.1. Since 16 May 2026, HDS providers must be certified under this version to continue hosting health data on behalf of third parties.
So, what changed? HDS 2.0 mainly strengthens the rules around where health data is hosted, transparency around access to it, and the scope of certification.
Health data must be hosted in the EEA. HDS 2.0 requires physical hosting of the health data concerned to take place within the European Economic Area (EEA): a requirement that wasn't part of the previous framework.
There’s more transparency around access from outside Europe. Providers must disclose certain transfers and remote access from outside the EEA, and explain the risks when they or their subcontractors are subject to non-European laws that could allow access to the data, as well as the measures taken to mitigate those risks.
The scope of certification is clearer. An HDS certificate can cover one or several of the six HDS activities, so “HDS-certified” doesn't necessarily mean that every service a provider offers is covered. HDS 2.0 makes it easier to identify exactly which activities are included in a provider's certification.
📌 The HDS framework continues to evolve: ANS has announced HDS v2.1 for October 2026, with additional transparency requirements around data transfers and exposure to non-European legislation.
What is the HDS certification process for cloud providers?
We won’t dive into every step of the HDS certification process here since it could fill an article of its own. But here’s what you need to know: obtaining HDS certification means meeting exceptionally high standards, particularly in areas such as:
Infrastructure security
Access confidentiality and traceability
Service continuity and availability
Strict compliance with the GDPR, supported by the ISO 27001 standard
Getting certified takes months of preparation, including audits by an independent organization accredited by the COFRAC, extensive documentation, detailed process updates, and most importantly, company-wide involvement that extends far beyond the security or infrastructure teams.
Here’s a visual summary of the key points:

As you can see, it’s not just a box to tick or a certificate to showcase on your website. It’s a deep, structural commitment that reshapes how hosting, maintenance, and even client relationships are approached in a field as sensitive as healthcare.
The HDS certification is valid for three years and includes annual surveillance audits. Scalingo’s HDS certification was renewed in September 2025 under the HDS 2.0 standard. It is valid until September 11, 2028, and covers all six HDS activities.
Scalingo: A Fully HDS-Certified PaaS & DbaaS
So what about Scalingo? We made the deliberate and ambitious choice to obtain certification across all six HDS scopes. This means our cloud hosting platform is fully compliant, from physical infrastructure to software operations and data backup.
This level of coverage is still rare in the French cloud ecosystem, and it allows us to support our healthcare clients with a turnkey solution. No need to manage multiple vendors or navigate regulatory complexity alone.
Beyond the certification itself, it reflects a deeper commitment and philosophy we believe in: Hosting health data is not just about ticking boxes. It is about taking long-term, collective responsibility.
At Scalingo, this commitment is reflected in a company-wide effort. From InfoSec and engineering to support and product teams, everyone is involved. And that’s what makes the certification meaningful. It’s not just a document, it’s something that lives in our everyday practices.
The HDS framework allows us to host dozens of sensitive healthcare applications, both in France and internationally, across a wide range of use cases including telemedicine, care coordination, clinical trials, patient journeys, and preventive care.
—> Learn more about Scalingo's HDS certified cloud hosting platform
Health Data Hosting FAQ
Still have questions? Here are the answers to the most common questions and concerns our users have about HDS hosting and what it involves.
1. Can health data be hosted on AWS, Azure, or Google Cloud?
Yes, but under some conditions.
In theory, AWS, Google Cloud, and other American hyperscalers can host health data in France, provided that their services are certified for the relevant HDS scopes. Some of their offerings have indeed received this certification, which is a positive step.
👉 However, caution is needed:
Not all services offered by these providers are covered by the certification.
It is the responsibility of the application provider to carefully verify which specific HDS scopes are actually certified (physical infrastructure? software platform? managed services? backups?).
Most importantly, hosting with a non-European provider can raise concerns about data sovereignty and GDPR compliance, particularly due to the implications of the US Cloud Act.
Regulatory bodies such as the CNIL, the Conseil d’État, and the ANS strongly recommend favoring sovereign solutions, hosted within the European Economic Area and not subject to conflicting extraterritorial laws.
2. What is the difference between ISO 27001 and HDS?
The ISO 27001 standard and the HDS certification share a common goal: ensuring a high level of information security. However, they serve slightly different purposes:
ISO 27001 is an international standard that defines best practices for securing information systems, across all industries. It is based on principles such as risk assessment, access management, and security governance.
HDS (Health Data Hosting) is a mandatory French certification required for hosting health data. It builds upon ISO 27001 but includes additional requirements specific to the healthcare sector, such as data sovereignty, enhanced traceability, and guaranteed service availability.
💡 At Scalingo, we are certified for both, to ensure secure, compliant, and sovereign health data hosting.
3. Is HDS certification enough to be GDPR compliant?
Not really.
HDS certification is complementary to, but does not replace, compliance with the GDPR (General Data Protection Regulation).
👉 To be GDPR compliant, a company must meet a set of legal obligations related to the protection of personal data, including:
having a lawful basis for data processing
being transparent with users
respecting individuals’ rights (such as access, rectification, and deletion)
collecting only the data that is strictly necessary
appointing a Data Protection Officer (DPO), in certain cases
On its side, the HDS certification focuses exclusively on the hosting of health data, with strict requirements around security, traceability, availability, and data sovereignty.
“ 🔐 At Scalingo, we provide hosting that is HDS certified and GDPR compliant. However, it is up to our clients to ensure that the rest of their application fully meets GDPR obligations (privacy policy, consent management, and more). ”
4. Are HDS and HIPAA the same thing?
At first glance, HIPAA (Health Insurance Portability and Accountability Act) and HDS certification appear to share the same goal: protecting sensitive health data. And in spirit, that’s true: both aim to ensure the confidentiality, security, and reliability of medical information.
However, in practice, the approaches are somewhat different.
HIPAA is a United States regulation that applies to the entire American healthcare system. It defines strict rules on data privacy, as well as broader patient rights and mandatory security measures.
Being HIPAA-compliant is therefore not sufficient to legally host health data in France. Likewise, HDS certification does not guarantee HIPAA compliance in the United States.
💡 At Scalingo, we support both French and international organizations, and we’re here to help you navigate between these frameworks based on your specific regulatory requirements.
5. Is HDS certification dependent on using a SecNumCloud region?
No. HDS certification does not require hosting in a cloud region qualified under SecNumCloud.
HDS is a certification specific to the healthcare sector. It governs how health data must be hosted and ensures a high level of security, confidentiality, and GDPR compliance. However, it does not mandate the use of a SecNumCloud-qualified provider.
SecNumCloud, on the other hand, is a separate high-security label issued by ANSSI (France’s National Cybersecurity Agency). It applies to cloud service providers across all sectors and is designed to ensure maximum data sovereignty, particularly in the face of extraterritorial laws such as the US Cloud Act.
In summary:
HDS: mandatory for hosting health data
SecNumCloud: recommended to enhance sovereignty, but not mandatory
6. What is a “Healthcare Professional Point of Contact”?
As part of HDS certification requirements, Scalingo must designate a healthcare professional point of contact for each client. This contact plays a critical role. They must be able to identify a licensed healthcare professional who is authorized to act when needed — for example, to approve access to health data or respond to a security incident.
Additionally, Scalingo must be able to provide this list to the relevant authority without delay, especially in the event that HDS certification is suspended or withdrawn. This is a requirement outlined in the official HDS framework (version 1.1.1f, requirement 4.5.4).
Planning a Healthcare Project? Let’s Talk.
Not sure about your HDS requirements? Looking for a GDPR-compliant cloud partner, certified in health data hosting, based in France, and deeply familiar with the needs of the healthcare sector?
👉 Get in touch with our team — we’d be happy to discuss your project.

Jennifer Taylor
At Scalingo, Jennifer leads growth and marketing initiatives, helping shape the company’s voice in the fast-evolving PaaS and cloud ecosystem. She loves translating complex cloud concepts into clear, engaging insights.
Stay Updated
Get articles and platform updates in your inbox.
Ready to Deploy with Confidence?
Experience zero-downtime deployments, intelligent auto-scaling, and fully managed infrastructure. Start deploying your applications on Scalingo today.
No credit card required • Deploy in minutes • Cancel anytime




