Blog · Web development
Health applications: what HDS hosting really requires

On this page
The certification covers the host, not your application. The six activities, what the 2024 framework changed, and what stays on your side.
The French HDS certification applies to the hosting provider, not to your application. That single sentence settles half the misunderstandings on the subject. If your product handles health data collected in a care context and you outsource its hosting, that provider must hold a certificate of conformity. Nothing in that certificate makes your code compliant, replaces your GDPR obligations, or automatically covers every layer of your infrastructure.
Since 16 May 2026, every certified host must be certified under the new framework, the 2024 one. This is a good moment to take the subject apart properly: who is actually in scope, what the certificate covers activity by activity, what it does not cover, and what stays on your side when you are the one publishing the application.
What the law actually says
The legal basis sits in article L1111-8 of the French Public Health Code. It covers any person hosting personal health data collected in the course of prevention, diagnosis, care or social and medico-social follow-up activities, on behalf of the natural or legal persons who produced or collected it, or on behalf of the patient themselves.
On digital media, that host must hold a certificate of conformity issued by bodies accredited by the French accreditation authority, Cofrac, or by the equivalent authority in another member state. The text adds a rule that product teams often overlook: hosting is carried out after the person being cared for has been duly informed, and unless they object on legitimate grounds. That notice therefore has to exist somewhere in your user journey, not only in a contract between you and your provider.
The same article sets an absolute prohibition: any transfer for consideration of identifying health data is forbidden, including with the consent of the person concerned. Breaching it points to article 226-21 of the French Criminal Code, which punishes misuse of purpose with five years’ imprisonment and a 300,000 euro fine. For comparison, that sits well above the usual administrative amounts, and on criminal ground.
One useful detail if you are digitising existing records: for paper media, the regime is not certification but an approval granted by the minister for culture.
Two criteria decide whether you are in scope
The first criterion concerns the data. The text does not say “any health data”, it says data “collected in the course of prevention, diagnosis, care or social and medico-social follow-up”. A wellbeing, nutrition or fitness tracking application that collects weight, sleep or heart rate outside any care pathway does not automatically fall into the HDS regime. Do not draw the opposite conclusion either: that data is very likely health data under the GDPR, therefore sensitive data, with everything that entails. The two regimes overlap without being the same, and that is exactly where projects get it wrong.
The second criterion concerns your role. Certification targets hosting carried out on behalf of a third party. An organisation hosting its own data on its own infrastructure, for its own account, does not need certification for that. On the other hand, if you are a software vendor and your service stores the data of your healthcare customers, you are hosting on behalf of third parties. Depending on your architecture, that means either relying entirely on a certified host for the activities concerned, or becoming certified yourself.
Six activities, and why “my host is HDS certified” means nothing
This is the least understood point, and the most expensive one to discover late. The framework splits hosting into six distinct activities, and a certificate only covers those the body was audited for.
- Providing and operationally maintaining physical sites, in other words data centres.
- Providing and operationally maintaining the hardware infrastructure: servers, storage, network.
- Providing and operationally maintaining the virtual infrastructure, virtualisation and containers included.
- Providing and operationally maintaining the application hosting platform: operating systems, managed databases.
- Administering and operating the information system containing the health data.
- Outsourced backup of the health data.
These six activities are grouped into two separate certificates. The physical infrastructure host covers the first two. The managed-service host covers the following four. A large cloud provider can therefore be perfectly certified on infrastructure without covering the administration and operation of your system, nor your outsourced backup. If you, or a non-certified managed services company, handle those activities, they fall outside the covered perimeter.
Good practice comes down to one question to ask before signing: which of the six activities does your certificate cover, and who covers the rest? Ask for the certificate itself, not a marketing claim, and cross-check it against the public list of certified hosts maintained by the French Digital Health Agency. The list states the perimeter and the validity, and it is the only arbiter.
What the 2024 framework changed
The new version of the framework was approved by a decree of 26 April 2024, published in the Journal officiel on 16 May 2024. The timetable ran as follows: new applicants have been assessed against this version since 16 November 2024, and already certified hosts had twenty-four months to comply, by 16 May 2026 at the latest. In practice, a certificate valid today necessarily rests on this version.
Three changes matter for a software vendor. The first is a requirement that data be physically located within the European Economic Area, which closes a debate that had dragged on for years. The second is a transparency requirement towards customers and the public about the risk of non-EU access to the data: a European host that is a subsidiary of a non-European group now has to state it rather than let you guess. The third is alignment with the 2022 version of ISO 27001, the framework’s foundation.
This mirrors a broader trend we see across other regulations, from NIS 2 to public procurement: the location and legal control of data are becoming compliance criteria, not just sales arguments.
On the mechanics, remember that the certificate is issued for three years, with a surveillance audit every year and a renewal audit at the end. A certificate is never a permanent acquisition, and its validity date deserves to be checked rather than assumed.
What HDS certification does not cover
A certified host gives you a foundation: physical security, availability, infrastructure access management, technical logging, reversibility. It says nothing about your application, and yet that is where most of the incidents we see actually happen.
Entirely on your side: authentication and permission management, tenant isolation in a shared architecture, application-level encryption of sensitive fields, business logging that lets you trace who consulted which record, export handling, and the robustness of your APIs. No hosting certificate compensates for an API that answers an incremental identifier without checking rights. We drew the same conclusions from a public incident in our article on securing applications, and the fundamentals are set out in our guide to website security.
Certification does not replace the GDPR either. Legal basis, impact assessment, retention periods, informing individuals, handling their rights, contractual framing of processors: all of that still has to be produced, and the CNIL treats health data as sensitive data under article 9. Our article on GDPR compliance for a website sets out the general framework.
Finally, it says nothing about your third-party integrations. An analytics tool, a session recorder, an instant messaging support widget or a transactional email service can all move health data out of a certified environment, sometimes through a single URL containing a record identifier. That is one more reason to prefer a sober, EU-hosted analytics setup, a subject we covered in our comparison of Google Analytics alternatives.
The contract, the part nobody reads
The HDS regime is as contractual as it is technical. The hosting contract must describe precisely which services are covered, activity by activity, rather than pointing at a generic statement. Check three things in particular.
Reversibility and return of data: in what format, within what timeframe and at what cost do you get all your data back if you leave, and in what form are the backups returned. It is the most neglected clause and the most expensive one to discover late.
The subcontracting chain: who actually operates behind your host, from which countries, and under what prior notice arrangements if that changes. The framework now requires transparency on the risk of non-EU access, so use it.
Finally, the split of responsibilities, formalised activity by activity. A responsibility matrix annexed to the contract is worth more than a sales conversation, because after an incident the first question asked will be about perimeter.
What it really costs
Certified hosting costs more than standard cloud, but that premium is almost never the main line item. The real cost lies in the architecture: environment isolation, encryption, usable logging, tested restore procedures, documented permission management. These are design choices, and they are far cheaper taken at the start than added afterwards.
If you have to become certified yourself as a vendor, expect a security management system level effort, anchored on ISO 27001, with an initial audit, an annual surveillance audit and a renewal at three years. That is a company-wide project, not a checkbox in a requirements document. Whether you should carry it or lean on a certified third party deserves to be settled early, because it drives your architecture.
In both cases, the natural place for these requirements is the project specifications, alongside performance and accessibility criteria.
Where to start, in four steps
First, qualify the data. Is it collected in the course of prevention, diagnosis, care or social and medico-social follow-up? If so, the HDS regime applies as soon as a third party hosts it. If not, you remain on GDPR ground, which is no small thing.
Then qualify your role. Are you hosting for your own account, or on behalf of your customers? The answer determines whether you must choose a certified host or become one.
Check the certificate, activity by activity, against the list maintained by the French Digital Health Agency, verifying both perimeter and validity date. Identify who covers the missing activities, in particular administration and operation, and outsourced backup.
Finally, handle what the certificate does not cover: impact assessment, patient information and right to object, permissions, business logging, a review of your third-party integrations, and contractual reversibility. That is half the work, and it is the half that belongs to you.
What we take away from it
HDS is not a badge you display, it is a perimeter you verify. A certificate covers some of the six activities, for three years, under annual audit, and since May 2026 necessarily under the 2024 framework, with its requirements on European Economic Area location and transparency about non-EU access.
The rest belongs to you: qualifying your data, your GDPR compliance, the security of your application and control over your integrations. A flawless host does not protect you from an over-talkative API, and that is precisely how the incidents the public remembers happen.
We design and take over business applications in the healthcare sector, with this constraint set during scoping rather than discovered during acceptance testing. If you want to know where you stand, let’s talk.
Read next
Guides on the same topic
Explore the topic further with a selection of complementary resources.