Is French HDS certification mandatory? Who actually needs it
“Do we need HDS certification?” is probably the most common question from companies approaching the French e-health market — and one where approximate answers cost the most. The rule itself is clear: hosting personal health data on behalf of third parties in France is a regulated activity, subject to certification. The whole difficulty is knowing whether your activity falls within scope. Here is how to decide.
What the law says
Article L.1111-8 of the French public-health code (Code de la santé publique), as rewritten by law no. 2016-41 of 26 January 2016, sets the principle: anyone hosting personal health data collected in the course of prevention, diagnosis, care or medico-social follow-up activities, on behalf of third parties, must hold a certificate of conformity. Decree no. 2018-137 of 26 February 2018 set out the procedure: certification is issued for three years by an accredited certification body, against the framework published by the ANS (Agence du Numérique en Santé, the French digital-health agency), with annual surveillance audits.
This scheme replaced the former ministerial approval: since April 2018, certification has been the only route. The HDS certification page summarises the full scheme — legal basis, steps, frequent questions.
The decisive test: hosting “on behalf of third parties”
The obligation does not target holding health data in general, but hosting it for others. Three practical consequences:
- In-house hosting is out of scope. A healthcare facility, laboratory or company hosting its own data, on its own servers, for its own account, does not need to be certified. As soon as it outsources, however, its provider does.
- Purely technical, one-off services are excluded. The texts carve out data entry, formatting, materialisation and dematerialisation services: digitising medical records is not hosting.
- The nature of the data matters more than the client’s sector. What triggers the obligation is personal health data collected in a prevention, care or medico-social context — not working “in health” in a loose sense.
Who is concerned in practice
The scope covers far more than data centres. The texts break hosting down into six certifiable activities — from physical sites and hardware infrastructure (activities 1 and 2, the “physical infrastructure host” certificate) to virtual infrastructure, the application platform, system administration and operation, and backup (activities 3 to 6, the “managed-services host” certificate). Typically concerned are:
- cloud providers and data centres holding clients’ health data;
- managed-service providers administering and operating health information systems for others;
- health SaaS vendors (practice software, telemedicine, medical appointment booking…) for the activities they operate themselves;
- outsourced backup providers handling health data.
The SaaS vendor case deserves a word: relying on a certified host is not always enough. If the vendor administers its own platform or manages its own backups, it performs hosting activities within the meaning of the framework — and must be certified for them. The sound method is to map who does what, activity by activity, across the whole technical chain.
Why the legislator closed this market
Making certification compulsory was no administrative whim: health data concentrates risks documented by research for over a decade. The systematic review by Fernández-Alemán and co-authors, published in 2013 in the Journal of Biomedical Informatics, surveys the literature on security and privacy in electronic health records and highlights the persistent gap between security requirements and observed practice (see the study). The review by Kruse et al., published in 2017 in Technology and Health Care, documents the rise of cyber threats specifically targeting healthcare (see the study). Requiring a certified baseline from every host in the sector is the French answer to that evidence.
Legal obligation and de facto obligation
Even players not directly subject to the obligation feel it by ricochet: an e-health project owner, facility or software vendor must choose certified providers for the covered activities, otherwise their own compliance collapses. The ANS publishes the list of certified hosts: checking that a provider appears on it, for the right activities, should be a systematic reflex before signing anything.
This mechanism — a text that imposes certification on the supplier and thereby structures the whole purchasing chain — distinguishes HDS from voluntary certifications such as ISO 27001, demanded by the market but not by law. We unpack that relationship in our comparison HDS certification vs ISO 27001.
Deciding your case in four questions
- Do you process personal health data collected in a prevention, diagnosis, care or medico-social context?
- Do you host it on behalf of third parties, or only for yourself?
- Which of the six certifiable activities do you perform in-house (physical sites, hardware infrastructure, virtual infrastructure, application platform, administration and operation, backup)?
- Are your subcontractors certified for the activities you delegate to them?
If the answers to questions 1 and 2 are “yes”, you are in scope for the activities identified in question 3 — and the framework in force, revised in 2024, will apply to your audit (what the 2024 framework changes).
Take action
If your activity is in scope, the question is not whether you will get certified, but when and on what perimeter. The HDS certification page gives you the full picture of the scheme, and the free ebook that comes with it walks through the entire journey, from activity mapping to the audit.
Frequently asked questions
+Is HDS certification mandatory for a health software vendor?
It depends on which hosting activities the vendor performs itself. If it merely relies on a certified host for the covered activities, part of the obligation sits with that host. If it operates listed activities in-house — system administration and operation, outsourced backup — it must be certified for those activities.
+Does a hospital hosting its own data need HDS certification?
No: the obligation targets hosting health data on behalf of third parties. An organisation hosting its own data, for its own account, is outside the scope. It must, however, use a certified host if it outsources that hosting.
+What happens if you host health data without certification?
The activity is unlawful under article L.1111-8 of the French public-health code, with the sanctions that follow. In practice the most immediate sanction is commercial: healthcare players are not allowed to entrust their data to an uncertified host, which closes the market.