HDS certification vs ISO 27001: differences, overlap, strategy
On the French e-health market, two acronyms appear in every tender: HDS and ISO 27001. They are cited together so often that they get conflated — wrongly. One is a sector-specific legal obligation, the other a voluntary international standard; one closes a market to the uncertified, the other separates competitors. Here is what really distinguishes them, and how to combine the two without paying twice for the same work.
Two schemes of different natures
| HDS certification | ISO 27001 certification | |
|---|---|---|
| Nature | French legal obligation (art. L.1111-8 of the public-health code) | Voluntary international standard |
| Scope | Hosting health data on behalf of third parties | Information security, any sector |
| Framework | Published by the ANS (French digital-health agency), built on ISO 27001 | ISO/IEC 27001 |
| Breakdown | Six certifiable activities, two certificate types | Perimeter defined by the organisation |
| Validity | 3 years, annual surveillance | 3 years, annual surveillance |
| If absent | Activity unlawful, market closed | No sanction (outside contractual demands) |
HDS certification conditions the lawfulness of the activity: hosting health data for others without the certificate is prohibited, and healthcare players are not allowed to entrust their data to an uncertified provider — the HDS certification page details that mechanism. ISO 27001 conditions competitiveness: no general law requires it, but clients demand it contractually, as the ISO 27001 certification page explains.
What HDS adds on top of the ISO 27001 base
The HDS framework is not a mere restatement of the standard: it takes its base — the information-security management system (ISMS), its risk analysis, its controls — and adds requirements specific to the health context:
- A regulatory breakdown into six activities (physical sites, hardware infrastructure, virtual infrastructure, application platform, administration and operation, backup), yielding two certificates: “physical infrastructure host” (activities 1-2) and “managed-services host” (activities 3-6). You do not certify “the company”; you certify activities.
- Mandatory contractual clauses between the host and its clients — a legal workstream with no equivalent in ISO 27001.
- Sovereignty and transparency requirements, strengthened by the framework revision approved by the order (arrêté) of 26 April 2024: physical storage of data within the European Economic Area for physical-infrastructure activities, and client information on hosting conditions and transfers (the detail of the 2024 revision).
- A health anchor: the scope is defined by the nature of the data (collected in a prevention, diagnosis, care or medico-social context), not by the organisation’s own choice.
This sector-specific tailoring answers a documented risk context: the systematic review by Fernández-Alemán and co-authors, published in 2013 in the Journal of Biomedical Informatics, already showed the gap between the security requirements of electronic health records and observed practice (see the study) — precisely the kind of gap a sector framework aims to close.
What ISO 27001 brings that HDS does not
The reverse is just as true. ISO 27001 is recognised internationally: if your market extends beyond France, the HDS certificate will mean nothing to your prospects, whereas ISO 27001 is the common language of information security — the literature review by Culot and co-authors, published in 2021 in The TQM Journal, documents its role as the global reference standard and the organisational benefits associated with adopting it (see the study). ISO 27001 can moreover cover your entire information perimeter if you so decide — HR, finance, R&D — whereas the HDS certificate only speaks to your health-data hosting activities.
In other words: HDS opens the French health market; ISO 27001 opens the rest of the world and structures the whole company. For an ambitious host or software vendor, the question is not “which one?” but “in which order?”.
Three combination strategies
- You are already ISO 27001 certified. The most favourable scenario: tell your HDS certifier, who can take base-level equivalence into account when the perimeter matches the activities to certify. The residual effort targets the framework’s specific requirements (contracts, localisation, health specifics).
- You start from scratch and target the French health market. Run the HDS journey directly: the framework incorporates the base, so no prior ISO 27001 certification is needed. You can leverage the ISMS built for HDS if you pursue ISO 27001 later.
- You want both. Pool the work: one ISMS, one risk analysis, one documentation corpus, two audits. Some certification bodies can coordinate the cycles — three years and annual surveillance in both cases, so you may as well synchronise them.
In every case, project sizing follows the same logic as for the base: our guide obtaining HDS certification: steps and audits walks the full path.
The classic trap: confusing conformity with coverage
Two confusions are expensive on this market. First: believing ISO 27001 “counts as” HDS — no, only HDS certification makes the hosting lawful. Second: believing that building on an HDS-certified cloud removes all obligations — no, each actor must be certified for the activities it performs itself; a vendor that administers its platform or manages its backups is in scope for those activities. Before any decision, map who does what, activity by activity, across your technical chain.
Take action
If you touch health-data hosting, HDS is your regulatory priority; ISO 27001 is your pooling and international-expansion lever. Frame your perimeter and strategy with the HDS certification page — the free ebook that comes with it details the full journey, including how to capitalise on an existing ISO 27001 base.
Frequently asked questions
+Does ISO 27001 certification exempt you from HDS certification?
No. To host health data on behalf of third parties in France, only the HDS certificate counts: it is what article L.1111-8 of the public-health code requires. An existing ISO 27001 certification does, however, make obtaining the HDS certificate much easier, since the framework builds on that base.
+Should you obtain ISO 27001 before aiming for HDS?
It is not a precondition: the HDS journey can be run directly, as the framework incorporates the base requirements. Many organisations run both in parallel, or capitalise on an existing ISO 27001 certification when its perimeter matches the hosting activities to certify.
+Is an HDS-certified host automatically GDPR compliant?
No. HDS certification evidences conformity with the French health-data hosting framework; GDPR imposes its own legal obligations (lawful bases, informing individuals, article 28 processing agreements), which remain to be handled in their own right, on the host's side as on the client's.