How to obtain French HDS certification: steps, audits, timelines
Obtaining French HDS certification (hébergeur de données de santé — certified health-data host) is entirely achievable, but it is a genuine company project: a demanding framework, two audit phases, a management system that must actually run. Here is the complete path for an entity hosting health data on behalf of third parties — with the vigilance points that save months.
Step 1 — Frame the perimeter: which activities to certify?
Everything starts with mapping your services against the six hosting activities defined by the texts: provision and operational maintenance of physical sites (1), of hardware infrastructure (2), of virtual infrastructure (3), of the application hosting platform (4), administration and operation of the information system (5), data backup (6). Activities 1 and 2 fall under the “physical infrastructure host” certificate, activities 3 to 6 under the “managed-services host” certificate.
This framing is the project’s structuring decision: too broad, and the audit becomes needlessly expensive; too narrow, and you remain unlawful on activities you actually perform — platform administration and backup are the classic omissions of SaaS vendors. To confirm you are within the obligation’s scope at all, start with our article who needs HDS certification?.
Step 2 — Get the framework and measure the gap
The certification framework is published by the ANS (Agence du Numérique en Santé, the French digital-health agency). It combines an ISO 27001 base — a full information-security management system (ISMS) — with requirements specific to health-data hosting: mandatory contractual clauses with clients, localisation and transparency guarantees, per-activity requirements. Mind the version: the framework was revised by an order (arrêté) of 26 April 2024, and that version applies to new certifications (the detail of what changed).
The gap analysis confronts your current state with each requirement: security governance, risk analysis, technical measures, contracts, subcontractor management. If you already hold an ISO 27001 certification on a relevant perimeter, tell your certifier: equivalence can be taken into account and the project accelerates considerably.
Step 3 — Close the gaps and let the system live
This is the heart of the project, and where most of the effort goes:
- Governance and risk analysis: security policy, risk assessment on the perimeter, treatment plan;
- Technical and organisational measures: access control, encryption, logging, incident management, business continuity, physical security for the relevant activities;
- The contractual layer: upgrading client contracts with the clauses imposed by the framework, and framing subcontractors (themselves certified for delegated activities);
- Evidence of operation: reviews, indicators, internal audits, handling of internal non-conformities.
That last point is decisive: an ISMS documented the day before the audit fools no one. Auditors look for a system that lives — which is consistent with the threat landscape: the systematic review by Kruse and co-authors, published in 2017 in Technology and Health Care, shows that threats against health information systems evolve continuously, making frozen compliance an illusion (see the study). Give your system a few months of history before calling in the auditor.
Step 4 — Choose the certification body
Only accredited bodies — accredited by COFRAC in France, or an equivalent European accreditor — can issue the HDS certificate. Request several quotes on a strictly identical perimeter (certificate types, activities, sites) and compare beyond price: knowledge of the health sector, auditor availability, schedule. The choice is a commitment: the same body will run your annual surveillance audits.
Step 5 — Pass the certification audit
The evaluation runs in two phases:
| Phase | Content | Vigilance point |
|---|---|---|
| Documentation audit | Review of the system: policies, procedures, risk analysis, contracts | Consistency between documents and the declared perimeter |
| On-site audit | Evidence gathering: interviews, observation, technical checks | Proof that the ISMS actually operates |
Non-conformities must be corrected within three months; failing that, the on-site audit must be repeated — with the cost and commercial delay that implies. A mock audit beforehand is the best investment to secure this passage: on that front, the method described in our guide to obtaining ISO 27001 certification largely applies, as the base is shared.
Step 6 — Use the certificate, prepare what follows
The certificate is issued for three years and puts you on the public list of certified hosts maintained by the ANS — on this market, that is the commercial argument that opens doors. The lifecycle does not stop there: annual surveillance audits, management of perimeter changes (new offer, new site, new subcontractor), then a full renewal audit at expiry.
A word on context: healthcare’s move to the cloud, documented as early as 2015 by the scoping review of Griebel and co-authors in BMC Medical Informatics and Decision Making, already identified security and the legal framework as the top barriers to adoption (see the study). HDS certification is precisely what removes those barriers in your clients’ eyes: a maintained certificate is worth more than an obtained one.
The three accelerators that change project duration
- An existing ISO 27001 base: with the framework’s core being shared, a valid certification on the right perimeter saves most of the ISMS work.
- A tight, well-argued perimeter: certify only the activities you actually perform, and delegate the rest to certified subcontractors.
- A sponsor at the right level: the trade-offs involved (technical investment, reworking client contracts) exceed a CISO’s remit; without executive backing, projects stall.
Take action
Map your activities, measure the gap, then engage an accredited certifier: every month gained is a month of lead on a market closed to the uncertified. The HDS certification page gathers the essentials of the scheme, and the free ebook that comes with it details every step of this journey.
Frequently asked questions
+How long does it take to obtain HDS certification?
There is no single regulatory timeline: the duration mostly depends on your starting point. An organisation already ISO 27001-certified on the right perimeter moves much faster than one that must build its information-security management system and let it run before the audit. Think in months, and factor the non-conformity correction window (three months maximum) into your planning.
+Who issues HDS certification?
Accredited certification bodies — accredited by COFRAC (the French accreditation committee) or an equivalent European accreditation body — which audit candidates against the framework published by the ANS, the French digital-health agency. The certificate is issued for three years, with annual surveillance audits.
+What happens if the audit finds non-conformities?
The host has three months to correct them. If corrections are not made within that window, the on-site audit must be repeated. Hence the value of securing the audit upfront with a serious gap analysis and a mock audit.