The 2024 HDS framework: what changes for certified health-data hosts
The French HDS scheme (hébergeur de données de santé — certified health-data hosting) went through its most significant revision in 2024 since the 2018 switch from ministerial approval to certification. A new framework, new sovereignty requirements, a transition timetable: if you host health data — or entrust it to a host — this revision concerns you directly. Here is what changed, and what to check today.
Where the revision comes from
The foundations did not move: article L.1111-8 of the French public-health code requires certification from any entity hosting personal health data on behalf of third parties, and decree no. 2018-137 of 26 February 2018 set the procedure — a three-year certificate, issued by an accredited body, with annual surveillance audits. The HDS certification page summarises that base.
What changed is the requirements framework itself: the historical version (v1.1, dating from 2018) was replaced by a new version approved by an order (arrêté) of 26 April 2024, published in spring 2024. The revision answered recurring criticisms: the old version’s silence on data localisation, uneven contractual practice, and the need to refresh the normative base built on ISO 27001.
Change no. 1 — Sovereignty enters the framework
This is the most commented change: the revised framework requires that, for physical-infrastructure activities — the provision and operational maintenance of physical sites (activity 1) and of hardware infrastructure (activity 2) — health data be physically stored within the European Economic Area.
Two readings matter. First, this is not a France-only localisation requirement: the whole EEA qualifies. Second, the requirement targets physical storage at infrastructure level; it does not by itself settle every question of transfers and third-country access — hence the revision’s second pillar.
Change no. 2 — Transparency on hosting conditions
The revised framework strengthens client information duties: the host must clearly set out the conditions under which data is hosted, notably regarding transfers and access to data from abroad. For clients — facilities, software vendors, e-health project owners — this genuinely shifts the balance: the localisation and legal exposure of data become explicit contractual elements, comparable from one host to another, rather than grey areas.
On the hosts’ side, this pillar translates into a contractual and documentation workstream: mapping flows precisely, qualifying possible third-country access, and bringing client contracts up to the expected clauses.
Change no. 3 — An updated base, clarified activities
The revision was also the occasion to refresh the framework’s normative base — still built on ISO 27001 — and to clarify the requirements applying to each of the six certifiable activities: physical sites (1), hardware infrastructure (2), virtual infrastructure (3), application hosting platform (4), administration and operation of the information system (5), backup (6). The two-certificate structure remains: “physical infrastructure host” for activities 1-2, “managed-services host” for activities 3-6. On how this base relates to the international standard, see our comparison HDS certification vs ISO 27001.
These choices follow a trajectory research had anticipated: as early as 2015, the scoping review by Griebel and co-authors in BMC Medical Informatics and Decision Making identified security and legal uncertainty as the top barriers to cloud adoption in healthcare (see the study), and the systematic review by Kruse et al., published in 2017 in Technology and Health Care, documented intensifying threats against health information systems (see the study). Guaranteed localisation and contractual transparency are direct answers to both findings.
The transition is over: where do you stand?
The revision came with a timetable: hosts certified under the previous version had a transition period to upgrade their certification; according to the published timetable, it ended in spring 2026. In other words, as you read this, the revised framework is the only reference:
- You are a certified host: your migration should be done. If any doubt remains about your situation, your certification body is your first port of call; do not let an obsolete certificate serve as sales collateral.
- You are starting a certification journey: you will be audited directly against the revised framework — bake the EEA-localisation and transparency requirements into your architecture and contracts from day one. Our guide to obtaining HDS certification walks the path.
- You are a host’s client: check on the public list maintained by the ANS (the French digital-health agency) that your provider’s certificate is current, for the right activities, and request the transparency information the framework now guarantees you.
What the revision changes in projects, concretely
| Topic | Before (v1.1) | Since the 2024 revision |
|---|---|---|
| Storage localisation (activities 1-2) | Not imposed by the framework | Physical storage within the EEA |
| Client information on transfers | Uneven practice | Strengthened transparency duties |
| Framework version audited | v1.1 | Framework approved by the order of 26 April 2024 |
| v1.1 certificates | Valid | Transition period ended |
For architects, the most structuring consequence is the first row: an infrastructure design conceived under the old version, with storage components outside the EEA for physical activities, must be reworked. For lawyers and sales teams, it is the second: transparency is no longer a differentiator, it is a requirement.
Take action
Whether you are a host or a client, the question is the same: is your situation aligned with the framework in force, not yesterday’s? The HDS certification page gives you the full picture of the scheme, and the free ebook that comes with it folds the 2024 revision into a complete journey, from perimeter to audit.
Frequently asked questions
+When did the new HDS framework come into application?
The new version of the certification framework was approved by an order (arrêté) of 26 April 2024. A transition period allowed hosts certified under the previous version to migrate; according to the published timetable, it ended in spring 2026. New certifications are issued against the revised framework.
+Does the 2024 framework require hosting health data in France?
No: the localisation requirement covers the European Economic Area, not French territory alone. For physical-infrastructure activities, health data must be physically stored within the EEA, and hosts must be transparent about hosting conditions and transfers.
+Is a certificate obtained under the previous v1.1 framework still valid?
The transition period provided for migrating to the revised framework has expired; hosts were required to switch before its end. If you are a host's client, check on the ANS public list that its certificate is current; if you are a host and have not migrated, contact your certification body without delay.