certifications7 min read

HDS Subcontracting: When Must a Health SaaS Vendor Be Certified Itself?

“Our cloud is HDS certified, so we are compliant.” That sentence turns up in almost every French e-health tender — and in most configurations it is simply wrong. HDS certification, France’s mandatory scheme for hosting personal health data, does not cover a company: it covers activities, listed one by one in the Public Health Code. If you perform one of them without a certificate, the fact that your infrastructure supplier is flawless will not save you. Here is how to map the chain from software vendor to cloud host to managed-service provider, and what to demand in writing.

Certification covers activities, not companies

Article L.1111-8 of the French Public Health Code requires a compliance certificate from anyone hosting personal health data on behalf of third parties. Article R.1111-9 breaks that hosting down into six activities:

  1. provision and operational upkeep of the physical sites housing the hardware infrastructure;
  2. provision and operational upkeep of the hardware infrastructure;
  3. provision and operational upkeep of the virtual infrastructure;
  4. provision and operational upkeep of the application hosting platform;
  5. administration and operation of the information system containing the health data;
  6. backup of health data.

Two certificate scopes follow: “physical infrastructure host” for activities 1 and 2, and “managed-service host” (hébergeur infogéreur) for activities 3 to 6. A player performing both trades needs both certificates. The certificate runs for three years, is issued by a certification body accredited by Cofrac, France’s national accreditation body, and is subject to an annual surveillance audit. Out of scope: data entry, formatting, digitisation and dematerialisation services — scanning records is not hosting. Our article on who is really covered by HDS certification sets out that entry test.

Why a certified cloud does not cover you

A typical health SaaS vendor rents virtual infrastructure from a provider certified for activities 1 to 3. Then it does the rest itself: deploying, patching, monitoring, managing access, orchestrating backups. But “administering and operating the information system containing the health data” (activity 5) and “backup” (activity 6) are certifiable activities in their own right. They are not covered by your supplier’s certificate, for the simple reason that your supplier does not perform them.

So the question is never “is my host certified?” but “who does what, activity by activity, and is that player certified for that specific activity?” The answer depends neither on your size nor on your revenue nor on your intentions: it depends on your operating architecture.

Table: who must be certified, in which configuration

Configuration Activities performed by the vendor Vendor’s own HDS certification
Vendor sells an on-premise licence; the customer operates everything None Not required
Vendor resells a certified third party’s SaaS with no operating access None Not required, but clauses must be passed on
Vendor rents certified IaaS and administers its own platform 5, often 6 Required for the activities performed
Vendor delegates operations to a certified managed-service host, keeping no admin access None Not required if the delegation is genuine and documented
Vendor hosts on its own servers and operates them 1 to 6 depending on the setup Required, potentially both certificates
Vendor processes only its own data, with no third-party customers Out of scope Not required (no hosting for others)

The fourth case is the commercially interesting one: outsourcing operations to a certified managed-service host spares the vendor from carrying certification itself. But the delegation must be real. Keeping an administration account “for support purposes” is enough to pull activity 5 back inside your scope — and to make the whole arrangement non-compliant.

Reading an HDS certificate: five checks, not one

The Agence du Numérique en Santé (ANS), France’s digital health agency, publishes the list of certified hosts, showing for each one the activities covered, the version of the framework applied and the certification body. According to the count published by ANS, more than 400 hosts were listed in spring 2026. Before signing:

  • The legal entity. A certificate names a specific legal person. A subsidiary, a trading name or a sister company is not covered.
  • The activities. A “physical infrastructure” certificate says nothing about managed services. Line the covered activities up against the ones you actually delegate.
  • The framework version. The revision approved by the order of 26 April 2024 replaced version 1.1; the migration deadline for legacy certificates was set at 16 May 2026. A provider still shown on v1.1 is a red flag (what the 2024 revision changed).
  • The dates. Issue and renewal dates must appear in the contract; ask the named certification body to confirm the certificate is in force.
  • The sites. The actual hosting locations, not the nationality of the group.

What the contract must contain

Article R.1111-11 of the Public Health Code sets a list of minimum clauses, which come on top of — and do not replace — those required by Article 28 GDPR for processors. They include the scope of the certificate and its dates, a description of the services with availability, integrity, confidentiality and auditability guarantees, the hosting locations, arrangements for exercising the data subject rights set out in Articles 15 to 21 GDPR, breach notification, service-level indicators, information on the use of external subcontractors together with an equivalent-protection undertaking, information on transfers to third countries, a ban on using the hosted health data for any purpose other than hosting, and the whole exit package: end-of-hosting services — including where certification is lost or withdrawn —, reversibility, full return of the data, then destruction with no copy retained, after formal agreement from the data controller.

The rule that catches vendors out

The decisive point lies elsewhere. The same article provides that where a data controller (or a patient) entrusts data to a service provider which itself relies on a certified host, the contract between the controller and that provider reproduces the clauses as they appear in the contract between the provider and the certified host.

In other words: your own terms as a vendor must mirror the contract you signed with your cloud provider. You cannot promise a teaching hospital a reversibility or a data location that your own supplier does not guarantee you. This is a requirement of contractual consistency across the whole chain — and the first thing a well-briefed hospital buyer will look at.

What changes on 26 September 2026

Decree no. 2026-209 of 24 March 2026 amended these provisions. It creates an Article R.1111-9-1 laying down the principle that personal health data must be stored exclusively on the territory of a Member State of the European Union or a party to the EEA Agreement. Transfers to a third country remain possible under GDPR conditions — an adequacy decision under Article 45, or appropriate safeguards under Article 46 with enforceable rights and effective remedies — it being understood that remote access from a third country counts as a transfer. The decree also adds a specific contract clause: where the host is subject to extra-European legislation that could compel access to the data, the contract must list those laws, state the absence of an adequacy decision where relevant, and describe the mitigation measures and the residual risks. These provisions take effect six months after the decree’s publication, i.e. on 26 September 2026. If your stack runs on a non-European cloud, or if support is delivered from a third country, now is the moment to document the chain.

HDS, GDPR and ISO 27001: three separate planes

An HDS certificate is not GDPR compliance: legal bases, transparency, records of processing, impact assessments and processor contracts all remain to be handled on their own merits, on both sides of the relationship. Conversely, ISO/IEC 27001 does not replace HDS: it is the information security management baseline the French framework builds on, not an authorisation to host health data in France. The sensible move is to share one management system rather than pay twice for the same work — our comparison of HDS and ISO 27001 frames the trade-off, and our article on ISO 27001 against GDPR and NIS2 shows how the three planes fit together.

What the research says about chain risk

Lawmakers did not invent this risk. Thomas H. McCoy and Roy H. Perlis, writing in JAMA in 2018, analysed health data breaches reported to US authorities between 2010 and 2017: over 2,100 incidents affecting more than 176 million individuals, with a steady shift from theft of physical media towards hacking and IT incidents (see the study). Juhee Kwon and M. Eric Johnson had already shown, in the Journal of the American Medical Informatics Association in 2013, that regulatory compliance in healthcare organisations depends less on isolated technical controls than on coherent configurations of security practices (see the study). The operational translation for a software vendor: one certified link in a badly mapped chain does not produce compliance.

Take action

Lay out your operating architecture, activity by activity, and match it against the certificates each link actually holds — including your own. If an activity is left orphaned, you have two options: delegate it to a player certified for that activity, or get certified yourself (the steps and the audit, the budget to plan for). Our guide to HDS certification gives the overview of the scheme, and the free ebook that goes with it walks through the full mapping exercise.

FAQ

Frequently asked questions

+Is relying on an HDS-certified cloud enough for a health software vendor?

No, not as a general rule. French HDS certification covers specific activities, and each player must be certified for the ones it performs itself. A vendor that administers and operates the information system holding the data, or manages its own backups, is performing activities listed in the Public Health Code and must be certified for them, even if the underlying infrastructure is rented from a certified cloud provider.

+How do you check a provider HDS certificate?

France's Agence du Numérique en Santé publishes the list of certified hosts, showing the activities covered and the version of the framework applied. Check that the legal entity listed is the one signing your contract, that the activities covered match those you delegate, and confirm the certificate is in force with the named certification body.

+Do the mandatory HDS contract clauses apply between a vendor and its own customer?

Yes. The Public Health Code provides that where a data controller uses a service provider which itself relies on a certified host, the contract between the controller and that provider must reproduce the clauses as they appear in the contract between the provider and the certified host. These clauses come on top of those required by Article 28 GDPR.

Read next