“HDS certified” reads like a checkbox: a provider either is, or isn’t. The reality is less binary. Two equally certified providers can differ on three points that carry real weight when health data is involved: the actual scope of their certification, their exposure to the law of a third country, and how much operational work they leave to the customer. Choosing an HDS cloud is therefore less about verifying a label than about asking three precise questions before signing.
Health data hosting (HDS, Hébergement de Données de Santé) is a French regulatory framework. It requires any organisation that hosts, operates or backs up health data on behalf of a third party to use an HDS-certified provider. The obligation stems from Article L.1111-8 of the French Public Health Code. The certification, issued by an independent accredited body, attests that a provider meets the requirements of the HDS framework within a defined scope. That scope is exactly what deserves a closer look.
What HDS certification covers
What counts as health data?
Health data is any information that identifies a person and reveals something about their physical or mental health. The GDPR (Articles 4 and 9) classifies it as a special category of data, subject to reinforced protection. This covers medical records, test results and prescriptions, but also less obvious cases: a food allergy recorded in a school canteen application is health data.
The six activities of the HDS framework
HDS certification is not a single block. The framework distinguishes six activities: provision and maintenance in operational and security conditions of physical sites, hardware infrastructure, virtual infrastructure and the application hosting platform, plus administration and operation of the information system and backup of health data. A provider can be certified across all six activities, or only some of them. An offer certified only on the infrastructure layers leaves administration, operation and backup to be organised elsewhere, and therefore contracted out to a third party or absorbed in-house. The exact scope of a certificate can be checked in the ANS register of certified providers.
Three criteria for choosing an HDS cloud
An HDS provider is judged on three axes. None is sufficient on its own, and no provider leads on all three at once: the decision comes down to fit with the project.
Certification scope
How many of the six activities is the provider certified for? Partial certification remains perfectly valid, but the uncovered part, often administration, operation or backup, then falls to the customer or to a third party who has to be identified and managed. The certificate states this, and the ANS register makes it possible to cross-check.
Exposure to extraterritorial legislation
This is the criterion most often confused with the previous one. HDS certification attests to a level of security and compliance; it says nothing about exposure to the CLOUD Act or FISA, the US laws that allow American authorities to request access to data held by a provider subject to US law, regardless of where that data is stored. A provider can therefore be HDS certified, run its servers in France, and still fall under that law through its ownership or its parent company. What decides the matter is not data location, but the legal regime of the operator.
France’s health data platform, formerly the Health Data Hub, illustrates this. Its data was hosted on HDS-certified infrastructure located in France, but operated by a company subject to US law. Ruling on the challenges brought against it, the Conseil d’État rejected the requests for annulment on 20 March 2026 (nos. 503159 and 504171), in a decision concerning a framed and time-limited authorisation, while acknowledging that access by US authorities to certain data could not be ruled out. In parallel, under the sovereignty requirements of the French SREN law, the State has begun migrating the platform to sovereign French hosting. HDS certification and immunity from extraterritorial legislation are two distinct guarantees, and this case shows they do not overlap.
The operating model
Once the provider is chosen, what is left to operate? An infrastructure provider (IaaS) supplies the resources, and the customer configures, secures and maintains everything running on top. A managed platform takes on part of those layers: encryption, isolation, backups, monitoring, updates. The two models serve different needs. A team that wants to master its own stack is comfortable with infrastructure; a health software vendor that would rather ship its application and delegate operations to reduce what it must keep compliant is better served by a managed platform. The right choice depends on the in-house skills available and on the time the team can realistically devote to operations.
| Criterion | US hyperscalers (AWS, Azure, Google Cloud) | French sovereign clouds (OVHcloud, Scaleway…) | Clever Cloud |
|---|---|---|---|
| HDS certification scope | Most often the infrastructure layers, with restrictions depending on the regions and services chosen. Application scope to be verified. | Varies by offer: some cover all six activities, others only part. To be checked in the ANS register. | All six activities of the framework. |
| Exposure to extraterritorial legislation (CLOUD Act, FISA) | Yes: companies subject to US law, including when data is hosted in Europe. | Outside the reach of these laws for operators with French ownership and jurisdiction. The decisive criterion is the operator’s legal regime, not server location alone. | No: French capital and headquarters, no US subsidiary, no transfer of health data outside the EEA. |
| Operating model | From infrastructure (IaaS) to managed services. Configuring and operating the compliance layers largely remains the customer’s responsibility. | From infrastructure to managed services, depending on the offer. | Platform operated end to end: encryption, isolation, backups, monitoring and automatic updates included. |
Certification scopes change over time and should be verified case by case in the ANS register. This table does not designate a “best” provider in absolute terms: it shows where each model is strong, and which criterion the decision actually turns on.
Three misconceptions about HDS hosting
“My provider is certified, so I have nothing left to do.” Using a certified provider does satisfy the obligation to host health data with a certified host, and the HDS contract provides the proof. But it does not make the customer certified, and it does not discharge its obligations as a data controller under the GDPR: the security of its application, access management, informing data subjects and respecting retention periods all remain its responsibility.
“HDS certified” means certified on everything. This is the costliest confusion, because it makes two offers look falsely comparable: certification may cover only part of the six activities. Two “HDS certified” providers are therefore not necessarily equivalent, and the gap is visible on their respective certificates, not on their homepage.
HDS and GDPR are the same thing. The GDPR is the European foundation for personal data protection. HDS certification is a French requirement specific to the hosting of health data, which adds to the GDPR rather than replacing it. Complying with one does not exempt you from the other.
Clever Cloud against these three criteria
Applied to Clever Cloud, the same grid gives a clear reading.
On scope, Clever Cloud is certified across the six activities of the HDS framework, in its version currently in force, and against ISO/IEC 27001:2022. The chain is covered from infrastructure through to backup. The certificate, issued by Bureau Veritas Certification France under number FR094504, is public and valid until 19 December 2027.
On extraterritorial exposure, sovereignty here rests on verifiable facts rather than on a slogan: French capital and headquarters, no subsidiary in the United States, no transfer of health data outside the European Economic Area. There is no attachment to US law, and therefore no exposure to the CLOUD Act or FISA to remove.
On the operating model, Clever Cloud operates the platform end to end. Encryption, isolation, automatic backups, monitoring and updates are built in, which reduces the configuration and operational surface on the customer’s side. HDS coverage remains conditional on signing a specific contract, a legal requirement of the framework.
This model holds up on real projects. Madietenligne, a platform for dietitians, was already HDS compliant on a bare-metal infrastructure managed in-house; it migrated all of its test and production environments in under fifteen days while maintaining compliance. Option Zéro, a public health application dedicated to addiction reduction and run by the CaPASSCité association, is also hosted there. Based on our internal measurements and customer feedback, migrating to the platform cuts the hosting bill by 30% on average and shortens time-to-market, by up to a factor of 8.
Choosing an HDS cloud with your eyes open
Choosing an HDS provider means putting an offer to three questions: what scope is it certified for, what law is it subject to, and what does it leave you to operate. Certification is the entry point, not the finish line. The criterion that weighs most varies from one project to the next: data sensitivity pushes legal exposure to the top, a small team pushes the operating model up. What remains is to run each shortlisted provider through those three filters, and to keep the one that fits the project rather than the one that ticks the most boxes.
FAQ
How do you choose an HDS-certified hosting provider?
How do you compare two HDS-certified providers?
On three criteria. Certification scope, by checking how many of the six activities of the framework each provider is certified for, via the ANS register. Exposure to extraterritorial legislation, which depends on the operator’s ownership and jurisdiction. And the operating model, which determines how much configuration and maintenance is left to the customer.
Is a French HDS provider necessarily sovereign?
Not automatically. A company based in France may fall under US law through its ownership or its parent company, and hosting in France is not enough to escape extraterritorial legislation. Sovereignty is verified through the operator’s legal regime, its capital, headquarters and applicable jurisdiction, rather than through server location alone.
Does using an HDS-certified provider make me HDS certified?
No. Certification is held by the provider, within its own scope. By using a certified provider you satisfy your obligation to host health data with a certified host, and the HDS contract is the proof, but you do not become certified yourself. You remain the data controller under the GDPR: application security, access management, informing data subjects and retention periods all remain your responsibility.
What is HDS health data hosting?
A French regulatory framework requiring organisations that handle health data on behalf of a third party to host it with an HDS-certified provider. The certification attests to a level of security and compliance within a scope defined by the framework.
Which data falls under HDS rules?
Any data that directly or indirectly identifies a person and relates to their physical or mental health. This includes medical records, prescriptions and test reports, but also less obvious information such as food allergies recorded in a school canteen application.
Who is subject to the HDS obligation?
Any organisation, public or private, that hosts, operates or backs up health data on behalf of a third party: hospitals, laboratories, health software vendors, insurers and mutual insurance companies, public services. Healthcare institutions that manage their own information system in-house fall under a distinct regime under Article L.1111-8 of the French Public Health Code.
What is the difference between HDS certification and ISO 27001?
ISO/IEC 27001 is an international information security management standard, applicable to any sector. HDS certification is a French requirement specific to health data, adding requirements of its own. The two complement each other: one does not exempt you from the other.
What are the risks of hosting health data without an HDS-certified provider?
Failing to use an HDS-certified provider for health data may lead to criminal penalties under the provisions of the French Public Health Code.
Is an HDS contract mandatory?
Yes. The framework requires a specific contract to be signed between the customer and the certified provider. That contract is what makes HDS coverage effective and allocates responsibilities between the parties.
