<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>HDS Archives | Clever Cloud</title>
	<atom:link href="https://www.clever.cloud/blog/tag/hds/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.clever.cloud/blog/tag/hds/</link>
	<description>From Code to Product</description>
	<lastBuildDate>Thu, 23 Jul 2026 14:30:42 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://cdn.clever-cloud.com/uploads/2023/03/cropped-cropped-favicon-32x32.png</url>
	<title>HDS Archives | Clever Cloud</title>
	<link>https://www.clever.cloud/blog/tag/hds/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>HDS Certification and Compliance: Scope, Limitations and Sovereignty</title>
		<link>https://www.clever.cloud/blog/features/2026/07/23/hds-certification-and-compliance-scope-limitations-and-sovereignty/</link>
		
		<dc:creator><![CDATA[Marjorie Darrigade]]></dc:creator>
		<pubDate>Thu, 23 Jul 2026 14:12:47 +0000</pubDate>
				<category><![CDATA[Features]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[HDS]]></category>
		<guid isPermaLink="false">https://www.clever.cloud/?p=25078</guid>

					<description><![CDATA[<p><img width="800" height="355" src="https://cdn.clever-cloud.com/uploads/2026/07/2026-07-17-clever-cloud-banniere-blog-hds-2-eng-1.png" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="hds Compliance" decoding="async" fetchpriority="high" srcset="https://cdn.clever-cloud.com/uploads/2026/07/2026-07-17-clever-cloud-banniere-blog-hds-2-eng-1.png 800w, https://cdn.clever-cloud.com/uploads/2026/07/2026-07-17-clever-cloud-banniere-blog-hds-2-eng-1-300x133.png 300w, https://cdn.clever-cloud.com/uploads/2026/07/2026-07-17-clever-cloud-banniere-blog-hds-2-eng-1-768x341.png 768w" sizes="(max-width: 800px) 100vw, 800px" /></p><!-- wp:paragraph -->
<p>This article distinguishes between three concepts that are often confused: what the certification guarantees, what it leaves out, and the points to check before entrusting health data to a provider.</p>
<!-- /wp:paragraph -->

<!-- wp:heading -->
<h2 class="wp-block-heading">HDS Certification and HDS Compliance: Two Distinct Concepts</h2>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>Certification is a status granted to the hosting provider following an audit. Compliance, however, is an obligation that remains shared between the hosting provider and its client. Confusing the two creates a false sense of security: the belief that outsourcing to a certified provider is sufficient to cover all of an organisation’s own obligations.</p>
<!-- /wp:paragraph -->

<!-- wp:heading {"level":3} -->
<h3 class="wp-block-heading">What the Certified Hosting Provider Is Responsible For</h3>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>Certification is issued by an accredited body following an audit covering the <a href="https://www.clever.cloud/health-data-hosting/">six activities defined in the HDS framework</a>. It attests that the hosting provider maintains a defined level of security for hosting, operating and backing up personal health data.</p>
<!-- /wp:paragraph -->

<!-- wp:heading {"level":3} -->
<h3 class="wp-block-heading">What Remains the Client’s Responsibility</h3>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>Using a certified hosting provider does not make the client itself certified. The certification remains that of the hosting provider; the client is brought into compliance only with regard to the hosting component. Its application-level obligations and its obligations under the GDPR remain its own. The framework also imposes a specific requirement: hosting health data requires a dedicated agreement between the client and the hosting provider, formalising the allocation of responsibilities.</p>
<!-- /wp:paragraph -->

<!-- wp:spacer {"height":"20px"} -->
<div style="height:20px" aria-hidden="true" class="wp-block-spacer"></div>
<!-- /wp:spacer -->

<!-- wp:heading -->
<h2 class="wp-block-heading">What the Certification Attests to, and What It Does Not Cover</h2>
<!-- /wp:heading -->

<!-- wp:heading {"level":3} -->
<h3 class="wp-block-heading">The Scope of the Six Activities: Partial Certification Leaves Areas Uncovered</h3>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>The HDS framework distinguishes between six activities, ranging from the provision of physical sites to outsourced backup, as well as the administration and operation of the information system. An offering may be certified for only part of this scope, often limited to the infrastructure layers. In such cases, administration and operation or backup remain outside the certified scope, and the resulting gap becomes a compliance burden for the client. Checking the exact scope of the certification, activity by activity, is therefore a prerequisite, not a detail.</p>
<!-- /wp:paragraph -->

<!-- wp:heading {"level":3} -->
<h3 class="wp-block-heading">The Boundary Between Hosting Security and Legal Sovereignty</h3>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>The certification attests to the technical and organisational security of the hosting service. It says nothing about the legal issue of who may be legally compelled to disclose the data. These are two separate matters. A hosting provider may meet the security requirements of the framework while remaining subject to non-European legislation. The French Court of Accounts states this unambiguously: at this stage, the HDS framework does not include the sovereignty requirements specific to the SecNumCloud qualification, particularly ownership control and protection against extraterritorial legislation. An HDS-certified hosting provider is therefore not automatically immune from these laws.</p>
<!-- /wp:paragraph -->

<!-- wp:spacer {"height":"20px"} -->
<div style="height:20px" aria-hidden="true" class="wp-block-spacer"></div>
<!-- /wp:spacer -->

<!-- wp:heading -->
<h2 class="wp-block-heading">HDS Certification and Extraterritorial Laws (Cloud Act, FISA)</h2>
<!-- /wp:heading -->

<!-- wp:heading {"level":3} -->
<h3 class="wp-block-heading">What HDS Regulations Actually Require</h3>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>The framework was tightened in early 2026. Decree No. 2026-209 of 24 March 2026, published in the French Official Journal on 26 March and adopted pursuant to Article 32 of the SREN Act of 21 May 2024, incorporates into the French Public Health Code obligations that had previously existed only in the certification framework. Its new Article R. 1111-9-1 establishes the principle that health data must be stored exclusively within the territory of a Member State of the European Union or a state party to the Agreement on the European Economic Area (EEA). A transfer to a third country, including in the form of remote access, remains possible, but only under the conditions set out in the GDPR: an adequacy decision by the European Commission or, failing that, appropriate safeguards.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>The decree also strengthens the hosting agreement and the information that must be provided to the client. The hosting provider must specify remote access from third countries, non-European legislation that may require the disclosure of data within the meaning of Article 48 of the GDPR, mitigation measures and residual risks. It also introduces a transparency obligation that did not previously exist: the publication and ongoing maintenance of a map of transfers outside the EEA, remote access and the risks of unauthorised access by third countries.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>However, these structural provisions will only enter into force six months after publication, at the end of September 2026; the other amendments have applied since the day following the publication of the decree.</p>
<!-- /wp:paragraph -->

<!-- wp:heading {"level":3} -->
<h3 class="wp-block-heading">What HDS Certification Does Not Address</h3>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>The extraterritorial risk itself. The regulations require the hosting provider to <strong>provide information</strong>, not to guarantee <strong>immunity</strong>. A hosting provider may be HDS certified, store data in France and still be within the reach of non-European legislation when its parent company is subject to that legislation. Microsoft Ireland illustrates this situation: the entity holds HDS certification and stores data in France, but cannot obtain the SecNumCloud qualification because it belongs to a group subject to US law. Storing data within national territory is necessary, but it is not sufficient to eliminate legal exposure.</p>
<!-- /wp:paragraph -->

<!-- wp:heading {"level":3} -->
<h3 class="wp-block-heading">Legal Immunity and Sovereignty: Two Distinct Requirements</h3>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>For the most sensitive data—large health databases, data relating to minors and data concerning criminal offences—the CNIL recommends using either a hosting provider subject exclusively to European law or a provider holding a qualification such as SecNumCloud, which includes a criterion of immunity from non-European laws.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>One nuance should be noted. The qualification provides <strong>legal</strong> immunity, but it may coexist with <strong>technological</strong> dependency: some qualified offerings rely on US components operated under licence. Sovereignty cannot therefore be inferred from a single certification or qualification; it also depends on the provider’s ownership structure and the origin of its technology.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>This recommendation applies to the most sensitive processing operations. Outside these cases, using a non-sovereign HDS hosting provider remains permitted: the CNIL states that no penalty has been imposed solely on the grounds that a non-sovereign hosting provider was used. The appropriate approach is not to decide on principle, but to assess the risk according to the sensitivity of the data being processed.</p>
<!-- /wp:paragraph -->

<!-- wp:spacer {"height":"20px"} -->
<div style="height:20px" aria-hidden="true" class="wp-block-spacer"></div>
<!-- /wp:spacer -->

<!-- wp:heading -->
<h2 class="wp-block-heading">Assessing a Hosting Provider’s Actual Compliance</h2>
<!-- /wp:heading -->

<!-- wp:heading {"level":3} -->
<h3 class="wp-block-heading">Certificate Validity and Accreditation</h3>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>An expired certificate, a certificate undergoing renewal or one issued by a non-accredited body does not provide the expected assurance. Two straightforward checks should be carried out: is the certificate currently valid, and is the body that issued it accredited by COFRAC for the HDS framework? A hosting provider’s status can also be checked in the official register of certified hosting providers maintained by the French Digital Health Agency.</p>
<!-- /wp:paragraph -->

<!-- wp:heading {"level":3} -->
<h3 class="wp-block-heading">Location of Storage and Operations</h3>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>Storing data in France is necessary, but it does not eliminate the risk on its own. Remote access for administration or operations from a third country reintroduces exposure, even when the data remains stored within France. The appropriate questions to ask the provider therefore cover both aspects: where is the data stored, and from which country and by which teams is the platform administered?</p>
<!-- /wp:paragraph -->

<!-- wp:heading {"level":3} -->
<h3 class="wp-block-heading">Reversibility and Transparency of Transfers</h3>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>A lack of reversibility creates a technical dependency that may prevent future compliance, for example <a href="https://www.clever.cloud/blog/features/2026/07/23/hds-migration-migrate-your-healthcare-data-with-no-perceptible-downtime/">if a migration to a sovereign solution becomes necessary</a>. In terms of transparency, the map of transfers outside the EEA made mandatory by the regulations provides a direct control point: its absence is a warning sign.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>These points can be assessed systematically using our ten-point assessment framework for evaluating the sovereignty of an HDS hosting provider.</p>
<!-- /wp:paragraph -->

<!-- wp:buttons -->
<div class="wp-block-buttons"><!-- wp:button -->
<div class="wp-block-button"><a class="wp-block-button__link wp-element-button" href="https://cdn.clever-cloud.com/uploads/2026/07/hds-and-digital-sovereignty-10-points-to-verify.pdf" target="_blank" rel="noreferrer noopener"><strong>View and download the framework</strong></a></div>
<!-- /wp:button --></div>
<!-- /wp:buttons -->

<!-- wp:spacer {"height":"42px"} -->
<div style="height:42px" aria-hidden="true" class="wp-block-spacer"></div>
<!-- /wp:spacer -->

<!-- wp:heading -->
<h2 class="wp-block-heading">Clever Cloud’s Position</h2>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>Clever Cloud is HDS certified across the entire scope of the framework. Regarding extraterritorial exposure, our guarantee is not based on holding our own SecNumCloud qualification, but on our legal status: French ownership and registered office, no subsidiary in the United States, hosting and operations carried out in France, and a commitment not to transfer any health data outside the European Economic Area. This structure places the company <a href="https://www.clever.cloud/commitments/">exclusively under European law</a>.</p>
<!-- /wp:paragraph -->

<!-- wp:spacer {"height":"150px"} -->
<div style="height:150px" aria-hidden="true" class="wp-block-spacer"></div>
<!-- /wp:spacer -->

<!-- wp:heading {"style":{"typography":{"textAlign":"center"}}} -->
<h2 class="wp-block-heading has-text-align-center">FAQ</h2>
<!-- /wp:heading -->

<!-- wp:html -->
<div style="height: 1px; background-color: #DEDDEE; margin: 30px auto; width: 100%;"></div>
<!-- /wp:html -->

<!-- wp:heading {"level":3} -->
<h3 class="wp-block-heading">Does HDS Certification Provide Protection Against the Cloud Act?</h3>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>No. The certification attests to the security of health data hosting. It is not intended to provide immunity from extraterritorial laws. Depending on its ownership structure, a certified hosting provider may remain subject to non-European legislation.</p>
<!-- /wp:paragraph -->

<!-- wp:heading {"level":3} -->
<h3 class="wp-block-heading">Can an HDS-Certified Hosting Provider Be Subject to US Law?</h3>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>Yes, when its parent company is subject to US law. An entity may hold HDS certification and store data in France while remaining within the reach of the Cloud Act or FISA.</p>
<!-- /wp:paragraph -->

<!-- wp:heading {"level":3} -->
<h3 class="wp-block-heading">Must health data be stored in France?</h3>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>No. The French HDS framework and Decree No. 2026-209 of 24 March 2026 require storage exclusively within the European Economic Area (the EU plus Norway, Iceland and Liechtenstein) rather than on French territory specifically. The rule is codified in Article R. 1111-9-1 of the French Public Health Code. Remote access from a third country remains possible, but only under the conditions set out in Chapter V of the GDPR (adequacy decision or appropriate safeguards), and it must be disclosed to the customer in the hosting agreement. Hosting located in France is therefore a contractual commitment made by the provider, not a regulatory requirement.</p>
<!-- /wp:paragraph -->

<!-- wp:heading {"level":3} -->
<h3 class="wp-block-heading">Does Using a Certified Provider Make Me “HDS Compliant”?</h3>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>No. The certification remains that of the hosting provider. The client is brought into compliance only with regard to the hosting component; its application-level and GDPR obligations remain, as does the requirement to sign a dedicated hosting agreement.</p>
<!-- /wp:paragraph -->

<!-- wp:heading {"level":3} -->
<h3 class="wp-block-heading">HDS and SecNumCloud: What Is the Difference?</h3>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>HDS certification is mandatory for hosting health data and attests to the security of that hosting. The SecNumCloud qualification, issued by the ANSSI, is voluntary and notably includes a criterion of immunity from non-European laws. To date, the HDS framework does not include the sovereignty requirements specific to SecNumCloud.</p>
<!-- /wp:paragraph -->]]></description>
										<content:encoded><![CDATA[<p><img width="800" height="355" src="https://cdn.clever-cloud.com/uploads/2026/07/2026-07-17-clever-cloud-banniere-blog-hds-2-eng-1.png" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="hds Compliance" decoding="async" srcset="https://cdn.clever-cloud.com/uploads/2026/07/2026-07-17-clever-cloud-banniere-blog-hds-2-eng-1.png 800w, https://cdn.clever-cloud.com/uploads/2026/07/2026-07-17-clever-cloud-banniere-blog-hds-2-eng-1-300x133.png 300w, https://cdn.clever-cloud.com/uploads/2026/07/2026-07-17-clever-cloud-banniere-blog-hds-2-eng-1-768x341.png 768w" sizes="(max-width: 800px) 100vw, 800px" /></p><!-- wp:paragraph -->
<p>This article distinguishes between three concepts that are often confused: what the certification guarantees, what it leaves out, and the points to check before entrusting health data to a provider.</p>
<!-- /wp:paragraph -->

<!-- wp:heading -->
<h2 class="wp-block-heading">HDS Certification and HDS Compliance: Two Distinct Concepts</h2>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>Certification is a status granted to the hosting provider following an audit. Compliance, however, is an obligation that remains shared between the hosting provider and its client. Confusing the two creates a false sense of security: the belief that outsourcing to a certified provider is sufficient to cover all of an organisation’s own obligations.</p>
<!-- /wp:paragraph -->

<!-- wp:heading {"level":3} -->
<h3 class="wp-block-heading">What the Certified Hosting Provider Is Responsible For</h3>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>Certification is issued by an accredited body following an audit covering the <a href="https://www.clever.cloud/health-data-hosting/">six activities defined in the HDS framework</a>. It attests that the hosting provider maintains a defined level of security for hosting, operating and backing up personal health data.</p>
<!-- /wp:paragraph -->

<!-- wp:heading {"level":3} -->
<h3 class="wp-block-heading">What Remains the Client’s Responsibility</h3>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>Using a certified hosting provider does not make the client itself certified. The certification remains that of the hosting provider; the client is brought into compliance only with regard to the hosting component. Its application-level obligations and its obligations under the GDPR remain its own. The framework also imposes a specific requirement: hosting health data requires a dedicated agreement between the client and the hosting provider, formalising the allocation of responsibilities.</p>
<!-- /wp:paragraph -->

<!-- wp:spacer {"height":"20px"} -->
<div style="height:20px" aria-hidden="true" class="wp-block-spacer"></div>
<!-- /wp:spacer -->

<!-- wp:heading -->
<h2 class="wp-block-heading">What the Certification Attests to, and What It Does Not Cover</h2>
<!-- /wp:heading -->

<!-- wp:heading {"level":3} -->
<h3 class="wp-block-heading">The Scope of the Six Activities: Partial Certification Leaves Areas Uncovered</h3>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>The HDS framework distinguishes between six activities, ranging from the provision of physical sites to outsourced backup, as well as the administration and operation of the information system. An offering may be certified for only part of this scope, often limited to the infrastructure layers. In such cases, administration and operation or backup remain outside the certified scope, and the resulting gap becomes a compliance burden for the client. Checking the exact scope of the certification, activity by activity, is therefore a prerequisite, not a detail.</p>
<!-- /wp:paragraph -->

<!-- wp:heading {"level":3} -->
<h3 class="wp-block-heading">The Boundary Between Hosting Security and Legal Sovereignty</h3>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>The certification attests to the technical and organisational security of the hosting service. It says nothing about the legal issue of who may be legally compelled to disclose the data. These are two separate matters. A hosting provider may meet the security requirements of the framework while remaining subject to non-European legislation. The French Court of Accounts states this unambiguously: at this stage, the HDS framework does not include the sovereignty requirements specific to the SecNumCloud qualification, particularly ownership control and protection against extraterritorial legislation. An HDS-certified hosting provider is therefore not automatically immune from these laws.</p>
<!-- /wp:paragraph -->

<!-- wp:spacer {"height":"20px"} -->
<div style="height:20px" aria-hidden="true" class="wp-block-spacer"></div>
<!-- /wp:spacer -->

<!-- wp:heading -->
<h2 class="wp-block-heading">HDS Certification and Extraterritorial Laws (Cloud Act, FISA)</h2>
<!-- /wp:heading -->

<!-- wp:heading {"level":3} -->
<h3 class="wp-block-heading">What HDS Regulations Actually Require</h3>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>The framework was tightened in early 2026. Decree No. 2026-209 of 24 March 2026, published in the French Official Journal on 26 March and adopted pursuant to Article 32 of the SREN Act of 21 May 2024, incorporates into the French Public Health Code obligations that had previously existed only in the certification framework. Its new Article R. 1111-9-1 establishes the principle that health data must be stored exclusively within the territory of a Member State of the European Union or a state party to the Agreement on the European Economic Area (EEA). A transfer to a third country, including in the form of remote access, remains possible, but only under the conditions set out in the GDPR: an adequacy decision by the European Commission or, failing that, appropriate safeguards.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>The decree also strengthens the hosting agreement and the information that must be provided to the client. The hosting provider must specify remote access from third countries, non-European legislation that may require the disclosure of data within the meaning of Article 48 of the GDPR, mitigation measures and residual risks. It also introduces a transparency obligation that did not previously exist: the publication and ongoing maintenance of a map of transfers outside the EEA, remote access and the risks of unauthorised access by third countries.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>However, these structural provisions will only enter into force six months after publication, at the end of September 2026; the other amendments have applied since the day following the publication of the decree.</p>
<!-- /wp:paragraph -->

<!-- wp:heading {"level":3} -->
<h3 class="wp-block-heading">What HDS Certification Does Not Address</h3>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>The extraterritorial risk itself. The regulations require the hosting provider to <strong>provide information</strong>, not to guarantee <strong>immunity</strong>. A hosting provider may be HDS certified, store data in France and still be within the reach of non-European legislation when its parent company is subject to that legislation. Microsoft Ireland illustrates this situation: the entity holds HDS certification and stores data in France, but cannot obtain the SecNumCloud qualification because it belongs to a group subject to US law. Storing data within national territory is necessary, but it is not sufficient to eliminate legal exposure.</p>
<!-- /wp:paragraph -->

<!-- wp:heading {"level":3} -->
<h3 class="wp-block-heading">Legal Immunity and Sovereignty: Two Distinct Requirements</h3>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>For the most sensitive data—large health databases, data relating to minors and data concerning criminal offences—the CNIL recommends using either a hosting provider subject exclusively to European law or a provider holding a qualification such as SecNumCloud, which includes a criterion of immunity from non-European laws.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>One nuance should be noted. The qualification provides <strong>legal</strong> immunity, but it may coexist with <strong>technological</strong> dependency: some qualified offerings rely on US components operated under licence. Sovereignty cannot therefore be inferred from a single certification or qualification; it also depends on the provider’s ownership structure and the origin of its technology.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>This recommendation applies to the most sensitive processing operations. Outside these cases, using a non-sovereign HDS hosting provider remains permitted: the CNIL states that no penalty has been imposed solely on the grounds that a non-sovereign hosting provider was used. The appropriate approach is not to decide on principle, but to assess the risk according to the sensitivity of the data being processed.</p>
<!-- /wp:paragraph -->

<!-- wp:spacer {"height":"20px"} -->
<div style="height:20px" aria-hidden="true" class="wp-block-spacer"></div>
<!-- /wp:spacer -->

<!-- wp:heading -->
<h2 class="wp-block-heading">Assessing a Hosting Provider’s Actual Compliance</h2>
<!-- /wp:heading -->

<!-- wp:heading {"level":3} -->
<h3 class="wp-block-heading">Certificate Validity and Accreditation</h3>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>An expired certificate, a certificate undergoing renewal or one issued by a non-accredited body does not provide the expected assurance. Two straightforward checks should be carried out: is the certificate currently valid, and is the body that issued it accredited by COFRAC for the HDS framework? A hosting provider’s status can also be checked in the official register of certified hosting providers maintained by the French Digital Health Agency.</p>
<!-- /wp:paragraph -->

<!-- wp:heading {"level":3} -->
<h3 class="wp-block-heading">Location of Storage and Operations</h3>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>Storing data in France is necessary, but it does not eliminate the risk on its own. Remote access for administration or operations from a third country reintroduces exposure, even when the data remains stored within France. The appropriate questions to ask the provider therefore cover both aspects: where is the data stored, and from which country and by which teams is the platform administered?</p>
<!-- /wp:paragraph -->

<!-- wp:heading {"level":3} -->
<h3 class="wp-block-heading">Reversibility and Transparency of Transfers</h3>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>A lack of reversibility creates a technical dependency that may prevent future compliance, for example <a href="https://www.clever.cloud/blog/features/2026/07/23/hds-migration-migrate-your-healthcare-data-with-no-perceptible-downtime/">if a migration to a sovereign solution becomes necessary</a>. In terms of transparency, the map of transfers outside the EEA made mandatory by the regulations provides a direct control point: its absence is a warning sign.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>These points can be assessed systematically using our ten-point assessment framework for evaluating the sovereignty of an HDS hosting provider.</p>
<!-- /wp:paragraph -->

<!-- wp:buttons -->
<div class="wp-block-buttons"><!-- wp:button -->
<div class="wp-block-button"><a class="wp-block-button__link wp-element-button" href="https://cdn.clever-cloud.com/uploads/2026/07/hds-and-digital-sovereignty-10-points-to-verify.pdf" target="_blank" rel="noreferrer noopener"><strong>View and download the framework</strong></a></div>
<!-- /wp:button --></div>
<!-- /wp:buttons -->

<!-- wp:spacer {"height":"42px"} -->
<div style="height:42px" aria-hidden="true" class="wp-block-spacer"></div>
<!-- /wp:spacer -->

<!-- wp:heading -->
<h2 class="wp-block-heading">Clever Cloud’s Position</h2>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>Clever Cloud is HDS certified across the entire scope of the framework. Regarding extraterritorial exposure, our guarantee is not based on holding our own SecNumCloud qualification, but on our legal status: French ownership and registered office, no subsidiary in the United States, hosting and operations carried out in France, and a commitment not to transfer any health data outside the European Economic Area. This structure places the company <a href="https://www.clever.cloud/commitments/">exclusively under European law</a>.</p>
<!-- /wp:paragraph -->

<!-- wp:spacer {"height":"150px"} -->
<div style="height:150px" aria-hidden="true" class="wp-block-spacer"></div>
<!-- /wp:spacer -->

<!-- wp:heading {"style":{"typography":{"textAlign":"center"}}} -->
<h2 class="wp-block-heading has-text-align-center">FAQ</h2>
<!-- /wp:heading -->

<!-- wp:html -->
<div style="height: 1px; background-color: #DEDDEE; margin: 30px auto; width: 100%;"></div>
<!-- /wp:html -->

<!-- wp:heading {"level":3} -->
<h3 class="wp-block-heading">Does HDS Certification Provide Protection Against the Cloud Act?</h3>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>No. The certification attests to the security of health data hosting. It is not intended to provide immunity from extraterritorial laws. Depending on its ownership structure, a certified hosting provider may remain subject to non-European legislation.</p>
<!-- /wp:paragraph -->

<!-- wp:heading {"level":3} -->
<h3 class="wp-block-heading">Can an HDS-Certified Hosting Provider Be Subject to US Law?</h3>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>Yes, when its parent company is subject to US law. An entity may hold HDS certification and store data in France while remaining within the reach of the Cloud Act or FISA.</p>
<!-- /wp:paragraph -->

<!-- wp:heading {"level":3} -->
<h3 class="wp-block-heading">Must health data be stored in France?</h3>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>No. The French HDS framework and Decree No. 2026-209 of 24 March 2026 require storage exclusively within the European Economic Area (the EU plus Norway, Iceland and Liechtenstein) rather than on French territory specifically. The rule is codified in Article R. 1111-9-1 of the French Public Health Code. Remote access from a third country remains possible, but only under the conditions set out in Chapter V of the GDPR (adequacy decision or appropriate safeguards), and it must be disclosed to the customer in the hosting agreement. Hosting located in France is therefore a contractual commitment made by the provider, not a regulatory requirement.</p>
<!-- /wp:paragraph -->

<!-- wp:heading {"level":3} -->
<h3 class="wp-block-heading">Does Using a Certified Provider Make Me “HDS Compliant”?</h3>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>No. The certification remains that of the hosting provider. The client is brought into compliance only with regard to the hosting component; its application-level and GDPR obligations remain, as does the requirement to sign a dedicated hosting agreement.</p>
<!-- /wp:paragraph -->

<!-- wp:heading {"level":3} -->
<h3 class="wp-block-heading">HDS and SecNumCloud: What Is the Difference?</h3>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>HDS certification is mandatory for hosting health data and attests to the security of that hosting. The SecNumCloud qualification, issued by the ANSSI, is voluntary and notably includes a criterion of immunity from non-European laws. To date, the HDS framework does not include the sovereignty requirements specific to SecNumCloud.</p>
<!-- /wp:paragraph -->]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>HDS migration: migrate your healthcare data with no perceptible downtime</title>
		<link>https://www.clever.cloud/blog/features/2026/07/23/hds-migration-migrate-your-healthcare-data-with-no-perceptible-downtime/</link>
		
		<dc:creator><![CDATA[Marjorie Darrigade]]></dc:creator>
		<pubDate>Thu, 23 Jul 2026 11:39:38 +0000</pubDate>
				<category><![CDATA[Features]]></category>
		<category><![CDATA[HDS]]></category>
		<category><![CDATA[migration]]></category>
		<guid isPermaLink="false">https://www.clever.cloud/?p=25057</guid>

					<description><![CDATA[<p><img width="800" height="355" src="https://cdn.clever-cloud.com/uploads/2026/07/2026-07-23-clever-cloud-banniere-blog-hds-eng.png" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="HDS Migration" decoding="async" srcset="https://cdn.clever-cloud.com/uploads/2026/07/2026-07-23-clever-cloud-banniere-blog-hds-eng.png 800w, https://cdn.clever-cloud.com/uploads/2026/07/2026-07-23-clever-cloud-banniere-blog-hds-eng-300x133.png 300w, https://cdn.clever-cloud.com/uploads/2026/07/2026-07-23-clever-cloud-banniere-blog-hds-eng-768x341.png 768w" sizes="(max-width: 800px) 100vw, 800px" /></p><!-- wp:paragraph -->
<p>The remaining questions are when such an operation becomes necessary, how it is carried out, and which pitfalls should be anticipated.</p>
<!-- /wp:paragraph -->

<!-- wp:heading -->
<h2 class="wp-block-heading">What is an HDS migration?</h2>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>An HDS migration is more than a simple infrastructure change: it involves transferring personal healthcare data whose hosting is regulated by law. The objective can be summed up in a single sentence: change hosting providers without leaving the compliance framework, either during or after the migration.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>HDS certification itself remains the responsibility of the hosting provider under <a href="https://www.clever.cloud/health-data-hosting/">the HDS framework and its six regulated activities</a>. Migrating does not invalidate this compliance; the objective is to preserve it throughout the transition from one hosting environment to another.</p>
<!-- /wp:paragraph -->

<!-- wp:spacer {"height":"20px"} -->
<div style="height:20px" aria-hidden="true" class="wp-block-spacer"></div>
<!-- /wp:spacer -->

<!-- wp:heading -->
<h2 class="wp-block-heading">When should you consider an HDS migration?</h2>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>Three situations justify switching the hosting environment for healthcare data.</p>
<!-- /wp:paragraph -->

<!-- wp:heading {"level":3} -->
<h3 class="wp-block-heading">Hosting that is not HDS certified</h3>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>In France, entrusting healthcare data to a hosting provider requires that provider to hold HDS certification (Article L.1111-8 of the French Public Health Code). An e-health application deployed on non-certified infrastructure therefore falls outside this regulatory framework, regardless of its technical quality. Migrating to a certified hosting provider addresses the hosting requirement, although it does not by itself fulfil the publisher’s other obligations, whether application-related or under the GDPR.</p>
<!-- /wp:paragraph -->

<!-- wp:heading {"level":3} -->
<h3 class="wp-block-heading">Hosting that is not sovereign or is subject to extraterritorial legislation</h3>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>Certification and legal sovereignty are not the same thing. A hosting provider may be HDS certified while still being subject to non-European legislation that could require the disclosure of data, such as the Cloud Act or FISA. For the most sensitive healthcare data, the CNIL recommends enhanced protection against access requests from third-country authorities, including hosting operated exclusively under European law. The distinction between HDS compliance and sovereignty deserves separate consideration; in the context of a migration, it mainly becomes a hosting provider selection criterion.</p>
<!-- /wp:paragraph -->

<!-- wp:heading {"level":3} -->
<h3 class="wp-block-heading">Operational overhead on self-managed infrastructure</h3>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>Infrastructure may be compliant while still being managed in-house, typically on bare metal. In this case, internal teams remain responsible for server configuration, monitoring, upgrades, and reversibility. As the platform grows, this operational burden becomes increasingly significant. It often leads software vendors that are already HDS compliant to adopt a managed platform, reducing operational workload without compromising compliance.</p>
<!-- /wp:paragraph -->

<!-- wp:spacer {"height":"70px"} -->
<div style="height:70px" aria-hidden="true" class="wp-block-spacer"></div>
<!-- /wp:spacer -->

<!-- wp:acf/avantages {"name":"acf/avantages","data":{"title":"How does an HDS migration work, step by step?","_title":"field_63878c81ae569","content":"\u003cp class=\u0022p1\u0022\u003eThe project follows five phases, from initial assessment to final compliance verification.\u003c/p\u003e","_content":"field_63878c9cae56a","main_picture":"","_main_picture":"field_63878cd5ae56b","advantages_collection_0_picto":"","_advantages_collection_0_picto":"field_6397417cac52f","advantages_collection_0_title":"Scoping and preliminary assessment","_advantages_collection_0_title":"field_63878d1aae56d","advantages_collection_0_content":"Before any transfer takes place, the scope must be clearly defined: which healthcare data is involved, which applications process it, and where the backups are located. This stage determines which HDS framework activities are actually involved and which data residency requirements must be met, including backup copies.","_advantages_collection_0_content":"field_63878d4dae56e","advantages_collection_0_link":"","_advantages_collection_0_link":"field_63878d66ae56f","advantages_collection_1_picto":"","_advantages_collection_1_picto":"field_6397417cac52f","advantages_collection_1_title":"HDS contractual agreement","_advantages_collection_1_title":"field_63878d1aae56d","advantages_collection_1_content":"Hosting healthcare data requires a dedicated agreement between the customer and the hosting provider. This is a requirement of the HDS framework, not a commercial formality: the agreement defines the allocation of responsibilities and must be in place before the production environment goes live.","_advantages_collection_1_content":"field_63878d4dae56e","advantages_collection_1_link":"","_advantages_collection_1_link":"field_63878d66ae56f","advantages_collection_2_picto":"","_advantages_collection_2_picto":"field_6397417cac52f","advantages_collection_2_title":"Data transfer and synchronization","_advantages_collection_2_title":"field_63878d1aae56d","advantages_collection_2_content":"This is the core operation: copying and synchronizing the data, deploying the applications, and restoring scheduled tasks and monitoring. Encryption at rest is enabled when databases and storage volumes are created. Depending on the source infrastructure, this phase may also require adapting file formats inherited from third-party storage systems.","_advantages_collection_2_content":"field_63878d4dae56e","advantages_collection_2_link":"","_advantages_collection_2_link":"field_63878d66ae56f","advantages_collection_3_picto":"","_advantages_collection_3_picto":"field_6397417cac52f","advantages_collection_3_title":"DNS switch: the only possible interruption","_advantages_collection_3_title":"field_63878d1aae56d","advantages_collection_3_content":"As long as the legacy and the new platforms coexist, the service continues to run on the former. The DNS switch to the new hosting environment is the only point at which an interruption may occur. When properly prepared, it remains imperceptible to users.","_advantages_collection_3_content":"field_63878d4dae56e","advantages_collection_3_link":"","_advantages_collection_3_link":"field_63878d66ae56f","advantages_collection_4_picto":"","_advantages_collection_4_picto":"field_6397417cac52f","advantages_collection_4_title":"Post-migration compliance verification","_advantages_collection_4_title":"field_63878d1aae56d","advantages_collection_4_content":"The migration does not end with the DNS switch. The final step is to verify that the certified scope covers the entire deployed environment, that backups comply with the same data residency requirements as the primary data, and that reversibility remains fully guaranteed.","_advantages_collection_4_content":"field_63878d4dae56e","advantages_collection_4_link":"","_advantages_collection_4_link":"field_63878d66ae56f","advantages_collection":5,"_advantages_collection":"field_63878cecae56c"},"mode":"auto"} /-->

<!-- wp:heading -->
<h2 class="wp-block-heading">Key considerations for an HDS migration</h2>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>Five recurring pitfalls deserve particular attention. Each one should prompt a question to your future hosting provider.</p>
<!-- /wp:paragraph -->

<!-- wp:acf/arguments {"name":"acf/arguments","data":{"items_0_title":"Partially certified scope","_items_0_title":"field_638a066e4d2ec","items_0_short_description":"Some offerings cover only part of the six activities defined by the HDS framework, often limited to the infrastructure layers. Partial coverage leaves parts of the environment outside the compliance scope and under the customer’s responsibility.","_items_0_short_description":"field_638a068d4d2ed","items_0_full_description":"","_items_0_full_description":"field_638a06af4d2ee","items_1_title":"Backup location","_items_1_title":"field_638a066e4d2ec","items_1_short_description":"Hosting primary data in France while storing backups elsewhere merely shifts the risk instead of eliminating it. Backup copies must comply with the same requirements as the original data.","_items_1_short_description":"field_638a068d4d2ed","items_1_full_description":"","_items_1_full_description":"field_638a06af4d2ee","items_2_title":"Remote administration from a third country","_items_2_title":"field_638a066e4d2ec","items_2_short_description":"Even when data is stored in France, it remains exposed if the platform is administered from a country subject to non-European legislation. In such cases, the HDS framework requires the hosting provider to inform its customer.","_items_2_short_description":"field_638a068d4d2ed","items_2_full_description":"","_items_2_full_description":"field_638a06af4d2ee","items_3_title":"Reversibility","_items_3_title":"field_638a066e4d2ec","items_3_short_description":"The inability to recover all data in a usable format creates vendor lock-in, which may prevent future compliance efforts.","_items_3_short_description":"field_638a068d4d2ed","items_3_full_description":"","_items_3_full_description":"field_638a06af4d2ee","items_4_title":"Division of responsibilities","_items_4_title":"field_638a066e4d2ec","items_4_short_description":"Using an HDS-certified hosting provider does not make the customer HDS certified. Responsibility for application compliance and GDPR compliance remains with the software publisher","_items_4_short_description":"field_638a068d4d2ed","items_4_full_description":"","_items_4_full_description":"field_638a06af4d2ee","items":5,"_items":"field_638a065a4d2eb"},"mode":"auto"} /-->

<!-- wp:heading -->
<h2 class="wp-block-heading">How do you choose an HDS hosting provider for your migration?</h2>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>Five criteria make the difference:</p>
<!-- /wp:paragraph -->

<!-- wp:list -->
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Certification covering all six activities</strong> defined by the HDS framework, not just the infrastructure layer.</li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li><strong>A valid certificate</strong> issued by an accredited certification body.</li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li><strong>Genuine sovereignty:</strong> headquarters and ownership based in France, no subsidiary subject to non-European law, and hosting infrastructure located in France.</li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li><strong>A fully managed platform</strong> that takes care of encryption, monitoring, backups, and updates instead of leaving these responsibilities to the customer.</li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li><strong>Documented reversibility</strong>, ensuring an exit strategy without technical lock-in.</li>
<!-- /wp:list-item --></ul>
<!-- /wp:list -->

<!-- wp:paragraph -->
<p>The last criterion deserves particular attention: a platform that operates an <a href="https://www.clever.cloud/blog/features/2025/03/19/hds-cloud-secure-hosting-of-healthcare-data-with-clever-cloud/">HDS cloud</a> end to end relieves customers of the operational layers where most compliance gaps tend to arise.</p>
<!-- /wp:paragraph -->

<!-- wp:spacer {"height":"28px"} -->
<div style="height:28px" aria-hidden="true" class="wp-block-spacer"></div>
<!-- /wp:spacer -->

<!-- wp:columns -->
<div class="wp-block-columns"><!-- wp:column {"verticalAlignment":"top","width":"33.33%"} -->
<div class="wp-block-column is-vertically-aligned-top" style="flex-basis:33.33%"><!-- wp:buttons {"layout":{"type":"flex","justifyContent":"center","verticalAlignment":"top"}} -->
<div class="wp-block-buttons"><!-- wp:button -->
<div class="wp-block-button"><a class="wp-block-button__link wp-element-button" href="https://cdn.clever-cloud.com/uploads/2026/07/practical-guide-to-hds-migration.pdf" target="_blank" rel="noreferrer noopener"><strong>Download the guide</strong></a></div>
<!-- /wp:button --></div>
<!-- /wp:buttons --></div>
<!-- /wp:column -->

<!-- wp:column {"verticalAlignment":"bottom","width":"66.66%"} -->
<div class="wp-block-column is-vertically-aligned-bottom" style="flex-basis:66.66%"><!-- wp:paragraph -->
<p>Checklist, migration steps, common mistakes, and hosting provider selection criteria. Find all of these in our <strong>Practical Guide to HDS Migration</strong>.</p>
<!-- /wp:paragraph --></div>
<!-- /wp:column --></div>
<!-- /wp:columns -->

<!-- wp:spacer {"height":"42px"} -->
<div style="height:42px" aria-hidden="true" class="wp-block-spacer"></div>
<!-- /wp:spacer -->

<!-- wp:heading -->
<h2 class="wp-block-heading">Case study: the Madietenligne migration</h2>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>Clever Cloud supports several e-health providers. The migration of <a href="https://www.clever.cloud/testimonial/madietenligne/">Madietenligne</a>, a platform dedicated to dietitians, provides a documented example: it moved from self-managed bare-metal infrastructure to Clever Cloud’s sovereign PaaS while remaining within the HDS framework. This case illustrates a migration driven by the need to reduce operational overhead rather than to move from a non-compliant to a compliant environment: the HDS framework was already being met before the migration.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>Key highlights:</p>
<!-- /wp:paragraph -->

<!-- wp:list -->
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Test and production environments migrated in <strong>less than fifteen days</strong>.</li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li><strong>500 GB </strong>of data transferred and synchronized.</li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li>Platform used by more than <strong>2,500 dietitians</strong>.</li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li>Zero-downtime deployments, with support responding within the same business day.</li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li>HDS compliance maintained, encryption at rest enabled, and<strong> migration away from Azure </strong>for file storage, removing a dependency on a provider subject to U.S. law.</li>
<!-- /wp:list-item --></ul>
<!-- /wp:list -->

<!-- wp:spacer {"height":"20px"} -->
<div style="height:20px" aria-hidden="true" class="wp-block-spacer"></div>
<!-- /wp:spacer -->

<!-- wp:heading -->
<h2 class="wp-block-heading">Key takeaways from an HDS migration</h2>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>A well-executed HDS migration answers three questions, in order: why migrate, how to migrate, and how to verify compliance. The process is manageable, service interruption is limited to the DNS switch, and compliance can be verified at every stage.</p>
<!-- /wp:paragraph -->

<!-- wp:spacer {"height":"20px"} -->
<div style="height:20px" aria-hidden="true" class="wp-block-spacer"></div>
<!-- /wp:spacer -->

<!-- wp:heading {"level":4} -->
<h4 class="wp-block-heading">To assess your current situation or prepare your migration project, </h4>
<!-- /wp:heading -->

<!-- wp:buttons -->
<div class="wp-block-buttons"><!-- wp:button -->
<div class="wp-block-button"><a class="wp-block-button__link wp-element-button" href="https://www.clever.cloud/contact-hds/">Get in touch with our team</a></div>
<!-- /wp:button --></div>
<!-- /wp:buttons -->

<!-- wp:spacer {"height":"150px"} -->
<div style="height:150px" aria-hidden="true" class="wp-block-spacer"></div>
<!-- /wp:spacer -->

<!-- wp:heading {"style":{"typography":{"textAlign":"center"}}} -->
<h2 class="wp-block-heading has-text-align-center">FAQ</h2>
<!-- /wp:heading -->

<!-- wp:html -->
<div style="height: 1px; background-color: #DEDDEE; margin: 30px auto; width: 100%;"></div>
<!-- /wp:html -->

<!-- wp:heading {"level":3} -->
<h3 class="wp-block-heading">How long does an HDS migration take?</h3>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>The duration depends on the data volume, the architecture, and the number of environments involved. As a reference point, one documented project covering both test and production environments was completed in less than fifteen days. This figure applies only to that specific case and should not be taken as representative of every migration.</p>
<!-- /wp:paragraph -->

<!-- wp:heading {"level":3} -->
<h3 class="wp-block-heading">Does an HDS migration cause service downtime?</h3>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>As long as the legacy and the new hosting environments coexist, the service remains available. The only possible interruption occurs during the DNS switch; when properly prepared, it is imperceptible to users.</p>
<!-- /wp:paragraph -->

<!-- wp:heading {"level":3} -->
<h3 class="wp-block-heading">Is a new contract required for an HDS migration?</h3>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>Yes. Hosting healthcare data requires a dedicated agreement with the hosting provider under the HDS framework. It must be signed before the production environment goes live.</p>
<!-- /wp:paragraph -->

<!-- wp:heading {"level":3} -->
<h3 class="wp-block-heading">After the migration, what remains my responsibility to stay HDS compliant?</h3>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>HDS certification remains the responsibility of the hosting provider. The software publisher remains responsible for application compliance and GDPR compliance. The migration brings the hosting component into compliance, but it does not cover all regulatory obligations.</p>
<!-- /wp:paragraph -->

<!-- wp:heading {"level":3} -->
<h3 class="wp-block-heading">Can I migrate from a non-sovereign hosting provider such as Azure or AWS?</h3>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>Yes. One purpose of an HDS migration may be to remove a dependency on a hosting provider subject to non-European legislation, for example by moving away from file storage operated by a non-European provider.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p></p>
<!-- /wp:paragraph -->]]></description>
										<content:encoded><![CDATA[<p><img width="800" height="355" src="https://cdn.clever-cloud.com/uploads/2026/07/2026-07-23-clever-cloud-banniere-blog-hds-eng.png" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="HDS Migration" decoding="async" loading="lazy" srcset="https://cdn.clever-cloud.com/uploads/2026/07/2026-07-23-clever-cloud-banniere-blog-hds-eng.png 800w, https://cdn.clever-cloud.com/uploads/2026/07/2026-07-23-clever-cloud-banniere-blog-hds-eng-300x133.png 300w, https://cdn.clever-cloud.com/uploads/2026/07/2026-07-23-clever-cloud-banniere-blog-hds-eng-768x341.png 768w" sizes="auto, (max-width: 800px) 100vw, 800px" /></p><!-- wp:paragraph -->
<p>The remaining questions are when such an operation becomes necessary, how it is carried out, and which pitfalls should be anticipated.</p>
<!-- /wp:paragraph -->

<!-- wp:heading -->
<h2 class="wp-block-heading">What is an HDS migration?</h2>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>An HDS migration is more than a simple infrastructure change: it involves transferring personal healthcare data whose hosting is regulated by law. The objective can be summed up in a single sentence: change hosting providers without leaving the compliance framework, either during or after the migration.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>HDS certification itself remains the responsibility of the hosting provider under <a href="https://www.clever.cloud/health-data-hosting/">the HDS framework and its six regulated activities</a>. Migrating does not invalidate this compliance; the objective is to preserve it throughout the transition from one hosting environment to another.</p>
<!-- /wp:paragraph -->

<!-- wp:spacer {"height":"20px"} -->
<div style="height:20px" aria-hidden="true" class="wp-block-spacer"></div>
<!-- /wp:spacer -->

<!-- wp:heading -->
<h2 class="wp-block-heading">When should you consider an HDS migration?</h2>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>Three situations justify switching the hosting environment for healthcare data.</p>
<!-- /wp:paragraph -->

<!-- wp:heading {"level":3} -->
<h3 class="wp-block-heading">Hosting that is not HDS certified</h3>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>In France, entrusting healthcare data to a hosting provider requires that provider to hold HDS certification (Article L.1111-8 of the French Public Health Code). An e-health application deployed on non-certified infrastructure therefore falls outside this regulatory framework, regardless of its technical quality. Migrating to a certified hosting provider addresses the hosting requirement, although it does not by itself fulfil the publisher’s other obligations, whether application-related or under the GDPR.</p>
<!-- /wp:paragraph -->

<!-- wp:heading {"level":3} -->
<h3 class="wp-block-heading">Hosting that is not sovereign or is subject to extraterritorial legislation</h3>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>Certification and legal sovereignty are not the same thing. A hosting provider may be HDS certified while still being subject to non-European legislation that could require the disclosure of data, such as the Cloud Act or FISA. For the most sensitive healthcare data, the CNIL recommends enhanced protection against access requests from third-country authorities, including hosting operated exclusively under European law. The distinction between HDS compliance and sovereignty deserves separate consideration; in the context of a migration, it mainly becomes a hosting provider selection criterion.</p>
<!-- /wp:paragraph -->

<!-- wp:heading {"level":3} -->
<h3 class="wp-block-heading">Operational overhead on self-managed infrastructure</h3>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>Infrastructure may be compliant while still being managed in-house, typically on bare metal. In this case, internal teams remain responsible for server configuration, monitoring, upgrades, and reversibility. As the platform grows, this operational burden becomes increasingly significant. It often leads software vendors that are already HDS compliant to adopt a managed platform, reducing operational workload without compromising compliance.</p>
<!-- /wp:paragraph -->

<!-- wp:spacer {"height":"70px"} -->
<div style="height:70px" aria-hidden="true" class="wp-block-spacer"></div>
<!-- /wp:spacer -->

<!-- wp:acf/avantages {"name":"acf/avantages","data":{"title":"How does an HDS migration work, step by step?","_title":"field_63878c81ae569","content":"\u003cp class=\u0022p1\u0022\u003eThe project follows five phases, from initial assessment to final compliance verification.\u003c/p\u003e","_content":"field_63878c9cae56a","main_picture":"","_main_picture":"field_63878cd5ae56b","advantages_collection_0_picto":"","_advantages_collection_0_picto":"field_6397417cac52f","advantages_collection_0_title":"Scoping and preliminary assessment","_advantages_collection_0_title":"field_63878d1aae56d","advantages_collection_0_content":"Before any transfer takes place, the scope must be clearly defined: which healthcare data is involved, which applications process it, and where the backups are located. This stage determines which HDS framework activities are actually involved and which data residency requirements must be met, including backup copies.","_advantages_collection_0_content":"field_63878d4dae56e","advantages_collection_0_link":"","_advantages_collection_0_link":"field_63878d66ae56f","advantages_collection_1_picto":"","_advantages_collection_1_picto":"field_6397417cac52f","advantages_collection_1_title":"HDS contractual agreement","_advantages_collection_1_title":"field_63878d1aae56d","advantages_collection_1_content":"Hosting healthcare data requires a dedicated agreement between the customer and the hosting provider. This is a requirement of the HDS framework, not a commercial formality: the agreement defines the allocation of responsibilities and must be in place before the production environment goes live.","_advantages_collection_1_content":"field_63878d4dae56e","advantages_collection_1_link":"","_advantages_collection_1_link":"field_63878d66ae56f","advantages_collection_2_picto":"","_advantages_collection_2_picto":"field_6397417cac52f","advantages_collection_2_title":"Data transfer and synchronization","_advantages_collection_2_title":"field_63878d1aae56d","advantages_collection_2_content":"This is the core operation: copying and synchronizing the data, deploying the applications, and restoring scheduled tasks and monitoring. Encryption at rest is enabled when databases and storage volumes are created. Depending on the source infrastructure, this phase may also require adapting file formats inherited from third-party storage systems.","_advantages_collection_2_content":"field_63878d4dae56e","advantages_collection_2_link":"","_advantages_collection_2_link":"field_63878d66ae56f","advantages_collection_3_picto":"","_advantages_collection_3_picto":"field_6397417cac52f","advantages_collection_3_title":"DNS switch: the only possible interruption","_advantages_collection_3_title":"field_63878d1aae56d","advantages_collection_3_content":"As long as the legacy and the new platforms coexist, the service continues to run on the former. The DNS switch to the new hosting environment is the only point at which an interruption may occur. When properly prepared, it remains imperceptible to users.","_advantages_collection_3_content":"field_63878d4dae56e","advantages_collection_3_link":"","_advantages_collection_3_link":"field_63878d66ae56f","advantages_collection_4_picto":"","_advantages_collection_4_picto":"field_6397417cac52f","advantages_collection_4_title":"Post-migration compliance verification","_advantages_collection_4_title":"field_63878d1aae56d","advantages_collection_4_content":"The migration does not end with the DNS switch. The final step is to verify that the certified scope covers the entire deployed environment, that backups comply with the same data residency requirements as the primary data, and that reversibility remains fully guaranteed.","_advantages_collection_4_content":"field_63878d4dae56e","advantages_collection_4_link":"","_advantages_collection_4_link":"field_63878d66ae56f","advantages_collection":5,"_advantages_collection":"field_63878cecae56c"},"mode":"auto"} /-->

<!-- wp:heading -->
<h2 class="wp-block-heading">Key considerations for an HDS migration</h2>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>Five recurring pitfalls deserve particular attention. Each one should prompt a question to your future hosting provider.</p>
<!-- /wp:paragraph -->

<!-- wp:acf/arguments {"name":"acf/arguments","data":{"items_0_title":"Partially certified scope","_items_0_title":"field_638a066e4d2ec","items_0_short_description":"Some offerings cover only part of the six activities defined by the HDS framework, often limited to the infrastructure layers. Partial coverage leaves parts of the environment outside the compliance scope and under the customer’s responsibility.","_items_0_short_description":"field_638a068d4d2ed","items_0_full_description":"","_items_0_full_description":"field_638a06af4d2ee","items_1_title":"Backup location","_items_1_title":"field_638a066e4d2ec","items_1_short_description":"Hosting primary data in France while storing backups elsewhere merely shifts the risk instead of eliminating it. Backup copies must comply with the same requirements as the original data.","_items_1_short_description":"field_638a068d4d2ed","items_1_full_description":"","_items_1_full_description":"field_638a06af4d2ee","items_2_title":"Remote administration from a third country","_items_2_title":"field_638a066e4d2ec","items_2_short_description":"Even when data is stored in France, it remains exposed if the platform is administered from a country subject to non-European legislation. In such cases, the HDS framework requires the hosting provider to inform its customer.","_items_2_short_description":"field_638a068d4d2ed","items_2_full_description":"","_items_2_full_description":"field_638a06af4d2ee","items_3_title":"Reversibility","_items_3_title":"field_638a066e4d2ec","items_3_short_description":"The inability to recover all data in a usable format creates vendor lock-in, which may prevent future compliance efforts.","_items_3_short_description":"field_638a068d4d2ed","items_3_full_description":"","_items_3_full_description":"field_638a06af4d2ee","items_4_title":"Division of responsibilities","_items_4_title":"field_638a066e4d2ec","items_4_short_description":"Using an HDS-certified hosting provider does not make the customer HDS certified. Responsibility for application compliance and GDPR compliance remains with the software publisher","_items_4_short_description":"field_638a068d4d2ed","items_4_full_description":"","_items_4_full_description":"field_638a06af4d2ee","items":5,"_items":"field_638a065a4d2eb"},"mode":"auto"} /-->

<!-- wp:heading -->
<h2 class="wp-block-heading">How do you choose an HDS hosting provider for your migration?</h2>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>Five criteria make the difference:</p>
<!-- /wp:paragraph -->

<!-- wp:list -->
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Certification covering all six activities</strong> defined by the HDS framework, not just the infrastructure layer.</li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li><strong>A valid certificate</strong> issued by an accredited certification body.</li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li><strong>Genuine sovereignty:</strong> headquarters and ownership based in France, no subsidiary subject to non-European law, and hosting infrastructure located in France.</li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li><strong>A fully managed platform</strong> that takes care of encryption, monitoring, backups, and updates instead of leaving these responsibilities to the customer.</li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li><strong>Documented reversibility</strong>, ensuring an exit strategy without technical lock-in.</li>
<!-- /wp:list-item --></ul>
<!-- /wp:list -->

<!-- wp:paragraph -->
<p>The last criterion deserves particular attention: a platform that operates an <a href="https://www.clever.cloud/blog/features/2025/03/19/hds-cloud-secure-hosting-of-healthcare-data-with-clever-cloud/">HDS cloud</a> end to end relieves customers of the operational layers where most compliance gaps tend to arise.</p>
<!-- /wp:paragraph -->

<!-- wp:spacer {"height":"28px"} -->
<div style="height:28px" aria-hidden="true" class="wp-block-spacer"></div>
<!-- /wp:spacer -->

<!-- wp:columns -->
<div class="wp-block-columns"><!-- wp:column {"verticalAlignment":"top","width":"33.33%"} -->
<div class="wp-block-column is-vertically-aligned-top" style="flex-basis:33.33%"><!-- wp:buttons {"layout":{"type":"flex","justifyContent":"center","verticalAlignment":"top"}} -->
<div class="wp-block-buttons"><!-- wp:button -->
<div class="wp-block-button"><a class="wp-block-button__link wp-element-button" href="https://cdn.clever-cloud.com/uploads/2026/07/practical-guide-to-hds-migration.pdf" target="_blank" rel="noreferrer noopener"><strong>Download the guide</strong></a></div>
<!-- /wp:button --></div>
<!-- /wp:buttons --></div>
<!-- /wp:column -->

<!-- wp:column {"verticalAlignment":"bottom","width":"66.66%"} -->
<div class="wp-block-column is-vertically-aligned-bottom" style="flex-basis:66.66%"><!-- wp:paragraph -->
<p>Checklist, migration steps, common mistakes, and hosting provider selection criteria. Find all of these in our <strong>Practical Guide to HDS Migration</strong>.</p>
<!-- /wp:paragraph --></div>
<!-- /wp:column --></div>
<!-- /wp:columns -->

<!-- wp:spacer {"height":"42px"} -->
<div style="height:42px" aria-hidden="true" class="wp-block-spacer"></div>
<!-- /wp:spacer -->

<!-- wp:heading -->
<h2 class="wp-block-heading">Case study: the Madietenligne migration</h2>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>Clever Cloud supports several e-health providers. The migration of <a href="https://www.clever.cloud/testimonial/madietenligne/">Madietenligne</a>, a platform dedicated to dietitians, provides a documented example: it moved from self-managed bare-metal infrastructure to Clever Cloud’s sovereign PaaS while remaining within the HDS framework. This case illustrates a migration driven by the need to reduce operational overhead rather than to move from a non-compliant to a compliant environment: the HDS framework was already being met before the migration.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p>Key highlights:</p>
<!-- /wp:paragraph -->

<!-- wp:list -->
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Test and production environments migrated in <strong>less than fifteen days</strong>.</li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li><strong>500 GB </strong>of data transferred and synchronized.</li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li>Platform used by more than <strong>2,500 dietitians</strong>.</li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li>Zero-downtime deployments, with support responding within the same business day.</li>
<!-- /wp:list-item -->

<!-- wp:list-item -->
<li>HDS compliance maintained, encryption at rest enabled, and<strong> migration away from Azure </strong>for file storage, removing a dependency on a provider subject to U.S. law.</li>
<!-- /wp:list-item --></ul>
<!-- /wp:list -->

<!-- wp:spacer {"height":"20px"} -->
<div style="height:20px" aria-hidden="true" class="wp-block-spacer"></div>
<!-- /wp:spacer -->

<!-- wp:heading -->
<h2 class="wp-block-heading">Key takeaways from an HDS migration</h2>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>A well-executed HDS migration answers three questions, in order: why migrate, how to migrate, and how to verify compliance. The process is manageable, service interruption is limited to the DNS switch, and compliance can be verified at every stage.</p>
<!-- /wp:paragraph -->

<!-- wp:spacer {"height":"20px"} -->
<div style="height:20px" aria-hidden="true" class="wp-block-spacer"></div>
<!-- /wp:spacer -->

<!-- wp:heading {"level":4} -->
<h4 class="wp-block-heading">To assess your current situation or prepare your migration project, </h4>
<!-- /wp:heading -->

<!-- wp:buttons -->
<div class="wp-block-buttons"><!-- wp:button -->
<div class="wp-block-button"><a class="wp-block-button__link wp-element-button" href="https://www.clever.cloud/contact-hds/">Get in touch with our team</a></div>
<!-- /wp:button --></div>
<!-- /wp:buttons -->

<!-- wp:spacer {"height":"150px"} -->
<div style="height:150px" aria-hidden="true" class="wp-block-spacer"></div>
<!-- /wp:spacer -->

<!-- wp:heading {"style":{"typography":{"textAlign":"center"}}} -->
<h2 class="wp-block-heading has-text-align-center">FAQ</h2>
<!-- /wp:heading -->

<!-- wp:html -->
<div style="height: 1px; background-color: #DEDDEE; margin: 30px auto; width: 100%;"></div>
<!-- /wp:html -->

<!-- wp:heading {"level":3} -->
<h3 class="wp-block-heading">How long does an HDS migration take?</h3>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>The duration depends on the data volume, the architecture, and the number of environments involved. As a reference point, one documented project covering both test and production environments was completed in less than fifteen days. This figure applies only to that specific case and should not be taken as representative of every migration.</p>
<!-- /wp:paragraph -->

<!-- wp:heading {"level":3} -->
<h3 class="wp-block-heading">Does an HDS migration cause service downtime?</h3>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>As long as the legacy and the new hosting environments coexist, the service remains available. The only possible interruption occurs during the DNS switch; when properly prepared, it is imperceptible to users.</p>
<!-- /wp:paragraph -->

<!-- wp:heading {"level":3} -->
<h3 class="wp-block-heading">Is a new contract required for an HDS migration?</h3>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>Yes. Hosting healthcare data requires a dedicated agreement with the hosting provider under the HDS framework. It must be signed before the production environment goes live.</p>
<!-- /wp:paragraph -->

<!-- wp:heading {"level":3} -->
<h3 class="wp-block-heading">After the migration, what remains my responsibility to stay HDS compliant?</h3>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>HDS certification remains the responsibility of the hosting provider. The software publisher remains responsible for application compliance and GDPR compliance. The migration brings the hosting component into compliance, but it does not cover all regulatory obligations.</p>
<!-- /wp:paragraph -->

<!-- wp:heading {"level":3} -->
<h3 class="wp-block-heading">Can I migrate from a non-sovereign hosting provider such as Azure or AWS?</h3>
<!-- /wp:heading -->

<!-- wp:paragraph -->
<p>Yes. One purpose of an HDS migration may be to remove a dependency on a hosting provider subject to non-European legislation, for example by moving away from file storage operated by a non-European provider.</p>
<!-- /wp:paragraph -->

<!-- wp:paragraph -->
<p></p>
<!-- /wp:paragraph -->]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
