HDS (Health Data Hosting) certification provides a framework for the hosting of personal health data, guaranteeing security, confidentiality and regulatory compliance. It is essential for all players in the healthcare sector, and for the security of sensitive data. At Feel Agile, we support you in obtaining and maintaining this demandingmandatory certification.

The HDS standard is a quality certification framework that defines the standard requirements for the secure hosting of personal healthcare data in France. It is based on the international ISO 27001 standard, which governs quality management and information systems security, and adds obligations specific to the healthcare sector.
HDS certification is a legal requirement for any organization hosting or handling personal health data in France. This certification, issued by an accredited certification body, is a genuine guarantee of quality and reliability.
HDS certification guarantees the security of healthcare data, protecting it against cyber-attacks, unauthorized access and accidental loss. It also ensures respect for medical confidentiality and patients' rights to privacy. By imposing stringent requirements, it guarantees the reliability, availability and integrity of hosting services, thereby reinforcing trust between industry stakeholders.
Beyond data protection, HDS certification is part of a strategic quality approach aimed at strengthening digital sovereignty in Europe. It fosters a competitive and secure digital healthcare ecosystem by encouraging organizations to adopt cybersecurity best practices, while guaranteeing their compliance with standards such as RGPD and ISO standards.
The new version of the HDS certification framework was published in the Journal Officiel on May 16, 2024, and is applicable from November 16, 2024. This evolution of the standardization framework reinforces requirements in terms of data security and protection.
.webp)
To obtain HDS certification, organizations must comply with ISO 27001:2022 by implementing an Information Security Management System (ISMS). This system must include requirements specific to healthcare data, including :
Certification is also based on a number of essential safety checks:
In terms of digital sovereignty, certification requires that :
HDS certification focuses on the availability and continuity of data access. Certified infrastructures must ensure permanent access to healthcare information, even in the event of an emergency or breakdown, to avoid any critical interruption in patient care.
The certification audit is carried out in two phases by independent auditors.
If the assessment is positive, a certification committee validates HDS certification for three years, often simultaneously with ISO 27001. Annual surveillance audits ensure continued compliance, and a renewal audit is required after three years to maintain certification.



Achieving HDS certification is a complex process, requiring a thorough understanding of security and compliance requirements. Expert guidance helps you avoid common mistakes, optimize compliance and prepare for thecertification audit with confidence.
Here are the main tips for a successful HDS certification process.
To ensure effective application of HDS requirements and fostercommitment to quality throughout the organization. Staff training and awareness-raising are key elements for a certified company.
Avoid errors during theaudit and structure your compliance approach by clearly defining the scope of certification. A clearly defined scope facilitates the auditors ' work and speeds up the certification process.
Alternatively, they can be carried out under strict conditions, such as standard contractual clauses (SCC) or equivalent, so as not to complicate the certification process. Compliance with this requirement considerably simplifies the quality process.
With sufficient traceability of access to personal health data (PHCD). A robust, documented quality system is essential for certification.
HDS certification offers a major competitive advantage, enabling companies to enter a regulated market, enhance their reputation and build lasting trust with customers and partners, while guaranteeing optimum security for sensitive data.
HDS certification is mandatory for hosting healthcare data in France, and is a prerequisite for access to this fast-growing market. It enables companies to offer their services in a highly regulated sector, particularly for healthcare providers and digital solutions. HDS certification is a sine qua non for any player in the digital health sector.
HDS certification demonstrates a commitment to quality, safety and legal compliance, reinforcing thecertified company 's reputation with customers, partners and healthcare institutions. This quality certification is a real guarantee of seriousness and professionalism.
HDS certification enables certified companies to stand out in national and international markets by demonstrating their ability to manage sensitive data to the highest standards. This is a strategic advantage when bidding for tenders or collaborating with players in the medical sector. A certified company inspires confidence and reassures interested parties.
All you need to know about the HDS standard
HDS certification applies to all organizations, public or private, that host, manage or operate personal health data.
This includes in particular:
- Data centers: Providing physical infrastructure to host healthcare information systems.
- Cloud service providers: Hosting healthcare data in virtual environments.
- Technical service providers: Managing or processing healthcare data on behalf of other entities (facilities management, backup, maintenance).
- Healthcare establishments: Hospitals, clinics, doctors' practices.
- Biomedical analysis laboratories: Hosting and processing medical results.
- Pharmaceutical industries: For storing and analyzing clinical data.
- Dispensaries and pharmacies: Managing sensitive medical information.
- Health insurers and mutual insurers: Hosting data relating to medical services.
- Non-governmental organizations (NGOs): Working in the medical or health field.
Health establishments (hospitals, clinics, doctors), biomedical laboratories, pharmacies, pharmaceutical companies, insurers and NGOs involved in the health sector do not generally need to obtain HDS certification themselves, unless they directly host personal health data. However, they do need to ensure that their hosting providers are HDS-certified, in order to guarantee the security and compliance of the personal health data they process.
Only organizations accredited by COFRAC or European equivalents can issue HDS certification. The official list is available on the COFRAC or Agence du Numérique en Santé (ANS) websites.
No, it is not necessary to be ISO 27001 certified before obtaining HDS certification. Both certifications can be obtained simultaneously through an integrated management system.
HDS certification includes ISO 27001, which means that the company must implement a compliant Information Security Management System (ISMS). During the certification process, the audit takes place in two parts:
- ISO 27001 audit: Verification of the ISMS and security measures.
- Specific HDS audit: Examination of additional requirements linked to the hosting of healthcare data.
With an integrated approach, it is possible to optimize compliance and pass both certifications at the same time, reducing project costs and timescales.
Calling in an external consultant is not mandatory, but strongly recommended for several reasons:
- Compliance expertise: A consultant is familiar with HDS certification requirements, and can quickly identify any discrepancies.
- Time savings: He or she facilitates the implementation of mandatory procedures and documents.
- Audit preparation: He or she can carry out a pre-audit to avoid non-conformities during the official audit.
- Optimization of resources: He or she helps structure an effective ISMS without unnecessarily mobilizing internal teams.
Do you have any questions? Would you like a quote for certification or support?