HDS certification is a legal requirement for any third-party organization that hosts personal health data on behalf of healthcare providers—including cloud service providers, IT companies, and software vendors. Beyond regulatory compliance, it is a key component of Europe's digital sovereignty strategy. By promoting cybersecurity best practices and alignment with GDPR and international standards, HDS fosters a secure, competitive, and resilient digital healthcare ecosystem.
The HDS standard is a certification framework that defines the requirements for secure hosting of healthcare data in France. It is based on the international ISO 27001 standard, which governs information systems security management, and adds obligations specific to the healthcare sector.
HDS certification is legally required for any third-party organization that hosts health data on behalf of healthcare professionals or institutions.
HDS certification guarantees the security of healthcare data, protecting it against cyber-attacks, unauthorized access and accidental loss. It also ensures respect for medical confidentiality and patients' rights to privacy. By imposing strict requirements, it guarantees the reliability, availability and integrity of hosting services, thereby reinforcing trust between industry players.
Beyond data protection, HDS certification is part of a strategic approach to strengthening digital sovereignty in Europe. It fosters a competitive and secure digital healthcare ecosystem by encouraging organizations to adopt cybersecurity best practices, while ensuring their compliance with regulations such as the GDPR and international standards.
The new version of the HDS certification standard was published in the Journal Officiel on May 16, 2024, and is applicable from November 16, 2024.
To obtain HDS certification, organizations must comply with ISO 27001:2022 by implementing an Information Security Management System (ISMS). This system must include requirements specific to healthcare data, including:
Certification is also based on a number of essential safety checks:
In terms of digital sovereignty, certification requires that :
HDS certification focuses on the availability and continuity of data access. Certified infrastructures must ensure permanent access to healthcare information, even in the event of an emergency or breakdown, to avoid any critical interruption in patient care.
The HDS certification cycle begins with preparation for the audit: choice of a certification body and implementation of an ISO 27001-compliant ISMS.
The audit takes place in two phases: a document review of policies and procedures, followed by an on-site audit of infrastructures and systems.
If the assessment is positive, a committee validates HDS certification for three years, often in conjunction with ISO 27001. Annual audits ensure compliance, and a renewal audit is required after three years.
Achieving HDS certification is a complex process, requiring a thorough understanding of security and compliance requirements. Expert support can help you avoid common mistakes, optimize compliance and prepare for the audit with confidence.
Here are the most important tips for successful HDS certification:
To ensure effective application of HDS requirements.
Avoid errors during the audit and structure your compliance approach.
Alternatively, they can be carried out under strict conditions, such as standard contractual clauses (SCC) or equivalent, so as not to complicate the certification process.
With sufficient traceability of DSCP access.
HDS certification offers a major competitive advantage, enabling companies to enter a regulated market, enhance their reputation and build lasting trust with customers and partners, while guaranteeing optimum security for sensitive data.
HDS certification is mandatory for hosting healthcare data in France, and is a prerequisite for access to this fast-growing market. It enables companies to offer their services in a highly regulated sector, particularly for healthcare providers and digital solutions.
Being HDS-certified demonstrates a commitment to security and legal compliance, reinforcing the company's reputation with customers, partners and healthcare institutions.
HDS certification enables companies to stand out in national and international markets by demonstrating their ability to manage sensitive data to the highest standards. This is a strategic advantage when bidding for tenders or collaborating with players in the medical sector.
All you need to know about the HDS standard
HDS certification applies to all organizations, public or private, that host, manage or operate personal health data.
This includes in particular:
- Data centers: Providing physical infrastructure to host healthcare information systems.
- Cloud service providers: Hosting healthcare data in virtual environments.
- Technical service providers: Managing or processing healthcare data on behalf of other entities (facilities management, backup, maintenance).
- Healthcare establishments: Hospitals, clinics, doctors' practices.
- Biomedical analysis laboratories: Hosting and processing medical results.
- Pharmaceutical industries: For storing and analyzing clinical data.
- Dispensaries and pharmacies: Managing sensitive medical information.
- Health insurers and mutual insurers: Hosting data relating to medical services.
- Non-governmental organizations (NGOs): Working in the medical or health field.
Health establishments (hospitals, clinics, doctors), biomedical laboratories, pharmacies, pharmaceutical companies, insurers and NGOs involved in the health sector do not generally need to obtain HDS certification themselves, unless they directly host personal health data. However, they do need to ensure that their hosting providers are HDS-certified, in order to guarantee the security and compliance of the personal health data they process.
Only organizations accredited by COFRAC or European equivalents can issue HDS certification. The official list is available on the COFRAC or Agence du Numérique en Santé (ANS) websites.
No, it is not necessary to be ISO 27001 certified before obtaining HDS certification. Both certifications can be obtained simultaneously through an integrated management system.
HDS certification includes ISO 27001, which means that the company must implement a compliant Information Security Management System (ISMS). During the certification process, the audit takes place in two parts:
- ISO 27001 audit: Verification of the ISMS and security measures.
- Specific HDS audit: Examination of additional requirements linked to the hosting of healthcare data.
With an integrated approach, it is possible to optimize compliance and pass both certifications at the same time, reducing project costs and timescales.
Calling in an external consultant is not mandatory, but strongly recommended for several reasons:
- Compliance expertise: A consultant is familiar with HDS certification requirements, and can quickly identify any discrepancies.
- Time savings: He or she facilitates the implementation of mandatory procedures and documents.
- Audit preparation: He or she can carry out a pre-audit to avoid non-conformities during the official audit.
- Optimization of resources: He or she helps structure an effective ISMS without unnecessarily mobilizing internal teams.
Do you have any questions? Would you like a quote for certification or support?