Support for HDS Certification

Host your clients' health data in full compliance with regulations. FeelAgile helps you obtain Health Data Host certification to secure your business, reassure healthcare providers, and open up new markets.

100% Satisfaction
13 Reference systems
Over 200 certified clients
Man who works with cyber regulations

+ Over 200 companies have already placed their trust in us

Logo aniah
jamespot logo
Logo airon telematica
Logo seqino
SBS Interactive logo
auqfood logo

Understanding Certification HDS
and the implications for your organization

HDS (Health Data Host) certification is a French regulatory requirement imposed byArticle L.1111-8 of the Public Health Code. Any organization that hosts, processes, or stores personal health data on behalf of third parties must be certified by a body accredited by COFRAC.

The HDS framework defines the security requirements that must be met to host health data in France. It is based on the ISO 27001:2022 standard and adds sector-specific requirements, including the management of healthcare professionals’ access permissions, continuity of data access, and digital sovereignty.

It serves both as a framework for regulatory compliance and as a strong signal of trust to your customers. In an industry where the reliability of the hosting provider is critical to patient care, HDS certification is the standard expected by all stakeholders.

Privacy
Protection of Personal Health Data
Sovereignty
Physical hosting in Europe, transparency regarding access from outside the EEA
Availability
Uninterrupted access to data, even in the event of an incident or emergency
Reference Document v2 · Order of April 26, 2024 · ISO 27001:2022
6 Covered lodging activities
2 Types of certificates (physical infrastructure / managed services)
3 years Certificate validity period
EEA Data localization required or equivalent safeguards mandatory
Certification issued by a body accredited by COFRAC (or a recognized European equivalent), the sole national accreditation body.
HDS Certification Program
From preparation to recertification — a certificate valid for 3 years with mandatory annual surveillance audits.
Project Phase · Steps 1 through 3
6 to 9 months on average
Maintenance · Steps 4 & 5
Valid for 3 years, followed by recertification
1
Gap analysis
1 to 2 months
2
Compliance
4 to 6 months
3
Certification audit
(Steps 1 & 2)
~2 months
4
Compliance audits
Year 1 & Year 2
5
Recertification
At age 3

Obtaining HDS Certification: Why Most Projects Fall Behind Schedule

HDS certification has become essential for entering the digital health market. But between interpreting the standards, coordinating teams, and producing documentation, the process takes longer than expected. Here are the six obstacles that companies going it alone consistently face.

A framework that is difficult to interpret on one's own

HDS combines ISO 27001:2022 with specific healthcare requirements. Determining which provisions apply to your exact scope requires a careful reading that few internal teams are able to master right away.

An audit that requires months of preparation

The certification body evaluates concrete evidence: policies, procedures, logs, and tests. Without a structured roadmap, teams end up going in all directions and deadlines are missed.

Non-conformities discovered too late are costly

A deficiency identified during the audit phase results in a delay in certification and costly remediation cycles. Early support helps address these issues before they become insurmountable.

Internal coordination is often the real obstacle

IT, legal, DPO, business units: HDS certification involves multiple teams simultaneously. Without dedicated leadership, responsibilities become diffuse and the project stalls.

Documentation is a job in its own right

Security policies, business continuity plans, clearance records, backup documentation: compiling a comprehensive and consistent set of documents is time-consuming for teams that are already stretched thin.

Certification requires ongoing maintenance

Achieving HDS certification is not an end in itself. Surveillance audits, managing changes to the information system, and updating documentation require constant vigilance, which is often underestimated.

FeelAgile turns these obstacles into manageable steps.

Our agile approach turns these challenges into manageable steps. A dedicated project manager guides you through each milestone, simply and efficiently.

Talk to an expert →


Support tailored to your your level of maturity

Whether you're starting from scratch or looking to accelerate an existing initiative, we offer the format that best suits your organization.

Autonomous platform

Take control of your HDS certification. At yourown pace.

Access our GRC platform and a comprehensive HDS playbook to independently structure your ISMS. The tool handles the framework; you stay in control.

What you get:

HDS Step-by-Step Guide
GRC Platform to Structure Your Cybersecurity Strategy
Ready-to-use templates and documents
Supervised by a CSM and consultant
Ad hoc support as needed

Key benefits:

  • Go at your own pace
  • Optimize your costs
  • Develop your skills in-house
  • Easily maintain your certification

Expert guidance

An HDS expert by your side. No blind spots.

Take advantage of a structured support program that combines consulting, training, and auditing to help you move faster, avoid critical mistakes, and feel confident on the day of your certification audit.

What you get:

Initial assessment of your readiness
Risk Analysis Workshops
Methodological Guidance
Training for Your Teams
Review and approval of your deliverables
Pre-certification mock audit
Support through the final audit

Key benefits:

  • Get your project moving
  • Reduce the risk of failure
  • Be prepared on the day of the audit
  • Build your skills with our experts
Premium

Turnkey project

Leave it all to us. Get your certification.

We manage every aspect of your HDS project: from the initial planning to obtaining the certificate. Your team can stay focused on its core business.

What you get:

Comprehensive project management
Dedicated project manager with weekly updates
Steering the WSIS
Documentation Writing
Coordination of internal teams
Preparing for and undergoing the audit
Support through to certification

Key benefits:

  • Maximum time savings
  • Minimum internal load
  • End-to-end structured project
  • Certification goal achieved more quickly

Why choose us—
—for your certification HDS ?

At Feel Agile, we help you achieve your certifications quickly and efficiently, while guaranteeing a high level of quality. Our agile approach, in-depth expertise and personalized support make all the difference.
Expert guidance
With Feel Agile, you benefit from reliable, pragmatic and results-oriented support to secure your certification and optimize your organization.

Your HDS support
, in 4 steps

Each step is clearly defined, documented, and monitored using specific metrics. You always know where you stand.

1

Assessment & Scope Definition

Assessment of your HDS maturity, definition of the scope of the solution, and identification of gaps relative to the framework. You’ll leave with a clear, prioritized roadmap.

⏱ 1 to 2 months
2

Analysis & Design

Analysis of risks associated with health data, drafting of security policies, and definition of applicable controls. Each deliverable complies with the standard’s requirements.

⏱ 2 to 7 months
3

Implementation of the WSIS

Implementation of HDS controls, team training, and system management. You demonstrate how your system actually works.

⏱ 1 to 3 months
4

Audit & Certification

Simulation of the full audit, correction of non-conformities, management review, followed by support during both phases of the audit conducted by the accredited certification body.

⏱ 3 to 4 weeks

FeelAgile, an expert incertification support

In addition to ISO 27001, we cover all information security certifications

ISO 27001 logo
HDS logo
SECNUMCLOUD logo
SOC2 logo
GDPR logo
ISO 42001 logo
ISO 9001 logo
ISO 13485 logo
NIS2 logo
ISO 27018 logo
Talk to our experts about your needs
Read more


Over 200 companies have obtained their certification with FeelAgile

Here’s what those who have experienced the program firsthand have to say.

★★★★★

"
We had very good support. Our quality system was very well studied by the project manager, which made the whole project easier."

Male image
Airon Telematica

Stefano FIORENTINI - CTO

★★★★★

"
Feel Agile has great process knowledge, a project plan with an efficient tempo and existing documentation material to save time."

Male image
Aniah

Mickaël KLAUS

★★★★★

"
Thanks to Feel Agile, we were able to obtain ISO 27001 certification without a single non-conformity, which is a rare achievement."

Profile photo Julien Caasagnabere
Val Solutions

Julien Cassagnabère -RSSI

FAQ

Frequently Asked Questions from Businesses About Support HDS

Everything you need to know about HDS

Who is concerned by HDS certification?

Any organization that hosts, manages, or processes personal health data is subject to the HDS certification requirement, regardless of whether it is public or private. This includes, in particular:

  • Data centers: physical infrastructure that houses health information systems
  • Cloud providers: hosting of health data in a virtualized environment
  • Technical service providers: IT outsourcing, data backup, and maintenance on behalf of third parties
  • Healthcare software providers (SaaS): whenever they host patient data
  • Healthcare facilities: hospitals, clinics, and medical practices that host their own data
  • Biomedical laboratories, pharmacies, insurance companies, mutual insurance companies, health NGOs

Do healthcare facilities need to be HDS-certified?

Not necessarily. A healthcare facility that outsources its data hosting to an external provider does not need to be HDS-certified itself—but it is required to verify that its provider is.

On the other hand, if the company hosts its data directly in-house, certification is required.

Best practice: Include a contractual clause requiring all your hosting providers to be HDS-certified.

Who can issue HDS certification?

Only certification bodies accredited by COFRAC (or a recognized European equivalent) are authorized to issue HDS certification. The official list is available at:

  • cofrac.fr
  • TheANS (French Digital Health Agency) website

Do you need to be ISO 27001 certified before pursuing HDS certification?

No. Both certifications can be obtained simultaneously through an integrated management system —which is, in fact, the recommended approach for minimizing time and costs.

The HDS certification incorporates the requirements of ISO 27001. The audit consists of two parts:

  • ISO 27001 Audit: Verification of the ISMS and Security Measures
  • Specific HDS Audit: Review of Requirements Specific to the Hosting of Health Data

Should I call in an external consultant?

This is not required, but it is strongly recommended, particularly for:

  • Reduce compliance time: quickly identify gaps in compliance with the standards
  • Ensuring a successful audit: An internal pre-audit helps prevent critical non-conformities
  • Building an effective ISMS without unnecessarily burdening internal teams
  • Controlling costs: targeted support helps avoid costly back-and-forth communication with the certifying body

How long does the HDS certification project take?

Location Estimated time
First certification, excluding ISO 27001 6 to 9 months
Organization already certified to ISO 27001 3 to 5 months

Costs vary depending on the scope (number of certified activities, size, initial maturity) and are broken down into: consulting support, technical upgrades, team training, and fees charged by the certifying body.

What happens after certification is obtained?

The HDS certificate is valid for 3 years, with:

  • A mandatory annual surveillance audit by the certification body
  • A comprehensive renewal audit at the end of the 3-year period

FeelAgile offers a compliance maintenance service that covers these audits, monitoring of regulatory changes, and the corrective actions needed to maintain your certification over the long term.

Does HDS certification cover the GDPR?

HDS certification and the GDPR are complementary but distinct. HDS focuses on the security of health data hosting; the GDPR provides a broader framework for the processing of all personal data.

An HDS-certified organization nevertheless has a solid foundation on which to build its GDPR compliance, particularly through its ISMS.

Our experts will get back to you within 24 hours.

Do you have any questions? Would you like a quote for certification or support?

Over 200 companies trust us
jamespot logo
auqfood logo
SBS Interactive logo
Logo seqino
Logo aniah
Logo airon telematica