Independent comparison · no paid rankings
Home / Blog / Where is your health data really stored?
Investigation

Where is your health data really stored?

Behind the HDS badge, the real location of health data is often murkier than marketing suggests. An investigation into certifications, scopes and the traps to avoid.

7 min read Updated Jul 19, 2026

Picture a private clinic moving its patient records to the cloud. The salesperson promises "healthcare compliance", the contract mentions GDPR, the website shows a padlock and a soothing line about European data centres. Six months later, an audit finds that the certified scope covers object storage only — not the application database — and that backups route through a region outside France. This is not a consultant's scare story. It is the kind of gap we keep finding when we read HDS attestations literally.

So the question is not "is my host serious?". It is sharper, and more uncomfortable: where does your health data actually live, under which legal status, and inside which exact technical scope?

What HDS is — and what it is not

Hébergeur de Données de Santé (HDS) certification frames the hosting of personal health data in France. It does not replace GDPR, a data-protection impact assessment, or your own duties as controller. It attests that a defined scope was audited against a required framework.

In other words: HDS is not a generic trust badge. It is a contractual and technical snapshot. Two "HDS" hosts can offer radically different guarantees depending on whether certification covers a dedicated private cloud, a managed offer, or only one isolated layer of the stack.

Many teams buy a badge. Very few read the attestation number, the expiry date and — above all — the scope described in the annex.

GDPR, HDS, SecNumCloud: three layers, one decision

Marketing loves to blend these acronyms. For a health project, you need to separate them.

GDPR sets the general rules for personal data in Europe: lawful basis, minimisation, individual rights, processors. Any serious European host should be able to operate under it — it is not a health differentiator.

HDS adds a French sector layer: security, traceability, continuity and governance requirements specific to health data. Without HDS on the right scope, you expose the facility and the software vendor to direct regulatory risk.

SecNumCloud, meanwhile, mainly answers the question of operational sovereignty against extraterritorial laws. Useful for some sensitive workloads, it does not waive HDS when health data is involved. Both certifications can coexist at the same provider; they do not say the same thing.

How to read an attestation without getting fooled

Before you sign, ask for the current attestation — not a marketing excerpt, not a screenshot from a "compliance" page. Then check four things, in this order.

First, the validity date. An expired or mid-renewal certification is not paperwork noise: it is a coverage gap. Next, the scope. Does it cover shared hosting, VPS, managed Kubernetes, object storage, backups, managed services? Most gaps hide here. Then the location of processing and replicas. Finally, the identity of any sub-processors — including an underlying public cloud.

What to checkWhat it revealsRed flag
Attestation number & dateWhether certification is actually currentMissing, vague or expired paperwork
Technical scopeWhat was really audited"Cloud offer" with no stack detail
Regions / data centresWhere data and copies resideUndocumented replication outside the EU
Sub-processingWho actually touches the infrastructureOpaque chain or unaddressed Cloud Act risk

This colder reading often reshuffles the shortlist. A lesser-known host that is transparent about scope can be safer for a patient record than a giant whose only certified offer is an enterprise SKU you are not buying.

What the market shows among French-speaking hosts

We cross-checked public sheets and compliance signals for several visible players on the French-speaking market. Three names clearly stand out as HDS in our directory: OVHcloud, 3DS Outscale and Cloud Temple.

That does not make them interchangeable. OVHcloud has a broad catalogue, so picking the right certified product remains the key issue. 3DS Outscale positions around French sovereign cloud. Cloud Temple leans more into trusted cloud and higher sovereignty requirements. In all three cases, the real work starts after the HDS logo: you must map your architecture (app, database, files, backups, logs) onto the scope that is actually covered.

Other excellent hosts for a blog, a shop or an API — and sometimes strong on GDPR or ISO 27001, such as Infomaniak — are simply not in the HDS game. Infomaniak states clearly that HDS certification is not planned. That is not a moral failure. It is a positioning choice. The problem starts when marketing implies the opposite.

The climax: certification does not tell you where your data lives

Here is the point marketing pages carefully avoid.

That is the summit of the investigation: the most common risk is not the total absence of certification. It is the illusion of coverage. Teams believe they chose a "health" host, when they actually bought an adjacent offer, a different region, or a managed layer outside the attestation.

Until you can trace the full path — production, backups, logs, admin support — you do not know where your health data is stored. You only know where the salesperson would like you to believe it is.

Building a solid decision, project by project

Rather than a magic checklist, start from your clinical or product reality. Which data is truly health data? Who is the controller? Do you need managed services, or only infrastructure? Does your software vendor already impose a cloud?

Only then align the host. Demand the attestation, have someone who understands the architecture review the scope, and reject vague wording such as "health-ready" or "GDPR / HDS prepared". For critical projects, HDS plus contractual clarity on location almost always beats sovereignty rhetoric without evidence.

To compare European hosts and filter those that surface health compliance, start with our hosting directory and the guide GDPR, HDS, SecNumCloud — who needs what?.

Frequently asked questions

What is HDS certification?

HDS (Hébergeur de Données de Santé) is a French certification required to host personal health data. It mandates a security, traceability and governance audit on a defined scope — not on a host's entire commercial catalogue.

Is a GDPR-compliant host automatically HDS?

No. GDPR applies to personal data processing across Europe. HDS is a stricter French sector obligation. Mixing the two remains the most common mistake among project teams.

Do you need HDS for a simple online medical calendar?

As soon as a service processes personal health data on behalf of a facility or professional, the HDS framework generally applies. A calendar storing consultation reasons, history or medical documents is not "out of scope" by default.

What is the difference between HDS and SecNumCloud?

HDS targets health data. SecNumCloud, issued by ANSSI, mainly focuses on protection against extraterritorial access for sensitive workloads. They sometimes complement each other; they do not replace each other.


Next time a quote mentions "healthcare compliance", ask one question: show me the scope. If the answer fits in a slogan, it is not an answer yet.

Compare European hosts

Filter by compliance, location and use case — then open the sheets to verify the real scope.

Browse the directory
Blog

Related reading

All articles →