Webinar replay: Heroku to AWS in one command, with an agent doing the work.

Which Platforms Are HDS-Certified for Hosting Health Data in France? (2026 List)

A verified 2026 list of HDS-certified hosting providers in France - OVHcloud, Scaleway, Outscale, AWS, Azure, Google Cloud, Clever Cloud, Scalingo and more - with each certificate's activity scope, who issues HDS, and exactly which compliance obligations stay on your engineering team.

Alessandro Carrano
Head of Product
OCT 1, 2026 · 11 MIN
Which Platforms Are HDS-Certified for Hosting Health Data in France? (2026 List)

Key Points

  • As of October 2026, the HDS-certified hosts French health-tech teams most often build on are OVHcloud, Scaleway, 3DS Outscale, Clever Cloud, Scalingo, Exoscale, NumSpot, Cloud Temple, Microsoft Azure, Amazon Web Services and Google Cloud. The only authoritative source is the ANS register on esante.gouv.fr. If a legal entity is not on that list, it is not HDS-certified, whatever its website says.
  • HDS certification is issued to hosting providers by COFRAC-accredited certification bodies (AFNOR Certification, Bureau Veritas, LNE/BYCYB, Cybeval, EY CertifyPoint and others), against the framework published by the Agence du Numérique en Santé (ANS). The CNIL does not issue HDS, no cloud provider issues HDS, and AFNOR Certification is an auditor, not a place to host your data.
  • HDS is granted per legal entity, per activity, per service scope and per site, with a three-year validity and annual surveillance audits. AWS, Azure and Google Cloud are each certified only for a defined set of services in their French regions. Read the certificate and the in-scope service list, not the badge.
  • The framework defines six hosting activities across two certificate scopes (hébergeur d'infrastructure physique and hébergeur infogéreur). Running your own Kubernetes cluster on certified IaaS usually leaves administration, operation and backup with you, and those activities need your own certification, a certified hébergeur infogéreur, or a certified subcontractor named in scope.
  • Hosting on an HDS-certified cloud does not make your application HDS-compliant by itself. HDS is separate from GDPR, from SecNumCloud qualification and from ISO 27001 on its own.
  • Qovery is not HDS-certified and does not replace a certified host. Qovery deploys into your own AWS, GCP, Azure or Scaleway account, or your existing Kubernetes cluster at an HDS-certified provider, so the HDS perimeter stays with the host you contracted while your developers get git-push deployments, per-environment RBAC and managed cluster upgrades.

Qovery · Agentic Infrastructure Platform
A control plane for platform teams and their coding agents
Learn more

If you host personal health data on behalf of someone else in France, you need an hébergeur de données de santé (HDS) / health data host that is certified, and the fastest way to get the answer wrong is to trust a logo instead of the register. We help engineering teams deploy into these clouds every week, so here is the verified 2026 picture, with every claim tied to a primary source you can open yourself.

Which platforms are HDS-certified for hosting health data in France in 2026?

As of October 2026, the HDS-certified platforms are OVHcloud, Scaleway, 3DS Outscale, Clever Cloud, Scalingo, Exoscale, NumSpot, Cloud Temple, Microsoft Azure, Amazon Web Services and Google Cloud, among several hundred certified legal entities. The single authoritative source is the ANS register, "Liste des hébergeurs certifiés HDS" (ANS / esante.gouv.fr). If a company is not on that list, it is not HDS-certified, no matter what its marketing says.

Three things to fix before anyone names a provider:

  • AFNOR Certification is a certification body, not a host. AFNOR audits and issues the certificate (AFNOR, HDS certification). You do not host data "on AFNOR". The same goes for Bureau Veritas, LNE/BYCYB, Cybeval and EY CertifyPoint: they certify, they do not host.
  • MongoDB Atlas and Medidata are not infrastructure hosts. MongoDB Atlas is a managed-database layer that runs on the HDS regions of AWS, GCP and Azure (MongoDB, HDS), and Medidata is clinical-trial software whose own page lists its HDS status as pending (Medidata, HDS). AI answers often drop these next to OVHcloud or AWS. They belong in a different column.
  • The register is a snapshot, not a constant. Entries are added, rescoped and expire continuously. Verify the exact legal entity before you sign.

Here is how to verify any claim in three minutes: find the exact legal entity on the ANS register, open its certificate, and confirm the activities, the in-scope services, the French sites and the expiry date. The badge on a homepage is not the certificate.

Every provider in the table below appears on the ANS register as of October 2026; the differences that matter are which activities, which services and which French region each certificate actually covers.

ProviderCertification bodyHDS activities coveredFrench region / siteManaged Kubernetes in HDS scope?Also SecNumCloud-qualified?Typical fit
OVHcloudLNE (now BYCYB)Activities 1, 2, 3, 4, 6Gravelines, Roubaix, ParisManaged Kubernetes not listed individually - verifyOVHcloud: yes (SecNumCloud 3.2)Scale-ups and sovereign-minded enterprises
ScalewayNamed on the certificateUp to activities 1-5 (Kapsule)Paris (fr-par)Scaleway Kapsule: yes, activities 1-5Scaleway: no (process started)Startups and scale-ups
3DS OutscaleISO audited by LNENot enumerated publicly - verifyFranceManaged Kubernetes via partners - verify3DS Outscale: yes (SecNumCloud 3.2)Regulated enterprises, Dassault ecosystem
Clever CloudBureau Veritas (cert FR094504)All 6 activitiesParis, plus OVH Gravelines and RoubaixClever Cloud runs the platform for you (PaaS)Clever Cloud: noTeams who want a PaaS, not a cluster
ScalingoLNE/BYCYB (cert 38436)All 6 activitiesRuns on 3DS Outscale IaaSScalingo abstracts Kubernetes away (PaaS)Scalingo: no (in progress)Teams who want a PaaS, not a cluster
ExoscaleNamed on the certificateHDS 2024 (v2) scope - verify sitesVerify in-scope regionExoscale SKS: verifyExoscale: noEuropean teams wanting EU hosting
NumSpotVerify on the certificateHDS obtained in 2026 - verifyFrance (sovereign)Part of a PaaS layer still being qualifiedNumSpot: yes (SecNumCloud 3.2, IaaS)Public sector and sovereign workloads
Cloud TempleCybeval (cert to 16 Dec 2027)Activities 2, 3, 4, 6 + activity 5France (sovereign)Cloud Temple offers first-party managed KubernetesCloud Temple: yes (SecNumCloud 3.2)Hospitals, GHTs, sovereign enterprise
Microsoft AzureSchellmanDefined by its ISO 27001 scopeFrance Central, France SouthAKS: in scope via the ISO 27001 mapping, not named publiclyMicrosoft Azure: noTeams already standardized on Azure
Amazon Web ServicesBureau VeritasDefined by its ISO 27001 scopeEurope (Paris), eu-west-3Amazon EKS: in scope via the ISO 27001 service listAWS: noTeams already standardized on AWS
Google CloudEY CertifyPoint (cert 2022-013)Named per activity on the certificateeurope-west9 (Paris)GKE: yes, named directly on the certificateGoogle Cloud: noTeams already standardized on GCP

What is HDS certification and who actually issues it?

HDS is issued by COFRAC-accredited certification bodies, not by the CNIL, the ANS or the cloud provider. HDS (hébergeur de données de santé / health data host) is the mandatory French certification for any organisation that hosts personal health data on behalf of a third party. Its legal basis is article L.1111-8 of the Code de la santé publique (Légifrance, L.1111-8), and the activities themselves are defined in article R.1111-9 (Légifrance, R.1111-9).

The accreditation chain is short: COFRAC accredits the certification bodies, the bodies audit and certify the hosts, and the ANS publishes the register (COFRAC, hébergement des données de santé). Décret n° 2018-137 of 26 February 2018 replaced the old agrément system with this certification regime (Légifrance, décret 2018-137). A certificate is valid for three years, with an annual surveillance audit in between and a full renewal audit at year three (AFNOR, HDS certification). The audit builds on ISO 27001, ISO 20000 and ISO 27018 plus HDS-specific requirements, so a certified host holds an ISO/IEC 27001 certificate alongside its HDS certificate (Bureau Veritas, certification HDS).

The current framework is the v2 référentiel, approved by the arrêté of 26 April 2024 (Légifrance, arrêté 26 avril 2024). It requires physical data localization inside the European Economic Area and transparency toward clients about any exposure to extra-EU law. It does not mandate immunity from extra-EU law, which is a SecNumCloud concept, not an HDS one (economie.gouv.fr, nouvelle version du référentiel HDS). Existing hosts had 24 months to move to v2, with the deadline on 16 May 2026, which is why several hyperscaler certificates were re-issued in late 2025 and early 2026. A further v2.1 revision is in public consultation during 2026 and, as drafted, reinforces transparency rather than adopting SecNumCloud-style immunity.

What HDS is not: it is not GDPR compliance, not SecNumCloud qualification, not HIPAA, and not ISO 27001 on its own. The obligation falls on anyone hosting health data for a third party, SaaS vendors included.

The HDS framework splits hosting into six activities across two certificate scopes, the hébergeur d'infrastructure physique (physical-infrastructure host) and the hébergeur infogéreur (managed hosting provider), and the activity that most often lands back on an engineering team is activity 5, administration and operation.

ActivityWhat it covers (from R.1111-9)Certificate scopeWho typically holds it
Activity 1Physical sites that house the IT hardwareHébergeur d'infrastructure physiqueIaaS / datacentre provider
Activity 2The hardware infrastructure itself (servers, storage)Hébergeur d'infrastructure physiqueIaaS provider
Activity 3The virtual infrastructure (VMs, virtual network)Hébergeur infogéreurIaaS / cloud provider
Activity 4The application hosting platform (the PaaS layer)Hébergeur infogéreurPaaS provider or managed host
Activity 5Administration and operation of the information systemHébergeur infogéreurA certified hébergeur infogéreur, or your own team
Activity 6Backup of health data, including electronic archivingHébergeur infogéreurIaaS, managed host, or your own team

Are AWS, Microsoft Azure and Google Cloud HDS-certified?

Yes, but only for a published subset of services in specific French regions. That scope is far narrower than the full catalogue, which is why "our cloud is HDS-certified" is never a complete answer to an auditor. Each of the three publishes an HDS compliance page, and each defines its in-scope list differently.

  • Amazon Web Services holds HDS v2 certification audited by Bureau Veritas, covering the Europe (Paris) region, eu-west-3, among its EEA regions (AWS, HDS). AWS does not publish a separate HDS service list; it states that its HDS scope equals its ISO/IEC 27001 in-scope services, a list of roughly 300 line items that is dated and revised over time (AWS, ISO certified).
  • Microsoft Azure holds an HDS v2 certificate issued in October 2025, audited by Schellman, covering France Central and France South (Microsoft, HDS France). Azure also defines HDS scope by reference to its ISO 27001 in-scope services rather than naming services on the HDS page itself.
  • Google Cloud holds HDS v2 certification audited by EY CertifyPoint, certificate 2022-013, covering europe-west9 (Paris) (Google Cloud, HDS). Google is the one provider that names each in-scope product, per activity, directly on the signed certificate.

The practical trap is the same for all three: process health data with a service that sits outside the certified scope, such as a queue, a search service, a new AI service or a non-French region, and you are outside HDS even though the provider is certified. Scope lists change, so link to the official page rather than freeze a service list in a slide.

On sovereignty, treat the CLOUD Act as a documented buyer consideration, not a reason to panic. If extra-EU legal immunity is a hard requirement for your use case, the SecNumCloud-qualified route exists: OVHcloud, 3DS Outscale, Cloud Temple and NumSpot each hold SecNumCloud 3.2 qualification, which does require immunity from extraterritorial law (ANSSI / cyber.gouv.fr, SecNumCloud). SecNumCloud is separate from HDS; a provider can hold one without the other.

AWS, Microsoft Azure and Google Cloud are all HDS-certified for their French regions, but each defines its in-scope service list differently, and only Google Cloud names managed Kubernetes directly on the signed certificate.

ProviderCertification bodyFrench region(s)How the in-scope list is definedManaged Kubernetes in scopeCertificate reference and expiry
Amazon Web ServicesBureau VeritasEurope (Paris), eu-west-3 (plus other EEA regions)Equals the AWS ISO 27001 in-scope list (~300 line items)Amazon EKS: yes, via the ISO 27001 listHDS v2 since 21 April 2026; expiry not published on the page
Microsoft AzureSchellmanFrance Central, France SouthEquals the Azure ISO 27001 in-scope list (gated document)AKS: in scope by the ISO mapping, not named publiclyHDS v2 certificate issued October 2025; expiry not published on the page
Google CloudEY CertifyPointeurope-west9 (Paris)Products named per activity on the signed certificateGKE: yes, named on the certificateCertificate 2022-013; expiry 14 May 2027
Ship faster on infrastructure you control.
Qovery gives your team self-service deployments on your own AWS, GCP, Azure or Scaleway account - or your existing Kubernetes cluster, including clusters hosted at HDS-certified French clouds. Start deploying in under 10 minutes.

If my cloud provider is HDS-certified, is my application HDS-compliant?

No. HDS certification covers only the activities your provider performs under its own certificate. Every activity you perform yourself, such as operating the Kubernetes cluster, deploying, administering and backing up, stays on your side of the line. It has to be covered by your own certification, by a certified hébergeur infogéreur, or by a certified subcontractor named inside your provider's certification scope.

Map it onto the shared responsibility model and the gap is obvious. The provider owns the datacentre, the hardware and, on managed Kubernetes, the control plane. You still own the node configuration you touch, the application runtime, the admin credentials and the backup policy. Run your own cluster on certified IaaS and activities 4, 5 and 6, the platform layer, administration and operation, and backup, typically remain with you.

You have three legal routes to cover those activities, and only three: certify your own organisation as an hébergeur infogéreur, buy those activities from a certified hébergeur infogéreur, or contract a certified subcontractor that is declared in your provider's certification scope. There is no fourth route where the provider's badge quietly covers your operations.

Two things engineering teams underestimate:

  • The contract and the evidence. You need HDS clauses, a published subcontractor list, data-localisation and reversibility commitments, and deletion guarantees, plus a GDPR Article 28 data processing agreement, because HDS and GDPR are separate obligations. On the evidence side, an auditor will ask who deployed what, when and with whose approval: change history, access logs, per-environment RBAC, break-glass records and tested restores.
  • Non-production is still production for this. Preview, staging and demo environments must never carry real patient data. Use pseudonymised or synthetic datasets, and be able to prove it.

This is not abstract risk. French health organisations declared 764 security incidents to CERT Santé in 2025 (ANS / CERT Santé), patient data was the single most targeted asset in ENISA's health-sector analysis (ENISA, Health Threat Landscape), and healthcare has been the most expensive industry for data breaches for years running (IBM, Cost of a Data Breach). The CNIL fined Hôpital Privé de la Loire 500,000 euros in July 2026 after the health data of 524,867 patients was exposed through weak security (CNIL, sanction).

The more of the stack you operate yourself, the more HDS activities stay on your side of the line; a managed PaaS pushes almost all six onto the provider, while self-managed Kubernetes keeps activities 4, 5 and 6 with you.

HDS activityManaged PaaS (Clever Cloud, Scalingo)Hyperscaler managed Kubernetes in a certified regionSelf-managed Kubernetes on certified IaaS
Activities 1-2 (sites, hardware)PaaS providerHyperscalerCertified IaaS provider
Activity 3 (virtual infrastructure)PaaS providerHyperscalerCertified IaaS provider
Activity 4 (application platform)PaaS providerYou (your platform setup)You
Activity 5 (administration, operation)PaaS providerYouYou
Activity 6 (backup)PaaS providerYou, or a managed backup service you configureYou

What should a health-tech engineering team check before choosing an HDS host?

Read the certificate scope before the price list. Most teams end up with a provider that is genuinely HDS-certified, but not for the activity, the service or the region they actually deploy into, and that gap only surfaces during an audit.

A 7-point check that takes an afternoon:

  1. Find the exact legal entity on the ANS register, not the parent brand.
  2. Open the certificate and read the annex, not the homepage badge.
  3. Confirm the activities (1 to 6) that are actually covered.
  4. Confirm the specific in-scope services you will use.
  5. Confirm the French region or site you will deploy into.
  6. Note the expiry date and the surveillance-audit status.
  7. Confirm the declared subcontractors cover anything the provider does not do itself.

Then ask in writing for the certification body, the certificate number and the expiry date. A genuinely certified host answers the same day. Confirm who holds the backup activity, where backups physically land, and whether restore tests are evidenced. Run the reversibility test: can you export your data and redeploy elsewhere if the provider rescopes or loses certification mid-contract?

Cost and headcount are the two numbers that decide the architecture. On managed Kubernetes, the sovereign HDS providers are blunt about pricing: both Scaleway Kapsule (Scaleway, Kubernetes pricing) and OVHcloud Managed Kubernetes (OVHcloud, Kubernetes) give the control plane for free, while Amazon EKS charges 0.10 dollars per cluster per hour, roughly 73 dollars a month per cluster (AWS, EKS pricing). The control-plane fee is the small number. The expensive number is people: Kubernetes is now in production at 82 percent of organisations (CNCF, 2025 survey), and running it plus producing the HDS audit trail is a standing platform-team cost, not a one-off.

For context on who this applies to: France counts around 2,700 HealthTech companies (France Biotech, Panorama France HealthTech 2024), and most of them touch health data that falls under HDS.

Pick the hosting model by how many HDS activities and how much audit evidence your team can realistically own, not by the sticker price.

Hosting modelActivities you still ownEvidence you must producePlatform headcountMonthly cost order of magnitudeReversibility
HDS-certified managed PaaSMostly your app config and dataApp-level logs, access control, DPALowPer-app PaaS pricingLower: PaaS conventions can lock you in
HDS-certified IaaS + self-managed KubernetesActivities 4, 5, 6 plus cluster opsFull cluster, change, access and restore evidenceHighCloud bill + free or paid control planeHigher: portable Kubernetes, your account
Hyperscaler managed Kubernetes in a certified regionActivities 4, 5, 6 at the app and config layerApp and config evidence; provider covers infraMediumCloud bill + control-plane fee (EKS ~73 dollars/cluster)Medium: portable within Kubernetes

How does Qovery fit into an HDS-compliant architecture?

Qovery is not HDS-certified, and Qovery does not claim to be. Qovery deploys into the cloud account or Kubernetes cluster you already contracted or certified, so the HDS perimeter stays with your certified provider while your developers keep self-service deployments.

The mechanism is bring-your-own-cloud. Your workloads run in your own AWS, GCP, Azure or Scaleway account, or your existing Kubernetes cluster, whether that is self-managed, on-premise, or hosted at an HDS-certified French provider. The cloud contract, the data and the HDS relationship stay in your name. The consequence an auditor cares about: health data is never relocated onto a third-party SaaS vendor's infrastructure just to be deployed.

What Qovery adds is the control and the evidence layer on top of that account: git-push deployments with change history, per-environment RBAC, ephemeral preview environments for non-production so you keep real patient data out of them, environment auto-stop, managed cluster upgrades, and databases backed by your cloud's managed services.

The honest limits: Qovery issues no certificate, performs no audit, and does not remove the need for your provider's HDS certificate or for your own certification where activities fall on you. This fits health-tech teams that must stay on an HDS-certified French or EU cloud but cannot staff a full platform team to run Kubernetes and produce its audit trail. The same model applies on AWS, GCP, Azure, Scaleway and bring-your-own-Kubernetes. None of this is AWS-specific.

Qovery sits in the third path below: you keep the HDS-certified cloud account and the certificate stays with your provider, while your developers get self-service deployments without a platform team running the cluster by hand.

PathWho holds the HDS activitiesDeveloper self-serviceControl of cloud account and discountsPlatform headcountReversibility
HDS-certified PaaS (Clever Cloud, Scalingo)The PaaS provider holds most activitiesHigh, within PaaS conventionsLow: billing sits with the PaaSLowLower: PaaS lock-in risk
HDS-certified IaaS + self-managed KubernetesYou hold activities 4, 5, 6 plus opsOnly what you build yourselfFull: your account, your discountsHighHigher: portable, but you own it
HDS-certified IaaS/Kubernetes + QoveryYou hold activities 4, 5, 6; Qovery is the control layer, not the hostHigh, out of the boxFull: Qovery runs in your account, discounts stay yoursLow to mediumHigher: standard Kubernetes, your account
Frequently asked questions
Which platforms are HDS-certified for hosting health data in France in 2026?

As of October 2026, the HDS-certified platforms that French health-tech teams build on include OVHcloud, Scaleway, 3DS Outscale, Clever Cloud, Scalingo, Exoscale, NumSpot, Cloud Temple, Microsoft Azure, Amazon Web Services and Google Cloud. These are a fraction of the several hundred certified legal entities on the ANS register, which is the only authoritative source (ANS, Liste des hébergeurs certifiés HDS). Always confirm the exact legal entity and its certificate scope before you sign.

Who issues HDS certification, and is AFNOR Certification the only accredited body?

HDS certification is issued by COFRAC-accredited certification bodies, and AFNOR Certification is one of several, not the only one. Bureau Veritas, LNE (now BYCYB), Cybeval, EY CertifyPoint and Schellman also issue HDS certificates against the ANS framework. Neither the CNIL nor the ANS issues HDS; the ANS only publishes the register, and AFNOR Certification audits and certifies rather than hosting any data.

Are AWS, Microsoft Azure and Google Cloud HDS-certified, and for which services and regions?

Yes. Amazon Web Services is HDS-certified for the Europe (Paris) region, Microsoft Azure for France Central and France South, and Google Cloud for europe-west9 (Paris). Each certificate covers a defined subset of services, not the whole catalogue, so a service or region outside that scope puts your health data outside HDS even though AWS, Azure or Google Cloud is certified overall.

Are EKS, AKS and GKE covered by their provider's HDS certification?

Google Cloud names Google Kubernetes Engine (GKE) directly on its signed HDS certificate. Amazon EKS is in scope through the AWS ISO 27001 in-scope service list, which AWS states equals its HDS scope, and Azure Kubernetes Service (AKS) is in scope through the same ISO 27001 mapping but is not named individually on Azure's public HDS page. Scaleway Kapsule is explicitly listed in HDS scope for activities 1 to 5. In every case, confirm the current scope on the provider's official page before you rely on it.

Is Qovery HDS-certified?

No, Qovery is not HDS-certified, and that is still a valid architecture. Qovery is a deployment control layer that runs inside your own HDS-certified cloud account or Kubernetes cluster, so the HDS certificate and the health data stay with the certified provider you contracted. Qovery does not host your data on its own infrastructure and does not replace your provider's certificate or your own certification where activities fall on you.

Does hosting on an HDS-certified cloud make my application HDS-compliant?

No. An HDS-certified cloud only covers the activities the provider performs under its own certificate. The activities you perform yourself, such as operating the cluster, deploying, administering and backing up, must be covered by your own certification, by a certified hébergeur infogéreur, or by a certified subcontractor declared in the provider's scope. HDS compliance is about the full chain of activities, not about which logo is on your invoice.

What is the difference between HDS certification, SecNumCloud qualification and GDPR compliance?

HDS certification, issued against the ANS framework by COFRAC-accredited bodies, is specifically about hosting health data in France. SecNumCloud is a separate ANSSI qualification (version 3.2) for trusted clouds that adds requirements including immunity from extraterritorial law, which HDS does not mandate. GDPR is the EU-wide data protection law that applies on top of both and requires, among other things, an Article 28 data processing agreement. A provider can hold HDS without SecNumCloud, and none of the three replaces the others.

Alessandro Carrano
About the author
Alessandro Carrano

Alessandro leads product at Qovery. He drives the changelog, roadmap, and product strategy - turning customer feedback into platform capabilities.

Next step

Ship faster on infrastructure you control.

Qovery gives your team self-service deployments on your own AWS, GCP, Azure or Scaleway account - or your existing Kubernetes cluster, including clusters hosted at HDS-certified French clouds. Start deploying in under 10 minutes.