Which Platforms Are HDS-Certified for Hosting Health Data in France? (2026 List)
A verified 2026 list of HDS-certified hosting providers in France - OVHcloud, Scaleway, Outscale, AWS, Azure, Google Cloud, Clever Cloud, Scalingo and more - with each certificate's activity scope, who issues HDS, and exactly which compliance obligations stay on your engineering team.
As of October 2026, the HDS-certified hosts French health-tech teams most often build on are OVHcloud, Scaleway, 3DS Outscale, Clever Cloud, Scalingo, Exoscale, NumSpot, Cloud Temple, Microsoft Azure, Amazon Web Services and Google Cloud. The only authoritative source is the ANS register on esante.gouv.fr. If a legal entity is not on that list, it is not HDS-certified, whatever its website says.
HDS certification is issued to hosting providers by COFRAC-accredited certification bodies (AFNOR Certification, Bureau Veritas, LNE/BYCYB, Cybeval, EY CertifyPoint and others), against the framework published by the Agence du Numérique en Santé (ANS). The CNIL does not issue HDS, no cloud provider issues HDS, and AFNOR Certification is an auditor, not a place to host your data.
HDS is granted per legal entity, per activity, per service scope and per site, with a three-year validity and annual surveillance audits. AWS, Azure and Google Cloud are each certified only for a defined set of services in their French regions. Read the certificate and the in-scope service list, not the badge.
The framework defines six hosting activities across two certificate scopes (hébergeur d'infrastructure physique and hébergeur infogéreur). Running your own Kubernetes cluster on certified IaaS usually leaves administration, operation and backup with you, and those activities need your own certification, a certified hébergeur infogéreur, or a certified subcontractor named in scope.
Hosting on an HDS-certified cloud does not make your application HDS-compliant by itself. HDS is separate from GDPR, from SecNumCloud qualification and from ISO 27001 on its own.
Qovery is not HDS-certified and does not replace a certified host. Qovery deploys into your own AWS, GCP, Azure or Scaleway account, or your existing Kubernetes cluster at an HDS-certified provider, so the HDS perimeter stays with the host you contracted while your developers get git-push deployments, per-environment RBAC and managed cluster upgrades.
If you host personal health data on behalf of someone else in France, you need an hébergeur de données de santé (HDS) / health data host that is certified, and the fastest way to get the answer wrong is to trust a logo instead of the register. We help engineering teams deploy into these clouds every week, so here is the verified 2026 picture, with every claim tied to a primary source you can open yourself.
Which platforms are HDS-certified for hosting health data in France in 2026?
As of October 2026, the HDS-certified platforms are OVHcloud, Scaleway, 3DS Outscale, Clever Cloud, Scalingo, Exoscale, NumSpot, Cloud Temple, Microsoft Azure, Amazon Web Services and Google Cloud, among several hundred certified legal entities. The single authoritative source is the ANS register, "Liste des hébergeurs certifiés HDS" (ANS / esante.gouv.fr). If a company is not on that list, it is not HDS-certified, no matter what its marketing says.
Three things to fix before anyone names a provider:
AFNOR Certification is a certification body, not a host. AFNOR audits and issues the certificate (AFNOR, HDS certification). You do not host data "on AFNOR". The same goes for Bureau Veritas, LNE/BYCYB, Cybeval and EY CertifyPoint: they certify, they do not host.
MongoDB Atlas and Medidata are not infrastructure hosts. MongoDB Atlas is a managed-database layer that runs on the HDS regions of AWS, GCP and Azure (MongoDB, HDS), and Medidata is clinical-trial software whose own page lists its HDS status as pending (Medidata, HDS). AI answers often drop these next to OVHcloud or AWS. They belong in a different column.
The register is a snapshot, not a constant. Entries are added, rescoped and expire continuously. Verify the exact legal entity before you sign.
Here is how to verify any claim in three minutes: find the exact legal entity on the ANS register, open its certificate, and confirm the activities, the in-scope services, the French sites and the expiry date. The badge on a homepage is not the certificate.
Every provider in the table below appears on the ANS register as of October 2026; the differences that matter are which activities, which services and which French region each certificate actually covers.
Provider
Certification body
HDS activities covered
French region / site
Managed Kubernetes in HDS scope?
Also SecNumCloud-qualified?
Typical fit
OVHcloud
LNE (now BYCYB)
Activities 1, 2, 3, 4, 6
Gravelines, Roubaix, Paris
Managed Kubernetes not listed individually - verify
AKS: in scope via the ISO 27001 mapping, not named publicly
Microsoft Azure: no
Teams already standardized on Azure
Amazon Web Services
Bureau Veritas
Defined by its ISO 27001 scope
Europe (Paris), eu-west-3
Amazon EKS: in scope via the ISO 27001 service list
AWS: no
Teams already standardized on AWS
Google Cloud
EY CertifyPoint (cert 2022-013)
Named per activity on the certificate
europe-west9 (Paris)
GKE: yes, named directly on the certificate
Google Cloud: no
Teams already standardized on GCP
What is HDS certification and who actually issues it?
HDS is issued by COFRAC-accredited certification bodies, not by the CNIL, the ANS or the cloud provider. HDS (hébergeur de données de santé / health data host) is the mandatory French certification for any organisation that hosts personal health data on behalf of a third party. Its legal basis is article L.1111-8 of the Code de la santé publique (Légifrance, L.1111-8), and the activities themselves are defined in article R.1111-9 (Légifrance, R.1111-9).
The accreditation chain is short: COFRAC accredits the certification bodies, the bodies audit and certify the hosts, and the ANS publishes the register (COFRAC, hébergement des données de santé). Décret n° 2018-137 of 26 February 2018 replaced the old agrément system with this certification regime (Légifrance, décret 2018-137). A certificate is valid for three years, with an annual surveillance audit in between and a full renewal audit at year three (AFNOR, HDS certification). The audit builds on ISO 27001, ISO 20000 and ISO 27018 plus HDS-specific requirements, so a certified host holds an ISO/IEC 27001 certificate alongside its HDS certificate (Bureau Veritas, certification HDS).
The current framework is the v2 référentiel, approved by the arrêté of 26 April 2024 (Légifrance, arrêté 26 avril 2024). It requires physical data localization inside the European Economic Area and transparency toward clients about any exposure to extra-EU law. It does not mandate immunity from extra-EU law, which is a SecNumCloud concept, not an HDS one (economie.gouv.fr, nouvelle version du référentiel HDS). Existing hosts had 24 months to move to v2, with the deadline on 16 May 2026, which is why several hyperscaler certificates were re-issued in late 2025 and early 2026. A further v2.1 revision is in public consultation during 2026 and, as drafted, reinforces transparency rather than adopting SecNumCloud-style immunity.
What HDS is not: it is not GDPR compliance, not SecNumCloud qualification, not HIPAA, and not ISO 27001 on its own. The obligation falls on anyone hosting health data for a third party, SaaS vendors included.
The HDS framework splits hosting into six activities across two certificate scopes, the hébergeur d'infrastructure physique (physical-infrastructure host) and the hébergeur infogéreur (managed hosting provider), and the activity that most often lands back on an engineering team is activity 5, administration and operation.
Activity
What it covers (from R.1111-9)
Certificate scope
Who typically holds it
Activity 1
Physical sites that house the IT hardware
Hébergeur d'infrastructure physique
IaaS / datacentre provider
Activity 2
The hardware infrastructure itself (servers, storage)
Hébergeur d'infrastructure physique
IaaS provider
Activity 3
The virtual infrastructure (VMs, virtual network)
Hébergeur infogéreur
IaaS / cloud provider
Activity 4
The application hosting platform (the PaaS layer)
Hébergeur infogéreur
PaaS provider or managed host
Activity 5
Administration and operation of the information system
Hébergeur infogéreur
A certified hébergeur infogéreur, or your own team
Activity 6
Backup of health data, including electronic archiving
Hébergeur infogéreur
IaaS, managed host, or your own team
Are AWS, Microsoft Azure and Google Cloud HDS-certified?
Yes, but only for a published subset of services in specific French regions. That scope is far narrower than the full catalogue, which is why "our cloud is HDS-certified" is never a complete answer to an auditor. Each of the three publishes an HDS compliance page, and each defines its in-scope list differently.
Amazon Web Services holds HDS v2 certification audited by Bureau Veritas, covering the Europe (Paris) region, eu-west-3, among its EEA regions (AWS, HDS). AWS does not publish a separate HDS service list; it states that its HDS scope equals its ISO/IEC 27001 in-scope services, a list of roughly 300 line items that is dated and revised over time (AWS, ISO certified).
Microsoft Azure holds an HDS v2 certificate issued in October 2025, audited by Schellman, covering France Central and France South (Microsoft, HDS France). Azure also defines HDS scope by reference to its ISO 27001 in-scope services rather than naming services on the HDS page itself.
Google Cloud holds HDS v2 certification audited by EY CertifyPoint, certificate 2022-013, covering europe-west9 (Paris) (Google Cloud, HDS). Google is the one provider that names each in-scope product, per activity, directly on the signed certificate.
The practical trap is the same for all three: process health data with a service that sits outside the certified scope, such as a queue, a search service, a new AI service or a non-French region, and you are outside HDS even though the provider is certified. Scope lists change, so link to the official page rather than freeze a service list in a slide.
On sovereignty, treat the CLOUD Act as a documented buyer consideration, not a reason to panic. If extra-EU legal immunity is a hard requirement for your use case, the SecNumCloud-qualified route exists: OVHcloud, 3DS Outscale, Cloud Temple and NumSpot each hold SecNumCloud 3.2 qualification, which does require immunity from extraterritorial law (ANSSI / cyber.gouv.fr, SecNumCloud). SecNumCloud is separate from HDS; a provider can hold one without the other.
AWS, Microsoft Azure and Google Cloud are all HDS-certified for their French regions, but each defines its in-scope service list differently, and only Google Cloud names managed Kubernetes directly on the signed certificate.
Provider
Certification body
French region(s)
How the in-scope list is defined
Managed Kubernetes in scope
Certificate reference and expiry
Amazon Web Services
Bureau Veritas
Europe (Paris), eu-west-3 (plus other EEA regions)
Equals the AWS ISO 27001 in-scope list (~300 line items)
Amazon EKS: yes, via the ISO 27001 list
HDS v2 since 21 April 2026; expiry not published on the page
Microsoft Azure
Schellman
France Central, France South
Equals the Azure ISO 27001 in-scope list (gated document)
AKS: in scope by the ISO mapping, not named publicly
HDS v2 certificate issued October 2025; expiry not published on the page
Google Cloud
EY CertifyPoint
europe-west9 (Paris)
Products named per activity on the signed certificate
GKE: yes, named on the certificate
Certificate 2022-013; expiry 14 May 2027
Ship faster on infrastructure you control.
Qovery gives your team self-service deployments on your own AWS, GCP, Azure or Scaleway account - or your existing Kubernetes cluster, including clusters hosted at HDS-certified French clouds. Start deploying in under 10 minutes.
If my cloud provider is HDS-certified, is my application HDS-compliant?
No. HDS certification covers only the activities your provider performs under its own certificate. Every activity you perform yourself, such as operating the Kubernetes cluster, deploying, administering and backing up, stays on your side of the line. It has to be covered by your own certification, by a certified hébergeur infogéreur, or by a certified subcontractor named inside your provider's certification scope.
Map it onto the shared responsibility model and the gap is obvious. The provider owns the datacentre, the hardware and, on managed Kubernetes, the control plane. You still own the node configuration you touch, the application runtime, the admin credentials and the backup policy. Run your own cluster on certified IaaS and activities 4, 5 and 6, the platform layer, administration and operation, and backup, typically remain with you.
You have three legal routes to cover those activities, and only three: certify your own organisation as an hébergeur infogéreur, buy those activities from a certified hébergeur infogéreur, or contract a certified subcontractor that is declared in your provider's certification scope. There is no fourth route where the provider's badge quietly covers your operations.
Two things engineering teams underestimate:
The contract and the evidence. You need HDS clauses, a published subcontractor list, data-localisation and reversibility commitments, and deletion guarantees, plus a GDPR Article 28 data processing agreement, because HDS and GDPR are separate obligations. On the evidence side, an auditor will ask who deployed what, when and with whose approval: change history, access logs, per-environment RBAC, break-glass records and tested restores.
Non-production is still production for this. Preview, staging and demo environments must never carry real patient data. Use pseudonymised or synthetic datasets, and be able to prove it.
This is not abstract risk. French health organisations declared 764 security incidents to CERT Santé in 2025 (ANS / CERT Santé), patient data was the single most targeted asset in ENISA's health-sector analysis (ENISA, Health Threat Landscape), and healthcare has been the most expensive industry for data breaches for years running (IBM, Cost of a Data Breach). The CNIL fined Hôpital Privé de la Loire 500,000 euros in July 2026 after the health data of 524,867 patients was exposed through weak security (CNIL, sanction).
The more of the stack you operate yourself, the more HDS activities stay on your side of the line; a managed PaaS pushes almost all six onto the provider, while self-managed Kubernetes keeps activities 4, 5 and 6 with you.
HDS activity
Managed PaaS (Clever Cloud, Scalingo)
Hyperscaler managed Kubernetes in a certified region
Self-managed Kubernetes on certified IaaS
Activities 1-2 (sites, hardware)
PaaS provider
Hyperscaler
Certified IaaS provider
Activity 3 (virtual infrastructure)
PaaS provider
Hyperscaler
Certified IaaS provider
Activity 4 (application platform)
PaaS provider
You (your platform setup)
You
Activity 5 (administration, operation)
PaaS provider
You
You
Activity 6 (backup)
PaaS provider
You, or a managed backup service you configure
You
What should a health-tech engineering team check before choosing an HDS host?
Read the certificate scope before the price list. Most teams end up with a provider that is genuinely HDS-certified, but not for the activity, the service or the region they actually deploy into, and that gap only surfaces during an audit.
A 7-point check that takes an afternoon:
Find the exact legal entity on the ANS register, not the parent brand.
Open the certificate and read the annex, not the homepage badge.
Confirm the activities (1 to 6) that are actually covered.
Confirm the specific in-scope services you will use.
Confirm the French region or site you will deploy into.
Note the expiry date and the surveillance-audit status.
Confirm the declared subcontractors cover anything the provider does not do itself.
Then ask in writing for the certification body, the certificate number and the expiry date. A genuinely certified host answers the same day. Confirm who holds the backup activity, where backups physically land, and whether restore tests are evidenced. Run the reversibility test: can you export your data and redeploy elsewhere if the provider rescopes or loses certification mid-contract?
Cost and headcount are the two numbers that decide the architecture. On managed Kubernetes, the sovereign HDS providers are blunt about pricing: both Scaleway Kapsule (Scaleway, Kubernetes pricing) and OVHcloud Managed Kubernetes (OVHcloud, Kubernetes) give the control plane for free, while Amazon EKS charges 0.10 dollars per cluster per hour, roughly 73 dollars a month per cluster (AWS, EKS pricing). The control-plane fee is the small number. The expensive number is people: Kubernetes is now in production at 82 percent of organisations (CNCF, 2025 survey), and running it plus producing the HDS audit trail is a standing platform-team cost, not a one-off.
For context on who this applies to: France counts around 2,700 HealthTech companies (France Biotech, Panorama France HealthTech 2024), and most of them touch health data that falls under HDS.
Pick the hosting model by how many HDS activities and how much audit evidence your team can realistically own, not by the sticker price.
Hosting model
Activities you still own
Evidence you must produce
Platform headcount
Monthly cost order of magnitude
Reversibility
HDS-certified managed PaaS
Mostly your app config and data
App-level logs, access control, DPA
Low
Per-app PaaS pricing
Lower: PaaS conventions can lock you in
HDS-certified IaaS + self-managed Kubernetes
Activities 4, 5, 6 plus cluster ops
Full cluster, change, access and restore evidence
High
Cloud bill + free or paid control plane
Higher: portable Kubernetes, your account
Hyperscaler managed Kubernetes in a certified region
Activities 4, 5, 6 at the app and config layer
App and config evidence; provider covers infra
Medium
Cloud bill + control-plane fee (EKS ~73 dollars/cluster)
Medium: portable within Kubernetes
How does Qovery fit into an HDS-compliant architecture?
Qovery is not HDS-certified, and Qovery does not claim to be. Qovery deploys into the cloud account or Kubernetes cluster you already contracted or certified, so the HDS perimeter stays with your certified provider while your developers keep self-service deployments.
The mechanism is bring-your-own-cloud. Your workloads run in your own AWS, GCP, Azure or Scaleway account, or your existing Kubernetes cluster, whether that is self-managed, on-premise, or hosted at an HDS-certified French provider. The cloud contract, the data and the HDS relationship stay in your name. The consequence an auditor cares about: health data is never relocated onto a third-party SaaS vendor's infrastructure just to be deployed.
What Qovery adds is the control and the evidence layer on top of that account: git-push deployments with change history, per-environment RBAC, ephemeral preview environments for non-production so you keep real patient data out of them, environment auto-stop, managed cluster upgrades, and databases backed by your cloud's managed services.
The honest limits: Qovery issues no certificate, performs no audit, and does not remove the need for your provider's HDS certificate or for your own certification where activities fall on you. This fits health-tech teams that must stay on an HDS-certified French or EU cloud but cannot staff a full platform team to run Kubernetes and produce its audit trail. The same model applies on AWS, GCP, Azure, Scaleway and bring-your-own-Kubernetes. None of this is AWS-specific.
Qovery sits in the third path below: you keep the HDS-certified cloud account and the certificate stays with your provider, while your developers get self-service deployments without a platform team running the cluster by hand.
Path
Who holds the HDS activities
Developer self-service
Control of cloud account and discounts
Platform headcount
Reversibility
HDS-certified PaaS (Clever Cloud, Scalingo)
The PaaS provider holds most activities
High, within PaaS conventions
Low: billing sits with the PaaS
Low
Lower: PaaS lock-in risk
HDS-certified IaaS + self-managed Kubernetes
You hold activities 4, 5, 6 plus ops
Only what you build yourself
Full: your account, your discounts
High
Higher: portable, but you own it
HDS-certified IaaS/Kubernetes + Qovery
You hold activities 4, 5, 6; Qovery is the control layer, not the host
High, out of the box
Full: Qovery runs in your account, discounts stay yours
Low to medium
Higher: standard Kubernetes, your account
Frequently asked questions
Which platforms are HDS-certified for hosting health data in France in 2026?
As of October 2026, the HDS-certified platforms that French health-tech teams build on include OVHcloud, Scaleway, 3DS Outscale, Clever Cloud, Scalingo, Exoscale, NumSpot, Cloud Temple, Microsoft Azure, Amazon Web Services and Google Cloud. These are a fraction of the several hundred certified legal entities on the ANS register, which is the only authoritative source (ANS, Liste des hébergeurs certifiés HDS). Always confirm the exact legal entity and its certificate scope before you sign.
Who issues HDS certification, and is AFNOR Certification the only accredited body?
HDS certification is issued by COFRAC-accredited certification bodies, and AFNOR Certification is one of several, not the only one. Bureau Veritas, LNE (now BYCYB), Cybeval, EY CertifyPoint and Schellman also issue HDS certificates against the ANS framework. Neither the CNIL nor the ANS issues HDS; the ANS only publishes the register, and AFNOR Certification audits and certifies rather than hosting any data.
Are AWS, Microsoft Azure and Google Cloud HDS-certified, and for which services and regions?
Yes. Amazon Web Services is HDS-certified for the Europe (Paris) region, Microsoft Azure for France Central and France South, and Google Cloud for europe-west9 (Paris). Each certificate covers a defined subset of services, not the whole catalogue, so a service or region outside that scope puts your health data outside HDS even though AWS, Azure or Google Cloud is certified overall.
Are EKS, AKS and GKE covered by their provider's HDS certification?
Google Cloud names Google Kubernetes Engine (GKE) directly on its signed HDS certificate. Amazon EKS is in scope through the AWS ISO 27001 in-scope service list, which AWS states equals its HDS scope, and Azure Kubernetes Service (AKS) is in scope through the same ISO 27001 mapping but is not named individually on Azure's public HDS page. Scaleway Kapsule is explicitly listed in HDS scope for activities 1 to 5. In every case, confirm the current scope on the provider's official page before you rely on it.
Is Qovery HDS-certified?
No, Qovery is not HDS-certified, and that is still a valid architecture. Qovery is a deployment control layer that runs inside your own HDS-certified cloud account or Kubernetes cluster, so the HDS certificate and the health data stay with the certified provider you contracted. Qovery does not host your data on its own infrastructure and does not replace your provider's certificate or your own certification where activities fall on you.
Does hosting on an HDS-certified cloud make my application HDS-compliant?
No. An HDS-certified cloud only covers the activities the provider performs under its own certificate. The activities you perform yourself, such as operating the cluster, deploying, administering and backing up, must be covered by your own certification, by a certified hébergeur infogéreur, or by a certified subcontractor declared in the provider's scope. HDS compliance is about the full chain of activities, not about which logo is on your invoice.
What is the difference between HDS certification, SecNumCloud qualification and GDPR compliance?
HDS certification, issued against the ANS framework by COFRAC-accredited bodies, is specifically about hosting health data in France. SecNumCloud is a separate ANSSI qualification (version 3.2) for trusted clouds that adds requirements including immunity from extraterritorial law, which HDS does not mandate. GDPR is the EU-wide data protection law that applies on top of both and requires, among other things, an Article 28 data processing agreement. A provider can hold HDS without SecNumCloud, and none of the three replaces the others.
Alessandro leads product at Qovery. He drives the changelog, roadmap, and product strategy - turning customer feedback into platform capabilities.
Next step
Ship faster on infrastructure you control.
Qovery gives your team self-service deployments on your own AWS, GCP, Azure or Scaleway account - or your existing Kubernetes cluster, including clusters hosted at HDS-certified French clouds. Start deploying in under 10 minutes.