icon-recherche-blog-bleu.svg
icone-fermer-recherche.svg

HDS 2.0 Certification: Key New Requirements for 2026

Last update: September 22, 2026
5min
Maxime Geffray

Article Summary

  • HDS 2.0 certification aligns with the 2022 version of the ISO 27001 standard.
  • The physical hosting of health data must now take place exclusively within the European Economic Area.
  • Hosting providers must publish a map of transfers outside the EEA and declare any subcontractors subject to extraterritorial laws.
  • Oodrive renewed its HDS 2.0 certification in January 2026.

Introduced in 2018, the HDS certification covers the hosting of personal health data. It serves as a reference framework for healthcare providers who outsource the hosting of the data they process.

Revised in 2024, the HDS 2.0 certification now includes stricter requirements regarding data sovereignty and new transparency obligations for service providers and their subcontractors with respect to extraterritorial laws.

What is HDS (Health Data Hosts) certification?

What is the purpose of HDS certification?

In France, the hosting of health data is regulated by HDS certification. It is mandatory for any entity hosting this information on behalf of third parties.

HDS certification guarantees that the provider implements the necessary security, availability, and confidentiality measures to protect personal health data. Certification audits are conducted by organizations accredited by COFRAC.

Who is subject to HDS certification?

It applies to all entities, public or private, that host data on behalf of healthcare facilities, healthcare professionals, mutual insurance companies, insurers, or their subcontractors.

The scope of HDS 2.0 certification is broad. It specifically applies to:

– Providers of physical/hardware infrastructure,
– Providers of virtual infrastructure and application platforms (cloud),
– Service providers responsible for the operation and administration of health information systems,
– Entities providing outsourced backup services for health data.

The new version, known as “HDS 2.0,” took effect for all new certification applications as of November 16, 2024. Hosting providers already certified under the previous version have a transition period until May 16, 2026, to achieve compliance.

Security at Oodrive

Our solutions comply with the strictest regulations as soon as they take effect, thanks to their “Security by Design” approach.

Why an HDS 2.0 version?

The original HDS framework published in 2018 laid a solid foundation, but over the past six years, digital transformation has accelerated in the healthcare sector. At the same time, cyberthreats have intensified, and the French and European regulatory frameworks have been strengthened. The adoption of the SREN Act in May 2024 also amended the provisions regarding the hosting of health data (Article 32).

Other factors also prompted the update to the HDS certification.

Modernization of security standards: The ISO 27001 standard, which forms the foundation of HDS certification, was itself updated in 2022. HDS 2.0 is now aligned with this revised version, which sets higher standards for risk management and security governance.


Sovereignty concerns: The explosive growth of cloud services and dependence on providers subject to extraterritorial laws (particularly U.S. laws) have highlighted the need for a more protective framework for sensitive data, such as citizens’ health information.


Ambiguities in the initial version of the HDS certification: It had become necessary to clarify and enhance transparency among health data hosting providers regarding the various types of activities for which they are certified (particularly Activity 5: administration and operation of health information systems).

HDS 2.0 Certification: Strengthened Requirements for Sovereignty and Transparency

The alignment of the HDS certification with the 2022 version of the ISO 27001 standard strengthens requirements regarding risk analysis, incident management, business continuity, and access traceability.

HDS 2.0 introduces explicit requirements regarding data sovereignty.

– The physical hosting of health data must take place exclusively in a country within the European Economic Area (EEA). This geographic location requirement did not exist in the initial version of the HDS framework. The French Digital Health Agency (ANS) notes, however, that while this requirement provides significant safeguards, it is not sufficient on its own to guarantee complete immunity from extraterritorial laws.

– In the event of remote access from a country outside the EU—by the hosting provider or one of its subcontractors—or if subject to non-European legislation, the hosting provider must contractually inform its client of this situation and specify the associated risks and the measures put in place.

– Mandatory publication on the hosting provider’s website of a map detailing data transfers to countries outside the EEA.

Protect Your Sensitive Data

Discover how Oodrive protects your sensitive data from extraterritorial laws through the SecNumCloud certification

In addition to these transparency requirements, HDS 2.0 formalizes and strengthens the contractual obligations between the hosting provider and its clients. This includes, in particular, the requirement to provide a detailed description of certified activities and a list of its processors, especially those that may be subject to extraterritorial laws.

Note: HDS 2.0 certification does not extend to the extraterritorial immunity requirements set forth in ANSSI’s SecNumCloud 3.2 standard. An upcoming revision, expected by 2027 in line with the future European Cybersecurity Certification Scheme for Cloud Services (EUCS), should bridge this gap.

Evolution of HDS Certification: Where to Start?

CIOs and CISOs at affected organizations should verify several key points immediately.

  • Confirm that their hosting providers are HDS 2.0 certified. After May 16, 2026, a v1 certificate will no longer be sufficient. The list of certified providers is available on the ANS website.
  • Audit their hosting contracts.
  • Verify the public transparency of their service providers. HDS 2.0 makes the mapping of transfers outside the EEA and the list of processors subject to extraterritorial laws legally enforceable. This information must be accessible on the hosting providers’ websites.
  • Engage the right internal stakeholders. The CIO, DPO, legal department, and compliance department must work together. HDS 2.0 is not a purely technical matter.

HDS 2.0: A Matter of Strategic Vigilance

The evolution of HDS 2.0 certification is far from being a simple administrative update; rather, it is a matter of strategic vigilance. CIOs and CISOs must begin preparing for these new requirements now by verifying their service providers’ compliance and securing their contractual chain.

For its part, Oodrive renewed its HDS certification—specifically, the latest version, HDS 2.0, in January 2026. This renewal is part of a comprehensive approach to building trust. It guarantees the robustness of Oodrive’s technical foundation and its security governance. For healthcare institutions, insurers, mutual insurance companies, and all organizations that handle health data, this renewal also signals continuity. Oodrive’s solutions meet the requirements of the updated standard, ensuring uninterrupted compliance for customers using the company’s collaboration solutions.

popup-newsletter.jpg
vague-newsletter.png
Subscription to the newsletter

Subscribe to receive all news related to trusted digital content

popup-newsletter.jpg
vague-newsletter.png
Subscription to the newsletter

Subscribe to receive all news related to trusted digital content

popup-newsletter.jpg
vague-newsletter.png
Subscription to the newsletter

Subscribe to receive all news related to trusted digital content

popup-newsletter.jpg
vague-newsletter.png
Subscription to the newsletter

Subscribe to receive all news related to trusted digital content

alerte.png
Nouveauté
Oodrive Cyber-Résilience

Anticipez la crise et restez opérationnel, même lorsque votre système d’information est à l’arrêt