The protection of health data now concerns many sectors of activity. Software publishers, healthcare establishments, public services, laboratories… More and more players need to guarantee secure hosting for this sensitive data.

Ready to secure and optimise your data hosting? Contact our teams to find out more!
Understanding Health Data Hosting (“Hébergement des Données de Santé” – HDS) cloud certification
What is health data?
Any information that makes it possible to identify a person and learn about their state of health, whether physical or mental, is health data (information collected during medical monitoring, results of medical examinations, information relating to an illness, allergy, treatment or disability, etc.).
What is HDS certification?
HDS (Health Data Hosting) certification aims to enhance the security and confidentiality of personal health data, thereby guaranteeing a trusted environment for e-health and patient monitoring. To meet these high standards, it is based on ISO-compliant standards and the RGPD. Issued by an accredited independent body, it covers six areas of activity: the provision and maintenance in operational and security conditions of physical sites, the hardware infrastructure, the virtual infrastructure, the platform for hosting IS applications processing personal health data, as well as the administration and operation of the IS and the backup of personal health data.
Why choose an HDS cloud?
A legal obligation for players in the healthcare sector
All players (public or private) who host, use or store health data for a third party (with the exception of IT archiving services, which are not affected by these obligations) must be HDS-certified. Only health establishments that manage their own information systems are exempt (L.1111-8 of the Public Health Code).
Data security and confidentiality
Unlike an on-premise infrastructure, where the company would have to manage data hosting, operation and security itself, a Platform as a Service HDS cloud like Clever Cloud enables these critical aspects to be automated. This guarantees rapid deployment, automatic scalability, one-click database control, advanced security (encryption, service continuity, anonymisation) and effortless maintenance, all in a certified way.
By choosing an HDS cloud, you can concentrate on your core business, while ensuring that your infrastructure complies with the highest standards of healthcare data protection.
Why choose Clever Cloud?
Clever Cloud is HDS certified for all 6 activities, in the updated version in force since 16 May 2024, guaranteeing full compliance for the hosting and management of healthcare data. But beyond this certification, our platform offers much more!
Clever Cloud is a sovereign cloud, designed in France
At Clever Cloud, we are convinced that it is fundamental to Europe’s strategic autonomy to rely on its own infrastructure and software technologies for hosting data and applications. This means that businesses and public authorities do not have to depend on solutions from outside Europe.
A secure, immutable cloud based on the zero trust security model
Thanks to automatic updates, vulnerabilities are corrected as soon as they are identified. What’s more, our approach is based on an immutable infrastructure: any code deployed on Clever Cloud runs in an ephemeral, reproducible environment. In the event of a compromise, any malicious modification to the code is automatically eliminated the next time it is deployed. We also avoid trusted networks. At Clever Cloud, every element of the network is identified, authenticated and communicates in encrypted form, preventing any attempt at intrusion or data exfiltration.

A resilient cloud
Our solution is scalable, secure and resilient. With Clever Cloud, everything is fully automated, freeing you from technical constraints and allowing you to concentrate on what’s essential. No infrastructure to manage, no server updates to perform, no orchestrators to maintain: simply deploy your code on Clever Cloud, and it works without interruption.
Performance, cost control and speed to market
On average, a customer who migrates to Clever Cloud sees his bill reduced by 30%. And all this while accelerating time-to-market by up to a factor of 7. What’s more, our transparent pricing is based on a self-scaling model: you define the resources you need and the maximum budget you want to commit. Per-second billing ensures optimised use, with no extra costs or waste. You only pay for what you use, in line with your needs.

A modular solution, with no adaptation constraints
Our Clever offering lets you round out your experience with various add-ons, available on our marketplace, such as an SSO identity manager, a single portal that connects all your services: a single identifier and a single password for all services. We offer this solution via the open source identity and access management (IAM) integrator Keycloak (an industry standard). This Keycloak fits perfectly into our HDS cloud and can be customised by adding plugins such as the federator of healthcare identity providers, Pro Santé Connect, a free standard service (OpenID protocol) developed and maintained by the ANS (“Agence du Numérique en Santé”).
In short, our solution integrates naturally into your environment, according to your needs, without the need for complex adaptations, while guaranteeing you an experience that meets the requirements of the healthcare sector.
Guidance and support
Our responsive support team is made up of French engineers, available to meet your needs and help you get the most out of our platform. You benefit from personalised support, guaranteeing performance, compliance and peace of mind when it comes to hosting your healthcare data.

Rely on Clever Cloud for HDS hosting of your sensitive data
FAQ
I need an HDS-certified host. Who should I choose?
What is healthcare data hosting (HDS)?
Healthcare data hosting (HDS) is a French regulatory framework that requires companies handling healthcare data to store it with an HDS-certified host. This certification guarantees a high level of security and compliance for the protection of medical information.
Why is it compulsory to use an HDS-certified hosting provider to store healthcare data?
The main objective is to ensure the confidentiality, integrity and availability of healthcare data. By requiring HDS certification, the regulations protect patients and ensure that their information is not lost or accessed by unauthorised third parties.
What data is covered by HDS regulations?
Any data directly or indirectly enabling a person to be identified and relating to their physical or mental health is concerned. This includes medical records, prescriptions, examination reports, but also less obvious information such as food allergies in school canteens.
I’m a SaaS publisher, which cloud should I choose?
Clever Cloud has been designed to meet the needs of publishers. Concentrate on your code, we’ll take care of the rest!
Who is affected by the regulations on health data?
Any company or organisation that stores, processes or transmits health data must comply with these regulations. This includes hospitals, laboratories, health software publishers, insurance companies and mutual insurers, public services, and any structure handling medical information.
How is HDS certification different from other security standards such as ISO 27001?
ISO 27001 is an international standard for information security in the broadest sense, while HDS certification is a French standard specific to healthcare data. It imposes additional requirements in terms of access management, traceability and physical security.
What requirements are covered by HDS certification?
HDS certification covers six key areas, from the physical management of infrastructures to the administration of systems and applications.
Is Clever Cloud certified for all HDS areas of activity?
Yes, we are certified for all six HDS activity areas, in the updated version in force since 16 May 2024, which means we can offer a hosting service covering all the needs associated with health data.
Why choose Clever Cloud to host healthcare data?
Clever Cloud combines compliance, performance and ease of use. Our infrastructure enables rapid deployment, automatic scalability, advanced security (encryption, continuity of service, anonymisation) and effortless maintenance, all in an HDS-certified environment.
What are the advantages of Clever Cloud over other HDS-certified hosting providers?
Unlike most traditional hosting providers, we offer all the benefits of an HDS-certified Platform as a Service (PaaS), as well as a Database as a Service (DBaaS) solution and additional certified services, via our marketplace.
As a PaaS provider, we offer:
- Significantly reduced time to market;
- Increased security with automatic updates;
- Cost is often lower than with other hosting providers.
- Fast, effortless production start-up;
- An elastic infrastructure that automatically adapts to needs;
- Instant deployment of managed databases;
- A platform that adapts easily to your technical environment.
How does Clever Cloud ensure the protection of health data?
We apply cybersecurity best practices:
- An unchanging infrastructure;
- Avoidance of trusted networks (‘zero trust security model’);
- Regular audits of our infrastructure;
- Proactive detection and correction of security vulnerabilities;
- You retain control of your data at all times, and can retrieve it whenever you want.
What are your service level agreements (SLAs)?
At Clever Cloud, we guarantee an availability rate of 99.9% per year for a standard contract, and 99.99% per year for customers with a Premium option.
Who can access the data stored on Clever Cloud?
Only the owners of the data and persons authorised by them may access it. Clever Cloud does not process or exploit its customers’ data.
What happens in the event of a security breach?
As soon as a security vulnerability is announced, Clever Cloud applies the necessary patch to its images automatically and extensively, so that remedial action can be taken as quickly as possible.
How do I migrate healthcare data to Clever Cloud?
Migration is simple: just log in, import your code, choose your databases and the servers on which you want to be hosted, and with a single command you can deploy your application.
Does HDS hosting at Clever Cloud require any technical adaptations?
No, you don’t need a complicated architecture to have a functional application. You just migrate your code and we’ll take care of the rest.
What types of applications or software can be hosted on Clever Cloud?
Any application that handles healthcare data can be hosted, whether it’s medical software, a telemedicine platform or a hospital ERP.
What are Clever Cloud’s contractual commitments regarding the hosting of healthcare data?
We guarantee HDS compliance, data security, service continuity and data reversibility in the event of contract termination. In addition, HDS hosting requires a contract and specific conditions, which implies a direct discussion with one of our sales representatives.
As a company handling health data, what are my legal obligations with regard to hosting?
You must ensure that your data is stored with an HDS-certified host and that it complies with the principles of the RGPD on the protection of personal data.
What happens if I don’t comply with the HDS hosting obligation?
Failure to comply with the obligation to use an HDS-certified host for health data may result in criminal penalties, in accordance with the provisions of the French Public Health Code. To find out more, please consult this section of the French Public Health Code.