Medidata and HDS (French Health Data Hosting)

HDS (Hébergeur de Données de Santé), or Health Data Hosting, refers to a French regulatory framework and the related certification that verifies an organization's compliance with baseline requirements for hosting French personal health data. Under the French Public Health Code, any organization hosting personal health data collected through healthcare activities in France is required to obtain HDS certification.

As data protection requirements continue to evolve across the globe, HDS certification has become a key benchmark for Medidata and other organizations that host personal health data in France.

Frequently Asked Questions

How does the HDS v 2.0 Framework affect Medidata and other global organizations?

Published in May 2024, the HDS v 2.0 framework introduces revisions to France's regulations governing the hosting of personal health data. The revised framework streamlines certification requirements, strengthens alignment with ISO 27001, expands contractual obligations, and enforces stricter data localization rules, including a requirement that healthcare data be hosted within the European Economic Area (EEA). Organizations may pursue certification under this updated framework to demonstrate secure, compliant management of healthcare data in accordance with French regulatory standards.

Which Medidata sub processors are HDS certified?

Amazon Web Services (AWS) and MongoDB are subprocessors of Medidata that  have achieved HDS certification for certain covered activities. Information about their respective HDS certifications may be obtained on each provider’s website:

What are my obligations as a Medidata Customer related to HDS certification?

While Medidata and our Processors (like AWS or MongoDB) handle elements of HDS requirements, you play an important role too. Generally, you're responsible for: telling us your data residency and recovery requirements upfront (like how quickly you need service restored after an outage), confirming those requirements are being met, managing your own users' access to the system and reviewing the access logs we provide, letting us know promptly if you experience a security incident on your end and naming someone as your point of contact for those situations, confirming you've received your data back if you leave the platform, and making sure your own staff understand how to handle sensitive data appropriately.

For more information on our Shared Responsibility as it relates to HDS, please refer to the Shared Responsibility Matrix attached to your HDS Addendum or visit the About Data Privacy section in the KnowledgeHub.

Where can I find information on Medidata's compliance with HDS Requirement No. 31?

Please refer to the Representation of Guarantees below.

Representation of Guarantees (Chapter 8 model)

Representation of Guarantees (Chapter 8 model)

Actor (Host/processor name) Role in hosting service HDS certified (yes/no/exempted) SecNumCloud 3.2 qualified Hosting Activities in which the player is involved Non-EEA access to DSCP (REQ 29 – specify country / adequacy) Third-country-law access risk in breach of EU law (REQ 30)
Medidata Solutions, Inc. Host Pending No Activities 3 – 6 Yes. Access may occur from regions outside the EEA, including the United States. Medidata leverages the EU-US Data Privacy Framework, which grants adequacy under certain conditions for US based access. Additionally, Medidata access from other Non-EEA regions would be subject to the 2021 Standard Contractual Clauses with clients, subjecting DSCP to minimum technical and organizational security measures. Information on our technical and organizational security measures are available on our Trust and Transparency Page. Yes; however, Medidata implements robust technical and organizational measures to mitigate the risks of access and believes we will not be required to disclose DSCP in breach of EU law. Information on our technical and organizational security measures are available on our Trust and Transparency Page.
Amazon Web Services Processor Yes No Activities 1 – 2 Yes. Medidata processors are required to execute our standard Data Protection Exhibit, which includes provisions relating to transfer into countries outside of the European Economic Area. Additionally, HDS processors would be subject to an HDS processor addendum. Please review AWS HDS materials on AWS HDS Resources Page. Yes; however, Processor provides mitigation measures to reduce risk of access to DSCP. Please review AWS HDS materials on AWS HDS Resources Page.
MongoDB Processor Yes No Activities 3 – 4 Yes. Medidata processors are required to execute our standard Data Protection Exhibit, which includes provisions relating to transfer into countries outside of the European Economic Area. Additionally, HDS processors would be subject to an HDS processor addendum. Please review Mongo HDS materials on MongoDB’s HDS Resources Page. Yes, however, MongoDB provides measures to mitigate risk of access to DSCP. Please review Mongo HDS materials on MongoDB’s HDS Resources Page.
Cognizant Worldwide Limited Processor No No Activities 3-6 Yes. Medidata processors are required to execute our standard Data Protection Exhibit, which includes provisions relating to transfer into countries outside of the European Economic Area. Additionally, HDS processors would be subject to an HDS processor addendum. Yes, however, Cognizant provides measures to mitigate risks to DSCP.