HDS-Certified Hosting

Our certifications for healthcare data hosting and managed services

Euris Health CLoud is certified for Healthcare Data Hosting (HDS) & ISO 27001

Euris Health Cloud is certified for Health data infrastructure hosting activities and managed services, which consists in secure hosting and managing services in its datacenters and in hybrid cloud (for instance in AWS and MS Azure datacenters) of personal health data, collected or produced by editors, services providers or patients.

Our certificates are available on our certifier’s platform : bycyb.com/moteur-de-recherche-certificats/

  • HDS => certificate no. 38164
  • ISO 27001 => certificate no. 38163
  • ISO 27701 => certificate no. 38269

Representation of guarantees

Euris Health Cloud (Cloud Santé®) has achieved the highest level of HDS certification, covering both available certification scopes: HDS Infrastructure Hosting and HDS Managed Services. This certification encompasses all six activities defined by the HDS framework : 

Provision and operational maintenance of the physical facilities used to host the hardware infrastructure of the information system processing data, including health data.

Provision and operational maintenance of the hardware infrastructure supporting the information system used to process data, including healthcare data.

Provision and operational maintenance of the application hosting platform of the information system.

Provision and operational maintenance of the virtual infrastructure of the information system used to process data, including healthcare data.

Administration and operation of the information system hosting data, including healthcare data.

Off-site backup of data, including healthcare data.

Consultez le communiqué de presse sur la certification HDS:2018 et ISO 27001

HIPAA compliance (USA)

HIPAA (Health Insurance Portability and Accountability Act) is a US federal law related to privacy and protection of physical health information (PHI). Adopted in 1996, it has been completed several times, as in 2009 with HITECH (Health Information Technology for Economy and Clinical Health) and in 2013 with the Finale Omnibus Rule, creating new obligation such as shared liability or data breach notification.
The purpose of this legislation, commonly known as HIPAA, is to ensure that health providers, as well as companies working with them, are aware of the importance of health data and have an environment that is conducive to their protection, both at the level of privacy and security. It also recognizes a shared responsibility between Cover Entities and their Business Associates, and also with their Subcontractors. That’s why the use and disclosure of this data are defined by this legislation.

Euris Health Cloud (Cloud Santé®) complies with HIPAA requirements by implementing the following principles:

  • No use or disclosure of information beyond the permissions granted by the contract or applicable law.
  • Implementation of appropriate safeguards to prevent unauthorized use or disclosure of protected information.
  • Notification and maintenance of a register for all incidents involving Protected Health Information (PHI).
  • Conducting Privacy Impact Assessments (PIAs) to identify potential privacy risks and define appropriate mitigation measures.
  • Embedding privacy by design principles from the outset of every project.
  • Implementation of a comprehensive data protection policy.
  • Physical security controls across Cloud Santé® infrastructure and data centers, including access control, badge authentication, security checkpoints, identity verification, and access logging.
  • Securing systems through unique user IDs, regularly updated passwords, and restricted, secure access to server rooms.
  • Ensuring full traceability, SSL-encrypted Internet communications, and secure remote access through Virtual Private Networks (VPNs).

CSL compliance (China’s Cybersecurity Law)

The Cybersecurity Law of the People’s Republic of China was officially implemented on June 1, 2017. The CSL is an evolution of the previously existent cybersecurity rules and regulations from various levels and fields, assimilating them to create a structured law at the macro-level.
The Cybersecurity Law also provides elaborate regulations and definitions on legal liability. For different types of illegal conduct, the Law sets a variety of punishments, such as fines, suspension for rectification, revocation of permits and business licenses, and others.
Although the new Cybersecurity Law is not a centralized law that regulates all aspects of data and privacy protection across all businesses, it gives clearer legal guidance on the issues related to cybersecurity and privacy protection in China.

china cybersecurity law logo

Compliance with the Health Security Framework

HDS certification and compliance with the French Health Data Security Framework are specifically designed for the healthcare sector to ensure the protection of patient data.

Euris complies with the Security Framework of the French National Health Data System (SNDS), which applies to all information systems providing access to SNDS data.

Euris’ highly secure infrastructure, certified HDS and ISO 27001/27701, ensures that access to data preserves confidentiality and integrity while providing full traceability of data access and processing activities.

By complying with the SNDS Security Framework, Euris is committed to implementing all the security measures defined within the framework, including:

Compliance with Cybersecurity Requirements

As a European leader in healthcare data hosting, Euris Health Cloud® is committed to extending its cybersecurity strategy across the entire supply chain while creating long-term value for its customers and partners.

To support this ambition, Euris Health Cloud® chose CyberVadis, a comprehensive cybersecurity risk assessment platform, to obtain an accurate evaluation of its cybersecurity maturity.

Following the completion of the assessment process, Euris Health Cloud® achieved the highest cybersecurity maturity rating. Compliance with CyberVadis requirements demonstrates the strength of our data security strategy and provides additional assurance that our information security management systems meet the highest standards for cybersecurity and data protection.

Multi-Region Infrastructure & Global Compliance (HDS, Security & Cybersecurity)

Security has become a non-negotiable requirement for our customers. Cybersecurity credentials are increasingly requested as organizations continue to integrate information security and data privacy standards into their operations and supply chain management.

Several of our customers specifically require CyberVadis cybersecurity assessments as part of their supplier qualification process. CyberVadis assessments are aligned with internationally recognized frameworks and regulations, including ISO 27001, the GDPR, the NIST Cybersecurity Framework (National Institute of Standards and Technology), and the New York Department of Financial Services Cybersecurity Regulation (23 NYCRR 500), providing one of the most comprehensive cybersecurity evaluations available.

Certification Numérique Responsable Niveau 1 (NR1)

Euris est titulaire du Label Numérique Responsable (NR) – Niveau 1. Cette distinction récompense les organisations qui intègrent les enjeux environnementaux, sociaux et éthiques dans leurs pratiques numériques. Euris a obtenu cette certification en juillet 2024, témoignant de son engagement à développer des services numériques plus responsables, à maîtriser son impact environnemental et à promouvoir une gouvernance durable du numérique.

Pour nos clients, cela représente la garantie de collaborer avec un partenaire qui associe sécurité des données, conformité réglementaire et responsabilité numérique, dans une démarche d’amélioration continue.

French Expertise & Technology

A Team Close to You

  • A dedicated project manager for your project
  • Fast deployment with coverage across Europe and worldwide
  • Projects successfully deployed in over 30 countries

100% Compliant, Secure & High-Performance Solutions

  • EU (HDS / GDPR / ISO 27001), US (HIPAA), China (CSL)
  • Trusted Third Party – RMO
  • 20+ years of expertise in healthcare. A cloud platform dedicated to healthcare.

Request the complete certification file by completing the form below

    By clicking this button, you consent the information collected on this form is recorded in a file computerized by Euris for the management of its customer relationship. Euris can inform you of its activities on an ad hoc basis or invite you to its events. In accordance with the French Law No. 78-17 of 6 January 1978 and the European Data Protection Regulation, you have the right of access, rectification and object the processing of your data, as well as the withdrawal of your consent at any time. For further information, please check our Privacy Policy.

    certification