As soon as a platform stores personal health data on behalf of a healthcare professional, it must sit on an HDS-certified host. The certification applies to the host, not the software vendor — but the vendor's architecture determines whether the obligation is actually met.
The first decision is a split
Not all data is health data. Cleanly separating the medical record from the user account, billing and analytics avoids imposing the strictest perimeter's constraints on the whole system.
What certification does not cover
- Application-level encryption and key management remain the vendor's responsibility.
- Access traceability must be designed into the application, not only the infrastructure.
- The data protection impact assessment remains the controller's own obligation.
Timing matters
Changing host after go-live costs several times what choosing well up front does. Settle it during design, alongside the data model.
A project or a question?
Partnerships, integrations, press — write to us directly.