By Michał Puchała · 2026-07-20 · 8 min read
What France's Health Data Hub Move Teaches Healthcare Leaders About Cloud Procurement
France's Health Data Hub is moving from Microsoft Azure to Scaleway after assessing more than 350 technical requirements. Its six-year path shows healthcare leaders how to assess jurisdiction, security, operational fit and reversibility before choosing a cloud.

France's Health Data Hub is moving its technology platform from Microsoft Azure to Scaleway, a European cloud company. The decision followed a two-and-a-half-month selection process covering more than 350 technical requirements. For healthcare leaders, the useful story is not simply that France changed cloud providers. It is how the organisation balanced data protection, operational capability and the ability to change course over six years.
The case offers a practical model for any healthcare organisation assessing where sensitive data should run. It also corrects a common misconception: European jurisdiction alone does not make a cloud suitable, while technical strength alone may not answer the legal and governance questions attached to health data.
A Six-Year Procurement Story, Not a Sudden Switch
The Health Data Hub, formally the Plateforme des données de santé, was created in 2019 to make French health data available for approved research and innovation. It chose Microsoft Ireland and Azure for its original platform. That choice became controversial because Microsoft Ireland belongs to a US group, even though the health data was stored in European data centres and the contract restricted transfers outside the EU.
French regulators and courts treated the situation with more nuance than much of the public debate. In 2020, the Conseil d'Etat found no serious and manifest illegality that justified immediately suspending the platform. It nevertheless recognised that access requests under US law could not be completely excluded and required additional precautions while a lasting solution was found under the supervision of France's data protection authority, the CNIL. The court's 2020 explanation described a managed risk, not a finding that every use of an American-owned cloud in Europe was unlawful.
That distinction still matters. In March 2026, the Conseil d'Etat upheld a specific CNIL authorisation for Health Data Hub processing connected to a European medicines research network. The court noted that the authorisation covered processing in French data centres, not a transfer of health data to the United States, and that contractual and technical safeguards were in place. The ruling also acknowledged that the possibility of a US authority seeking access could not be entirely eliminated.
The new hosting decision arrived one month later. On 23 April 2026, the Health Data Hub announced Scaleway as its future host. It expects to manage a copy of France's main national health insurance database on the new platform between the end of 2026 and the beginning of 2027. This is a planned transition from an accepted interim position to a platform judged better suited to the organisation's long-term requirements.
Compliance Was the Entry Ticket, Not the Whole Decision
Health data attracts stricter controls because disclosure or misuse can directly harm patients. France therefore requires organisations that host personal health data for others to hold Health Data Host, or HDS, certification. The requirement covers the security management and operating practices of the host, not only the physical location of its servers.
The HDS framework has also become more precise about sovereignty. Its revised version requires physical health-data hosting in the European Economic Area and greater transparency when remote access or foreign law may create exposure outside that area. The French Digital Health Agency explains that location offers meaningful protection but is not sufficient on its own to guarantee immunity from extraterritorial law.
This is the first procurement lesson: treat certification as a minimum condition, not as the whole assessment. HDS is specific to France, and other European countries use different national rules and assurance schemes. A healthcare company operating across borders must identify the requirements attached to each dataset, legal entity and care setting before comparing providers.
The CNIL's position shows what sits beyond the certificate. For the most sensitive databases, it recommends protection against disclosure to authorities in third countries, including the use of a host subject exclusively to European law or one holding an appropriate security qualification. Its Health Data Hub recommendations also call for a complete view of platform security so that the organisations responsible for the data understand the conditions under which it is processed.
Procure for the Workload, Not the Label
Legal control was central to the Health Data Hub decision, but it did not replace the technical assessment. The platform holds large and varied datasets used by researchers. It needs to add computing capacity when demand rises, protect data through several independent layers of security, and remain available as research projects change.
The Health Data Hub says it designed the platform around common cloud standards and multiple layers of defence. Its selection process involved experts from the French government's digital directorate, the national research institute Inria and the health ministry. Competing offers were assessed through standardised questions and discussions, with the final choice based on security, scalability and resilience across more than 350 requirements.
A mid-sized healthcare company does not need a 350-line questionnaire merely to imitate a national platform. It does need requirements tied to its actual workload. A patient portal has different availability and identity needs from an archive of medical images. A clinical research environment needs controlled researcher access and reproducible analysis, while a hospital scheduling system puts continuity first.
Start by grouping workloads according to data sensitivity, operational importance and acceptable interruption. Then ask providers to show how they meet the requirements of each group. This produces a more credible decision than selecting one cloud label for the whole organisation.
Reversibility Starts Before the Migration
The strongest lesson from the Health Data Hub is easy to miss. According to its April announcement, the platform had been designed for reversibility since its creation in 2019. The team anticipated that the hosting market and its own requirements would change, even though a suitable alternative was not available at the time.
Reversibility means more than a contractual right to leave. The organisation must be able to export its data in usable formats, rebuild the application elsewhere, replace provider-specific functions and transfer operational knowledge to the next team. It must also know which dependencies will take the longest to change, including identity systems, database services, monitoring and security controls.
This work is best done while the current platform is stable. Architecture documents should identify which parts can move easily and which are tied to one provider. Operating instructions, recovery procedures and ownership of encryption keys should remain under the customer's control. Contracts should state what assistance, access and data deletion evidence the provider must supply during an exit.
The Health Data Hub case does not show that every dependency can be removed. Its announcement says some security capabilities still need to be built with the new host. That honesty is useful. A credible migration plan records remaining gaps, assigns owners and makes go-live conditional on evidence that the required controls work.
Evidence Matters More Than Provider Claims
Cloud procurement often begins with broad assurances about residency, security and compliance. Those claims are useful for creating a shortlist, but they are not enough for a decision involving health data. Buyers need evidence at the level where the service will actually operate.
For jurisdiction, that means identifying the contracting entity, parent company, relevant laws and every subcontractor with administrative access. For data control, it means documenting storage locations, remote support paths, encryption-key ownership, backups and deletion procedures. For resilience, it means testing recovery against an agreed target rather than accepting a general availability statement.
The same principle applies to certifications. Confirm the exact legal entity, services, regions and activities covered by each certificate. France's HDS scheme, for example, distinguishes physical infrastructure from managed hosting activities. A logo on a provider page may apply to only part of the service chain that processes your data.
Proof should continue after the contract is signed. Ask for regular assurance reports, incident records, updated subcontractor lists and evidence from recovery exercises. A provider can satisfy the procurement criteria on day one and still drift away from the required position as services, ownership or support arrangements change.
A Practical Test for Healthcare Leaders
The Health Data Hub's scale is unusual, but its decision process can be reduced to six questions that work for a hospital group, health-tech company, laboratory or pharmaceutical business:
- Which datasets and systems carry the greatest patient, regulatory and operational consequences?
- Which national and EU rules apply to each workload, and what evidence will an auditor or customer expect?
- Who can access the data in normal operations, support incidents and exceptional legal circumstances?
- Can the provider meet the required capacity, recovery and security outcomes with services available today?
- What would have to change to move the workload again, and has that path been tested?
- Which gaps are acceptable during transition, who owns them and what evidence is required before go-live?
These questions should be answered jointly by leadership, legal and privacy teams, and the people who operate the systems. The board sets the acceptable exposure. The data protection team interprets the obligations. The technical team determines whether the proposed controls and migration path can work in practice.
The timing also matters beyond France. The European Health Data Space will gradually expand the secure exchange and secondary use of health data across the EU, with major provisions beginning to apply in 2029. Healthcare organisations that map their data, access paths and cloud dependencies now will be better prepared for that more connected environment.
France's decision is therefore neither a universal instruction to leave Azure nor proof that choosing a European provider settles every risk. It demonstrates a calmer approach: protect the current system, define the long-term control you need, keep the architecture reversible and move when a suitable option can prove it meets the workload.
Thinking about migration? Book a free consultation to discuss your situation.