Health Data Hosting:
HDS Certification in Final Stages
EIS Software LTD (Ireland) has successfully passed the official Health Data Host (HDS) audit and is currently in the final stages of receiving formal certification. Our compliance applies specifically to EIS OneSuite™.
To provide the highest level of security and compliance, our service is hosted on Amazon Web Services (AWS) infrastructure, specifically in Region France 3 (Paris). AWS is a fully HDS-certified cloud provider for physical hosting. Building upon this secure foundation, EIS Software LTD has successfully passed its own HDS audit for our specific operational and administrative roles, ensuring end-to-end protection for your sensitive health information.
Our Compliance Status & Audited Scope
| Status | Audit successfully completed, formal certification pending. |
| Audited Entity | EIS Software LTD (Ireland) |
| Operational Scope | Our audit covers our corporate entity and the operational activities conducted from our European offices in Lithuania, Latvia, and Poland. |
| HDS Version | HDS v2.0 |
| Auditing Body | AFNOR |
| Audit Completion Date | August, 2026 |
| Expected Certification Date | Q4, 2026 |
Our official HDS certificate will be available for download here, and our entity will be listed in the official ANS HDS directory, as soon as the certificate is formally issued.
Scope of Pending Certification
HDS certification follows a shared-responsibility model. While AWS provides the HDS-certified physical infrastructure, EIS Software LTD has successfully audited for the following specific activities to guarantee the protection of your health data:
| Activity 3 | Provision and maintenance of the application hosting platform. |
| Activity 4 | Provision and maintenance of virtual infrastructure. |
| Activity 5 | Administration and operation of the information system. |
Data Location and Residency
EIS Software LTD does not operate physical data centres. Instead, all health data is securely hosted and processed on AWS Region France 3 (Paris).
No transfer of personal heath data to a country outside the European Economic Area.
Requirement # 31
[REQ 31] The Host shall make public and update the mapping of transfers of DSPs to a country outside the European Economic Area, including any remote access referred to in Requirement No 29 as well as the description of risks of unauthorized access covered by Requirement No 30. The arrangements for informing the public must take the following form:
- If the certified activity is SecumCloud qualified (version 3.2), the Host must provide the following information: “No risk of access imposed by the legislation of a third country in breach of EU law”;
- If the certified activity does not benefit from a SecumCloud qualification (version 3.2) and does not involve a transfer of DSCP to a country outside the European Economic Area, the Host must provide the following information: ” No transfer of personal health data to a country outside the European Economic Area
- If the certified activity does not benefit from a SecumCloud qualification (version 3.2) and includes one or more transfers of DSCPs to a country outside the European Economic Area or a risk of unauthorised access covered by Requirement no 30, the Host must provide the information in the table provided in Chapter 8.
The Host must make this information available to the public in a legible manner on a dedicated page of an accessible website and communicate the URL of the page to the awarding body. This URL shall be published in the list of certified hosts on the ANS website.
Our Security Commitments
Even as we await the final certificate, our infrastructure and internal processes fully comply with the stringent requirements of the HDS framework. Leveraging AWS’s secure foundation and our own strict protocols, we provide:
| Access Control | Strict, least-privilege access management, role-based permissions, and multi-factor authentication (MFA) across all our European operational offices. |
| Encryption | State-of-the-art encryption protocols for all data, both in transit and at rest. |
| Audit & Monitoring | Continuous audit logging, threat detection, and 24/7 system monitoring. |
| Incident Management | A dedicated security team with a rapid-response incident management protocol. |
Transparency and Contacts
We believe in complete accountability regarding how your data is handled.
List of Subprocessors & Cloud Providers
List of Subprocessors & Cloud Providers:
Contact our Security Team:
Data Protection Officer (DPO)
Security Enquiries
























