Health Data Hosting:

HDS Certification in Final Stages

EIS Software LTD (Ireland) has successfully passed the official Health Data Host (HDS) audit and is currently in the final stages of receiving formal certification. Our compliance applies specifically to EIS OneSuite™.

To provide the highest level of security and compliance, our service is hosted on Amazon Web Services (AWS) infrastructure, specifically in Region France 3 (Paris). AWS is a fully HDS-certified cloud provider for physical hosting. Building upon this secure foundation, EIS Software LTD has successfully passed its own HDS audit for our specific operational and administrative roles, ensuring end-to-end protection for your sensitive health information.

Our Compliance Status & Audited Scope

Transparency is at the core of our operations. Below is the current status of our HDS compliance process:
Status
Audit successfully completed, formal certification pending.
Audited Entity
EIS Software LTD (Ireland)
Operational Scope
Our audit covers our corporate entity and the operational activities conducted from our European offices in Lithuania, Latvia, and Poland.
HDS Version
HDS v2.0
Auditing Body
AFNOR
Audit Completion Date
August, 2026
Expected Certification Date
Q4, 2026

Our official HDS certificate will be available for download here, and our entity will be listed in the official ANS HDS directory, as soon as the certificate is formally issued.

Scope of Pending Certification

HDS certification follows a shared-responsibility model. While AWS provides the HDS-certified physical infrastructure, EIS Software LTD has successfully audited for the following specific activities to guarantee the protection of your health data:

Activity 3
Provision and maintenance of the application hosting platform.
Activity 4
Provision and maintenance of virtual infrastructure.
Activity 5
Administration and operation of the information system.

Data Location and Residency

EIS Software LTD does not operate physical data centres. Instead, all health data is securely hosted and processed on AWS Region France 3 (Paris).
No transfer of personal heath data to a country outside the European Economic Area.

Requirement # 31

[REQ 31] The Host shall make public and update the mapping of transfers of DSPs to a country outside the European Economic Area, including any remote access referred to in Requirement No 29 as well as the description of risks of unauthorized access covered by Requirement No 30. The arrangements for informing the public must take the following form:

  • If the certified activity is SecumCloud qualified (version 3.2), the Host must provide the following information: “No risk of access imposed by the legislation of a third country in breach of EU law”;
  • If the certified activity does not benefit from a SecumCloud qualification (version 3.2) and does not involve a transfer of DSCP to a country outside the European Economic Area, the Host must provide the following information: ” No transfer of personal health data to a country outside the European Economic Area
  • If the certified activity does not benefit from a SecumCloud qualification (version 3.2) and includes one or more transfers of DSCPs to a country outside the European Economic Area or a risk of unauthorised access covered by Requirement no 30, the Host must provide the information in the table provided in Chapter 8.

The Host must make this information available to the public in a legible manner on a dedicated page of an accessible website and communicate the URL of the page to the awarding body. This URL shall be published in the list of certified hosts on the ANS website.

Our Security Commitments

Even as we await the final certificate, our infrastructure and internal processes fully comply with the stringent requirements of the HDS framework. Leveraging AWS’s secure foundation and our own strict protocols, we provide:

Access Control
Strict, least-privilege access management, role-based permissions, and multi-factor authentication (MFA) across all our European operational offices.
Encryption
State-of-the-art encryption protocols for all data, both in transit and at rest.
Audit & Monitoring
Continuous audit logging, threat detection, and 24/7 system monitoring.
Incident Management
A dedicated security team with a rapid-response incident management protocol.

Transparency and Contacts

We believe in complete accountability regarding how your data is handled.

Privacy Statement

List of Subprocessors & Cloud Providers

List of Subprocessors & Cloud Providers:

Amazon Web Services (AWS), DataDog, CyberArk/Idira, Fivetran, SIA EIS Group , UAB EIS Group Lietuva, EIS Software Poland Sp.z.o.o. , EIS Software Limited

Contact our Security Team:

Data Protection Officer (DPO)