The verdict in three sentences
As soon as a business app stores health data for patients or clinicians, it must sit with a certified health data host (HDS in France, typically C5 and ISO 27001 in Germany) for EUR 150 to 900 per month depending on volume and redundancy. Add a data protection impact assessment (DPIA) of EUR 2,000 to 6,000, access logging and encryption at rest. The risk of non-compliance is serious: regulators can fine up to 4% of global turnover or EUR 20M.
What health data hosting certification covers
Certifications such as France's HDS (aligned with ISO 27001, updated in 2024) or Germany's BSI C5 cover physical infrastructure, virtual infrastructure, managed operations and backup. An app developer does not need to be certified if they rely on a certified host for all hosting activities, but they must pick the right scope and sign a compliant contract.
| Certified hosting offer | Typical content | 2026 monthly cost |
|---|---|---|
| Small certified instance | 1 server, daily backup, data in the EU | EUR 150 to 300 |
| High-availability instance | 2 servers, replicated database, DR plan | EUR 350 to 600 |
| Fully managed certified hosting | 24/7 monitoring, patching, on-call | EUR 600 to 900 |
| Medical document storage | 500 GB encrypted, versioning | EUR 40 to 120 |
| Off-site certified backup | Second site copy, 30-day retention | EUR 50 to 150 |
| Standard non-certified hosting | Not allowed for this data | Not applicable |
Major clouds (European offers from AWS, Azure, Google, plus OVHcloud, IONOS, Open Telekom Cloud) provide certified regions. The premium over standard hosting is around 20 to 40%.
Obligations beyond the host
A certified host only solves part of compliance. The app itself must be designed to protect data: role-based access control, traceability, encryption, retention periods.
| Obligation | What to implement | 2026 indicative cost (excl. VAT) |
|---|---|---|
| DPIA (GDPR impact assessment) | Risk mapping, measures, DPO opinion | EUR 2,000 to 6,000 |
| Access logging | Who viewed which record and when, kept 6 months to 1 year | EUR 1,500 to 4,000 |
| Encryption at rest and in transit | Encrypted database and files, TLS 1.3 | EUR 800 to 2,500 |
| Strong authentication | MFA or national health ID login for clinicians | EUR 1,500 to 5,000 |
| Consent and rights management | Access, rectification, record export | EUR 1,500 to 3,500 |
| Outsourced DPO | If no internal DPO | EUR 300 to 900/month |
| Annual penetration test | Grey box before go-live | EUR 6,000 to 15,000 |
A DPIA is mandatory for large-scale processing of health data. It must be done before go-live and reviewed with every significant change.
Mini case study
Julian, founder of a network of 6 rehabilitation centres in Berlin (4,200 patients per year), is launching an app to track exercises and assessments between sessions.
Compliance budget: high-availability certified instance at EUR 450 per month, i.e. EUR 5,400 per year; DPIA at EUR 3,500; logging, encryption and MFA built into development for EUR 6,500; outsourced DPO at EUR 400 per month, i.e. EUR 4,800 per year. Year one: EUR 20,200, then about EUR 10,200 per year. Compared with the risk of a fine or breach (notifying 4,200 patients, forensics, reputation), this cost is about EUR 2.40 per patient per year at steady state.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
FAQ
Does a wellness app without prescriptions need certified hosting?
It depends on the data: step counts alone are not necessarily health data, but rehabilitation assessments or conditions are. When in doubt, a DPIA at EUR 2,000 to 6,000 settles it.
Can we host with a US cloud provider?
Yes if the region and service are certified and data stays in the EU, but extraterritorial access risk must be analysed in the DPIA. Public health contracts increasingly favour sovereign cloud offers.
How long should access logs be kept?
Usually 6 months to 1 year according to regulator guidance, and the logs themselves must be protected against tampering.
What fines apply for non-compliance?
Up to EUR 20M or 4% of global turnover; in practice, recent fines against health players range from tens of thousands to over EUR 1M.
How long does compliance take?
Allow 6 to 10 weeks for the DPIA, migration to the certified host and traceability development.
Let's scope your project. We build your health app on certified hosting with traceability, encryption and a DPIA, backed by an indicative budget and a 6 to 10 week plan. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.

