Skip to main content

How we protect your data.

Data protection, information security, and regulatory compliance — here you will find the key facts about our technical and organizational setup.

Data Protection

GDPR-compliant

Processing based on the legal basis of Art. 6 and Art. 9 GDPR. No processing of patient data without the hospital's legal basis.

Data stays in the EU

All patient data is processed and stored exclusively in data centers within the European Union.

Application-level C5 attestation in preparation

Our own application-level C5 attestation is in preparation. Available evidence and its respective scope are provided for your hospital’s review.

No training on patient data

Patient data is not used for training AI models. Hospital data remains isolated within the respective tenant context.

For live certifications, sub-processors, and incident notices, see our Trust Center.

How we protect your data

A protection plan for original records, identity and health data.

01

Extraction

Data from all sources is captured — referral letters, findings, lab results, handwritten notes.

02

Account for three data categories

OriginalsIdentity data + pseudonymHealth data + pseudonym

03

Limit data used for processing

Our protection plan includes data minimisation and pseudonymisation. Technical and organisational documentation describes the data flows and specific safeguards.

04

Trace sources and processing

Source references support review of information taken from records. We clarify the scope of logging and access rights with your hospital.

Patient data is processed within the EU and is not used to train AI models. Agreed data flows and safeguards are documented.

Information Security

aiomics is certified to ISO/IEC 27001:2022. TÜV NORD CERT confirms in its certificate dated 18 May 2026 that aiomics operates a management system in accordance with the requirements of ISO/IEC 27001:2022 — covering the development, operation, and maintenance of the aiomics generative AI healthcare SaaS solution.

ISO/IEC 27001:2022 certified

TÜV NORD CERT GmbH

Certificate registration no.
44 121 251903
Validity
18 May 2026 – 17 May 2029
Scope
Development, operation, and maintenance of the aiomics generative AI healthcare SaaS solution.

EU AI Act

Regulatory assessment is carried out for each defined functional scope. Intended purpose, AI output labelling, and review responsibilities are documented in the management system. We provide your hospital with documentation of the assessment and intended use on request.

All AI outputs of the platform are labeled as suggestions and drafts. Physician review and approval is required at every step.

Works Council

For discussions with the works council, we provide information about purpose, functional scope, data processing and working practices. These discussions can also cover access rights, logging and potential effects on staff. The hospital assesses consultation requirements for the particular deployment.

Independent Evaluation

The effectiveness of aiomics is currently being evaluated in an independent scientific study at the Charité Institute for Medical Informatics. Results will be published upon completion.

Technical Standards and Coding Systems

Interfaces

HL7v2 · FHIR R4 · ISiK · IHE XDS.b

Coding

ICD-10-GM · LOINC

Questions about data protection, regulation, or integration?

Get in touch

We respond personally — no call center, no automated emails.