How we protect your data.
Data Protection
GDPR-compliant
Processing based on the legal basis of Art. 6 and Art. 9 GDPR. No processing of patient data without the hospital's legal basis.
Data stays in the EU
All patient data is processed and stored exclusively in data centers within the European Union.
Application-level C5 attestation in preparation
Our own application-level C5 attestation is in preparation. Available evidence and its respective scope are provided for your hospital’s review.
No training on patient data
Patient data is not used for training AI models. Hospital data remains isolated within the respective tenant context.
For live certifications, sub-processors, and incident notices, see our Trust Center.
How we protect your data
A protection plan for original records, identity and health data.
01
Extraction
Data from all sources is captured — referral letters, findings, lab results, handwritten notes.
02
Account for three data categories
03
Limit data used for processing
Our protection plan includes data minimisation and pseudonymisation. Technical and organisational documentation describes the data flows and specific safeguards.
04
Trace sources and processing
Source references support review of information taken from records. We clarify the scope of logging and access rights with your hospital.
Patient data is processed within the EU and is not used to train AI models. Agreed data flows and safeguards are documented.
Information Security
aiomics is certified to ISO/IEC 27001:2022. TÜV NORD CERT confirms in its certificate dated 18 May 2026 that aiomics operates a management system in accordance with the requirements of ISO/IEC 27001:2022 — covering the development, operation, and maintenance of the aiomics generative AI healthcare SaaS solution.
ISO/IEC 27001:2022 certified
TÜV NORD CERT GmbH
- Certificate registration no.
- 44 121 251903
- Validity
- 18 May 2026 – 17 May 2029
- Scope
- Development, operation, and maintenance of the aiomics generative AI healthcare SaaS solution.
EU AI Act
Regulatory assessment is carried out for each defined functional scope. Intended purpose, AI output labelling, and review responsibilities are documented in the management system. We provide your hospital with documentation of the assessment and intended use on request.
All AI outputs of the platform are labeled as suggestions and drafts. Physician review and approval is required at every step.
Works Council
For discussions with the works council, we provide information about purpose, functional scope, data processing and working practices. These discussions can also cover access rights, logging and potential effects on staff. The hospital assesses consultation requirements for the particular deployment.
Independent Evaluation
The effectiveness of aiomics is currently being evaluated in an independent scientific study at the Charité Institute for Medical Informatics. Results will be published upon completion.
Technical Standards and Coding Systems
HL7v2 · FHIR R4 · ISiK · IHE XDS.b
ICD-10-GM · LOINC
Questions about data protection, regulation, or integration?
Get in touchWe respond personally — no call center, no automated emails.