ISO/IEC 27001:2022 certified. Processing in the EU.
- ISO/IEC 27001:2022
- certified by TÜV NORD CERT
- 44 121 251903
- certificate number, valid to 17 May 2029
- EU
- processing and storage exclusively in the European Union
- No training
- patient data is not used to train AI models
Information security
In its certificate dated 18 May 2026, TÜV NORD CERT confirms that aiomics operates an information security management system in accordance with ISO/IEC 27001:2022. In annual surveillance audits the certification body checks that it continues to meet the requirements.
ISO/IEC 27001:2022 certified
TÜV NORD CERT GmbH
- Certificate registration no.
- 44 121 251903
- Validity
- 18 May 2026 – 17 May 2029
- Scope
- Development, operation and maintenance of the aiomics generative AI healthcare SaaS solution.
BSI C5: our own application-level C5 attestation is in preparation. Until then, we provide the existing evidence, each with its scope, for your hospital's review.
Data protection
Processing on your behalf under the GDPR
Aiomics processes patient data on behalf of the hospital, under a data processing agreement in accordance with Art. 28 GDPR. The legal basis for processing is Art. 6 and Art. 9 GDPR; we process no patient data without the hospital's legal basis.
Data stays in the EU
Patient data is processed and stored exclusively in data centres within the European Union.
Separate tenants
Each hospital's data stays in its own tenant, separated from the data of other hospitals.
No training on patient data
Patient data is not used to train AI models.
Current certificates, sub-processors and security notices are listed at trust.aiomics.io.
Protection plan
A protection plan for original records, identity data and health data
01
Read
The platform reads what the hospital provides: letters, findings, lab results, scans and faxes.
02
Distinguish three kinds of data
03
Limit data used for processing
The protection plan includes data minimisation and pseudonymisation. The technical and organisational documentation describes the data flows and safeguards.
04
Trace sources and processing
Sourced statements keep their source. We set the scope of logging and access rights together with your hospital.
Schematic illustration. The agreed data flows and safeguards are documented for each hospital.
Sign-off and responsibility
A physician or the responsible professional signs off every document, and can check any sourced statement against its source in one click.
For reports and physician letters, the integrOS review layer compares the draft with its sources in a separate pass. References that the sources do not support are removed, and the draft is written again. Short standard letters started from the boards (acceptance, rejection, requests for documents) get a reference check only.
Errors and omissions can still remain, including in the original records. That is why professional sign-off is a fixed part of the workflow. The hospital decides who signs off which documents and whether additional technical approval stages are needed.
EU AI Act
We assess the regulatory classification for the defined functionality and intended use. Our management system records intended purpose, labelling obligations and responsibilities. On request, you receive the relevant documents and the state of the assessment for the scope agreed with your hospital.
Works council
For discussions with the works council, we provide information about purpose, functional scope, data processing and working practices. The platform shows usage analytics only at team level and only for groups of ten or more; that limit is set in the software. We discuss access rights, logging and potential effects on staff with you. The hospital assesses the consultation requirements for the particular deployment.
Independent evaluation
Work with aiomics is being evaluated independently and scientifically at the Charité Institute of Medical Informatics. The Charité evaluates independently and does not endorse aiomics. The evaluation is ongoing; we will report results once they are published.
Data model, interfaces, coding
FHIR R4 is the internal data model. Direct connections, for example via HL7 v2, FHIR or ISiK, are assessed and agreed for each system. Most interfaces still need to be built or configured; the starting route is file export and agreed handovers.
ICD-10-GM · LOINC
Report a vulnerability
If you believe you have found a security vulnerability in one of our systems, please email security@aiomics.io. We acknowledge reports within 3 working days.
Less searching. Less writing. More medicine.
Let's talk about the first workflow in your hospital.
Book a conversation