EU compliance
Nine guarantees, and how to verify each one
Where the data is, and who controls it
Data in Italy
Verifiable now
The medical record, photographs, and backups are on Italian infrastructure, within the European Union. Not on U.S. clouds, and with no replicas outside the EU.
Proof Check the registry yourself: a ‘whois’ query on the site’s address returns ARUBA-NET, Aruba S.p.A., country IT. The full supply chain is in the sub-processors list.
CheckNo intermediaries
Verifiable now
Between your browser and our server, there’s no one else: no content delivery network, no third-party proxy, no externally managed application firewall. No non-European entities in the data path.
Proof The domain resolves directly to the infrastructure’s address: a DNS query shows this, and anyone can verify it, even against us.
CheckYou are the data controller
Verifiable now
The patients are yours, the medical record is yours, and you make the treatment decisions. We are processors and act on your written instructions.
Proof Full Art. 28 GDPR agreement published, no form to fill out. You sign it before starting, and your consultant can read it now.
Check
What you can do with it
European code of conduct
Verifiable now
The provider hosting the data adheres to the CISPE cloud services code of conduct, approved by the CNIL in 2021 under Art. 40 of the GDPR.
Proof Registration is in the public CISPE registry, which isn’t managed by us or the provider.
Verify at the sourceEvery access is logged
Verifiable now
Whoever opens a record leaves a line: who, when, which resource, and the outcome. The lines are linked by a chain of hashes, so they can’t be rewritten afterward without it being visible.
Proof You can consult the register, not just us, and it’s the measure Art. 32 GDPR explicitly names. The chain is verified by a public page, no registration required.
CheckExiting is a feature
Verifiable now
Export everything in FHIR R4, an international healthcare standard, anytime and without asking our permission. If you switch providers, your data goes with you.
Proof Art. 20 GDPR on portability, prescription 2.6 of Annex II of the EHDS regulation, and the application guidelines of Art. 78 of the medical code of ethics, which require physicians to prioritize services with a platform-independent format.
Check
What we don’t do, and what we don’t have
A list of wins alone isn’t a document: it’s an advertising brochure
No training on your data
Verifiable now
The providers of the models we use are contractually excluded from training on data processed through our calls. Dictation is transcribed by a European provider, and the audio isn’t stored.
Proof Every provider is listed in the sub-processors register, with their headquarters, service, data category, and legal basis.
CheckISO 27001: the data center yes, we no
We don’t have it
The certification belongs to the infrastructure host and covers the data center. It doesn’t address our code, access control, or key management, and we don’t present it as if it did.
Proof We adopt the Annex A controls as a reference, without third-party certification. It’s stated in paragraph 12 of the security measures sheet.
CheckCE marking: from 2029, and no one has it yet
Not yet enforceable
The European Health Data Space regulation will make CE marking mandatory for electronic health records. Today, it can’t be applied: the Commission’s implementing acts are missing.
Proof Reg. (EU) 2025/327, Arts. 39 and 41, applicable from March 26, 2027, and March 26, 2029, for priority categories. Be wary of anyone claiming compliance already today.
Check
The regulation that changes the rules
From 2029 a medical record must be CE marked
Regulation (EU) 2025/327 establishes the European Health Data Space and sets out a harmonized framework for electronic health record systems. It applies from 26 March 2027, and from 26 March 2029 for systems intended for priority categories of health data.
This isn’t a formality for the procurement office: it’s a product requirement. Anyone selling a medical record system will have to prove they meet these standards, and those who don’t will be pushed out of the European market.
Today, no one can apply the CE marking: the European Commission’s implementing acts on the testing environment and data exchange format are still missing. If a provider claims it now, they’re telling you something about themselves.
REG. (EU) 2025/327 · CHAPTER III
- Art. 37
- Technical documentationThe manufacturer drafts it before placing the system on the market and keeps it updated. It demonstrates compliance with the essential requirements of Annex II.
- Art. 39
- EU Declaration of ConformityCertifies compliance with essential requirements. Remains accessible for at least ten years from the date of placement on the market.
- Art. 40
- European Digital Test EnvironmentHarmonised software components must be assessed there before being placed on the market. Common specifications are delegated to implementing acts of the Commission.
- Art. 41
- CE conformity markingApplied visibly, legibly, and indelibly on documents accompanying the system before it is placed on the market.
Measured, not promised
The requirements where an answer is already possible
Four requirements in Annex II don’t depend on the missing implementing acts. We can address those now, including where we’re halfway there.
- 2.6
- Exiting must not be cumbersomeSoddisfatta
No features that make authorised export cumbersome for replacing the system with another product. How Full export in FHIR R4 is a built-in feature, available without asking for our permission.
- 3.1
- Identify who accessesSoddisfatta
Reliable mechanisms for identifying and authenticating healthcare professionals. How Two-factor authentication, hardened sessions, separate roles, practice compartments.
- 3.2 e 3.3
- Log access and review itSoddisfatta
Logging of every access event, with tools to analyse the data. How FHIR AuditEvent log linked by a hash chain, which you can review yourself.
- 3.4
- Differentiated retention and accessParziale
Retention periods and access rights vary by data origin and category. How Differentiated retention is active; granularity by source is not. We’re telling you now, not when they ask.
This isn’t a courtesy on our part
Being able to take your data with you is your duty, not our concession
Gli indirizzi applicativi allegati all’art. 78 del codice di deontologia medica chiedono al medico di usare sistemi affidabili e di privilegiare i servizi che consentano la creazione di un formato indipendente rispetto alla piattaforma, senza che sia impedito il riuso dell’informazione, assicurandone disponibilità, riservatezza e modalità di conservazione.
In other words: choosing a management system you can’t leave isn’t just a commercial risk: it’s a deontological issue for you. The same requirement is set out in Article 20 of the GDPR on data portability and Prescription 2.6 of Annex II of the European Regulation.
That’s why export here is a feature, not a request: FHIR R4, complete, whenever you want, without going through us. It’s also why we have no interest in locking you in with a proprietary format: we’d rather tell you upfront.
For your consultant
Everything public, no form to fill out
A provider hiding the contract behind a request form is already telling you something. These are available now, even before you talk to us.
- Data processing agreementArticle 28 between you, the data controller, and us, the data processor.
- Sub-processorsWho accesses data besides us, including their headquarters, service, and legal basis.
- Security measuresThe record pursuant to Article 32, including declared limitations.
- The eight questionsShort answers, no generic reassurances.