◆ SECURITY
Information security and compliance
Edith Care - AI for human-centered work in assessment, care and support
Version 3.0 · 2026-08-18
Summary
We understand that healthcare handles some of society's most sensitive information. Information security and compliance have therefore been core design principles from day one.
Edith Care is documentation support - not an electronic health record system and not a medical device. All clinical content created in Edith Care remains draft material until the responsible registered psychologist reviews, approves and transfers it to the clinic's health record system.
OUR CORE SECURITY PROMISES
- •All patient data (database, AI processing, file storage) is stored and processed in Azure Sweden Central
- •All information is encrypted, both at rest and in transit
- •Full traceability - every access to patient data is logged
- •AI summarises and suggests only - all clinical judgements are made by registered health professionals
- •Full compliance with UK GDPR, the Data Protection Act 2018 and applicable professional record-keeping standards
- •Aligned with the EU AI Act, whose main obligations have applied since 2 August 2026
01
Compliance
Edith Care is designed to support the care provider in meeting the relevant rules for processing personal data in healthcare.
UK GDPR and the Data Protection Act 2018
Health data is special category data under UK GDPR Article 9. Edith Care processes such data on the basis of Article 9(2)(h) (processing necessary for the provision of health care, under a duty of confidentiality), together with a Schedule 1 condition in the Data Protection Act 2018.
PRINCIPLES BUILT INTO EDITH CARE
- •Lawfulness and transparency - processing rests on a documented legal basis
- •Purpose limitation - patient data is used solely for documentation support
- •Data minimisation - only necessary data is processed
- •Storage limitation - data is deleted from Edith Care after transfer to the health record system
- •Integrity and confidentiality - technical and organisational safeguards
- •Data protection by design - built into all development
DATA PROCESSING AGREEMENT (ARTICLE 28)
- •A data processing agreement is concluded with every care provider using Edith Care
- •The agreement governs purpose, data categories, security measures, sub-processors, data residency, deletion routines and audit rights
DATA PROTECTION IMPACT ASSESSMENT (DPIA)
- •Edith Care supports the care provider's obligation to carry out a data protection impact assessment (Article 35)
- •Documentation of technical and organisational measures is provided as supporting material
Clinical record keeping and confidentiality
RECORD KEEPING
- •AI-generated content in Edith Care is a draft for the clinical record
- •The responsible registered psychologist reviews, edits and approves all content before transfer to the health record system
- •The clinician who signs the record entry is accountable for its accuracy
INFORMATION SECURITY
- •Individual user identification and authentication
- •Access control based on a documented needs and risk analysis
- •Complete access logging
- •Encrypted transfer of patient data
The EU AI Act (2024/1689)
The EU AI Act applies in stages: prohibitions on unacceptable risk since February 2025, obligations for general-purpose AI models since August 2025, and the bulk of the rules, including the high-risk requirements, since 2 August 2026. The Act applies to Edith Care as an EU-established provider and shapes how the service is built in every market.
CLASSIFICATION
Edith Care is classified as documentation support that neither makes nor influences clinical decisions. The system performs no diagnostics, no symptom scoring and gives no treatment recommendations. Based on MDCG 2019-11 rev.1 and Annex III of the AI Act, Edith Care is assessed as not constituting a high-risk AI system.
MEASURES IN PLACE
- •Risk management system with documented risks and mitigations (Article 9)
- •Technical documentation of the system's design and function (Article 11)
- •Transparency - clear explanation of the AI's capabilities and limitations (Article 13)
- •Human oversight - every suggestion is reviewed by a registered health professional (Article 14)
- •AI literacy - training material and ongoing support for users (Article 4)
Medical device classification
Edith Care is a documentation tool, not a medical device under the UK Medical Devices Regulations 2002 or EU MDR 2017/745. Its intended purpose is to support psychologists with text structuring, language quality and formatting of assessment reports. The system performs no diagnostics, no symptom scoring and gives no treatment recommendations. All clinical judgements are made solely by the registered psychologist.
In line with MDCG 2019-11 rev.1, software that stores, archives or communicates data without clinical interpretation does not qualify as a medical device. A self-assessment has been carried out and documented.
Edith Care follows the MHRA's ongoing work on AI assistants in healthcare and will adapt its classification and compliance if needed.
02
Data protection and encryption
Data storage in Sweden
All patient data - database, AI processing and file storage - is stored and processed in Sweden via Microsoft Azure Sweden Central (data centres in Sandviken/Gävle and Staffanstorp), under Microsoft's EU Data Boundary commitments. For UK customers this is a transfer to the EEA, which benefits from UK adequacy.
Support services for product analytics (PostHog) and AI monitoring (Langfuse) are hosted in the EU and process metadata only - never patient data. Azure Sweden Central is ISO 27001 and SOC 2 certified.
Encryption
| Protection level | Standard | Description |
|---|---|---|
| At rest | AES-256 | Industry standard for sensitive data |
| In transit | TLS 1.3 | Latest and most secure standard |
| Key management | Azure Key Vault | Dedicated key management with strict access control |
| Audio files | AES-256 + deletion | Encrypted during processing, deleted after transcription |
| Database | AES-256 + SSL | Azure-managed encryption with enforced SSL connections |
No unencrypted patient data is stored or transmitted.
Access control
| Authentication | Strong authentication with multi-factor authentication (MFA) |
| Role-based permissions | Users see and work with data for their own patients only |
| Individual accounts | No shared accounts are permitted |
| Session control | Automatic logout after inactivity |
| Permission assignment | Supports the care provider's documented needs and risk analysis |
03
Traceability and logging
Full traceability is essential to support the care provider's obligation to control access to patient data.
What is logged
| Field | Description |
|---|---|
| User ID | Who accessed the data |
| Timestamp | When the access occurred |
| Action type | Read, write, export, delete |
| Resource | Which patient case or resource was involved |
| Outcome | Whether access was granted or denied |
Log management
- •Logs are stored securely and protected against tampering
- •Log data never contains clinical patient content - only metadata and identifiers
- •The care provider can request log extracts for internal control and on patient request
- •Automatic alerts on anomalous access patterns
- •Logs are retained in line with the care provider's policy and applicable legal requirements
04
AI and human control
Edith Care uses AI to support registered psychologists in their documentation work - never to replace professional clinical judgement. This is a fundamental design principle.
AI as documentation support, not clinical decision-making
- •AI suggests text structure, phrasing and summaries
- •AI performs no diagnostics, no symptom scoring and gives no treatment recommendations
- •All clinical judgements are made solely by the registered psychologist
- •AI-generated content is clearly marked as suggestions requiring professional review
Transparency and explainability
Whenever AI generates a suggestion, it is always clear that:
- •It is a draft that requires review by a registered psychologist
- •The psychologist is accountable for the final record content
- •AI has limitations and can produce incorrect or incomplete suggestions
- •The tool is documentation support, not clinical decision support
Information to patients
Edith Care recommends that care providers inform patients that AI-assisted documentation is used. Support for this is provided through:
- •Recommended wording for the clinic's privacy notice
- •Guidance for verbal information at the start of an assessment
- •Clear information that AI does not influence the clinical judgement
Secure AI infrastructure
| No public AI | Data is never sent to public AI services (such as ChatGPT, Gemini or similar) |
| No training on customer data | Patient data is never used to train AI models |
| EU/EEA processing | All AI processing takes place in Sweden (Azure Sweden Central) |
| Agreements with AI vendors | Explicit prohibition on using data for model training |
| Product analytics (PostHog) | Receives event names and resource IDs only - never patient names, clinical text or health data. Hosted in the EU. |
| AI monitoring (Langfuse) | In production, no AI prompts or responses are recorded - only metadata (response times, token counts, model version). Hosted in the EU. |
05
Data lifecycle and retention
Edith Care's role in the documentation flow
Edith Care handles patient data as draft record material - drafts that are worked on and reviewed by the psychologist before transfer to the clinic's official health record system. Edith Care is not the health record system.
THE DOCUMENTATION FLOW
- 1.Session recording - audio recorded in Edith Care
- 2.Transcription - audio converted to text
- 3.AI-assisted report writing - AI helps with structure and phrasing
- 4.Review by the psychologist - the registered psychologist reviews and edits
- 5.Transfer to the record system - approved content is transferred
- 6.Signing in the record system - the psychologist signs the record entry
- 7.Deletion from Edith Care - patient data is deleted from Edith Care
Data handling per phase
| Phase | Data type | Retention in Edith Care | Action |
|---|---|---|---|
| Recording | Audio file | Temporary - deleted after transcription | Encrypted during processing |
| Transcription | Transcript | Until the report is complete | Available to the psychologist |
| Report writing | Draft report | Until the report is approved and transferred | AI support available |
| Transfer | Final report | Deleted after confirmed transfer | Automatic or manual deletion |
Retention responsibility
- •Statutory retention of clinical records rests with the health record system, not with Edith Care
- •Edith Care deletes patient data after transfer to the record system, according to the configured retention period
- •The care provider sets the retention period in Edith Care (recommendation: 30 days after transfer)
- •Deletion is permanent and verifiable
Data minimisation
- •Audio files are deleted immediately after successful transcription
- •Transcripts and drafts are deleted after transfer to the record system
- •Only the data needed for the current documentation purpose is processed
- •No personal data is retained in Edith Care longer than necessary
06
Infrastructure and suppliers
Infrastructure overview
| Component | Supplier | Region | Certification |
|---|---|---|---|
| Application hosting | Microsoft Azure | Sweden Central | ISO 27001, SOC 2, C5 |
| AI model (text) | Azure OpenAI Service | Sweden Central | ISO 27001, SOC 2 |
| AI model (transcription) | Azure Speech Services | Sweden Central | ISO 27001, SOC 2 |
| Key management | Azure Key Vault | Sweden Central | FIPS 140-2 Level 2 |
| Data storage | Azure Blob Storage | Sweden Central | ISO 27001, SOC 2 |
Note: the web application is delivered via Vercel (CDN and edge network). In Edith Care's architecture Vercel acts solely as a reverse proxy for static frontend files and API calls forwarded to Azure Sweden Central. No edge functions, serverless functions or log drains that process patient data are enabled. All persistent data storage and AI processing takes place in Azure Sweden Central.
Network security
- •Encrypted communication between all components (TLS 1.3)
- •Firewall protection at application and network level
- •Regular security scanning
- •Penetration testing planned as part of ongoing certification work
Requirements on cloud suppliers
All infrastructure suppliers meet the following minimum requirements:
- •Data centres in Sweden (Azure Sweden Central)
- •ISO 27001 certification (information security)
- •GDPR compliance and a data processing agreement under Article 28
- •Support for encryption at rest and in transit
- •Provision for audit and transparency
Sub-processors
All sub-processors handling personal data are covered by:
- •A data processing agreement with specific requirements for health data
- •A prohibition on processing outside the EU/EEA without approval
- •An explicit prohibition on using patient data for model training
- •A requirement to notify Edith Care of changes affecting data security
A named list of sub-processors is set out in Annex 2 of our data processing agreement.
07
Incident management
In the event of a security or personal data breach, Edith Care follows established routines:
| Step | Deadline | Action |
|---|---|---|
| Detection | Immediately | Internal classification and containment of the incident |
| Notification to the care provider | Within 24 hours | The care provider is informed of type, scope and recommended actions |
| Notification to the ICO | Within 72 hours | The controller notifies the ICO. Edith Care provides supporting material. |
| Information to patients | Without undue delay | The care provider informs affected patients where risk is high. Edith Care assists. |
| Investigation | Ongoing | Root cause analysis and remediation plan |
| Follow-up | Within 30 days | Documentation of lessons learned and improvements |
08
Additional regulatory compliance
Network and information security
Healthcare is treated as an essential service under UK network and information systems rules, and our EU operations fall under the Swedish Cybersecurity Act (2025:1506) implementing NIS2. Edith Care supports the care provider's compliance through:
- •Robust incident management with the ability to report security incidents within 24 hours
- •Systematic security work with documented risk assessments
- •Supply chain security - all sub-processors undergo security review
- •Continuity planning and operational continuity routines
Data portability
- •Complete data export in standard formats
- •Support for switching provider without technical obstacles
- •Documented APIs and data formats
- •Assistance with migration to another provider
Accessibility
The website partially conforms to WCAG 2.2 level AA and was last assessed internally on 31 March 2026. Known limitations and how to give feedback are set out in our accessibility statement.
Digital identity
Edith Care follows the development of the European Digital Identity Wallet (EUDI Wallet) and is preparing for integration as national solutions become available.
09
Current status
Security level
All handling of patient data operates at production-grade security. Encryption, access control, logging and compliance are implemented and active.
In development
The following work is under way:
- •Validation of AI-generated content against source material
- •Penetration testing as part of ongoing certification work
10
Contact information
For questions about information security and data protection, contact:
Edith Care (Jobello Technology AB)
Company registration number: 559311-6907
Data protection lead: Fredrik Gordh Riseby
fredrik[at]edithcare[dot]se
This document describes Edith Care's security architecture and compliance for use in healthcare. For detailed technical documentation on infrastructure and suppliers, contact us for our technical annex. The document is updated on an ongoing basis as regulation and the product evolve.