E
Log in

◆ SECURITY

Information security and compliance

Edith Care - AI for human-centered work in assessment, care and support

Version 3.0 · 2026-08-18

Summary

We understand that healthcare handles some of society's most sensitive information. Information security and compliance have therefore been core design principles from day one.

Edith Care is documentation support - not an electronic health record system and not a medical device. All clinical content created in Edith Care remains draft material until the responsible registered psychologist reviews, approves and transfers it to the clinic's health record system.

OUR CORE SECURITY PROMISES

  • All patient data (database, AI processing, file storage) is stored and processed in Azure Sweden Central
  • All information is encrypted, both at rest and in transit
  • Full traceability - every access to patient data is logged
  • AI summarises and suggests only - all clinical judgements are made by registered health professionals
  • Full compliance with UK GDPR, the Data Protection Act 2018 and applicable professional record-keeping standards
  • Aligned with the EU AI Act, whose main obligations have applied since 2 August 2026

01

Compliance

Edith Care is designed to support the care provider in meeting the relevant rules for processing personal data in healthcare.

UK GDPR and the Data Protection Act 2018

Health data is special category data under UK GDPR Article 9. Edith Care processes such data on the basis of Article 9(2)(h) (processing necessary for the provision of health care, under a duty of confidentiality), together with a Schedule 1 condition in the Data Protection Act 2018.

PRINCIPLES BUILT INTO EDITH CARE

  • Lawfulness and transparency - processing rests on a documented legal basis
  • Purpose limitation - patient data is used solely for documentation support
  • Data minimisation - only necessary data is processed
  • Storage limitation - data is deleted from Edith Care after transfer to the health record system
  • Integrity and confidentiality - technical and organisational safeguards
  • Data protection by design - built into all development

DATA PROCESSING AGREEMENT (ARTICLE 28)

  • A data processing agreement is concluded with every care provider using Edith Care
  • The agreement governs purpose, data categories, security measures, sub-processors, data residency, deletion routines and audit rights

DATA PROTECTION IMPACT ASSESSMENT (DPIA)

  • Edith Care supports the care provider's obligation to carry out a data protection impact assessment (Article 35)
  • Documentation of technical and organisational measures is provided as supporting material

Clinical record keeping and confidentiality

RECORD KEEPING

  • AI-generated content in Edith Care is a draft for the clinical record
  • The responsible registered psychologist reviews, edits and approves all content before transfer to the health record system
  • The clinician who signs the record entry is accountable for its accuracy

INFORMATION SECURITY

  • Individual user identification and authentication
  • Access control based on a documented needs and risk analysis
  • Complete access logging
  • Encrypted transfer of patient data

The EU AI Act (2024/1689)

The EU AI Act applies in stages: prohibitions on unacceptable risk since February 2025, obligations for general-purpose AI models since August 2025, and the bulk of the rules, including the high-risk requirements, since 2 August 2026. The Act applies to Edith Care as an EU-established provider and shapes how the service is built in every market.

CLASSIFICATION

Edith Care is classified as documentation support that neither makes nor influences clinical decisions. The system performs no diagnostics, no symptom scoring and gives no treatment recommendations. Based on MDCG 2019-11 rev.1 and Annex III of the AI Act, Edith Care is assessed as not constituting a high-risk AI system.

MEASURES IN PLACE

  • Risk management system with documented risks and mitigations (Article 9)
  • Technical documentation of the system's design and function (Article 11)
  • Transparency - clear explanation of the AI's capabilities and limitations (Article 13)
  • Human oversight - every suggestion is reviewed by a registered health professional (Article 14)
  • AI literacy - training material and ongoing support for users (Article 4)

Medical device classification

Edith Care is a documentation tool, not a medical device under the UK Medical Devices Regulations 2002 or EU MDR 2017/745. Its intended purpose is to support psychologists with text structuring, language quality and formatting of assessment reports. The system performs no diagnostics, no symptom scoring and gives no treatment recommendations. All clinical judgements are made solely by the registered psychologist.

In line with MDCG 2019-11 rev.1, software that stores, archives or communicates data without clinical interpretation does not qualify as a medical device. A self-assessment has been carried out and documented.

Edith Care follows the MHRA's ongoing work on AI assistants in healthcare and will adapt its classification and compliance if needed.

02

Data protection and encryption

Data storage in Sweden

All patient data - database, AI processing and file storage - is stored and processed in Sweden via Microsoft Azure Sweden Central (data centres in Sandviken/Gävle and Staffanstorp), under Microsoft's EU Data Boundary commitments. For UK customers this is a transfer to the EEA, which benefits from UK adequacy.

Support services for product analytics (PostHog) and AI monitoring (Langfuse) are hosted in the EU and process metadata only - never patient data. Azure Sweden Central is ISO 27001 and SOC 2 certified.

Encryption

Protection levelStandardDescription
At restAES-256Industry standard for sensitive data
In transitTLS 1.3Latest and most secure standard
Key managementAzure Key VaultDedicated key management with strict access control
Audio filesAES-256 + deletionEncrypted during processing, deleted after transcription
DatabaseAES-256 + SSLAzure-managed encryption with enforced SSL connections

No unencrypted patient data is stored or transmitted.

Access control

AuthenticationStrong authentication with multi-factor authentication (MFA)
Role-based permissionsUsers see and work with data for their own patients only
Individual accountsNo shared accounts are permitted
Session controlAutomatic logout after inactivity
Permission assignmentSupports the care provider's documented needs and risk analysis

03

Traceability and logging

Full traceability is essential to support the care provider's obligation to control access to patient data.

What is logged

FieldDescription
User IDWho accessed the data
TimestampWhen the access occurred
Action typeRead, write, export, delete
ResourceWhich patient case or resource was involved
OutcomeWhether access was granted or denied

Log management

  • Logs are stored securely and protected against tampering
  • Log data never contains clinical patient content - only metadata and identifiers
  • The care provider can request log extracts for internal control and on patient request
  • Automatic alerts on anomalous access patterns
  • Logs are retained in line with the care provider's policy and applicable legal requirements

04

AI and human control

Edith Care uses AI to support registered psychologists in their documentation work - never to replace professional clinical judgement. This is a fundamental design principle.

AI as documentation support, not clinical decision-making

  • AI suggests text structure, phrasing and summaries
  • AI performs no diagnostics, no symptom scoring and gives no treatment recommendations
  • All clinical judgements are made solely by the registered psychologist
  • AI-generated content is clearly marked as suggestions requiring professional review

Transparency and explainability

Whenever AI generates a suggestion, it is always clear that:

  • It is a draft that requires review by a registered psychologist
  • The psychologist is accountable for the final record content
  • AI has limitations and can produce incorrect or incomplete suggestions
  • The tool is documentation support, not clinical decision support

Information to patients

Edith Care recommends that care providers inform patients that AI-assisted documentation is used. Support for this is provided through:

  • Recommended wording for the clinic's privacy notice
  • Guidance for verbal information at the start of an assessment
  • Clear information that AI does not influence the clinical judgement

Secure AI infrastructure

No public AIData is never sent to public AI services (such as ChatGPT, Gemini or similar)
No training on customer dataPatient data is never used to train AI models
EU/EEA processingAll AI processing takes place in Sweden (Azure Sweden Central)
Agreements with AI vendorsExplicit prohibition on using data for model training
Product analytics (PostHog)Receives event names and resource IDs only - never patient names, clinical text or health data. Hosted in the EU.
AI monitoring (Langfuse)In production, no AI prompts or responses are recorded - only metadata (response times, token counts, model version). Hosted in the EU.

05

Data lifecycle and retention

Edith Care's role in the documentation flow

Edith Care handles patient data as draft record material - drafts that are worked on and reviewed by the psychologist before transfer to the clinic's official health record system. Edith Care is not the health record system.

THE DOCUMENTATION FLOW

  1. 1.Session recording - audio recorded in Edith Care
  2. 2.Transcription - audio converted to text
  3. 3.AI-assisted report writing - AI helps with structure and phrasing
  4. 4.Review by the psychologist - the registered psychologist reviews and edits
  5. 5.Transfer to the record system - approved content is transferred
  6. 6.Signing in the record system - the psychologist signs the record entry
  7. 7.Deletion from Edith Care - patient data is deleted from Edith Care

Data handling per phase

PhaseData typeRetention in Edith CareAction
RecordingAudio fileTemporary - deleted after transcriptionEncrypted during processing
TranscriptionTranscriptUntil the report is completeAvailable to the psychologist
Report writingDraft reportUntil the report is approved and transferredAI support available
TransferFinal reportDeleted after confirmed transferAutomatic or manual deletion

Retention responsibility

  • Statutory retention of clinical records rests with the health record system, not with Edith Care
  • Edith Care deletes patient data after transfer to the record system, according to the configured retention period
  • The care provider sets the retention period in Edith Care (recommendation: 30 days after transfer)
  • Deletion is permanent and verifiable

Data minimisation

  • Audio files are deleted immediately after successful transcription
  • Transcripts and drafts are deleted after transfer to the record system
  • Only the data needed for the current documentation purpose is processed
  • No personal data is retained in Edith Care longer than necessary

06

Infrastructure and suppliers

Infrastructure overview

ComponentSupplierRegionCertification
Application hostingMicrosoft AzureSweden CentralISO 27001, SOC 2, C5
AI model (text)Azure OpenAI ServiceSweden CentralISO 27001, SOC 2
AI model (transcription)Azure Speech ServicesSweden CentralISO 27001, SOC 2
Key managementAzure Key VaultSweden CentralFIPS 140-2 Level 2
Data storageAzure Blob StorageSweden CentralISO 27001, SOC 2

Note: the web application is delivered via Vercel (CDN and edge network). In Edith Care's architecture Vercel acts solely as a reverse proxy for static frontend files and API calls forwarded to Azure Sweden Central. No edge functions, serverless functions or log drains that process patient data are enabled. All persistent data storage and AI processing takes place in Azure Sweden Central.

Network security

  • Encrypted communication between all components (TLS 1.3)
  • Firewall protection at application and network level
  • Regular security scanning
  • Penetration testing planned as part of ongoing certification work

Requirements on cloud suppliers

All infrastructure suppliers meet the following minimum requirements:

  • Data centres in Sweden (Azure Sweden Central)
  • ISO 27001 certification (information security)
  • GDPR compliance and a data processing agreement under Article 28
  • Support for encryption at rest and in transit
  • Provision for audit and transparency

Sub-processors

All sub-processors handling personal data are covered by:

  • A data processing agreement with specific requirements for health data
  • A prohibition on processing outside the EU/EEA without approval
  • An explicit prohibition on using patient data for model training
  • A requirement to notify Edith Care of changes affecting data security

A named list of sub-processors is set out in Annex 2 of our data processing agreement.

07

Incident management

In the event of a security or personal data breach, Edith Care follows established routines:

StepDeadlineAction
DetectionImmediatelyInternal classification and containment of the incident
Notification to the care providerWithin 24 hoursThe care provider is informed of type, scope and recommended actions
Notification to the ICOWithin 72 hoursThe controller notifies the ICO. Edith Care provides supporting material.
Information to patientsWithout undue delayThe care provider informs affected patients where risk is high. Edith Care assists.
InvestigationOngoingRoot cause analysis and remediation plan
Follow-upWithin 30 daysDocumentation of lessons learned and improvements

08

Additional regulatory compliance

Network and information security

Healthcare is treated as an essential service under UK network and information systems rules, and our EU operations fall under the Swedish Cybersecurity Act (2025:1506) implementing NIS2. Edith Care supports the care provider's compliance through:

  • Robust incident management with the ability to report security incidents within 24 hours
  • Systematic security work with documented risk assessments
  • Supply chain security - all sub-processors undergo security review
  • Continuity planning and operational continuity routines

Data portability

  • Complete data export in standard formats
  • Support for switching provider without technical obstacles
  • Documented APIs and data formats
  • Assistance with migration to another provider

Accessibility

The website partially conforms to WCAG 2.2 level AA and was last assessed internally on 31 March 2026. Known limitations and how to give feedback are set out in our accessibility statement.

Digital identity

Edith Care follows the development of the European Digital Identity Wallet (EUDI Wallet) and is preparing for integration as national solutions become available.

09

Current status

Security level

All handling of patient data operates at production-grade security. Encryption, access control, logging and compliance are implemented and active.

In development

The following work is under way:

  • Validation of AI-generated content against source material
  • Penetration testing as part of ongoing certification work

10

Contact information

For questions about information security and data protection, contact:

Edith Care (Jobello Technology AB)

Company registration number: 559311-6907

Data protection lead: Fredrik Gordh Riseby

fredrik[at]edithcare[dot]se

This document describes Edith Care's security architecture and compliance for use in healthcare. For detailed technical documentation on infrastructure and suppliers, contact us for our technical annex. The document is updated on an ongoing basis as regulation and the product evolve.