Skip to main content
IusMedical

Trust Center

Compliance and data sovereignty

Before patient data enters an external system, the DPO has to give the go-ahead: this is where many projects stall. At IusMedical the documentation is in place from the first meeting, and the data does not leave Europe.

Prepared for DPO scrutiny

Health data is a special category of personal data (Article 9 GDPR): legal basis, security and traceability must be demonstrated before work even begins. We keep them documented, service by service.

  • A legal basis for each service, with the applicable article (Article 9(2)(h) for care, point (f) for the defence of legal claims)
  • Sensitive data encrypted at rest and in transit
  • Relevant operations logged, with retention aligned to the purposes
  • Patient identifiers pseudonymised in databases and absent from logs
  • Framework verified with our legal partner
Medical management and the DPO reviewing compliance documentation together

AI Act: the decision stays with the doctor

The real question is about responsibility: the output is a proposal, and the signature remains with the person. Cartella Clinica Sicura operates at the level of document validation - completeness, consistency and compliance, not diagnosis or clinical decision-making. Referto Sicuro supports the drafting of the report without taking the place of the doctor's judgement. The compliance architecture is built on the substantive requirements of the AI Act: risk management, human oversight, traceability.

Art. 14

The signature stays with the doctor

The output is a proposal: on reports, the doctor signs; on medical records, it is the reviewer's tool. Every acceptance, correction or rejection leaves a trace.

Art. 13 + 50

Transparency about origin

An always-visible notice states that the output is AI support and that the final decision rests with the doctor. The instructions for use are documented and can be handed over.

Art. 9

Risk under observation

Every interaction is classified by clinical risk and monitored; we track over time how much the doctor corrects. Risk management documentation is kept up to date.

Art. 12

Every step can be reconstructed

Every interaction leaves a record: what was asked, with what outcome, and when. Enough to retrace the workflow in an audit or in litigation.

Data sovereignty

Where does the data end up? It stays in Europe.

AI processing in data centres within the EU, storage and backup on European infrastructure, encrypted at rest and in transit. The entire data cycle - processing, storage, backup, logs - stays on the continent.

No transfers outside the EU
Map of the countries of the European Union, with EU member states highlighted
Processing
Storage and backup
Logs and audit trail

The DPO's dossier, already on the table

At the first meeting we hand over a complete compliance dossier: the documents the DPO has to give an opinion on are already prepared, to be read and signed.

DocumentContentsReference
Impact assessment (DPIA)Purposes, categories of data subjects, security measures, risk assessmentArticle 35 GDPR
Record of processing activitiesData categories, purposes, retention, sub-processorsArticle 30 GDPR
Legal basisSpecific reference to the applicable article for each serviceArticle 6 / Article 9 GDPR
AI Act documentationRisk management, instructions for use, risk classificationRegulation (EU) 2024/1689
Supplier security profileTechnical and organisational measures, data residency, sub-processors, continuityENISA standards
Standard DPAContract to sign as it stands, or to adapt to the template in useArticle 28 GDPR

Sub-processors, DPA, reporting

Two people checking a document together during a compliance due diligence

Who processes the data

A small number of European suppliers for AI processing, storage and backup. The list of sub-processors, with processing categories and hosting region, is available to the DPO on request.

A DPA to sign as it stands

A standard Data Processing Agreement, available for signature. If the organisation prefers its own template, we discuss the clauses with our legal partner.

Security reports

Vulnerabilities or security incidents: write to privacy@iusmedical.it. We practise responsible disclosure.

Talk to the compliance team

Due diligence, security assessments, aligning the DPA with the template in use, pre-litigation reviews.