E
Log in

SECURITY

Information security and compliance

Edith Care - AI for human-centered work in assessment, care and support

Version 2.0 · 2026-03-31

Summary

We understand that behavioral health providers handle some of society's most sensitive information. Information security and compliance have therefore been core design principles from day one.

Edith Care is documentation support, not an electronic health record system and not a medical device. Clinical content remains draft material until a licensed clinician reviews and approves it.

OUR CORE SECURITY PROMISES

  • All patient data is stored and processed in the EU (Azure Sweden Central) — US-based hosting is coming ahead of our US launch
  • All information is encrypted at rest and in transit
  • Full traceability through access logging
  • AI summarizes and suggests only — clinicians make every decision
  • Built under the EU's GDPR, among the strictest privacy regimes in the world; HIPAA readiness program underway
  • Prepared for the EU AI Act

01

Compliance

Edith Care is designed and operated under the EU's GDPR, one of the strictest data protection frameworks in the world. Ahead of our US launch we have begun our HIPAA readiness program, preparing to operate as a business associate under HIPAA — talk to us about your regulatory requirements before onboarding protected health information.

Data protection under GDPR

  • Processing is performed on behalf of the care provider with Edith Care as processor
  • Individual user accounts and role-based permissions
  • All access to patient data is logged automatically
  • Patient data is used only for documentation support

US compliance roadmap

  • US-based data hosting is coming ahead of our US launch — today all data is hosted in the EU (Azure Sweden Central)
  • HIPAA readiness program underway: formal security risk analysis, HIPAA policy framework and workforce training
  • Business Associate Agreements (BAAs) with customers — and with every subprocessor that touches PHI — as part of US onboarding
  • SOC 2 Type II preparation is underway as part of the same security program
  • Patient data is never used to train AI models — a commitment we keep in every market, stricter than HIPAA requires

AI position — built for emerging US AI rules

  • The system makes no clinical decisions and performs no diagnosis — it compiles and suggests, the clinician reviews everything
  • AI-generated content is clearly marked as suggestions
  • All clinical assessments are made by licensed professionals
  • This human-in-the-loop design aligns with emerging US state rules for AI in clinical settings, such as Illinois' WOPR Act, which expressly permits administrative and documentation AI
  • Technical documentation and risk management are maintained continuously

02

Data protection and encryption

Encryption

ProtectionStandardDescription
StorageAES-256Industry standard for sensitive data
TransferTLS 1.3Modern secure transport encryption
Key managementAzure Key VaultDedicated key management with strict access control
Audio filesAES-256 + deletionEncrypted during processing and deleted after transcription

Access control

  • Strong authentication with multi-factor authentication
  • Users only see data for their own patients
  • No shared accounts are allowed
  • Automatic logout after inactivity

03

Traceability, incidents and vendors

  • Logs are protected against tampering and contain metadata only
  • Personal data incidents follow established procedures
  • Care providers are informed about incidents within 24 hours
  • All persistent storage and AI processing happens in the EU (Azure Sweden Central)
  • Sub-processors are bound by data processing agreements and bans on model training with customer data