E
Log in

◆ SECURITY

Information security and compliance

Edith Care - AI for human-centered work in assessment, care and support

Version 3.0 · 2026-08-18

Summary

We understand that behavioral health providers handle some of society's most sensitive information. Information security and compliance have therefore been core design principles from day one.

Edith Care is documentation support - not an electronic health record system and not a medical device. All clinical content created in Edith Care remains draft material until the responsible licensed clinician reviews, approves and transfers it to the practice's record system.

OUR CORE SECURITY PROMISES

  • All patient data is stored and processed in the EU (Azure Sweden Central) - US-based hosting is coming ahead of our US launch
  • All information is encrypted, both at rest and in transit
  • Full traceability - every access to patient data is logged
  • AI summarizes and suggests only - all clinical judgments are made by licensed clinicians
  • Built under the EU's GDPR, among the strictest privacy regimes in the world; HIPAA readiness program underway
  • Aligned with the EU AI Act, whose main obligations have applied since 2 August 2026

01

Compliance

Edith Care is designed and operated under the EU's GDPR, one of the strictest data protection frameworks in the world. Ahead of our US launch we are building the US-specific layer on top of that foundation.

Where we are today

We want to be plain about what is in place and what is not. Edith Care is a European company serving European customers today. Nothing on this page should be read as a claim that we are HIPAA compliant or that a Business Associate Agreement is available yet.

IN PLACE TODAY

  • GDPR compliance, including data processing agreements with every customer
  • Encryption at rest and in transit, with dedicated key management
  • Individual accounts, role-based permissions and complete access logging
  • A contractual prohibition on using customer data to train AI models

COMING AHEAD OF OUR US LAUNCH

  • US-based data hosting - today all data is hosted in the EU (Azure Sweden Central)
  • HIPAA readiness program: formal security risk analysis, HIPAA policy framework and workforce training
  • Business Associate Agreements (BAAs) with customers, and with every subprocessor that touches PHI
  • SOC 2 Type II preparation as part of the same security program

Until a BAA is executed, Edith Care should not be used to process protected health information.

US state privacy laws

Comprehensive state privacy statutes increasingly treat health and mental health data as sensitive data requiring heightened protection. Edith Care is built to support those requirements:

  • Purpose limitation - patient data is used solely for documentation support
  • Data minimization - only necessary data is processed
  • No sale of personal data and no targeted advertising, in any market
  • Support for access, correction and deletion requests from individuals
  • Contractual controls flowed down to every subprocessor

Clinical record keeping

  • AI-generated content in Edith Care is a draft for the clinical record
  • The responsible licensed clinician reviews, edits and approves all content before transfer to the record system
  • The clinician who signs the record entry is accountable for its accuracy
  • Individual user identification, authentication and complete access logging

The EU AI Act (2024/1689)

The EU AI Act applies to Edith Care as an EU-established provider, and its main obligations have applied since 2 August 2026. US customers benefit from the same engineering discipline even where no equivalent US federal requirement exists yet.

CLASSIFICATION

Edith Care is classified as documentation support that neither makes nor influences clinical decisions. The system performs no diagnostics, no symptom scoring and gives no treatment recommendations. Based on MDCG 2019-11 rev.1 and Annex III of the AI Act, Edith Care is assessed as not constituting a high-risk AI system.

MEASURES IN PLACE

  • Risk management system with documented risks and mitigations (Article 9)
  • Technical documentation of the system's design and function (Article 11)
  • Transparency - clear explanation of the AI's capabilities and limitations (Article 13)
  • Human oversight - every suggestion is reviewed by a licensed clinician (Article 14)
  • AI literacy - training material and ongoing support for users (Article 4)

Device classification

Edith Care is a documentation tool, not a medical device. Its intended purpose is to support clinicians with text structuring, language quality and formatting of assessment reports. The system performs no diagnostics, no symptom scoring and gives no treatment recommendations. All clinical judgments are made solely by the licensed clinician. A self-assessment has been carried out and documented, and we will re-examine it against FDA guidance ahead of our US launch.

02

Data protection and encryption

Where data is stored

All patient data - database, AI processing and file storage - is stored and processed in the EU via Microsoft Azure Sweden Central (data centers in Sandviken/Gävle and Staffanstorp), under Microsoft's EU Data Boundary commitments. US-based hosting is coming ahead of our US launch; until then, EU hosting is the honest description of where your data lives.

Support services for product analytics (PostHog) and AI monitoring (Langfuse) are hosted in the EU and process metadata only - never patient data. Azure Sweden Central is ISO 27001 and SOC 2 certified.

Encryption

Protection levelStandardDescription
At restAES-256Industry standard for sensitive data
In transitTLS 1.3Latest and most secure standard
Key managementAzure Key VaultDedicated key management with strict access control
Audio filesAES-256 + deletionEncrypted during processing, deleted after transcription
DatabaseAES-256 + SSLAzure-managed encryption with enforced SSL connections

No unencrypted patient data is stored or transmitted.

Access control

AuthenticationStrong authentication with multi-factor authentication (MFA)
Role-based permissionsUsers see and work with data for their own patients only
Individual accountsNo shared accounts are permitted
Session controlAutomatic logout after inactivity
Permission assignmentDocumented permission assignment with systematic review

03

Traceability and logging

Full traceability is essential to support the provider's obligation to control access to patient data.

What is logged

FieldDescription
User IDWho accessed the data
TimestampWhen the access occurred
Action typeRead, write, export, delete
ResourceWhich patient case or resource was involved
OutcomeWhether access was granted or denied

Log management

  • Logs are stored securely and protected against tampering
  • Log data never contains clinical patient content - only metadata and identifiers
  • The provider can request log extracts for internal control and on patient request
  • Automatic alerts on anomalous access patterns
  • Logs are retained in line with the provider's policy and applicable legal requirements

04

AI and human control

Edith Care uses AI to support licensed clinicians in their documentation work - never to replace professional clinical judgment. This is a fundamental design principle.

AI as documentation support, not clinical decision-making

  • AI suggests text structure, phrasing and summaries
  • AI performs no diagnostics, no symptom scoring and gives no treatment recommendations
  • All clinical judgments are made solely by the licensed clinician
  • AI-generated content is clearly marked as suggestions requiring professional review

Transparency and explainability

Whenever AI generates a suggestion, it is always clear that:

  • It is a draft that requires review by a licensed clinician
  • The clinician is accountable for the final record content
  • AI has limitations and can produce incorrect or incomplete suggestions
  • The tool is documentation support, not clinical decision support

Information to patients

Edith Care recommends that providers inform patients that AI-assisted documentation is used. Support for this is provided through:

  • Recommended wording for the practice's notice of privacy practices
  • Guidance for verbal information at the start of an assessment
  • Clear information that AI does not influence the clinical judgment

Secure AI infrastructure

No public AIData is never sent to public AI services (such as ChatGPT, Gemini or similar)
No training on customer dataPatient data is never used to train AI models - a commitment we keep in every market, stricter than HIPAA requires
EU processingAll AI processing takes place in the EU (Azure Sweden Central)
Agreements with AI vendorsExplicit prohibition on using data for model training
Product analytics (PostHog)Receives event names and resource IDs only - never patient names, clinical text or health data. Hosted in the EU.
AI monitoring (Langfuse)In production, no AI prompts or responses are recorded - only metadata (response times, token counts, model version). Hosted in the EU.

05

Data lifecycle and retention

Edith Care's role in the documentation flow

Edith Care handles patient data as draft record material - drafts that are worked on and reviewed by the clinician before transfer to the practice's official record system. Edith Care is not the record system.

THE DOCUMENTATION FLOW

  1. 1.Session recording - audio recorded in Edith Care
  2. 2.Transcription - audio converted to text
  3. 3.AI-assisted report writing - AI helps with structure and phrasing
  4. 4.Review by the clinician - the licensed clinician reviews and edits
  5. 5.Transfer to the record system - approved content is transferred
  6. 6.Signing in the record system - the clinician signs the record entry
  7. 7.Deletion from Edith Care - patient data is deleted from Edith Care

Data handling per phase

PhaseData typeRetention in Edith CareAction
RecordingAudio fileTemporary - deleted after transcriptionEncrypted during processing
TranscriptionTranscriptUntil the report is completeAvailable to the clinician
Report writingDraft reportUntil the report is approved and transferredAI support available
TransferFinal reportDeleted after confirmed transferAutomatic or manual deletion

Retention responsibility

  • Statutory retention of clinical records rests with the record system, not with Edith Care
  • Edith Care deletes patient data after transfer to the record system, according to the configured retention period
  • The provider sets the retention period in Edith Care (recommendation: 30 days after transfer)
  • Deletion is permanent and verifiable

Data minimization

  • Audio files are deleted immediately after successful transcription
  • Transcripts and drafts are deleted after transfer to the record system
  • Only the data needed for the current documentation purpose is processed
  • No personal data is retained in Edith Care longer than necessary

06

Infrastructure and vendors

Infrastructure overview

ComponentVendorRegionCertification
Application hostingMicrosoft AzureSweden CentralISO 27001, SOC 2, C5
AI model (text)Azure OpenAI ServiceSweden CentralISO 27001, SOC 2
AI model (transcription)Azure Speech ServicesSweden CentralISO 27001, SOC 2
Key managementAzure Key VaultSweden CentralFIPS 140-2 Level 2
Data storageAzure Blob StorageSweden CentralISO 27001, SOC 2

Note: the web application is delivered via Vercel (CDN and edge network). In Edith Care's architecture Vercel acts solely as a reverse proxy for static frontend files and API calls forwarded to Azure Sweden Central. No edge functions, serverless functions or log drains that process patient data are enabled. All persistent data storage and AI processing takes place in Azure Sweden Central.

Network security

  • Encrypted communication between all components (TLS 1.3)
  • Firewall protection at application and network level
  • Regular security scanning
  • Penetration testing planned as part of ongoing certification work

Requirements on cloud vendors

All infrastructure vendors meet the following minimum requirements:

  • ISO 27001 certification (information security)
  • GDPR compliance and a data processing agreement under Article 28
  • Support for encryption at rest and in transit
  • Provision for audit and transparency
  • BAAs will be required from every subprocessor that touches PHI ahead of our US launch

Subprocessors

All subprocessors handling personal data are covered by:

  • A data processing agreement with specific requirements for health data
  • A prohibition on processing outside the EU/EEA without approval
  • An explicit prohibition on using patient data for model training
  • A requirement to notify Edith Care of changes affecting data security

A named list of subprocessors is provided as part of onboarding.

07

Incident management

In the event of a security or data breach, Edith Care follows established routines:

StepDeadlineAction
DetectionImmediatelyInternal classification and containment of the incident
Notification to the providerWithin 24 hoursThe provider is informed of type, scope and recommended actions
Regulatory notificationPer applicable lawThe provider notifies the relevant authorities. Edith Care provides supporting material.
Information to patientsWithout undue delayThe provider informs affected patients where risk is high. Edith Care assists.
InvestigationOngoingRoot cause analysis and remediation plan
Follow-upWithin 30 daysDocumentation of lessons learned and improvements

Breach notification timelines vary by state and, once a BAA is in place, by the HIPAA Breach Notification Rule. Contractual deadlines are set in the agreement.

08

Additional regulatory compliance

Security program

Our EU operations fall under the Swedish Cybersecurity Act (2025:1506) implementing NIS2. US customers benefit from the same controls:

  • Robust incident management with the ability to report security incidents within 24 hours
  • Systematic security work with documented risk assessments
  • Supply chain security - all subprocessors undergo security review
  • Continuity planning and operational continuity routines
  • SOC 2 Type II preparation is underway as part of the same security program

Data portability

  • Complete data export in standard formats
  • Support for switching vendor without technical obstacles
  • Documented APIs and data formats
  • Assistance with migration to another vendor

Accessibility

The website partially conforms to WCAG 2.2 level AA and was last assessed internally on 31 March 2026. Known limitations and how to give feedback are set out in our accessibility statement.

09

Current status

Security level

All handling of patient data operates at production-grade security. Encryption, access control, logging and GDPR compliance are implemented and active.

In development

The following work is under way:

  • US-based data hosting ahead of our US launch
  • HIPAA readiness program and BAA availability
  • SOC 2 Type II preparation
  • Validation of AI-generated content against source material
  • Penetration testing as part of ongoing certification work

10

Contact information

For questions about information security and data protection, contact:

Edith Care (Jobello Technology AB)

Company registration number: 559311-6907

Data protection lead: Fredrik Gordh Riseby

fredrik[at]edithcare[dot]se

This document describes Edith Care's security architecture and compliance for use in behavioral health. For detailed technical documentation on infrastructure and vendors, contact us for our technical annex. The document is updated on an ongoing basis as regulation and the product evolve.