◆ SECURITY
Information security and compliance
Edith Care - AI for human-centered work in assessment, care and support
Version 3.0 · 2026-08-18
Summary
We understand that behavioral health providers handle some of society's most sensitive information. Information security and compliance have therefore been core design principles from day one.
Edith Care is documentation support - not an electronic health record system and not a medical device. All clinical content created in Edith Care remains draft material until the responsible licensed clinician reviews, approves and transfers it to the practice's record system.
OUR CORE SECURITY PROMISES
- •All patient data is stored and processed in the EU (Azure Sweden Central) - US-based hosting is coming ahead of our US launch
- •All information is encrypted, both at rest and in transit
- •Full traceability - every access to patient data is logged
- •AI summarizes and suggests only - all clinical judgments are made by licensed clinicians
- •Built under the EU's GDPR, among the strictest privacy regimes in the world; HIPAA readiness program underway
- •Aligned with the EU AI Act, whose main obligations have applied since 2 August 2026
01
Compliance
Edith Care is designed and operated under the EU's GDPR, one of the strictest data protection frameworks in the world. Ahead of our US launch we are building the US-specific layer on top of that foundation.
Where we are today
We want to be plain about what is in place and what is not. Edith Care is a European company serving European customers today. Nothing on this page should be read as a claim that we are HIPAA compliant or that a Business Associate Agreement is available yet.
IN PLACE TODAY
- •GDPR compliance, including data processing agreements with every customer
- •Encryption at rest and in transit, with dedicated key management
- •Individual accounts, role-based permissions and complete access logging
- •A contractual prohibition on using customer data to train AI models
COMING AHEAD OF OUR US LAUNCH
- •US-based data hosting - today all data is hosted in the EU (Azure Sweden Central)
- •HIPAA readiness program: formal security risk analysis, HIPAA policy framework and workforce training
- •Business Associate Agreements (BAAs) with customers, and with every subprocessor that touches PHI
- •SOC 2 Type II preparation as part of the same security program
Until a BAA is executed, Edith Care should not be used to process protected health information.
US state privacy laws
Comprehensive state privacy statutes increasingly treat health and mental health data as sensitive data requiring heightened protection. Edith Care is built to support those requirements:
- •Purpose limitation - patient data is used solely for documentation support
- •Data minimization - only necessary data is processed
- •No sale of personal data and no targeted advertising, in any market
- •Support for access, correction and deletion requests from individuals
- •Contractual controls flowed down to every subprocessor
Clinical record keeping
- •AI-generated content in Edith Care is a draft for the clinical record
- •The responsible licensed clinician reviews, edits and approves all content before transfer to the record system
- •The clinician who signs the record entry is accountable for its accuracy
- •Individual user identification, authentication and complete access logging
The EU AI Act (2024/1689)
The EU AI Act applies to Edith Care as an EU-established provider, and its main obligations have applied since 2 August 2026. US customers benefit from the same engineering discipline even where no equivalent US federal requirement exists yet.
CLASSIFICATION
Edith Care is classified as documentation support that neither makes nor influences clinical decisions. The system performs no diagnostics, no symptom scoring and gives no treatment recommendations. Based on MDCG 2019-11 rev.1 and Annex III of the AI Act, Edith Care is assessed as not constituting a high-risk AI system.
MEASURES IN PLACE
- •Risk management system with documented risks and mitigations (Article 9)
- •Technical documentation of the system's design and function (Article 11)
- •Transparency - clear explanation of the AI's capabilities and limitations (Article 13)
- •Human oversight - every suggestion is reviewed by a licensed clinician (Article 14)
- •AI literacy - training material and ongoing support for users (Article 4)
Device classification
Edith Care is a documentation tool, not a medical device. Its intended purpose is to support clinicians with text structuring, language quality and formatting of assessment reports. The system performs no diagnostics, no symptom scoring and gives no treatment recommendations. All clinical judgments are made solely by the licensed clinician. A self-assessment has been carried out and documented, and we will re-examine it against FDA guidance ahead of our US launch.
02
Data protection and encryption
Where data is stored
All patient data - database, AI processing and file storage - is stored and processed in the EU via Microsoft Azure Sweden Central (data centers in Sandviken/Gävle and Staffanstorp), under Microsoft's EU Data Boundary commitments. US-based hosting is coming ahead of our US launch; until then, EU hosting is the honest description of where your data lives.
Support services for product analytics (PostHog) and AI monitoring (Langfuse) are hosted in the EU and process metadata only - never patient data. Azure Sweden Central is ISO 27001 and SOC 2 certified.
Encryption
| Protection level | Standard | Description |
|---|---|---|
| At rest | AES-256 | Industry standard for sensitive data |
| In transit | TLS 1.3 | Latest and most secure standard |
| Key management | Azure Key Vault | Dedicated key management with strict access control |
| Audio files | AES-256 + deletion | Encrypted during processing, deleted after transcription |
| Database | AES-256 + SSL | Azure-managed encryption with enforced SSL connections |
No unencrypted patient data is stored or transmitted.
Access control
| Authentication | Strong authentication with multi-factor authentication (MFA) |
| Role-based permissions | Users see and work with data for their own patients only |
| Individual accounts | No shared accounts are permitted |
| Session control | Automatic logout after inactivity |
| Permission assignment | Documented permission assignment with systematic review |
03
Traceability and logging
Full traceability is essential to support the provider's obligation to control access to patient data.
What is logged
| Field | Description |
|---|---|
| User ID | Who accessed the data |
| Timestamp | When the access occurred |
| Action type | Read, write, export, delete |
| Resource | Which patient case or resource was involved |
| Outcome | Whether access was granted or denied |
Log management
- •Logs are stored securely and protected against tampering
- •Log data never contains clinical patient content - only metadata and identifiers
- •The provider can request log extracts for internal control and on patient request
- •Automatic alerts on anomalous access patterns
- •Logs are retained in line with the provider's policy and applicable legal requirements
04
AI and human control
Edith Care uses AI to support licensed clinicians in their documentation work - never to replace professional clinical judgment. This is a fundamental design principle.
AI as documentation support, not clinical decision-making
- •AI suggests text structure, phrasing and summaries
- •AI performs no diagnostics, no symptom scoring and gives no treatment recommendations
- •All clinical judgments are made solely by the licensed clinician
- •AI-generated content is clearly marked as suggestions requiring professional review
Transparency and explainability
Whenever AI generates a suggestion, it is always clear that:
- •It is a draft that requires review by a licensed clinician
- •The clinician is accountable for the final record content
- •AI has limitations and can produce incorrect or incomplete suggestions
- •The tool is documentation support, not clinical decision support
Information to patients
Edith Care recommends that providers inform patients that AI-assisted documentation is used. Support for this is provided through:
- •Recommended wording for the practice's notice of privacy practices
- •Guidance for verbal information at the start of an assessment
- •Clear information that AI does not influence the clinical judgment
Secure AI infrastructure
| No public AI | Data is never sent to public AI services (such as ChatGPT, Gemini or similar) |
| No training on customer data | Patient data is never used to train AI models - a commitment we keep in every market, stricter than HIPAA requires |
| EU processing | All AI processing takes place in the EU (Azure Sweden Central) |
| Agreements with AI vendors | Explicit prohibition on using data for model training |
| Product analytics (PostHog) | Receives event names and resource IDs only - never patient names, clinical text or health data. Hosted in the EU. |
| AI monitoring (Langfuse) | In production, no AI prompts or responses are recorded - only metadata (response times, token counts, model version). Hosted in the EU. |
05
Data lifecycle and retention
Edith Care's role in the documentation flow
Edith Care handles patient data as draft record material - drafts that are worked on and reviewed by the clinician before transfer to the practice's official record system. Edith Care is not the record system.
THE DOCUMENTATION FLOW
- 1.Session recording - audio recorded in Edith Care
- 2.Transcription - audio converted to text
- 3.AI-assisted report writing - AI helps with structure and phrasing
- 4.Review by the clinician - the licensed clinician reviews and edits
- 5.Transfer to the record system - approved content is transferred
- 6.Signing in the record system - the clinician signs the record entry
- 7.Deletion from Edith Care - patient data is deleted from Edith Care
Data handling per phase
| Phase | Data type | Retention in Edith Care | Action |
|---|---|---|---|
| Recording | Audio file | Temporary - deleted after transcription | Encrypted during processing |
| Transcription | Transcript | Until the report is complete | Available to the clinician |
| Report writing | Draft report | Until the report is approved and transferred | AI support available |
| Transfer | Final report | Deleted after confirmed transfer | Automatic or manual deletion |
Retention responsibility
- •Statutory retention of clinical records rests with the record system, not with Edith Care
- •Edith Care deletes patient data after transfer to the record system, according to the configured retention period
- •The provider sets the retention period in Edith Care (recommendation: 30 days after transfer)
- •Deletion is permanent and verifiable
Data minimization
- •Audio files are deleted immediately after successful transcription
- •Transcripts and drafts are deleted after transfer to the record system
- •Only the data needed for the current documentation purpose is processed
- •No personal data is retained in Edith Care longer than necessary
06
Infrastructure and vendors
Infrastructure overview
| Component | Vendor | Region | Certification |
|---|---|---|---|
| Application hosting | Microsoft Azure | Sweden Central | ISO 27001, SOC 2, C5 |
| AI model (text) | Azure OpenAI Service | Sweden Central | ISO 27001, SOC 2 |
| AI model (transcription) | Azure Speech Services | Sweden Central | ISO 27001, SOC 2 |
| Key management | Azure Key Vault | Sweden Central | FIPS 140-2 Level 2 |
| Data storage | Azure Blob Storage | Sweden Central | ISO 27001, SOC 2 |
Note: the web application is delivered via Vercel (CDN and edge network). In Edith Care's architecture Vercel acts solely as a reverse proxy for static frontend files and API calls forwarded to Azure Sweden Central. No edge functions, serverless functions or log drains that process patient data are enabled. All persistent data storage and AI processing takes place in Azure Sweden Central.
Network security
- •Encrypted communication between all components (TLS 1.3)
- •Firewall protection at application and network level
- •Regular security scanning
- •Penetration testing planned as part of ongoing certification work
Requirements on cloud vendors
All infrastructure vendors meet the following minimum requirements:
- •ISO 27001 certification (information security)
- •GDPR compliance and a data processing agreement under Article 28
- •Support for encryption at rest and in transit
- •Provision for audit and transparency
- •BAAs will be required from every subprocessor that touches PHI ahead of our US launch
Subprocessors
All subprocessors handling personal data are covered by:
- •A data processing agreement with specific requirements for health data
- •A prohibition on processing outside the EU/EEA without approval
- •An explicit prohibition on using patient data for model training
- •A requirement to notify Edith Care of changes affecting data security
A named list of subprocessors is provided as part of onboarding.
07
Incident management
In the event of a security or data breach, Edith Care follows established routines:
| Step | Deadline | Action |
|---|---|---|
| Detection | Immediately | Internal classification and containment of the incident |
| Notification to the provider | Within 24 hours | The provider is informed of type, scope and recommended actions |
| Regulatory notification | Per applicable law | The provider notifies the relevant authorities. Edith Care provides supporting material. |
| Information to patients | Without undue delay | The provider informs affected patients where risk is high. Edith Care assists. |
| Investigation | Ongoing | Root cause analysis and remediation plan |
| Follow-up | Within 30 days | Documentation of lessons learned and improvements |
Breach notification timelines vary by state and, once a BAA is in place, by the HIPAA Breach Notification Rule. Contractual deadlines are set in the agreement.
08
Additional regulatory compliance
Security program
Our EU operations fall under the Swedish Cybersecurity Act (2025:1506) implementing NIS2. US customers benefit from the same controls:
- •Robust incident management with the ability to report security incidents within 24 hours
- •Systematic security work with documented risk assessments
- •Supply chain security - all subprocessors undergo security review
- •Continuity planning and operational continuity routines
- •SOC 2 Type II preparation is underway as part of the same security program
Data portability
- •Complete data export in standard formats
- •Support for switching vendor without technical obstacles
- •Documented APIs and data formats
- •Assistance with migration to another vendor
Accessibility
The website partially conforms to WCAG 2.2 level AA and was last assessed internally on 31 March 2026. Known limitations and how to give feedback are set out in our accessibility statement.
09
Current status
Security level
All handling of patient data operates at production-grade security. Encryption, access control, logging and GDPR compliance are implemented and active.
In development
The following work is under way:
- •US-based data hosting ahead of our US launch
- •HIPAA readiness program and BAA availability
- •SOC 2 Type II preparation
- •Validation of AI-generated content against source material
- •Penetration testing as part of ongoing certification work
10
Contact information
For questions about information security and data protection, contact:
Edith Care (Jobello Technology AB)
Company registration number: 559311-6907
Data protection lead: Fredrik Gordh Riseby
fredrik[at]edithcare[dot]se
This document describes Edith Care's security architecture and compliance for use in behavioral health. For detailed technical documentation on infrastructure and vendors, contact us for our technical annex. The document is updated on an ongoing basis as regulation and the product evolve.