Trust and security

Your record. Your audit log. Your call.

Hilbi is an overlay and never becomes the system of record. Every read and write is logged, and the log is yours to export. Certifications, sub-processors and residency are named below.

How IQ handles data
  • Overlay, never the record
  • Immutable, exportable audit log
  • Residency named per market
Your record. Your audit log. Your call.

ISO/IEC 27001

with ISO 27799 for health data

Art. 28 GDPR

processor under a written agreement

How the record is governed

Four statements a data protection officer can check rather than take on trust.

The record stays yours

Under Act 576/2004 Coll. and Act 372/2011 Coll. the health record is the provider's. Hilbi sits above it and never becomes it.

Every read and write is logged

The trail is immutable and yours to export. The clinician's signature is a gate before a record entry is final, not a convention.

Where the data is processed

Stated per market in the table below, because the answer differs by market and one global sentence would be wrong somewhere.

What happens if you stop

Your record never left your system. The audit log exports, patient-held data exports as a FHIR R4 bundle, retention runs on a stated clock.

Which rules apply, and where we stand

Per market. Status is stated in words as well as colour.

SlovakiaCzechiaIndiaUnited States
Data protection regimeGDPR (EU) 2016/679GDPR (EU) 2016/679DPDP Act 2023HIPAA 45 CFR 160/164
Health-record lawAct 576/2004 Coll.Act 372/2011 + Decree 98/2012ABDM / HPR scopeState law varies
Basis for health data in careArt. 9(2)(h) GDPRArt. 9(2)(h) GDPRConsent under DPDPHIPAA permitted use
Processing locationEuropean UnionEuropean UnionIndiaUnited States
Contract with the providerArt. 28 processing agreementArt. 28 processing agreementProcessing agreementBusiness associate agreement
Breach notificationArt. 33 / 34 GDPRArt. 33 / 34 GDPRDPDP duty to notifyHIPAA Breach Notification Rule
Audit trailImmutable, exportableImmutable, exportableImmutable, exportableImmutable, exportable
Secondary use of health dataEHDS Reg. (EU) 2025/327EHDS Reg. (EU) 2025/327Outside EHDS scopeOutside EHDS scope
Information security managementISO/IEC 27001 recertificationISO/IEC 27001 recertificationISO/IEC 27001 recertificationISO/IEC 27001 recertification
Sector security dutyNIS2 positionNIS2 positionNot assessedNot assessed
Accessibility of the patient surfaceEAA / EN 301 549EAA / EN 301 549Not assessedNot assessed
Status keyIn forceIn progressReadiness

In force: applies today and can be evidenced. In progress: under way and dated. Readiness: the position is prepared and the market opens next.

Certification status, stated plainly

A certificate is either issued or it is not. Nothing here is rounded up.

ISO/IEC 27001
Recertification is in progress, scoped to the group structure. No certificate number, issuing body or date is rendered on this page until the certificate is issued.In progress
Certification scope
The group structure rather than a single operating entity, so one statement covers the markets the platform runs in.In progress
Standards the platform is built against
The full register (HL7 FHIR R4, ISO 27799, ISO 82304-1, ISO 13606, ISO 13485, ISO 14971, IEC 62304, MDR 2017/745, ERAS, EMRAM) is published in the standards register on this page.In force
Sub-processors
Fourteen sub-processors, each with its purpose and its processing location, listed per market in the sub-processor register.In force
Penetration testing and vulnerability disclosure
Annual penetration test with quarterly vulnerability scanning. The report is available under agreement and disclosures reach the security contact published on this page.In force
Data processing agreement
Available before signature rather than after, for each market's regime.In force
Retention and deletion
Audit records for 10 years, clinical documents under national retention law, patient-held data until the patient deletes it. Deletion evidence is issued on request.In force
Exit and portability
Audit log export, patient-held data as an HL7 FHIR R4 bundle, and the deletion timetable that follows.In force

What a data protection officer asks first

Who owns the clinical record?

You do, and it stays in your system of record. Hilbi is an overlay and is built so that it cannot become the system of record.

Are you ISO 27001 certified?
What is in the audit log, and can we export it?
Does the same answer apply in every market?
What happens to our data if we stop using Hilbi?

Monthly briefing

The signal, once a month.

What changed in European health data, what we shipped, and what it means for a provider. Nothing else.

One email a month. One click to leave.