Trust and security
Your record. Your audit log. Your call.
Hilbi is an overlay and never becomes the system of record. Every read and write is logged, and the log is yours to export. Certifications, sub-processors and residency are named below.
- Overlay, never the record
- Immutable, exportable audit log
- Residency named per market

ISO/IEC 27001
with ISO 27799 for health data
Art. 28 GDPR
processor under a written agreement
How the record is governed
Four statements a data protection officer can check rather than take on trust.
The record stays yours
Under Act 576/2004 Coll. and Act 372/2011 Coll. the health record is the provider's. Hilbi sits above it and never becomes it.
Every read and write is logged
The trail is immutable and yours to export. The clinician's signature is a gate before a record entry is final, not a convention.
Where the data is processed
Stated per market in the table below, because the answer differs by market and one global sentence would be wrong somewhere.
What happens if you stop
Your record never left your system. The audit log exports, patient-held data exports as a FHIR R4 bundle, retention runs on a stated clock.
Which rules apply, and where we stand
Per market. Status is stated in words as well as colour.
| Slovakia | Czechia | India | United States | |
|---|---|---|---|---|
| Data protection regime | ||||
| Health-record law | ||||
| Basis for health data in care | ||||
| Processing location | ||||
| Contract with the provider | ||||
| Breach notification | ||||
| Audit trail | ||||
| Secondary use of health data | ||||
| Information security management | ||||
| Sector security duty | ||||
| Accessibility of the patient surface |
In force: applies today and can be evidenced. In progress: under way and dated. Readiness: the position is prepared and the market opens next.
Certification status, stated plainly
A certificate is either issued or it is not. Nothing here is rounded up.
- ISO/IEC 27001
- Recertification is in progress, scoped to the group structure. No certificate number, issuing body or date is rendered on this page until the certificate is issued.
- Certification scope
- The group structure rather than a single operating entity, so one statement covers the markets the platform runs in.
- Standards the platform is built against
- The full register (HL7 FHIR R4, ISO 27799, ISO 82304-1, ISO 13606, ISO 13485, ISO 14971, IEC 62304, MDR 2017/745, ERAS, EMRAM) is published in the standards register on this page.
- Sub-processors
- Fourteen sub-processors, each with its purpose and its processing location, listed per market in the sub-processor register.
- Penetration testing and vulnerability disclosure
- Annual penetration test with quarterly vulnerability scanning. The report is available under agreement and disclosures reach the security contact published on this page.
- Data processing agreement
- Available before signature rather than after, for each market's regime.
- Retention and deletion
- Audit records for 10 years, clinical documents under national retention law, patient-held data until the patient deletes it. Deletion evidence is issued on request.
- Exit and portability
- Audit log export, patient-held data as an HL7 FHIR R4 bundle, and the deletion timetable that follows.
What a data protection officer asks first
Who owns the clinical record?
Are you ISO 27001 certified?
What is in the audit log, and can we export it?
Does the same answer apply in every market?
What happens to our data if we stop using Hilbi?
Monthly briefing
The signal, once a month.
What changed in European health data, what we shipped, and what it means for a provider. Nothing else.