Vertrauen & Compliance
Für das regulierte Gesundheitswesen gebaut.
Gesundheitsdaten sind die sensibelsten Daten überhaupt, und genau so behandeln wir sie. Zu jedem Rahmenwerk unten gibt es eine eigene Seite für Compliance- und Beschaffungsprüfungen; Unterlagen auf Anfrage.
GDPR
Desha.ai processes personal and health data in line with the EU GDPR (2016/679) and the UK GDPR / Data Protection Act 2018. Processing is consent-governed and purpose-limited, data subjects can exercise their rights at any time, and we operate as a processor under Article 28 terms for our healthcare customers.
HIPAA
Desha.ai self-assesses its workflows against the HIPAA Privacy, Security and Breach Notification Rules, for US covered entities and their business associates. We will sign a Business Associate Agreement (BAA), apply the Security Rule’s administrative, physical and technical safeguards to Protected Health Information (PHI), and honour the minimum-necessary and breach-notification requirements. (HIPAA has no government “certification”; conformance is demonstrated through the BAA and our control attestations.)
NHS DSP Toolkit
For engagements that touch NHS patient data, Desha.ai aligns to the Data Security and Protection (DSP) Toolkit, the annual self-assessment against the National Data Guardian’s ten data-security standards. Our controls are designed to meet the “Standards Met” threshold.
ISO 27001
Desha.ai operates an information-security programme aligned to the ISO/IEC 27001:2022 control set (Annex A) and a risk-based Information Security Management System (ISMS). Formal certification is on our roadmap; today we map our controls to the standard and can share that mapping.
End-to-End Encryption
All Desha.ai data is encrypted in transit and at rest. Sensitive health and identity fields receive additional protection, and cryptographic keys are managed through a controlled lifecycle.
Zero-PII Storage
Desha.ai is built on data minimisation. Directly identifying information is segregated from health data, tokenised wherever possible, kept out of logs and analytics, and never used to train third-party models. We call this our Zero-PII principle: the analytics, monitoring and model layers operate on de-identified data.
SOC 2 Type II
Desha.ai is working toward a SOC 2 Type II report against the AICPA Trust Services Criteria. We are building the control environment a Type II opinion requires. No auditor is engaged and no observation period has begun; we hold no SOC 2 report today. We will publish here if and when that changes.
HL7 FHIR R4
Desha.ai represents clinical data using HL7 FHIR Release 4, the modern healthcare interoperability standard, so patient records, medications and adherence can be exchanged cleanly with EHRs and partner systems, and patients can export their data in a portable, machine-readable form.
Diese Seiten fassen die Position von Desha.ai für die Due-Diligence-Prüfung zusammen. Sie sind rein informativ, legen keine internen Systeme offen und stellen weder eine Zusicherung noch eine Rechtsberatung dar. Vertragliche Bedingungen regeln unser DPA / BAA.
