Compliance

How we handle patient data

Amorphous turns unstructured clinical notes into structured, coded data that the hospital can query. We do this as a processor. The hospital decides the purpose, the scope and the retention, and we act on its documented instructions under an Article 28 (GDPR) agreement.

Five core facts

  1. 01

    The hospital is the controller

    Your hospital decides why data is processed, which data, and for how long. Where an EMR vendor sits between us, we act as sub-processor.

  2. 02

    The purpose is management information

    Operations, quality improvement, audit, coding and reimbursement integrity, always at the level of populations and pathways. The system does not inform decisions about the diagnosis or treatment of individual patients.

  3. 03

    The re-identification key never reaches us

    Identifying details are removed while the data is structured. Dates are shifted by a per-patient offset so clinical intervals survive. The key that links records back to patients stays with the hospital and its EMR vendor. We cannot re-identify anyone.

  4. 04

    Everything stays in the EU

    All processing runs on European infrastructure. Customer data is never used to train or fine-tune models.

  5. 05

    Certified, audited, dated

    ISO 27001 for information security, ISO 27017 for cloud security and ISO 42001 for AI management, all certified by Bureau Veritas, audited in June 2026 and valid to July 2029. Our data protection model has passed an independent GDPR audit covering hosting and our sub-processor role.

    • ISO 27001Information Security
    • ISO 27017Cloud Security
    • ISO 42001AI Management

    Certified by Bureau Veritas

How responsibility is shared

01

Controller

Hospital

  • Decides the purpose
  • Owns the DPIA
  • Answers patient requests
02

Holds the key

EMR Vendor

  • Provides the source systems
  • Holds the re-identification key with the hospital
03

Processor

Amorphous

  • Structures and codes the data
  • Enables the hospital to run the analytics

FAQ