Technical and Organisational Measures

Last updated

Version history

Language

Tandem Health builds AI-based clinical documentation software for healthcare. Protecting customer data is central to how we operate. This page explains, in plain language, how we keep your data safe. It is an informational summary and does not replace our master services agreement, data processing agreement (DPA) or other contractual terms. 

For current certificates, attestation reports and our sub-processor list, visit our Trust Center at trust.tandemhealth.ai

At a Glance 

Topic

What we do

Hosting

Microsoft Azure, EU only (primary region Sweden Central)

Data residency

All data, including backups, stays within the Azure EU data boundary

Encryption

AES-256 at rest; TLS 1.2/1.3 in transit; extra tenant-key encryption for patient data

Access

Named accounts, MFA everywhere, least-privilege, quarterly access reviews

AI

Patient data is never used to train models; human review always required

Availability

99.9% uptime; daily encrypted backups; RTO 1h / RPO 3min

Business Continuity & Disaster Recovery

BCP updated and tested annually, DR tested annually with quarterly recovery tests

Monitoring

24/7 managed detection and response

Certifications

ISO 27001:2022, ISO 13485:2016, ISO 42001:2023, ISO 27701:2025

Hosting and Data Residency 

We run entirely on Microsoft Azure in the EU, with our primary region in Sweden Central and services spread across three availability zones for resilience. 

All customer and patient data, including backups, stays within the Azure EU data boundary. Personal data is not transferred outside the EU unless agreed in your contract; where transfers occur, we rely on GDPR Chapter V safeguards (Standard Contractual Clauses and Transfer Impact Assessments where applicable). 

Encryption 

  • Data at rest is encrypted with AES-256 across storage, databases and backups, using FIPS 140-2 validated modules. 

  • Patient data fields receive an additional layer of application-level encryption using per-clinic (tenant) keys that we manage. 

  • Data in transit uses TLS 1.2 as a minimum and TLS 1.3 for external connections, with mutual TLS for EHR integrations where supported. 

  • Keys are generated, stored and rotated in a managed key vault; tenant keys are hosted with an EU-based provider outside of Azure, ensuring that Azure can never access patient data from our storage. 

Access Control 

We limit access to systems and data by role, business need and authentication: 

  • Employees use personalised accounts with multi-factor authentication across corporate, production, VPN and privileged access. 

  • Production can only be reached from Tandem-managed devices over a secure VPN with phishing-resistant MFA. 

  • Privileged access is time-bound (maximum two hours), justified and logged. 

  • Access reviews run quarterly, with deviations fixed within 7 days. 

  • Support staff can only reach customer or patient data with a justified, logged and time-limited request; you are notified within 72 hours of any access beyond contractual terms. 

  • Access is limited to the purposes defined in the DPA. 

You stay in control of your side too: assigning user roles, configuring SSO/MFA and eID options, and removing access when users no longer need it. 

Data Segregation 

Customer data is isolated per tenant, enforced at the database layer with row-level security. Production, test and administrative environments are kept separate, and real personal data is prevented from entering non-production environments. 

Data Retention and Deletion 

  • Audio is deleted as soon as transcription completes, normally within 30 seconds (maximum 24 hours if a segment cannot be transcribed). 

  • Patient data is minimised after 30 days by default (removing names, identifiers and contact details); retention is configurable per agreement. 

  • Deleted data ages out of backups within 7 days. 

  • All customer and patient data is destroyed within 30 days of contract termination. Ad-hoc erasure requests are completed within the GDPR 30-day window, with evidence available on request. 

Availability and Resilience 

  • 99.9% availability, measured on a rolling 3-month basis. 

  • Runs across three availability zones with EU-wide load balancing. 

  • Daily encrypted, zone-redundant backups with point-in-time recovery, retained 7 days inside the EU. 

  • Recovery objectives: RTO 1 hour, RPO 3 minutes. 

  • Disaster recovery and business continuity plans tested at least annually. 

  • Live service status at status.tandemhealth.ai

Logging and Monitoring 

Audit logs are centrally aggregated and cannot be modified after ingestion. System logins, access-rights changes, PHI access and privileged activity are logged and retained per the regulations in your country. Security events are monitored 24/7 by an external managed detection and response provider. You can request access and audit logs through your account manager. 

Product and Application Security 

We develop under a regulated change-control process aligned to IEC 62304 and ISO 81001-5-1. Every change is peer-reviewed and impact-assessed for performance, security, clinical and privacy risk. Our pipeline includes static analysis, secret scanning, software composition analysis and an SBOM. External penetration tests are run at least annually by a CREST-certified provider. We patch vulnerabilities and material weaknesses according to severity: Critical within 3 hours, High within 3 days, Medium within 30 days, Low within 90 days. 

Incident Response 

We maintain documented processes to detect, handle, escalate and report security and data protection incidents, with a severity model and a dedicated incident response team. We notify affected customers of personal data breaches without undue delay and within the timeframes set in your agreement and applicable law. Regulatory reporting (GDPR, MDR vigilance, EU AI Act) runs in parallel with customer notification. 

Contact: incidents — incident@tandemhealth.se; security reports — security@tandemhealth.ai; privacy — privacy@tandemhealth.ai

Privacy and Data Protection 

We maintain a data protection framework with an external Data Protection Officer, Article 30 records of processing, DPIA processes, and documented data subject request handling. Employees handling data are bound by confidentiality obligations and trained at least annually. Our processing of patient data is designed to align with applicable national healthcare rules, including the Swedish Patient Data Act (patientdatalagen) for Swedish customers. 

AI Governance 

We operate an AI management system certified to ISO 42001, with a company-wide AI policy, an AI inventory and pre-deployment testing. 

  • Patient data is never used to train, fine-tune, evaluate or improve AI models. Fine-tuning uses synthetic clinical scenarios created by our clinicians. 

  • Text generation uses Azure OpenAI in the EU data zone with transient processing only (under 24 hours) and no retention of prompts or completions. 

  • Speech-to-text uses self-hosted EU models and, for customers who opt in, an EU provider running in zero-retention mode under a no-training clause. 

  • All AI outputs must be reviewed and verified by the responsible healthcare professional before use, human oversight is always maintained. 

Our Scribe, Coder and Clinical Decision Support products are CE-marked Class IIa medical devices under EU MDR and high-risk AI systems under the EU AI Act, where Tandem acts as provider and customers act as deployers. 

Sub-processors 

We govern every third party that processes personal data with a DPA, confidentiality obligations, supervision rights and Chapter V safeguards where required. Our current sub-processor list is published on the Trust Center. We notify customers of sub-processor changes in line with your DPA (typically 14 days) with an objection process. AI vendors must sign a no-training clause before engagement. 

Certifications and Attestations 

Framework

Status

ISO 27001:2022

Certified

ISO 13485:2016

Certified

ISO 42001:2023

Certified

ISO 27701:2025

Certified

NEN 7510 (Netherlands)

Certified

ENS Nivel Alto (Spain)

Certified

UK Cyber Essentials Plus

Certified

BSI C5 (Germany)

Attested (C5 Type 2 report)

LVV Class A1 (Finland)

Certified and registered with Valvira

EU MDR 2017/745

CE-marked, Class IIa

UK MDR

MHRA registered, market approval through CE mark

Current certificates, scope statements and validity dates are available on the Trust Center, which is always the authoritative source. 

Questions? 

For security reviews, questionnaires or documentation, contact your account manager or email security@tandemhealth.ai. For privacy reviews, questionnaires or documentation, contact us at privacy@tandemhealth.ai