Security and privacy

Patient data must be safe. Here is how.

Short answers to what clinics ask: where the data is, who can see it, and what the AI is allowed to do.

See what's included

The essentials first

Login with BankID

Doctors sign in with Norwegian BankID at the "substantial" assurance level. No passwords, no shared accounts.

No patient register

MedAid keeps no register of patients. Each consultation is stored on its own, with no name, national ID number or other identifier, and is deleted automatically 30 days after the last activity.

Data stored in Norway

Clinical notes, transcripts and documents are stored in Microsoft Azure in Norway (Norway East).

AI processing in the EU/EEA

Transcription and notes are produced with Azure OpenAI in Sweden. The data stays in Europe.

No training on your data

Microsoft does not use the data to train AI models. That is contractual.

Audio deleted at once

The audio recording is deleted as soon as the note is written.

Encrypted all the way

Everything is encrypted in transit and at rest.

You approve everything

No text goes on to a patient, to NAV or into a record unless you have read and copied it.

Consent is stored

The patient's consent to AI is confirmed before recording, and stored with a timestamp and the version of the consent text. Without it the server refuses the job too.

Where the data is

We use Microsoft Azure. These are the places.

Storage: Norway

Databases, files, search and logs run in Norway East.

AI: Sweden (EU)

Azure OpenAI in our own Azure tenant, on a resource in Sweden.

Video: Norway

Azure Communication Services with data location in Norway.

Website: Netherlands

The website itself is served from Azure in West Europe. It holds no patient data.

Login: Criipto (EU/EEA)

BankID login goes through Criipto.

Payments: Stripe

Only customer data about the doctor or clinic. Never patient data.

What the AI gets, and doesn't get

The AI gets the audio recording and what you attach to the consultation. It produces drafts.

A draft may suggest diagnosis codes, but you choose and approve them. It never suggests Norwegian billing codes — you pick those, and MedAid only warns when a note is missing what a code requires. It sends nothing.

When the assistant answers clinical questions, it searches a fixed set of Norwegian sources — the Directorate of Health, FHI, the national drug handbook, Helsebiblioteket, Felleskatalogen, LVH and RELIS — plus any you add yourself, and it shows where the answer came from. The query is built from clinical keywords, not raw record text; even so, never type a patient name into the chat.

For the clinic's privacy work

The clinic is the data controller. MedAid is the data processor.

We have a data protection impact assessment (DPIA) input package based on the Norwegian Directorate of Health's template that the clinic can build on. It is version 0.1 and still a draft — not yet reviewed by a lawyer or a data protection officer. Ask us and we will send it.

We follow the supplier guide of Normen, the Norwegian code of conduct for information security in healthcare. The clinic makes its own assessment, as Normen requires. Privacy questions: post@medaid.no.

Common questions

Common questions

How long is data kept?

Audio is deleted as soon as the note is written. Documents you upload in a conversation are deleted after 24 hours. The consultation, with its note and transcript, stays in your account for 30 days after the last activity and is then deleted automatically. If you need the note for longer, copy it into your record system — which is where it belongs anyway.

Is patient data used to train AI?

No. Never.

Can other doctors see my patients?

No. Even in a clinic, every doctor has their own consultations and notes. The clinic shares the invoice and templates, not patient data.

Is MedAid Normen-certified?

Normen is not a certification scheme. We follow its supplier guide and give the clinic the material it needs for its own assessment.

Want to see the documentation?

Get in touch and we will send the DPIA package and answer questions from IT or your data protection officer.

Contact us