Skip to main content

For healthcare providers

Security, patient data, and responsibility

Evira is developed for use in healthcare. The healthcare provider retains clinical responsibility and is the data controller for patient and care data. Evira processes the data on behalf of the healthcare provider and protects it through encryption, strong authentication, access control, and traceable logging.

  • CE marked in accordance with MDR, Class I
  • GDPR and data processing agreement
  • Patient data within the EU/EEA
  • Two-factor authentication and encryption

Clear division of responsibility from the start

Evira is used as part of the healthcare provider's own treatment. This means that the medical relationship and responsibility for the patient remain with the healthcare provider.

The healthcare provider

  • Holds the clinical responsibility

    The healthcare provider is responsible for assessment, treatment plan, medical decisions, and patient follow-up.

  • Is the data controller for healthcare data

    The healthcare provider determines why and how patient and healthcare data should be used in healthcare and how long the data needs to be stored according to applicable regulations.

  • Determines who has access

    It is the healthcare provider who decides which employees should be able to work with patients in Evira.

Evira

  • Is the data processor for patient and healthcare data

    Evira processes the data according to the healthcare provider's documented instructions and data processing agreement.

  • Is responsible for the technical platform

    Evira is responsible for the operation, security, maintenance, and technical support of the platform.

  • Supports the healthcare provider's review

    We provide documentation for, among other things, data protection, information security, technical architecture, and local risk assessments.

How patient data is protected

Security is built into the platform's architecture and covers both the information stored and access to it.

Encryption

AES-256 for storage: personal data in Evira is stored encrypted with AES-256.

TLS 1.3 for transfer: communication between the app, clinic interface, and Evira's services is encrypted with TLS 1.3.

Encryption keys are managed at patient level and are destroyed upon permanent deletion of patient data.

Strong authentication

Access to clinical and administrative accounts with patient data requires two-factor authentication.

For healthcare professionals, Evira can support, among other things:

  • SITHS
  • BankID
  • Two-factor authentication and one-time codes

Access control

Users should only be able to access the information they need for their role.

Evira uses access control and time-limited access tokens to restrict what information a user or service can access.

Clinics' data is kept separate from each other.

Pseudonymisation and data minimisation

Direct personal identifiers are replaced with pseudonymised identifiers where possible.

Evira uses unique identifiers for patients and other objects and designs data flows so that identifying information does not need to be processed when not necessary.

Traceability

Access to Evira's API is logged. The logs make it possible to track, among other things:

  • which user made a request
  • when it was carried out
  • which part of the service was used
  • the result of the request

Data within the EU/EEA

Evira uses IT and operations providers within the EU/EEA for the storage and operation of patient data.

Detailed information about architecture, data flows, operating environment, and relevant subcontractors can be provided as part of an information security or data protection review.

In the patient app, sensitive views are also protected with biometric authentication or a PIN code where supported by the phone.

Built for review and procurement

A healthcare provider should not have to start from a blank document when Evira is to undergo a security review.

We have established a basis that can be used by operations, IT, information security, data protection, and procurement.

Data Processing Agreement

The agreement regulates, among other things, responsibilities, the processing of patient data, security measures, and how Evira may process the data on behalf of the healthcare provider.

DPIA basis

We assist the healthcare provider with the information needed for an impact assessment, such as processing activities, data flows, technical security measures, and risk-mitigating measures.

Technical documentation

We can provide documentation about:

  • system architecture and data flows
  • authentication and access control
  • encryption
  • logging and traceability
  • operation and backup
  • incident management
  • continuity and recovery

Information security

Evira operates a structured information security management system in line with the principles of ISO/IEC 27001.

Information security policy and additional security documentation can be shared upon review.

Security testing

Evira conducts technical security reviews and penetration tests of the platform. Documentation and summaries can be made available within the framework of a customer review.

Medical technology and patient safety

Evira is CE marked as a medical device according to the EU Medical Device Regulation, MDR, class I.

This means that the platform is subject to requirements including documentation, risk management, follow-up, and quality throughout the product's lifecycle.

Evira is a treatment support. The medical responsibility and clinical decisions always rest with the healthcare provider.

The core platform is developed and maintained by Evira, which gives us control over development, security work, quality assurance, and how changes are introduced into the product.

Clinical safety is also monitored in research

Since Evira is used for recurring weight measurements in children, eating behaviour, among other things, has been specifically monitored in clinical research.

In the three-year follow-up of the first Evira cohort, no patient received an eating disorder diagnosis during treatment or in the subsequent year.

Read more about research and clinical results and in references.

Operations, backup, and incident management

Security also means that the service must be available when needed.

Backup and recovery

Data is backed up regularly. Backups are encrypted and access is restricted.

Continuity and disaster recovery

There are documented processes for restoring the platform and data in the event of a severe disruption.

Incident management

Security and operational incidents are assessed based on their severity and handled according to established incident processes. Affected customers are informed in case of significant impact.

Ongoing maintenance

The platform is continuously maintained and updated. Security updates and corrections are handled as part of the ordinary development process.

Documents and supporting materials

For those who wish to delve deeper, more detailed documentation is available.

Privacy Policy

How Evira processes personal data and how responsibility is allocated.

Open document (PDF)

Information Security Policy

The principles behind Evira's information security work.

Open document (PDF)

Declaration of Conformity

Documentation of Evira's CE marking and regulatory status.

Open document (PDF)

Security and data protection package

Technical architecture, data flows, security measures and other documentation for IT, data protection or procurement reviews.

Request security documentation

See also how an implementation works on the page about clinic implementation.

Frequently asked questions about security and patient data

Request security documentation

Tell us what type of review you are conducting, and we will get back to you with relevant documentation.

Fields marked with * are required.