For healthcare providers
Security, patient data, and responsibility
Evira is developed for use in healthcare. The healthcare provider retains clinical responsibility and is the data controller for patient and care data. Evira processes the data on behalf of the healthcare provider and protects it through encryption, strong authentication, access control, and traceable logging.
- CE marked in accordance with MDR, Class I
- GDPR and data processing agreement
- Patient data within the EU/EEA
- Two-factor authentication and encryption
Clear division of responsibility from the start
Evira is used as part of the healthcare provider's own treatment. This means that the medical relationship and responsibility for the patient remain with the healthcare provider.

The healthcare provider
Holds the clinical responsibility
The healthcare provider is responsible for assessment, treatment plan, medical decisions, and patient follow-up.
Is the data controller for healthcare data
The healthcare provider determines why and how patient and healthcare data should be used in healthcare and how long the data needs to be stored according to applicable regulations.
Determines who has access
It is the healthcare provider who decides which employees should be able to work with patients in Evira.
Evira
Is the data processor for patient and healthcare data
Evira processes the data according to the healthcare provider's documented instructions and data processing agreement.
Is responsible for the technical platform
Evira is responsible for the operation, security, maintenance, and technical support of the platform.
Supports the healthcare provider's review
We provide documentation for, among other things, data protection, information security, technical architecture, and local risk assessments.
How patient data is protected
Security is built into the platform's architecture and covers both the information stored and access to it.

Encryption
AES-256 for storage: personal data in Evira is stored encrypted with AES-256.
TLS 1.3 for transfer: communication between the app, clinic interface, and Evira's services is encrypted with TLS 1.3.
Encryption keys are managed at patient level and are destroyed upon permanent deletion of patient data.
Strong authentication
Access to clinical and administrative accounts with patient data requires two-factor authentication.
For healthcare professionals, Evira can support, among other things:
- SITHS
- BankID
- Two-factor authentication and one-time codes
Access control
Users should only be able to access the information they need for their role.
Evira uses access control and time-limited access tokens to restrict what information a user or service can access.
Clinics' data is kept separate from each other.
Pseudonymisation and data minimisation
Direct personal identifiers are replaced with pseudonymised identifiers where possible.
Evira uses unique identifiers for patients and other objects and designs data flows so that identifying information does not need to be processed when not necessary.
Traceability
Access to Evira's API is logged. The logs make it possible to track, among other things:
- which user made a request
- when it was carried out
- which part of the service was used
- the result of the request
Data within the EU/EEA
Evira uses IT and operations providers within the EU/EEA for the storage and operation of patient data.
Detailed information about architecture, data flows, operating environment, and relevant subcontractors can be provided as part of an information security or data protection review.
In the patient app, sensitive views are also protected with biometric authentication or a PIN code where supported by the phone.
Built for review and procurement
A healthcare provider should not have to start from a blank document when Evira is to undergo a security review.
We have established a basis that can be used by operations, IT, information security, data protection, and procurement.

Data Processing Agreement
The agreement regulates, among other things, responsibilities, the processing of patient data, security measures, and how Evira may process the data on behalf of the healthcare provider.
DPIA basis
We assist the healthcare provider with the information needed for an impact assessment, such as processing activities, data flows, technical security measures, and risk-mitigating measures.
Technical documentation
We can provide documentation about:
- system architecture and data flows
- authentication and access control
- encryption
- logging and traceability
- operation and backup
- incident management
- continuity and recovery
Information security
Evira operates a structured information security management system in line with the principles of ISO/IEC 27001.
Information security policy and additional security documentation can be shared upon review.
Security testing
Evira conducts technical security reviews and penetration tests of the platform. Documentation and summaries can be made available within the framework of a customer review.
Medical technology and patient safety
Evira is CE marked as a medical device according to the EU Medical Device Regulation, MDR, class I.
This means that the platform is subject to requirements including documentation, risk management, follow-up, and quality throughout the product's lifecycle.
Evira is a treatment support. The medical responsibility and clinical decisions always rest with the healthcare provider.
The core platform is developed and maintained by Evira, which gives us control over development, security work, quality assurance, and how changes are introduced into the product.
Clinical safety is also monitored in research
Since Evira is used for recurring weight measurements in children, eating behaviour, among other things, has been specifically monitored in clinical research.
In the three-year follow-up of the first Evira cohort, no patient received an eating disorder diagnosis during treatment or in the subsequent year.
Read more about research and clinical results and in references.
Operations, backup, and incident management
Security also means that the service must be available when needed.
Backup and recovery
Data is backed up regularly. Backups are encrypted and access is restricted.
Continuity and disaster recovery
There are documented processes for restoring the platform and data in the event of a severe disruption.
Incident management
Security and operational incidents are assessed based on their severity and handled according to established incident processes. Affected customers are informed in case of significant impact.
Ongoing maintenance
The platform is continuously maintained and updated. Security updates and corrections are handled as part of the ordinary development process.
Documents and supporting materials
For those who wish to delve deeper, more detailed documentation is available.
Privacy Policy
How Evira processes personal data and how responsibility is allocated.
Open document (PDF)Information Security Policy
The principles behind Evira's information security work.
Open document (PDF)Declaration of Conformity
Documentation of Evira's CE marking and regulatory status.
Open document (PDF)Security and data protection package
Technical architecture, data flows, security measures and other documentation for IT, data protection or procurement reviews.
Request security documentationSee also how an implementation works on the page about clinic implementation.
Frequently asked questions about security and patient data
Request security documentation
Tell us what type of review you are conducting, and we will get back to you with relevant documentation.