Tamper-resistant audit trail
Medical-record operations are logged to a SHA-256 hash-chain audit trail, so data changes are traceable and hard to alter silently.
Health data is the most sensitive personal data there is. Here is a concrete explanation of the security controls — not just 'secure & encrypted' — mapped to the obligations of UU 27/2022 on Personal Data Protection, complete with an honest boundary of responsibility.
Legal standing
Patient health data qualifies as specific (sensitive) personal data under UU 27/2022 on Personal Data Protection. A hospital generally acts as the data controller — responsible for the lawful basis of processing, security, fulfilment of data-subject rights, and handling of breach incidents.
A good information system does not remove that responsibility, but provides the technical controls that make it achievable and provable. Here is what Adievia provides — as it is.
Technical controls
Every control is labeled with its status as it is — Live, Partial, or Maturing. We do not mark everything "done".
Medical-record operations are logged to a SHA-256 hash-chain audit trail, so data changes are traceable and hard to alter silently.
Sensitive data is encrypted at the column level at rest; transport is secured with TLS 1.2/1.3. Full coverage across every sensitive field is still being matured.
Access rights per role and per module, kept in sync between the application and the database — supporting the need-to-know principle over patient data.
Multi-factor options (TOTP RFC 6238, passkey/WebAuthn, backup codes) are being matured; accounts can be required to use MFA once finalized.
An honest boundary
Technology handles the controls; organizational compliance still belongs to the hospital.
Appointing a DPO, drafting data-protection policies, the lawful basis of processing (consent), and the obligation to notify the authority and data subjects of a breach are the hospital's responsibility as the data controller. Adievia provides the audit trail, encryption, and access controls that support meeting those obligations — not a replacement for them. An honest vendor does not promise that "PDP compliance is handled automatically".
FAQ
Because hospitals process patient data, including health data that qualifies as specific (sensitive) personal data. Under UU 27/2022, a hospital generally acts as the personal-data controller — responsible for the lawful basis of processing, security, fulfilment of data-subject rights, and incident handling.
Not just "secure and encrypted": a tamper-resistant SHA-256 hash-chain audit trail, field-level AES-256-GCM encryption for sensitive data at rest, TLS 1.2/1.3 in transit, and granular RBAC. For MFA and full encryption coverage, some parts are still being matured toward launch — we state this as it is.
The system supports logging and traceability (audit trail) that help detect and investigate incidents. However, the legal obligation to notify the authority and data subjects of a breach, along with appointing a DPO, remains the hospital's responsibility as the data controller. We provide the technical controls, not a replacement for organizational compliance.
Yes. Data portability is one of the rights set out in the PDP Law. Adievia lets you export data to standard formats (CSV, FHIR R4 JSON, SQL) at any time — with no vendor lock-in.