Security and data protection

Sensitive data requires robust protection

MedHelp helps employers manage sick leave and rehabilitation. This means that we process data that requires a particularly high level of protection.

That is why information security and data protection are integrated into how we develop, operate and manage our health platform. Our work includes both technical and organisational safeguards – from encryption and access control to continuous risk management and incident preparedness.

With MedHelp, you get:

  • A health platform certified to ISO/IEC 27001:2022
  • Data storage in Sweden
  • Encryption of data at rest and in transit
  • Role-based access control and multi-factor authentication
  • Support for SSO and BankID
  • Regular vulnerability scans and annual penetration tests

Certified information security

Security that is independently assessed - not just promised

MedHelp's health platform is certified to ISO/IEC 27001:2022. The certification means that we take a systematic, risk-based approach to information security and that our work is reviewed by an independent third party.

Our security work includes technical, organisational and physical safeguards to ensure the confidentiality, integrity and availability of information.

GDPR and responsibility for personal data

The platform is designed for the processing of personal data in accordance with the GDPR. When MedHelp processes data on behalf of an employer, we act as a data processor and enter into a data processing agreement with the customer.

Our approach is based, among other things, on the principles of data minimisation and least privilege. This means that users only have access to the data required for their role and responsibilities.

How we protect your data

Encryption

Data is encrypted both at rest and in transit. Encryption and key management follow established security principles.

Access control and authentication

Role-based access control limits users' access according to their permissions. Multi-factor authentication and logging provide additional protection and traceability.

The platform supports:

  • SSO via SAML 2.0 and OpenID Connect
  • Integration with identity providers such as Microsoft Entra ID
  • Self-service using BankID

Data is stored in Sweden

MedHelp's data is stored in AWS data centres in Sweden. This means that the geographical storage and processing of the data takes place in Sweden.

AWS is, however, a US-owned provider. MedHelp addresses this as part of its data protection and supplier security work, using relevant agreements, technical safeguards and controls for the processing of personal data.

Customer data is logically segregated. Files are stored in separate, encrypted file storage areas, and the solution is continuously tested and validated.

Continuous security testing

We carry out regular vulnerability scans and annual penetration tests. Identified vulnerabilities are prioritised and remediated within defined timeframes based on risk.

A summary of completed penetration tests can be shared with customers on request.

Frequently asked questions

Need more information?

We are happy to help IT, security and procurement teams with questions and supplementary documentation as part of a security assessment.

SECURITY AND TRUST

Meets the highest security standards

MedHelp is built for organisations that set high standards for security and data protection. Our processes, systems and ways of working are designed to protect sensitive information and create confidence for both employers and employees.

ISO 27001

We are certified to ISO 27001 – the highest standard for information security

GDPR

The service is designed to meet the requirements of GDPR

EU/EES

All servers are located within the EU/EEA

SFTP

Encrypted file transfer and automatic backup