Security and data protection
Sensitive data requires robust protection
MedHelp helps employers manage sick leave and rehabilitation. This means that we process data that requires a particularly high level of protection.
That is why information security and data protection are integrated into how we develop, operate and manage our health platform. Our work includes both technical and organisational safeguards – from encryption and access control to continuous risk management and incident preparedness.
With MedHelp, you get:
- A health platform certified to ISO/IEC 27001:2022
- Data storage in Sweden
- Encryption of data at rest and in transit
- Role-based access control and multi-factor authentication
- Support for SSO and BankID
- Regular vulnerability scans and annual penetration tests
Certified information security
Security that is independently assessed - not just promised
MedHelp's health platform is certified to ISO/IEC 27001:2022. The certification means that we take a systematic, risk-based approach to information security and that our work is reviewed by an independent third party.
Our security work includes technical, organisational and physical safeguards to ensure the confidentiality, integrity and availability of information.
GDPR and responsibility for personal data
The platform is designed for the processing of personal data in accordance with the GDPR. When MedHelp processes data on behalf of an employer, we act as a data processor and enter into a data processing agreement with the customer.
Our approach is based, among other things, on the principles of data minimisation and least privilege. This means that users only have access to the data required for their role and responsibilities.
How we protect your data
Encryption
Data is encrypted both at rest and in transit. Encryption and key management follow established security principles.
Access control and authentication
Role-based access control limits users' access according to their permissions. Multi-factor authentication and logging provide additional protection and traceability.
The platform supports:
- SSO via SAML 2.0 and OpenID Connect
- Integration with identity providers such as Microsoft Entra ID
- Self-service using BankID
Data is stored in Sweden
MedHelp's data is stored in AWS data centres in Sweden. This means that the geographical storage and processing of the data takes place in Sweden.
AWS is, however, a US-owned provider. MedHelp addresses this as part of its data protection and supplier security work, using relevant agreements, technical safeguards and controls for the processing of personal data.
Customer data is logically segregated. Files are stored in separate, encrypted file storage areas, and the solution is continuously tested and validated.
Continuous security testing
We carry out regular vulnerability scans and annual penetration tests. Identified vulnerabilities are prioritised and remediated within defined timeframes based on risk.
A summary of completed penetration tests can be shared with customers on request.
Frequently asked questions
Yes. The platform is certified to ISO/IEC 27001:2022.
Data is stored in AWS data centres in Sweden. AWS is a US-owned provider, which is addressed through relevant agreements, technical safeguards and supplier controls.
Yes. Data is encrypted both at rest and in transit.
MedHelp acts as a data processor when we process data on behalf of an employer. The processing is governed by a data processing agreement and is based, among other things, on the principle of least privilege.
Yes. We carry out annual penetration tests and regular vulnerability scans. A summary can be shared with customers on request.
Yes. The platform supports SSO via SAML 2.0 and OpenID Connect, for example through Microsoft Entra ID, as well as self-service using BankID.
The customer's data can be exported in accordance with agreed procedures. The data is then deleted in a controlled manner in accordance with the agreement and applicable data protection requirements.
Need more information?
We are happy to help IT, security and procurement teams with questions and supplementary documentation as part of a security assessment.
Meets the highest security standards
MedHelp is built for organisations that set high standards for security and data protection. Our processes, systems and ways of working are designed to protect sensitive information and create confidence for both employers and employees.