Security & compliance

Built for German healthcare.
From the ground up.

Patient data, medical documentation and billing. No room for shortcuts. This page states how meda handles it.

Data protection

What is structurally true, before any practice data flows.

GDPR compliant.

In line with German healthcare requirements.

Hosted in the EU.

Our servers are in EU data centers, encrypted in transit and at rest.

AVV included.

A data processing agreement with every contract.

Audio is not stored.

Notes stay under your control.

Fails safe by construction.

If an AI stage fails, the deterministic answer stands. Nothing guesses on your behalf.

Traceable by design.

Every approved code keeps its link to the note.

Sovereignty, precisely

Our servers are in Europe.

meda reads the documentation — nothing enters your PVS unless you approve it — and every code is a physician's decision. Sovereignty here isn't a server location. It's the architecture.

Documentation and billing context. Nothing goes back without your approval, AVV-covered.

meda reads the documentation above the PVS; nothing is written back without approval.
Product data and website data kept in two separate systems, never mixed.
The AVV is the boundary: a data processing agreement is in place before any practice data flows.

Security questions? Ask them directly.

We answer data protection and compliance questions before anything else. AVV and technical documentation on request.

Book a call