Security
Answers to frequently asked questions about data security, GDPR compliance, and patient data protection.
Does Cora have medical device certification?
Cora does not diagnose or make medical decisions. It is a tool supporting the creation of medical documentation and operates under the full control of a specialist. If you need information about our regulatory status or ongoing certification processes, we will be happy to share details during a conversation or at the implementation stage.
How is data secured?
Data security was one of the priorities when building Cora. Data is encrypted both during transmission and while stored on servers. Only authorised users have access to it, and all solutions are designed in accordance with security best practices and GDPR requirements.
What happens if a data breach occurs?
We do everything to minimise the risk of such a situation. We apply multi-layer security, access controls, and data encryption. If a security incident were to occur despite this, we act in accordance with applicable regulations and prepared procedures. This includes analysing the event, securing the system, collaborating with the facility, and fulfilling obligations under GDPR.
Is using Cora compliant with GDPR?
Yes. Cora was designed with medical documentation work in mind and processes data in accordance with GDPR requirements. We sign a data processing agreement with each facility, and the entire process has been prepared to facilitate compliance with patient data protection obligations.
Where is data stored?
Data is stored on AWS servers located in Frankfurt, within the European Union. This ensures it remains subject to European data protection regulations.
Does data leave the European Union?
No. Data is processed and stored in infrastructure located in the EU. We exclusively use services and configurations that meet the requirements of European data protection regulations.
Who has access to recordings and documentation?
Only authorised users within the facility have access to data. Cora employees do not view or listen to patient recordings. Service access is strictly controlled and used only when necessary to resolve a reported issue.
Is data encrypted?
Yes. Data is encrypted both during transmission and storage. This means it is protected at every stage of using the system.
Can I delete all data after ending cooperation?
Yes. Data remains under the facility's control. After ending cooperation, it can be deleted in accordance with established policies or exported if needed.
Does Cora make medical decisions?
No. Cora is a tool that supports documentation creation. It prepares a draft note based on a patient conversation, but the doctor or specialist decides on its final content and approves the documentation.
Do I need patient consent to record a visit?
It depends on the legal basis for data processing adopted by a given facility. In practice, most of our clients consult this process with their Data Protection Officer or a lawyer. If needed, we provide documents and information to help prepare appropriate procedures.
Does the US Cloud Act mean patient data could be shared with US authorities?
This is one of the most frequently asked questions. Data processed by Cora is stored on servers located in the European Union and is subject to European data protection regulations. We use solutions designed with GDPR compliance in mind and apply encryption and appropriate technical safeguards. If your facility is conducting a detailed legal analysis, we provide documentation describing our architecture and data processing methods.
Do you help with preparing a DPIA (Data Protection Impact Assessment)?
Yes. We know that many facilities conduct a DPIA before implementing a new solution. For this assessment, we provide a complete set of information about how data is processed, the security measures applied, and the system architecture. This allows the Data Protection Officer or security team to efficiently conduct the required analysis.
What security documentation do you provide?
At the solution evaluation stage, we provide documents necessary for verifying security and GDPR compliance. Depending on the facility's needs, these may include a data processing agreement, a description of technical and organisational measures, infrastructure information, and materials supporting the preparation of a DPIA.
Does Cora use patient data to train AI models?
No. Patient data is not used to train artificial intelligence models or shared for this purpose with third parties. It remains exclusively within the processing environment necessary for preparing medical documentation.