industries · Healthcare

GDPR and the EHDS with the clinical record kept in-house

Clinical data never leaves Europe, or your network if you choose: inference only on EU infrastructure, an on-premise option and zero logs. Consultation transcription is the case with immediate ROI.

compliance

Compliance, built into the stack.

Every regulatory demand mapped to a platform capability that ships built in, with nothing to configure.

GDPR Art. 9

Regulation (EU) 2016/679, Art. 9

RequiresHealth data is a special category with reinforced protection: processing needs a specific legal basis, and confidentiality and residency come under real scrutiny.

HelmcodeZero logs by architecture and EU-only inference; for the strictest cases, the same stack runs on-premise, so no clinical record leaves your network.

EHDS

Regulation (EU) 2025/327 · in force since 26 Mar 2025, general application from 26 Mar 2027 (staged)

RequiresGovernance, portability and controlled secondary use of electronic health data, with traceability of who processes what and where.

HelmcodeAn auditable EU stack with documented data flows: you can show where inference runs and keep the data inside your perimeter.

AI Act

Regulation (EU) 2024/1689 · high-risk when the clinical AI is a medical device (Art. 6(1), Annex I)

RequiresClinical AI that is a medical device or its safety component carries high-risk obligations of traceability, data governance and human oversight.

HelmcodeOpen models with published model cards and licenses make the system documentable; classifying each clinical use is a matter for your regulatory team.

This page is an informational overview, not legal advice. For your obligations and the risk classification of each system, consult qualified legal counsel. AI Act Guide →

what the regulators clarified

What MDCG 2025-6 settles about clinical AI.

In June 2025 the medical device regulators of every Member State and the AI Board answered jointly how the MDR, the IVDR and the AI Act apply together to clinical AI. Not binding, but four of its answers change how you would build. Obligations start on 2 August 2027.

01

Not every clinical AI is high risk

High risk under Article 6(1) needs two conditions at once: the system is a medical device or a safety component of one, and a notified body assesses it. Both, not either. A transcription assistant that is neither does not inherit the regime.

02

Built in-house sits somewhere else

Question 35: an MDAI made and used only inside an EU health institution, under Article 5(5) of the MDR, skips third-party assessment and is not high risk. Other AI Act duties still apply, and the regulators say further requirements are coming.

03

Two trails, and neither is the content

Traceability is asked for twice: of the device across its lifecycle, and of the system’s own functioning, through the logs Article 12 requires. Neither is a record of what a clinician typed, so zero logs at the inference layer and a functional trail in your app are compatible.

04

The training-data duty does not transfer

Article 10 wants training data representative of the target population, examined for bias and documented. Buying inference discharges none of it, and fine-tuning on your own clinical data puts it on you. The Commission still owes guidance on how it works in practice.

MDCG + AIB · Medical Device Coordination Group and Joint Artificial Intelligence Board "Interplay between the MDR & IVDR and the Artificial Intelligence Act", AIB 2025-1 / MDCG 2025-6, 19 June 2025. Endorsed by both groups, made up of representatives of all Member States. Its own cover states that it is not a Commission document and is not legally binding. read the report →

use cases

Your most common use cases.

The cases with the most traction in the sector, each with its own page in detail.

Recommended open models.

A starting point per task type. The full guide maps 80 cases to the open model for each one.

Whisper large-v3MIT · STT in Helmcode
The open standard for multilingual clinical transcription, run in the EU or on-premise.
DeepSeek V4 FlashMIT · 1M ctx in Helmcode
Volume workhorse for history summaries and clinical documentation, on a flat rate.
qwen3-embedding + rerankApache 2.0 · embeddings in Helmcode
Semantic search over protocols and guidelines: the base of clinical RAG.

in progressWe are distilling and quantizing these open models into small, tightly specialised versions, trained for one task rather than for all of them. A model like that runs on less hardware, answers faster and fits where the big one does not, your own datacenter included. If you have a process with volume and stable criteria, that is the conversation we want to have with you.

// faq

Questions, answered.

What the sector's technical, compliance and business teams ask.

Can I transcribe medical consultations under GDPR?

Yes. Whisper runs on EU infrastructure or on-premise, with zero logs: audio and transcripts are never stored and never train models. For special-category health data (GDPR Art. 9), the on-premise option keeps everything inside your own network.

Does clinical data leave my network?

Only if you allow it. The default is EU-only inference with zero logs; the on-premise deployment runs the same models and API inside your own datacenter, so no clinical record ever leaves your perimeter.

What does the EHDS require from an AI system on health data?

The EHDS (Regulation (EU) 2025/327, in force since 26 March 2025, general application from 26 March 2027 and secondary use from 26 March 2029) sets governance, portability and controlled secondary use of electronic health data. An auditable EU stack with documented data flows and an on-premise option makes those requirements far easier to meet than a foreign API.

Is a clinical AI model high-risk under the AI Act?

When the AI is a medical device or a safety component of one, it is high-risk under the AI Act via Article 6(1) and Annex I (with MDR/IVDR), with obligations applying on the product timeline. Not every clinical assistant qualifies; the classification of each system is a matter for your regulatory team. An open, auditable stack makes documenting it easier.

Can we use open models with patient data?

Yes. What matters is where the weights run, not their origin: open weights executed on EU infrastructure or on-premise keep patient data inside your control and make the system auditable end to end.

// get started

START BURNING TOKENS

Skip the AI infra work. Deploy your first private inference endpoint today.

Flat rate. EU data. OpenAI API compatible.