Security and procurement

Security and procurement information for healthcare organizations

Dr.MaxHealth operates from Hamburg, Germany. Every evaluation or pilot is governed by written terms defining the permitted data scope, processing roles, security measures, retention, subprocessors, transfers, and deletion requirements.

01

Data protection

Controller and processor roles
The healthcare organization remains the controller for patient data. Dr.MaxHealth acts as a processor under written terms concluded before any processing begins.
Scoped processing
Patient data is processed only within the record scope agreed in writing: laboratory results, diagnoses, medications, encounters, and clinical notes as defined per engagement.
Encryption in transit
All traffic and data exchange with Dr.MaxHealth is served over TLS.
Clinical responsibility
Output requires review by a qualified healthcare professional. PULSE does not diagnose, prescribe, or act on patients.
US engagements
Privacy, security, contractual, and deployment requirements for US engagements are assessed during procurement before any patient data is processed. Dr.MaxHealth does not make a blanket public HIPAA or BAA-availability claim.

02

Access and environment controls

Role-based access requirements
Role-based access requirements for an engagement are agreed and documented in writing before any patient data is processed.
Environment requirements
Environment separation requirements for evaluation and deployment are defined per engagement and documented before any patient data is processed.
European operation
Dr.MaxHealth is operated from Hamburg, Germany by DMH Software UG (haftungsbeschränkt).

03

Data use and retention

Purpose limitation
Customer data is processed only for purposes agreed in writing.
Retention and deletion
Retention periods and deletion procedures are defined per engagement and recorded in the written terms.
Subprocessors
Subprocessors used in an engagement are disclosed to the customer during technical discovery.
International transfers
Transfer requirements are assessed per engagement before any data exchange.
Website data
This website does not intentionally set advertising or marketing cookies. Hosting providers may process technical request and usage data for delivery, security, and service operation. Demo requests are used only to respond to the enquiry. Never send patient data through this website.
Scope of this website
This website covers the public marketing site at drmaxhealth.de. The future platform at drmaxhealthplatform.de is not live and will have its own separate notice before launch.

Data Protection Officer: Dr. Maksym Kitsera office@drmaxhealth.de

04

Documentation available on request

Security and data-governance documentation is shared directly with evaluating organizations. Request it from the contact below and state your review scope.

  • Security overviewOverview of current security measures, shared under NDA.
  • Technical and organizational measuresThe measures applicable to the proposed engagement scope.
  • Data-processing agreementTemplate terms for clinical evaluation and pilot engagements.
  • Engagement-specific subprocessor informationSubprocessors relevant to the agreed deployment scope.
  • Data-retention and deletion termsRetention periods and deletion procedures for the engagement.