Data and Information Security
We guarantee the highest medical quality in eye care – and in the handling of data.
The responsible and confidential handling of your data as well as the data of your customers is a central concern for us and part of our understanding of quality. With the following measures, we guarantee the highest standard of data security for our platform and cooperation:
- The Ocumeda platform ensures full compliance with the European General Data Protection Regulation (GDPR) and ensures that all data is processed exclusively in accordance with these guidelines.
- We rely on cloud partners whose systems are regularly audited and certified according to international security standards such as ISO/IEC 27001 as well as the German BSI C5. All data is stored in Europe.
- Ocumeda has a certified quality management system according to ISO 13485 for consistent compliance with regulatory requirements during the development and provision of safe medical devices.
- External experts regularly perform penetration tests to detect and remedy potential security vulnerabilities at an early stage.
- All data is securely encrypted both during transmission and storage. Wherever personal information is not required, we rely on anonymization/pseudonymization.
- Access rights to health data are strictly restricted: Only you, the reporting ophthalmologist, and your customers have access. Transfer to unauthorized third parties is excluded.
- We act in compliance with data protection regulations and independently. All operational data remains in your sole control and cannot be viewed by third parties.
- Our information security management system is regularly audited by external experts to verify the effectiveness of our system and to identify and remedy potential security vulnerabilities at an early stage.
If you have any questions regarding data security, please feel free to contact it-security@ocumeda.com.


