Data and Information Security

We guarantee the highest medical quality in eye care – and in the handling of data.

The responsible and confidential handling of your data as well as the data of your customers is a central concern for us and part of our understanding of quality. With the following measures, we guarantee the highest standard of data security for our platform and cooperation: 

  • The Ocumeda platform ensures full compliance with the European General Data Protection Regulation (GDPR) and ensures that all data is processed exclusively in accordance with these guidelines. 

  • We rely on cloud partners whose systems are regularly audited and certified according to international security standards such as ISO/IEC 27001 as well as the German BSI C5. All data is stored in Europe. 

  • Ocumeda has a certified quality management system according to ISO 13485 for consistent compliance with regulatory requirements during the development and provision of safe medical devices. 

  • External experts regularly perform penetration tests to detect and remedy potential security vulnerabilities at an early stage. 

  • All data is securely encrypted both during transmission and storage. Wherever personal information is not required, we rely on anonymization/pseudonymization. 

  • Access rights to health data are strictly restricted: Only you, the reporting ophthalmologist, and your customers have access. Transfer to unauthorized third parties is excluded. 

  • We act in compliance with data protection regulations and independently. All operational data remains in your sole control and cannot be viewed by third parties. 

  • Our information security management system is regularly audited by external experts to verify the effectiveness of our system and to identify and remedy potential security vulnerabilities at an early stage.

  • If you have any questions regarding data security, please feel free to contact it-security@ocumeda.com.


;