Reports in consumer tools
Under time pressure, a report containing patient data gets pasted into a chatbot to tidy it up. No processing agreement, no logging, no idea where the data ends up.
Healthcare
Clinicians spend a large part of their time on administration. AI can help, but patient data does not belong in a consumer tool. werqly runs AI on a node in your own server room, with roles per department, safeguards on national ID and patient numbers, and an audit log that records who used which data and when.
Running in your server room
Role: Clinician
Safeguards active
Insight: anonymous (default)
werqly Node — dedicated AI node, in your server room or in our European datacentres
The risk
Under time pressure, a report containing patient data gets pasted into a chatbot to tidy it up. No processing agreement, no logging, no idea where the data ends up.
Banning AI does not remove the administrative burden. It only makes the use invisible to the data protection officer.
Health data comes with national security and hosting requirements that must be demonstrable. A standalone AI tool without logging does not fit them.
Use cases
Automations are built per organisation, usually following from the TIMA Scan. Always supportive: the clinician checks and decides.
A first version of a report, which the clinician checks and completes.
The relevant information from a record, gathered for a handover or referral.
Draft letters to the GP or referring physician, based on the report.
Your organisation’s guidelines, protocols and work instructions searchable, with sources.
Recurring themes in complaints and incident reports made visible for quality management.
Preparing registration and billing work, checked by the administration.
Regulation
werqly does not make processing patient data lawful by itself. It does give your organisation an environment that fits into your information security.
| Framework | What it asks | How werqly fits |
|---|---|---|
| National health-data hosting rules | Several EU countries set specific requirements: HDS certification for hosting health data in France, a C5 attestation for cloud use in Germany, NEN 7510 compliance in the Netherlands. | A node in your own server room keeps health data within your organisation. werqly holds neither HDS nor C5, and its NEN 7510 certification is in progress. |
| Medical confidentiality | Patient data only for those directly involved in the patient’s care. | Roles per department and function determine which sources and automations someone may use. |
| GDPR: health data (Art. 9) and DPIA (Art. 35) | Health data is a special category of personal data. Large-scale processing usually requires a data protection impact assessment. | Processing on a dedicated node in your server room, without transfer to third parties, makes the DPIA more manageable. |
| Medical Device Regulation (EU 2017/745) | Software intended for diagnosis or treatment can be a medical device. | werqly is not a medical device. Use it for administration and support, not for diagnostic or treatment decisions. |
This page is not legal advice. Always assess the use of AI with your own data protection officer, compliance function or professional body.
Recommended setup
For patient data we recommend your own server room: the data then never leaves your organisation. With werqly Pro management, werqly operates the node remotely as a processor; when self-managed, your IT department does so.
Calculator
Enter your work email. Our AI looks up the size of your organisation and works out four setups for you: in the cloud or in your own server room, self-managed or with werqly Pro management.
Looking up your organisation and working out the proposals…
For patient data we recommend your own server room. werqly holds neither HDS nor C5 certification and its NEN 7510 certification is in progress; werqly Cloud suits work without patient data.
Dedicated node in our European datacentres
Your node in your own server room or rack
werqly Pro management
We operate the node and the models
— per month
—
werqly Pro management
We operate the node and the models
— per month
—
Self-managed
Your IT department operates it; we supply software and updates
— per month
—
Self-managed
Your IT department operates it; we supply software and updates
— per month
—
Indicative amounts, excluding VAT. Custom automations are quoted separately. Only the quote is binding.
FAQ
That depends on your own assessment: the legal basis, a DPIA, and how werqly fits your national security and hosting requirements. The setup in your own server room, without transfer to third parties, is built for it. Involve your data protection officer from the start.
No. werqly supports administration and documentation. The clinician checks the output and makes the decisions. Applications intended for diagnosis or treatment fall under the Medical Device Regulation.
Yes, as a project with your EHR vendor. Such a connection is read-only, scoped per role and part of the DPIA. Expect it to be the part that needs the most preparation.
Prompts, documents and output are processed on the node in your server room. The management link carries configuration, updates and only the insights you release. With werqly Pro management, werqly is a processor and maintenance is covered by the processing agreement.