ERC Group
Governance

Protecting data that cannot be re-collected

A breach in a national health system is not a service incident. These are the controls that protect patient data across every deployment we run.

01

Platform controls

Built into the platform rather than configured per installation, so every deployment inherits the same baseline.

01

Encryption in transit and at rest

SHA-256 encryption for stored data and TLS for all data in transit, including integration traffic between the platform and external national services.

02

Role-based access control

Access is granted by clinical and administrative role, scoped to facility and department, so a user sees only the records their function requires.

03

Full audit logging

Every record access, modification and export is logged with user, timestamp and context, and the log is retained for the period the contracting authority requires.

04

De-identification

GDPR-compliant de-identification for secondary use, so research, reporting and analytics run without exposing identifiable patient data.

05

Authentication

Integration with national identity providers and enterprise directories, with multi-factor authentication available for administrative and remote access.

06

Segregation between tenants

Multi-tenant deployments keep hospital instances logically isolated inside clustered environments, so one facility cannot reach another's records.

02

Where data lives

Health data sovereignty is a procurement requirement before it is a technical one.

  • National data residency

    National programmes run inside the country's own infrastructure. Patient data does not leave the jurisdiction unless the contracting ministry explicitly directs otherwise.

  • Deployment model is yours to choose

    On-premise, private cloud or hybrid, delivered as Docker containers. We do not require that data be hosted on infrastructure we control.

  • Defined data ownership

    The contracting authority owns the data. Our access is limited to what support and maintenance require, and is logged like any other access.

03

Operational security

Controls matter less than what happens on the day something goes wrong.

01

Incident response

Defined severity levels, response times and escalation paths, including notification obligations to the contracting authority and, where applicable, data protection regulators.

02

Vulnerability management

Dependencies and platform components are monitored for known vulnerabilities, with patching prioritised by severity and deployed through controlled release management.

03

Business continuity

Backup, restore and failover procedures tested against recovery objectives agreed per programme, because national systems have no acceptable maintenance window.

04

Change control

Versioned releases with documented approval and rollback, so a security fix can be deployed without becoming an availability incident.

Our information security management system is certified to ISO 27001. Certification documents and audit summaries are available for tender submissions on the quality and certification page.

04

Reporting a vulnerability

If you believe you have found a security issue in one of our systems, we want to hear about it directly and we will not pursue researchers who report in good faith.

Need our security documentation?

We can provide security architecture documentation, certification evidence and completed security questionnaires for procurement.