From Scare to Care
Document No.: AC-2026-0816 / Vilnius
Date: August 16, 2026
Applicant: MB "AtidusCare", Švitrigailos St. 26-23, Vilnius

OFFICIAL STATEMENT REGARDING PRODUCT TECHNICAL PILOTING AND GDPR COMPLIANCE

In response to institutional inquiries and questions raised by legal departments of healthcare institutions regarding the pilot deployment of the digital assistant "AtidusCare", the production and legal teams of MB "AtidusCare" formally confirm the following key characteristics of the platform:

1. TRANSIENT DATA PROCESSING WITHOUT DATA RETENTION

All transcription and clinical context analysis processes are performed exclusively within server volatile memory (RAM-only) on private cloud infrastructure located in Frankfurt, Germany. Once the physician's speech has been converted into text and a medical SOAP note has been generated, the audio file and all associated metadata are automatically and irreversibly deleted within 15 seconds. No historical records, patient histories, or residual traces of consultation data are stored on persistent storage devices. This approach complies with Article 5(1) of Directive 2001/29/EC and Article 5(1)(e) of the GDPR.

2. HUMAN-IN-THE-LOOP MODEL

Our solution operates locally as a client-side browser extension and does not use any direct API integrations with the national E-Health platform. The application does not autonomously sign, submit, or transfer any records into centralized healthcare registries. It merely provides an editable draft within the extension interface. A licensed physician reviews the generated text, manually corrects any inaccuracies produced by artificial intelligence, and performs the final manual transfer (COPY/PASTE) during an authorized and secure session. Final clinical and legal responsibility remains entirely with the healthcare professional. Consequently, the system is not subject to the regulatory requirements applicable to high-risk Software as a Medical Device (SaMD).

3. AUTOMATIC DE-IDENTIFICATION AND DATA MINIMIZATION

In accordance with Article 5(1)(c) of the GDPR (Data Minimization), the system processes only the information strictly necessary to perform its intended function. During consultation processing, our semantic filtering mechanism automatically removes personal identifiers, including names, surnames, and specific addresses, before generating the final output displayed on screen. This approach is consistent with GDPR Recital 26, under which anonymized information falls outside the scope of GDPR regulation. Furthermore, the initial deployment phase utilizes an asynchronous post-consultation dictation model, effectively eliminating patient consent barriers during processing.