GDPR, HIPAA, NHS DSPT and GxP, built in
We design, host and operate platforms that meet the regulations health and life-sciences organisations answer to, and hand you the evidence to prove it.
The frameworks we design and host to
UK GDPR & Data Protection Act 2018
UK data residency, encryption, role-based access, retention controls and support for your DPIAs and records of processing.
Applies to: UKEU GDPR
EU-region hosting, data processing agreements, data minimisation and controls for lawful cross-border data flows.
Applies to: EUHIPAA
US-hosted environments on HIPAA-eligible cloud services, with administrative, physical and technical safeguards and audit controls.
Applies to: US clientsNHS DSPT
Controls aligned to the NHS Data Security and Protection Toolkit, with evidence to support your annual submission.
Applies to: NHSISO 27001
Security controls and documentation aligned to an ISO 27001 information security management system.
Applies to: GlobalCyber Essentials Plus
Firewalls, secure configuration, access control, malware protection and security update management as standard.
Applies to: UKGAMP 5 · Annex 11 · Part 11
Computerised system validation, electronic records and signatures, and audit-ready validation documentation.
Applies to: Pharma & medtechALCOA+ data integrity
Records that are attributable, legible, contemporaneous, original and accurate, and complete, consistent, enduring and available.
Applies to: GxP dataWe design, build and operate your platform to meet these frameworks and provide the evidence your assessors and auditors need. Compliance is a shared responsibility: your organisation remains the data controller or covered entity. Arithmia's own UK/EU GDPR, NHS DSPT, Cyber Essentials Plus, ISO 27001 and HIPAA programmes are in progress.
How we get you compliant, and keep you there
Gap assessment
Review your data, systems and obligations against the frameworks that apply to you.
Control design
Map each requirement to technical and organisational controls in your platform.
Build and evidence
Implement the controls and collect the evidence your assessors and auditors need.
Continuous assurance
Monitor, patch, log and review, with evidence refreshed for each audit cycle.
Who is responsible for what
Compliance in the cloud is shared between the cloud provider, Arithmia and your organisation. We document every control so there are no gaps.
| Area | Cloud provider (AWS / Azure) | Arithmia | Your organisation |
|---|---|---|---|
| Physical data centre security | Cloud provider | — | — |
| Network, encryption and infrastructure setup | Shared | Arithmia | — |
| Patching, monitoring and backups | — | Arithmia | — |
| Identity and access control | — | Arithmia configures | You approve users |
| Validation documentation (GxP) | — | Arithmia prepares | You review and sign off |
| Lawful basis, DPIAs and data protection policies | — | Arithmia supports | You own |
Arithmia's compliance roadmap
We hold ourselves to the same standards we build for you.
Standards we design to
Certifications in progress
Find out where you stand
Our readiness assessment reviews your compliance position against GDPR, HIPAA, NHS DSPT and GxP, and gives you a clear roadmap.