Patient data under European jurisdiction. Operations without interruption.
HEALTH DATA
The most heavily regulated category of data in the public sector
Patient data falls under the special categories of the GDPR, medical record-keeping is a statutory duty, and NIS2 classifies healthcare as critical infrastructure. At the same time, a growing share of health IT is operated by non-European suppliers under foreign jurisdiction. What matters for a data controller is not physical location, but jurisdiction over the data, control of access, and continuity of operations.
THE PLATFORM
Five healthcare requirements, and the platform's answer to each
Patient data under European jurisdiction
A clean European ownership and operations chain means the data leaves neither the EU nor your control. Location, operations and jurisdiction move together.
Systems that must not leave the hospital
The whole platform can be delivered and operated in your own datacentre. Latency-critical and local clinical systems stay on site.
Operations without interruption
Distributed architecture with no central points of failure, failover in seconds, and local autonomy if connectivity is lost.
NIS2 for healthcare, documented
Security, audit logging and supplier governance are part of the platform, not bolted on. The documentation matches what regulators ask for.
A controlled route out of hyperscaler dependency
A planned migration path away from non-European platforms, with performance and compliance validated before the final rollout.
OPERATIONS
Clinical operations cannot tolerate downtime
Clinical systems run around the clock. The architecture is distributed with no central points of failure, failover is measured in seconds, and each location operates independently if it loses connectivity to the others. Sensitive traffic between locations runs on a closed optical network, bypassing the public internet.
PROCUREMENT
Procurement through public framework agreements
In Denmark, Edora is available across the whole engagement: migration and IT consultancy via SKI 02.17, servers, storage and complete datacentre solutions via 02.03, and IT operations via the 02.22 dynamic purchasing system. From hardware through to operations, procurement, jurisdiction and compliance hang together.
QUESTIONS & ANSWERS
What healthcare organisations most often assess
Is "data in Europe" enough on its own?
Not by itself. A platform operated by a non-European operator is subject to that operator's home legislation, regardless of the servers sitting in Europe. Edora is owned, operated and controlled at every level from Denmark, so location, operations and jurisdiction move together.
Can systems sit at the hospital itself?
Yes. The whole platform can be delivered and operated in your own datacentre via EU Cloud in a Box. Latency-critical and local clinical systems stay on site, and data does not leave the building.
What happens if connectivity is lost?
Each location operates independently. If the connection drops, operations, self-service and workloads continue locally, and replication resumes automatically once connectivity is restored.
How does the platform support NIS2?
Security, audit logging, access management and supplier governance are built into the platform. That produces the documentation regulators ask for, rather than controls bolted on afterwards.
Can we migrate away again?
Yes. The platform is open source with no proprietary layers, so workloads and data can be moved. An exit is technically real, not merely described in a contract.