Healthcare / Clinical AI

Clinical AI data, audit-ready and EEA-resident

Clinical AI training data is special-category data under GDPR Article 9: every recording, image, and patient record needs documented consent, provenance, and an erasure path a regulator can trace. YPAI builds that audit trail into collection and annotation from the first recording, across eight clinical modalities, on self-hosted European infrastructure. US contractual requirements are reviewed during scoping.

  • Norwegian company / EEA jurisdiction
  • GDPR Article 9 / 30-day erasure SLA
  • EU AI Act Article 10 aligned
  • US healthcare requirements assessed during scoping

Regulatory posture

Cite the regulation by article, not the marketing

Procurement reviewers cite articles, not adjectives. Four frameworks dominate clinical AI review; here is YPAI's position under each, including what YPAI does not certify.

  • EU AI Act

    Annex III item 5 / Article 10

    Aligned with Article 10 data-governance obligations. YPAI supplies documentation supporting your conformity assessment. YPAI does not certify your AI system as compliant.

  • GDPR

    Articles 6, 7, and 9

    Documented per-contributor consent for health and biometric data under Article 9(2)(a). 30-day erasure SLA. Withdrawal workflow with audit trail.

  • EEA processing

    Norway jurisdiction / project-specific review

    EEA residency by default. Healthcare-specific consent, residency, and data-handling controls are documented before scope acceptance.

  • EU MDR

    Class IIa+ / CE + AI Act dual-track

    Audit artifacts support your CE plus AI Act dual-track conformity assessment. YPAI does not certify your SaMD. We supply the evidence trail your notified body asks for.

Clinical modalities

Eight clinical modalities, one consent chain

One DPA, one audit trail, one named project lead. Every modality inherits the same consent chain, 30-day erasure SLA, and audit pack, so a multimodal clinical project clears procurement review once instead of once per vendor.

Modality Clinical sub-domains Domain expertise Output formats
Modality Ambient clinical speech
Sub-domains Multi-party encounter recording, dictation, code-switching speech, ambient documentation workflows
Expertise Contributor network across all Nordic languages and major EU languages, drawn from a pool of 210,000+ contributors. Clinical contributors are credential-checked per engagement.
Output Time-aligned transcripts and speaker turns, with consent and provenance metadata per recording.
Modality Medical imaging
Sub-domains Radiology, cardiology, pathology, DICOM and HL7v2 imaging workflows
Expertise Clinical professional involvement and credential requirements are configured for the task. Metric, reference set, threshold, and adjudication path are defined in the acceptance plan.
Output DICOM in and out, with annotation layers delivered in your target schema.
Modality EHR document extraction
Sub-domains Structured field extraction with FHIR and HL7v2 mapping, clinical-note de-identification, document classification
Expertise Medical records annotation. Clinical-domain credentialing applied to high-risk fields: medication, dosage, allergy.
Output FHIR and HL7v2 output schemas, mapped to your target profiles.
Modality Biomedical literature
Sub-domains Clinical text corpora, entity and relation annotation, RAG-eval data
Expertise Clinical and scientific annotation. Source-license review applied at the corpus level.
Output Source-attributed text plus annotation layer. Per-record license trace.
Modality Voice biometrics
Sub-domains Speaker verification training, voiceprint enrolment data, GDPR Article 9 explicit consent
Expertise Special-category data handling. Per-contributor consent record with withdrawal trace.
Output Audio plus consent metadata. Withdrawal endpoint on file.
Modality Clinical coding
Sub-domains ICD-10/11, SNOMED-CT, LOINC, RxNorm coding training data
Expertise Coder credentials verified before assignment. Second-pass QA on disputed codes.
Output Source record plus code assignment plus rationale.
Modality Clinical trials
Sub-domains Trial document collection, protocol annotation, eligibility-criteria extraction
Expertise Clinical and scientific annotation against the trial protocol.
Output Structured annotations traceable to the source document, in the schema your team specifies.
Modality Federated learning
Sub-domains Sovereign-compute layer, multi-site governance frameworks, deployment infrastructure
Expertise Custom AI infrastructure for regulated buyers: sovereign compute, multi-site governance, deployment support.
Output Reference architecture plus deployment pipeline. Not a stand-alone dataset purchase.

Jurisdiction

EEA-resident infrastructure, by default

Jurisdiction is an architecture decision. YPAI is a Norwegian company on self-hosted European servers, with a short EEA-resident sub-processor list disclosed in the DPA: legal exposure sits under EEA frameworks only.

  • Norwegian company

    Norwegian legal entity, EEA jurisdiction. Headquartered in Oslo, Norway.

  • Self-hosted European servers

    Production data on YPAI-operated European infrastructure. Self-hosted servers inside the EEA.

  • Sub-processor transparency

    Short EEA-resident sub-processor list disclosed in the DPA at scoping. SCCs available for buyer-directed transfers.

  • Norwegian jurisdiction

    Norwegian legal entity, with residency, subprocessor and transfer controls defined per project. Legal exposure under EEA frameworks only.

Audit artifacts

Routine deliverables, not special requests

An audit trail assembled after the request is a finding, not a defence. Every project ships the artifact set a notified body or regulator can ask for, delivered with the dataset.

Consent

  • consent_records.jsonl (per contributor, per purpose)
  • erasure_sla_30d.md
  • withdrawal_trace.csv (with audit log)

Provenance

  • provenance_ledger.csv (per recording)
  • dataset_versions.changelog (immutable)
  • sampling_methodology.md

Quality + disclosure

  • qa_artifacts.jsonl (per modality)
  • demographic_dialect_distribution.csv
  • de_identification_method.md
  • subprocessor_disclosure.md

Nordic clinical speech

Clinical Nordic speech, in production

Danish, Norwegian, Swedish, and Finnish clinical speech, collected inside the EEA from thousands of native-speaker contributors across the Nordics, running in production in Augnito Omni, YPAI's clinical speech product.

DA

Danish

Clinical accents and regional terminology

NO

Norwegian

Bokmål and Nynorsk. Regional clinical accents.

SV

Swedish

Code-switching Swedish-English in clinical settings

FI

Finnish

Finnish clinical terminology. Swedish-speaking minority dialect coverage.

Engagement

Custom contracts, 4 to 12 weeks

Named project lead. DPA included with every engagement. Delivery commitments are co-defined per engagement and contracted, not asserted.

Next step

Scope a clinical AI data project

Bring the model objective, modality, and conformity track. YPAI returns a scoped statement of work, a DPA, and a pilot plan with task-specific metrics, acceptance criteria, timing, and commercial terms.