Frameworks we applyOne discipline. Every framework that matters for healthcare AI.
Healthcare AI rarely falls under a single regulator. BlitzSafe maps your product to the regimes that actually apply — US, EU, and Romania — and runs the controls in production rather than only writing them down in a policy folder.
HIPAA
Health Insurance Portability and Accountability Act
Safeguards for Protected Health Information across the Privacy, Security, and Breach Notification Rules. We design BAAs, access controls, audit trails and breach workflows around HIPAA's required and addressable specifications.
Aligned · BAA available
GDPR
EU General Data Protection Regulation 2016/679
Lawful basis, data subject rights (access, erasure, portability), DPIA for high-risk processing, records of processing, processor obligations, and 72-hour breach notification.
Aligned · DPA available
SOC 2
AICPA Trust Services Criteria (Security, Availability, Confidentiality, Processing Integrity, Privacy)
Security, availability, confidentiality, processing integrity, and privacy controls. We help you reach Type II readiness with auditable evidence collection, change management, and continuous monitoring.
Type II readiness in progress
ISO/IEC 27001
Information Security Management System
An information security management system aligned to Annex A controls. Risk register, statement of applicability, asset inventory, vendor risk, and incident response — all maintained as living documents tied to engineering reality.
Implementation
ISO/IEC 42001
Artificial Intelligence Management System
The first international AI management standard. Model lifecycle governance, AI risk assessments, dataset documentation, post-deployment monitoring and human oversight — applied to your models, not just to your policies.
Implementation
EU AI Act
Regulation (EU) 2024/1689 on Artificial Intelligence
Risk-tier classification, prohibited use cases, high-risk obligations (data governance, transparency, human oversight, post-market monitoring) and general-purpose AI provider duties — mapped against your specific medical workflows.
Mapped · Article-by-article gap analysis
Romanian Law 190/2018
GDPR national implementation in Romania
Romania-specific provisions for processing health data, employment-context personal data, and the role of the DPO. Critical for clinics operating in Romania alongside CNAS reporting obligations.
Aligned
eIDAS
Regulation (EU) 910/2014 on electronic identification and trust services
Electronic signatures, seals and timestamps with legal effect across the EU. We use qualified trust services for clinical consent, contracts and audit-grade signed records.
In production
Status reflects current alignment, not third-party certification. Independent audit reports are issued by external auditors and shared under NDA on request.