# HEALTHCARE · DATA & AI · DACH
One patient. Four systems. None of them agree.
Healthcare providers accumulate CRMs, billing platforms and clinical systems that never fit together — over data that is legally special. We unify it with privacy-by-design, so compliance is documented, not assumed.
# WHERE IT BREAKS
Where healthcare data breaks down.
Fragmented patient records
Multiple CRMs and billing platforms, none talking to each other. Marketing sends duplicate mailings, billing cannot reconcile, and the same patient ID means two different people across two systems.
▸ how we solve it
We build a conservative identity-resolution pipeline — not just name and DOB, but address history, contact patterns and billing identifiers — validated against a manually verified sample, and biased toward not merging when in doubt.
Special-category data, "we think we're fine"
Health data is an Article 9 special category under GDPR — a stricter legal basis, a DPIA, and higher stakes on every merge. Most providers can't actually show the audit trail a supervisory authority would ask for.
▸ how we solve it
Privacy by design, in the literal order of work: pseudonymization, consent tracking and full audit trails go in before the first record is merged — so every merge is traceable to who, when and which rule, not retrofitted after.
The MDR boundary
Software that influences diagnosis or treatment can be a medical device under the MDR — and when it uses AI, high-risk under the AI Act. It is easy to drift across that line by accident and inherit an obligation you never scoped.
▸ how we solve it
We keep the platform firmly on the analytics side of the MDR boundary and flag explicitly when a requested feature would cross into medical-device or AI-Act-high-risk territory, so the decision is deliberate, not accidental.
# PROOF
A unified customer data platform for a healthcare provider.
A healthcare provider ran on 4 CRMs and 3 billing platforms with no unified view. We built one source of truth in an EU-hosted warehouse with privacy-by-design and full GDPR audit trails — resolving duplicates conservatively rather than risk merging two strangers' records.
87%
Duplicates resolved
7
Systems unified
GDPR
Privacy-by-design
16 wk
End to end
# REGULATORY
The regulatory angle: GDPR Article 9 & MDR adjacency.
Health data is a special category under GDPR Article 9: processing needs a stricter legal basis, usually a Data Protection Impact Assessment, and audit trails that stand up to a supervisory authority — which is why, in our CDP work, the trails went in before the first record was merged, not after. Separately, watch the MDR line: software that influences diagnosis or treatment can qualify as a medical device, and AI that does so is high-risk under the AI Act (Annex I, via the MDR). We keep the data platform on the analytics side of that boundary and name the crossing point when a feature approaches it — so you never inherit a medical-device obligation by accident.
# FAQ
Common questions.
How do you unify patient data without wrong merges?
Conservative identity resolution: every matching rule signed off by the compliance lead, validated against known cases, and biased toward not merging when in doubt — in healthcare a false-positive merge means combining two strangers' records. In our CDP work 87% of duplicates were resolved; the rest stayed deliberately separate rather than risk a bad merge.How does GDPR Article 9 change a data platform for health data?
It raises the bar on legal basis and documentation: you typically need a DPIA, a stricter basis for processing, and audit trails in place before merging — not retrofitted. In practice that means pseudonymization, consent tracking and traceability (who merged what, when, by which rule) are part of the build order, not a later compliance pass.When does healthcare software cross into MDR / medical-device territory?
When it influences diagnosis or treatment rather than just reporting on operations. A CDP or analytics platform normally stays on the analytics side; a feature that scores clinical risk or guides a treatment decision can tip into medical-device (MDR) and, if AI-driven, AI-Act high-risk. We flag that boundary explicitly so crossing it is a deliberate, scoped decision.
Patient data spread across systems that don't agree?
A 30-min call with the two people who would run it. We will tell you within 48 hours whether we are the right fit.
book-call// or write: hello@saloid.com · gräfelfing · de