Zerintia HealthTech HIPAA

Zerintia HealthTech meets HIPAA requirements to enter the U.S. market

03/09/2026

The digital health company, Zerintia HealthTech, meets the HIPAA requirements to operate in the United States and strengthens its GDPR compliance measures.

Working with hospitals and healthcare organizations in the United States takes more than technology built for clinical environments. In addition, the company behind that technology also has to show that its processes for protecting and handling medical information meet the requirements of the U.S. healthcare system.

Zerintia HealthTech has completed that adaptation process. As a result, it removes one of the main barriers to entry in the country for future collaborations.

What do the HIPAA requirements mean?

HIPAA (Health Insurance Portability and Accountability Act) sets the requirements for protecting medical information in the United States. It applies to certain healthcare organizations and, depending on their activity, to the companies that handle data on their behalf.

Unlike standards such as ISO/IEC 27001, there is no official HIPAA certification that an external body can issue. That is why Zerintia HealthTech refers to this work as adaptation to applicable requirements, not certification.

The process included strengthening and implementing security measures such as multi-factor authentication (MFA), role-based access permissions, and logging all access to information for auditing purposes, along with formalizing an incident response protocol with defined roles and notification timelines. The company also reviewed the documentation needed to operate in the United States, including Business Associate Agreements (BAAs) and applicable privacy policies.

GDPR: a requirement that continues to be strengthened

The starting point with GDPR is different. Compliance isn’t a new goal. Instead, it’s a legal requirement that was already part of how Zerintia HealthTech operates and manages projects built with 4RemoteHealth, its medical telepresence platform.

What has changed is the scope of the review. Data retention periods have been updated, data processing agreements (DPAs) with processors have been reviewed, and a Data Protection Impact Assessment (DPIA) has been carried out. Together, these steps confirm that existing measures still meet the company’s current needs as it has evolved.

Health data receives enhanced protection in Europe. Therefore, controls need to be revisited as technology, projects, and markets evolve.

Security built into 4RemoteHealth’s design

Security isn’t an added layer, it’s part of the platform’s design. 4RemoteHealth encrypts clinical communications and controls access through role-based permissions. In addition, it supports different deployment options, cloud-based or on an organization’s own infrastructure, depending on each healthcare organization’s security policies and technical needs. That flexibility matters especially in settings like operating rooms, ICUs, and ambulances, where security requirements can vary significantly from one facility to another.

Adapting to HIPAA and strengthening GDPR-related measures mark a new step in Zerintia HealthTech’s international strategy. As a result, the company opens the door to new healthcare projects in the United States while consolidating its activity in Europe.

Request a demo of 4RemoteHealth and see how it adapts to the needs of each healthcare organization.