HEALTH-TECH · NORWAY / EU

Every medical record —
one encrypted, patient-owned repository.

All medical records · Sovereign · End2End Encryption · The patient owns the key.

NORWAY / EU · 2026

The problem

Patients do not control their own medical record —
and the consequences compound with every provider they visit.

Fragmented

Siloed systems

Records, imaging, lab results and treatment history sit in siloed clinic systems. Patients cannot move between providers without losing history or repeating tests and radiographs.

Opaque

Consent & control

Most patients have no visibility into who processes their health data, for what purpose, or how to withdraw consent — despite the protections GDPR Article 9 nominally gives them.

Consequential

A clinical problem

Without a unified view, early warning signs are missed and disease progresses that did not need to. Fragmentation is not an administrative problem; it is a clinical one.

These are not three problems. They are one — the patient has lost the control of their own care.

Our vision

Your data.
Your health.
Your consent.

We are building the first health platform where the patient is the crypto key owner — not the clinic, not the software vendor, not the insurer. The repository holds ciphertext it cannot read on its own.

  • You see what we see.
    AI findings, confidence levels and the clinician's view — in plain language, never a black box.
  • You decide who processes your data.
    Granular consent per purpose, one-click withdrawal, and access that expires on its own.
  • You travel with your history.
    Records follow you across providers and borders in FHIR-compatible form. Control without lock-in.
"Trust is the product. Everything else is infrastructure."
Why now

The regulatory clock has started in our favour.

The European Health Data Space obliges every member state to make records exchangeable. AIUTO Tech builds the trusted layer.

Mar 2025

EHDS in force

Regulation (EU) 2025/327 enters into force. Norway adopts through the EEA.

2026–2028

The build window

Implementation is specified but unbuilt. This is the period in which the trusted layer gets chosen.

Mar 2029

Primary use applies

Patient summaries and ePrescriptions must be exchangeable across the EU.

2031

Imaging & labs

Imaging, image reports and laboratory results come into scope.

Compliance is being treated as a cost centre across the sector. We are treating it as the product.

Every incumbent must retrofit consent, portability and erasure onto systems that were never designed for them. A repository designed patient-first from the first line of code does not carry that debt — and can be the layer the retrofitters plug into.

What we are building

Architecture at a glance —
three trust zones.

The citizen holds the key. The professional borrows it, briefly. The repository never has it.

Citizen (patient)

Wallet

holds the private key

Consent dashboard

grant · scope · revoke

Digital identity

BankID / Vipps
Access-control plane

Consent ledger

append-only, immutable

Authorization service

short-lived scoped tokens

Key-wrapping service

HSM-backed, time-stamped
Sovereign repository

Encrypted store

ciphertext only, no master key

Immutable audit log

every read and write

EHDS gateway

HL7 FHIR APIs

The medical professional sits outside all three — authenticated by HelseID, admitted only inside an active, time-boxed consent window.

GDPR Article 9·EHDS (EU) 2025/327·HL7 FHIR·HelseID·BankID / Vipps·MDR pathway planned·EU AI Act

Standards and frameworks the platform is designed against. Certification status is disclosed on request.

How it works

Envelope encryption and separated duties.

Every record is sealed with its own key — and no single service can turn permission into readable data.

Every record, its own key
01

Sealed individually

Each record is encrypted with its own single-use data key. There is no shared key and no master key anywhere in the system.

02

Wrapped to the patient

That data key is wrapped to the patient's public key, generated on-device inside the phone's secure element and never exportable.

03

Stored blind

The repository stores ciphertext plus wrapped keys. It has no ability to open either. A full breach yields unreadable data.

Separation of duties — three services, none of which can fabricate access alone

Consent ledger

An append-only record of every grant, scope and expiry — the legal and technical source of truth at once. Revocations are new events, never edits.

Authorization service

Converts a live consent grant into short-lived, tightly scoped tokens. No grant means no token, with no exception path.

Key-wrapping service

Re-wraps the in-scope record keys to the grantee's key for the window — the bridge from permission to actual decryption.

How a single record is opened — end to end
01

Clinician signs in with HelseID and requests access.

02

Patient grants a scoped, time-boxed consent from the wallet.

03

Consent ledger records it; a short-lived token is issued.

04

In-scope record keys are re-wrapped to the clinician.

05

Ciphertext is served and decrypted client-side, until expiry.

The operator never holds a key it can use alone — every path to plaintext runs through a live patient grant.

The product
Designed

Design specification — the surfaces below are specified and designed. Build begins on close of the current round.

Two surfaces — the patient's,
and the clinician's.

Patient — consent dashboard

Grant

Pending requests show who, where, what and why. The patient picks a duration and approves with a biometric tap — that tap is the signing key authorising the grant.

Scope

Never all-or-nothing: by category (imaging, prescriptions, labs, notes), by time range, and by sensitivity tier — withholding flagged records even from a broad grant.

Revoke

Every live grant shows a countdown. One tap writes a revocation event and kills the wrapped keys near-instantly. Expiry is the norm; revocation is the exception.

Clinician — request & submit

Request

Authenticated with HelseID, the clinician asks for access. Authentication is not authorisation — the default state is no data.

View in window

On approval the clinician's key unwraps exactly the in-scope records, for exactly the granted window. Decryption is client-side — the store serves only ciphertext.

Submit

New records are sealed with a fresh key wrapped to the patient, and signed with HelseID. A clinician can file a result without holding any right to read the history.

The honest limit: revocation stops future access but cannot un-see what was already read — which is why every use triggers a notification and an immutable log entry.

Phase 1 — Build

The platform, the consent ledger and the encryption layer. Specified now, built on close of the current round.

Phase 2 — Clinical pilots

Partner practices join once the platform reaches beta. Workflow validation, clinical data and the first real consent grants.

Team & governance

Clinical credibility plus platform execution.

Erik J. M. Asbjørnsen, CEO & co-founder
CEO & co-founder · AIUTO Tech AS

Erik J. M. Asbjørnsen

Leads business strategy, investor relations, regulatory planning, product and brand — bringing cross-disciplinary entrepreneurial execution to the venture.

Øystein Misje, clinical partner and dentist
Clinical partner · dentist

Øystein Misje

Senior clinical partner bringing practice leadership, access to clinical validation data and the dental-domain expertise required for AI training and regulatory submissions.

Svein Sande, clinical partner and general practitioner
Clinical partner · medical doctor

Svein Sande

Senior clinical partner bringing general-practice domain expertise for protocol development, workflow design and regulatory submissions.

Ownership

AIUTO Tech AS is held 50/50 by Aiuto AS and Skandinavia Holding AS.

Advisers to appoint

Data protection officer, Norwegian counsel on the option scheme.

Questions

The obvious objections — answered plainly.

Closing

The time is NOW

The architecture is designed. The company is capitalised. The regulatory window is open and dated.

The window is dated

EHDS obligations land in 2029 and 2031. The layer everyone else plugs into gets chosen in 2026–2028 — not after the deadlines arrive.

Retrofit debt compounds

Every month an incumbent spends bolting consent onto plaintext is a month we do not have to spend. That gap only widens while we move.

Trust is won once

The first credible patient-owned repository becomes the default. Anyone arriving second has to displace it rather than simply build it.

We are not early — we are building trust.

Contact
Erik J. M. Asbjørnsen
CEO & co-founder, AIUTO Tech AS · Norway

Prefer email? Write directly.

erik@aiutotech.ai →