NEN 7510EU jurisdictionGDPR & NIS2

Sovereign cloud for healthcare

Patient data is special category personal data under the GDPR and should not fall under US jurisdiction. Appfront is a software and app agency: we build healthcare applications, portals and integrations so they run on sovereign, EU-based infrastructure, and we migrate existing healthcare software to it. For data centre and IaaS, we work with specialised Dutch partners holding healthcare certifications; we handle the coordination, development and management of the software.

What is a sovereign cloud for healthcare?

A sovereign cloud is cloud infrastructure fully governed by European law and owned by European entities. For healthcare this distinction is especially important: patient data is special category personal data under the GDPR, and a US cloud provider falls under the US CLOUD Act and FISA, even when the servers are located in a European data centre. In practice this creates friction in data processing agreements: the provider cannot guarantee that disclosure to US authorities is ruled out, while the healthcare organisation, as controller, remains accountable for it.

A sovereign cloud for healthcare places patient data and healthcare applications under EU jurisdiction, on infrastructure controlled by European companies. This aligns with NEN 7510, the Dutch standard for information security in healthcare, and with the NIS2 Directive, which takes effect in the Netherlands through the Cybersecurity Act on 15 August 2026 and designates healthcare as a critical sector. Appfront builds and migrates the software that runs on that sovereign infrastructure: portals, healthcare applications and integrations. You can read our general approach on our page about building a sovereign cloud; this page covers how that applies to healthcare.

It's important to understand that sovereignty is not an all-or-nothing choice. It often starts with the most sensitive category, the systems that process patient data, with less sensitive workloads following later. We make that assessment together with you, based on your data classification and the requirements of your regulators and chain partners.

How we approach this

1
Inventory and risk analysis
We map your applications, data flows and integrations: where patient data resides, which suppliers process it, and where processor agreements or NEN 7510 requirements create friction.
2
Architecture and partner selection
We design an architecture on EU-sovereign infrastructure and, together with you, select a Dutch infrastructure partner holding healthcare certifications such as NEN 7510 and ISO 27001.
3
Build or migrate
We build the healthcare application or portal, or migrate your existing software, including HL7 and FHIR integrations, access control and logging.
4
Operations and ongoing development
After go-live, we provide monitoring, security updates and ongoing development, so the environment keeps complying with evolving legislation such as NIS2.

What we build and manage

Care applications and portals
Patient portals, clinical decision-support applications and internal care applications, built to run on sovereign EU infrastructure.
HL7 and FHIR integrations
Secure data exchange with EHRs, hospital information systems and chain partners based on open healthcare standards.
Migration of existing healthcare software
We move existing applications and databases from hyperscalers to sovereign environments, with attention to continuity of care processes.
Private AI for healthcare data
As an extension, we set up private AI so that language models working with patient data remain within your own sovereign environment.
Data minimisation and logging
Only necessary data is processed, with authorisation and access logging aligned with NEN 7510.
Management and monitoring
Ongoing maintenance, security updates and monitoring of the sovereign environment.

For whom

Healthcare facilities and hospitals

Organisations that process patient data and need to justify their cloud choices to regulators, patients and chain partners.

Mental health

Institutions that manage highly sensitive records and set especially strict requirements for confidentiality, authorisation and access logging.

Long-term care (VVT)

Nursing and care homes and home care organisations that exchange data with many chain partners and want control over where that data is stored.

Healthcare ICT suppliers

Software companies that want to offer their healthcare product as sovereign, because customers ask for it in tenders and data processing agreements.

Technology and approach

We build with open, portable technology so your care applications are not tied to a single supplier. Where possible we use containers and infrastructure as code, and for data exchange we use open healthcare standards such as HL7 and FHIR. The infrastructure runs with Dutch partners holding healthcare certifications; we implement encryption, access control and logging in line with NEN 7510 and the GDPR.

EU-based cloud with healthcare certifications
HL7 / FHIR
Kubernetes / containers
Infrastructure as Code
Encryption in transit and at rest
Authorisation and access logging
OWASP security
Monitoring and logging

Why Appfront

Appfront is an independent software and app agency. We don't sell hosting and we are not a data centre: the infrastructure comes from specialised Dutch partners holding healthcare certifications, while the software and coordination come from us. This way you combine certified Dutch infrastructure with custom software that fits your healthcare processes precisely, from patient portal to EHR integration.

Our advice on providers and architecture isn't coloured by a platform of our own: we don't earn from the infrastructure, we earn from software that works well. That also means we'll be honest if a fully sovereign setup isn't necessary for your situation and a hybrid approach will do.

  • Independent of hyperscalers and hosting providers
  • Experience with portals, integrations and migrations
  • Privacy and data minimisation from the architecture onwards
  • Open standards such as HL7 and FHIR, so you aren't locked in again

Related services

See also building a sovereign cloud and building private AI. If you're looking more broadly, read our overview of the best sovereign cloud solutions for healthcare and of the best healthcare software agencies.

Frequently Asked Questions

What does a sovereign cloud mean for healthcare?
A sovereign cloud is infrastructure that falls entirely under European law and European ownership. For healthcare, this means patient data and care applications stay out of reach of US legislation such as the US CLOUD Act and FISA, and that you can genuinely honour processing agreements under EU law.
Is it allowed to store patient data with a US cloud provider?
It's a sensitive matter. Patient data is special category personal data under the GDPR. A US provider is subject to the US CLOUD Act, even if the servers are located in the EU. As a result, data processing agreements often founder in practice on whether disclosure to US authorities can be ruled out. A sovereign EU environment removes that legal risk.
How does this relate to NEN 7510?
NEN 7510 is the Dutch standard for information security in healthcare. We build applications with access control, logging and encryption that align with it, and for the infrastructure we work with Dutch partners who hold healthcare certifications such as NEN 7510 and ISO 27001.
Does our healthcare organisation fall under NIS2?
The healthcare sector is one of the critical sectors under the NIS2 Directive, which is being implemented in the Netherlands through the Cybersecurity Act with entry into force on 15 August 2026. Many healthcare organisations and healthcare ICT suppliers will consequently have a duty of care and a reporting obligation. Control over where data is stored and who can access it is an important foundation for that.
Does Appfront provide the infrastructure itself?
No. We are a software and app agency, not a hosting provider or data centre. We build and migrate the healthcare applications, portals and integrations and handle the coordination; for data centre and IaaS, we work with specialised Dutch infrastructure partners holding healthcare certifications.
Can you build integrations with our EHR or hospital information system?
Yes. We build integrations based on standards such as HL7 and FHIR, so your sovereign applications can exchange data securely with EHRs, hospital information systems and chain partners. We also bring existing integrations into scope during a migration.

Getting started with a sovereign cloud for healthcare

Do you want to bring patient data and care applications under EU jurisdiction, or set up a new healthcare platform sovereignly? We're happy to help you think through the approach, the architecture and the right Dutch infrastructure partner.

Edit content