Compliance & Security

Compliance & Security

Regulatory and security considerations built in from day one — not bolted on. Here’s how we approach quality, data protection, and operational resilience.

Our ISO Accreditation Journey

Carmedin is actively working toward ISO 9001 (Quality Management) and ISO 27001 (Information Security Management) accreditation. This is a live, ongoing initiative — not a claimed certification. We’re building the management systems, documentation, and controls these standards require as part of how we operate day to day, not as a one-time compliance exercise.

Data Protection & Privacy

As a Curaçao-incorporated entity within the Kingdom of the Netherlands, our data protection obligations are informed by GDPR/AVG standards. Where engagements touch the Dutch healthcare context, we design with NEN7510 — the Dutch standard for information security in healthcare — in mind. Patient and client data is handled according to the principle of least privilege, with access controls appropriate to the sensitivity of clinical and diagnostic information.

Service Level Agreements Across Four Criticality Tiers

Every engagement is backed by a formal SLA, structured across four criticality tiers — Mission Critical, Professional, Standard, and Essential. Tier assignment is based on the criticality of the work itself, not the size of the client. A small clinic running mission-critical diagnostic operations has access to the same tier options as a large reference laboratory.

Tier 1: Mission Critical

For systems where downtime directly affects patient care or diagnostic turnaround.

Tier 2: Professional

For core operational systems with high availability expectations.

Tier 3: Standard

For day-to-day systems where brief interruptions are tolerable.

Tier 4: Essential

For supporting systems and lower-urgency support needs.

Incident Response & Cybersecurity Procedures

Beyond routine helpdesk incident handling, we maintain formal incident response and cybersecurity procedures specific to healthcare and patient-data breach scenarios. These procedures cover detection, containment, notification, and post-incident review — recognizing that a breach involving clinical or diagnostic data carries different obligations and urgency than a typical IT outage.

Questions about our compliance posture?

If you’re evaluating us as part of a procurement or tender process, we’re glad to provide more detail.