Compliance & Security
Regulatory and security considerations built in from day one — not bolted on. Here’s how we approach quality, data protection, and operational resilience.
Our ISO Accreditation Journey
Carmedin is actively working toward ISO 9001 (Quality Management) and ISO 27001 (Information Security Management) accreditation. This is a live, ongoing initiative — not a claimed certification. We’re building the management systems, documentation, and controls these standards require as part of how we operate day to day, not as a one-time compliance exercise.
Data Protection & Privacy
As a Curaçao-incorporated entity within the Kingdom of the Netherlands, our data protection obligations are informed by GDPR/AVG standards. Where engagements touch the Dutch healthcare context, we design with NEN7510 — the Dutch standard for information security in healthcare — in mind. Patient and client data is handled according to the principle of least privilege, with access controls appropriate to the sensitivity of clinical and diagnostic information.
Service Level Agreements Across Four Criticality Tiers
Every engagement is backed by a formal SLA, structured across four criticality tiers — Mission Critical, Professional, Standard, and Essential. Tier assignment is based on the criticality of the work itself, not the size of the client. A small clinic running mission-critical diagnostic operations has access to the same tier options as a large reference laboratory.
Tier 1: Mission Critical
For systems where downtime directly affects patient care or diagnostic turnaround.
Tier 2: Professional
For core operational systems with high availability expectations.
Tier 3: Standard
For day-to-day systems where brief interruptions are tolerable.
Tier 4: Essential
For supporting systems and lower-urgency support needs.
Incident Response & Cybersecurity Procedures
Beyond routine helpdesk incident handling, we maintain formal incident response and cybersecurity procedures specific to healthcare and patient-data breach scenarios. These procedures cover detection, containment, notification, and post-incident review — recognizing that a breach involving clinical or diagnostic data carries different obligations and urgency than a typical IT outage.
Questions about our compliance posture?
If you’re evaluating us as part of a procurement or tender process, we’re glad to provide more detail.