[{"data":1,"prerenderedAt":335},["ShallowReactive",2],{"update-en-20260811-access-management":3,"related-posts-20260716-mdr-iib-20251230-data-leaks-and-ai-en":68},{"id":4,"title":5,"body":6,"description":49,"extension":50,"meta":51,"navigation":61,"ogImage":62,"path":63,"robots":62,"seo":64,"sitemap":65,"stem":66,"__hash__":67},"updates/en/updates/20260811-access-management.md","From pilot to hospital-wide use, without another user directory",{"type":7,"value":8,"toc":43},"minimark",[9,13,18,21,24,27,31,34,37,40],[10,11,12],"p",{},"Most healthcare professionals will never see this feature. They only notice that they can sign in with their hospital account. Behind that simple login, Ask Aletta automatically creates and manages user accounts through the organisation's identity provider. When the pilot expands, IT does not have to maintain a separate list of Ask Aletta users.",[14,15,17],"h2",{"id":16},"one-place-for-users-and-access","One place for users and access",[10,19,20],{},"When a new employee is given access to Ask Aletta through the identity provider, their Ask Aletta account is created automatically. If the employee changes roles, Ask Aletta updates their permissions. If the hospital withdraws access, their access to Ask Aletta ends as well.",[10,22,23],{},"This is automatic user provisioning. The hospital records access once in its own system, and Ask Aletta uses that information. An IT team does not have to process the same change or departure separately in Ask Aletta.",[10,25,26],{},"Inviting a few users by hand works during a small pilot. It becomes a recurring task once several departments or locations join. An account can also remain active after someone changes roles or leaves the organisation. Ask Aletta follows the changes recorded in the central directory.",[14,28,30],{"id":29},"sign-in-under-the-organisations-policies","Sign in under the organisation's policies",[10,32,33],{},"Employees use Single Sign-On to access Ask Aletta with their existing work account. The connection uses SAML or OIDC, common standards for SSO. These employees do not need a separate Ask Aletta password.",[10,35,36],{},"The hospital remains in control of its password rules and multi-factor authentication requirements. If it requires MFA through its own identity provider, the same check applies when an employee signs in to Ask Aletta; MFA can also be configured within Ask Aletta itself, including for accounts that use SSO.",[10,38,39],{},"Employees get the same sign-in process they already know. IT does not have another set of passwords and recovery flows to manage.",[10,41,42],{},"The difference becomes visible when a pilot expands. New colleagues receive their account without a separate round of invitations, and IT continues to manage permissions in the same place. Even when several departments join, nobody has to review the Ask Aletta accounts one by one.",{"title":44,"searchDepth":45,"depth":45,"links":46},"",2,[47,48],{"id":16,"depth":45,"text":17},{"id":29,"depth":45,"text":30},"Ask Aletta automatically creates and manages user accounts through the organisation's identity provider while retaining its existing SSO and MFA policies.","md",{"date":52,"publishAt":53,"category":54,"author":55,"translations":56,"relatedPosts":58},"2026-08-11","2026-08-11T10:00:00+02:00","product","aram.zegerius",{"nl":57},"20260811-toegangsbeheer",[59,60],"20260716-mdr-iib","20251230-data-leaks-and-ai",true,null,"/en/updates/20260811-access-management",{"title":5,"description":49},{"loc":63},"en/updates/20260811-access-management","_d48G3DB4cTYW_n42b8mgPgc4I4b90Tc5gomhAdtK_s",[69,221],{"id":70,"title":71,"body":72,"description":208,"extension":50,"meta":209,"navigation":61,"ogImage":62,"path":216,"robots":62,"seo":217,"sitemap":218,"stem":219,"__hash__":220},"updates/en/updates/20260716-mdr-iib.md","We're pursuing MDR Class IIb certification",{"type":7,"value":73,"toc":199},[74,91,94,98,101,104,107,111,114,117,121,124,127,131,134,137,141,152,155,158,161,165,168,171,186,189,193,196],[75,76,78],"key-takeaways",{"title":77},"In short",[79,80,81,85,88],"ul",{},[82,83,84],"li",{},"Ask Aletta is evolving from a reactive knowledge platform into a proactive AI assistant embedded in the clinical workflow.",[82,86,87],{},"The intended purpose of that product puts it on the path towards certification as Class IIb medical device software under the MDR.",[82,89,90],{},"Having already achieved ISO 27001 certification, we are now working towards completing the MDR certification process within the next few months.",[10,92,93],{},"We haven't written publicly about this before, so consider this an introduction and a look at where Ask Aletta is headed.",[14,95,97],{"id":96},"mediocre-certified-beats-great-uncertified","Mediocre certified beats great uncertified",[10,99,100],{},"Here is an uncomfortable truth about healthcare software: a mediocre certified product will beat a great uncertified one almost every time.",[10,102,103],{},"Certification does not automatically make a product good, but it does show that the manufacturer has met defined requirements for safety, quality and risk management. In healthcare, where patient safety is on the line, those assurances matter. For regulated clinical uses, certification is therefore not simply a preference but a condition of entry. Hospitals, GP practices and procurement departments cannot adopt an uncertified product for an intended use that requires compliance with the Medical Device Regulation.",[10,105,106],{},"From the beginning, we set out to build a product that is both great and certified.",[14,108,110],{"id":109},"our-first-foundation-iso-27001","Our first foundation: ISO 27001",[10,112,113],{},"We took an important first step by becoming ISO 27001 certified. Information security is fundamental to software that healthcare professionals must be able to rely on, particularly when that software will eventually work with clinical context and patient information.",[10,115,116],{},"Rather than adding security processes later, we wanted this foundation in place early, before beginning the next stage of our regulatory journey.",[14,118,120],{"id":119},"where-we-are-today-reactive","Where we are today: reactive",[10,122,123],{},"Today, Ask Aletta is a reactive AI knowledge platform: healthcare professionals ask a question, and Ask Aletta helps them find an answer.",[10,125,126],{},"They use the platform to search clinical guidelines, summarise documents, draft patient communication and support referral letters. All of this happens in the browser and begins with a request from the user. It is already very useful, as our users tell us every day, but it is not yet the product we ultimately set out to build.",[14,128,130],{"id":129},"where-were-going-proactive","Where we're going: proactive",[10,132,133],{},"The future of Ask Aletta is a proactive AI assistant that works inside a healthcare professional's HIS, EHR or patient communication platform. It will be embedded in the clinical workflow, with an understanding of the context in which the healthcare professional is working and the history of the patient in front of them.",[10,135,136],{},"With that context, Ask Aletta will help healthcare professionals prepare for consultations, support clinical decisions, draft documents and surface relevant information before they have thought to ask for it. This is how we want Ask Aletta to develop from a reactive knowledge platform into a proactive assistant within the care process.",[14,138,140],{"id":139},"why-that-requires-mdr-certification","Why that requires MDR certification",[10,142,143,144,151],{},"Whether software qualifies as a medical device depends on its intended purpose. The product we intend to build will provide information used to support diagnostic and therapeutic decisions for individual patients, bringing it within the scope of the ",[145,146,150],"a",{"href":147,"rel":148},"https://eur-lex.europa.eu/eli/reg/2017/745/oj/eng",[149],"nofollow","EU Medical Device Regulation",".",[10,153,154],{},"Under Rule 11 of the MDR, software that informs diagnostic or therapeutic decisions may be classified as Class IIb when those decisions could result in a serious deterioration in a person's health or a surgical intervention. Based on the intended purpose and risk profile of the product we are building, Class IIb is the pathway we are pursuing.",[10,156,157],{},"This requires us to demonstrate far more than technical performance. The process includes systematic risk management, clinical evaluation, quality management, verification, validation and continuous monitoring after the product enters the market.",[10,159,160],{},"For the product we envision, there is no responsible shortcut around that work. If we want Ask Aletta to operate inside the clinical workflow, at the moment important decisions are made, we must meet the standards that decisions of that weight demand. That is why we are pursuing MDR Class IIb certification and why we are doing the work now.",[14,162,164],{"id":163},"why-we-think-healthcare-needs-this","Why we think healthcare needs this",[10,166,167],{},"This is more than a product decision; it is a bet on what healthcare needs. Healthcare costs are rising as the population ages, while fewer healthcare professionals are being asked to care for more patients.",[10,169,170],{},"We believe AI can make a meaningful contribution in two areas:",[79,172,173,180],{},[82,174,175,179],{},[176,177,178],"strong",{},"Quality of care."," Making it easier for care to follow the guidelines and evidence that healthcare professionals have collectively agreed represent best practice.",[82,181,182,185],{},[176,183,184],{},"Efficiency."," Supporting healthcare professionals directly inside their existing workflow, rather than asking them to interrupt that workflow to use another tool.",[10,187,188],{},"AI will not solve the pressures facing healthcare on its own. Applied responsibly, in the right place and with the right safeguards, however, it can help healthcare professionals spend more of their time on the work that only they can do.",[14,190,192],{"id":191},"closer-than-you-might-think","Closer than you might think",[10,194,195],{},"This is not a distant roadmap item. We are already well into the process and aim to complete the Class IIb certification process within the next few months.",[10,197,198],{},"There is still important work ahead, and certification is never something to take for granted, but the direction is clear. We will share more about the process as we progress. For now, we wanted you to know what we are building towards and why.",{"title":44,"searchDepth":45,"depth":45,"links":200},[201,202,203,204,205,206,207],{"id":96,"depth":45,"text":97},{"id":109,"depth":45,"text":110},{"id":119,"depth":45,"text":120},{"id":129,"depth":45,"text":130},{"id":139,"depth":45,"text":140},{"id":163,"depth":45,"text":164},{"id":191,"depth":45,"text":192},"Ask Aletta is evolving from a reactive clinical knowledge platform into a proactive AI assistant embedded in the clinical workflow. Here is why that requires MDR Class IIb certification.",{"date":210,"category":211,"author":212,"readingTime":213,"translations":214},"2026-07-16","news","tijs.stehmann",4,{"nl":215},"we-gaan-voor-mdr-klasse-iib","/en/updates/20260716-mdr-iib",{"title":71,"description":208},{"loc":216},"en/updates/20260716-mdr-iib","pYL4DheM_uSf2I3M4UEEm_qGtsKgKXGPftSgZdvbJMc",{"id":222,"title":223,"body":224,"description":323,"extension":50,"meta":324,"navigation":61,"ogImage":62,"path":330,"robots":62,"seo":331,"sitemap":332,"stem":333,"__hash__":334},"updates/en/updates/20251230-data-leaks-and-ai.md","Data leaks through AI: why healthcare must be extra vigilant",{"type":7,"value":225,"toc":317},[226,235,239,242,245,249,252,255,258,262,265,268,272,275,283,286,314],[10,227,228,229,234],{},"Last weekend, Dutch financial newspaper Het Financieele Dagblad published ",[145,230,233],{"href":231,"rel":232},"https://fd.nl/bedrijfsleven/1582289/tientallen-meldingen-over-datalekken-door-ai-gebruik-privacywaakhond-waarschuwt-voor-risico-s",[149],"an article"," about a trend that doesn't surprise us, but does concern us: the number of data leaks caused by AI use in the workplace is growing. The Dutch Data Protection Authority received dozens of reports in 2024 and 2025, and the number keeps rising.",[14,236,238],{"id":237},"what-went-wrong-in-eindhoven","What went wrong in Eindhoven?",[10,240,241],{},"The FD describes an incident at the municipality of Eindhoven. After a sample period of just 30 days, it turned out that employees had shared CVs, youth care documents, and internal reports with free AI chatbots like ChatGPT and Claude.",[10,243,244],{},"How big the leak actually is, the municipality doesn't know. The data was only retained for 30 days. After that, the scope can no longer be determined.",[14,246,248],{"id":247},"why-this-directly-affects-healthcare","Why this directly affects healthcare",[10,250,251],{},"The article explicitly mentions youth care documents. Those are by definition documents containing sensitive patient information, protected by medical confidentiality.",[10,253,254],{},"But the problem is broader. In daily practice, healthcare professionals copy and paste dozens of times a day. From EHR to letter, from lab result to consult, from note to search query. It's efficient and inevitable.",[10,256,257],{},"But in that hectic flow, it can happen: you accidentally include personal data in a question to an AI tool. With free tools like ChatGPT, that information disappears into a black box. You don't know where it goes, whether it's used for training, or whether it ever comes back in answers to other users.",[14,259,261],{"id":260},"shadow-ai-the-invisible-risk","Shadow AI: the invisible risk",[10,263,264],{},"The FD introduces the term \"shadow AI\": employees who, on their own initiative, use free AI tools, out of sight of the organisation. Even when an organisation offers paid, secure alternatives, people often reach for what they know.",[10,266,267],{},"The solution isn't to ban AI. That doesn't work, and isn't desirable either. The solution is to provide secure alternatives that make the right behaviour easy.",[14,269,271],{"id":270},"how-ask-aletta-does-this-differently","How Ask Aletta does this differently",[10,273,274],{},"We have taken this risk seriously from the start. That's why we built automatic PII detection into Ask Aletta.",[10,276,277,278,282],{},"Every question is automatically checked for personal data, ",[279,280,281],"em",{},"before"," it is processed. We do this with our own detection model, running entirely on our own infrastructure in the Netherlands. No external cloud providers. No third parties.",[10,284,285],{},"If we detect something? You get a notification immediately as a user. With one click, you anonymise the sensitive data and your search query can still be carried out safely.",[287,288,291,292,291,305],"div",{"className":289},[290],"image-row","\n  ",[293,294,295,296,295,301,291],"figure",{},"\n    ",[297,298],"img",{"src":299,"alt":300},"/images/updates/pii-detection-nl.png","PII detection warning in Ask Aletta",[302,303,304],"figcaption",{},"Detection of personal data",[293,306,295,307,295,311,291],{},[297,308],{"src":309,"alt":310},"/images/updates/pii-detection-masked-nl.png","Anonymised question in Ask Aletta",[302,312,313],{},"Anonymised with one click",[10,315,316],{},"In the rush of daily practice, a small mistake is quickly made. We help you prevent it.",{"title":44,"searchDepth":45,"depth":45,"links":318},[319,320,321,322],{"id":237,"depth":45,"text":238},{"id":247,"depth":45,"text":248},{"id":260,"depth":45,"text":261},{"id":270,"depth":45,"text":271},"The Dutch Data Protection Authority is sounding the alarm. We explain what this means for healthcare professionals.",{"date":325,"category":211,"author":55,"translations":326,"relatedPosts":328},"2025-12-30",{"nl":327},"20251230-datalekken-en-ai",[329],"20251111-personal-data-detection","/en/updates/20251230-data-leaks-and-ai",{"title":223,"description":323},{"loc":330},"en/updates/20251230-data-leaks-and-ai","7x1D5E5FBNYeOqLLxneRExYp3EecTvTg1AbedOf-vKQ",1786722069812]