AI · Quality and safety
SAFETY AND QUALITY

Clinical safety and privacy by design 

ReHub integrates privacy principles into its architecture: movement data is processed locally in real time, without storing images or identifying biometric parameters. ReHub is developed and operated in compliance with applicable MDR and GDPR requirements, within a security framework compliant with the ENS at the HIGH level. DyCare manages the applicable requirements of the EU AI Regulation according to its implementation schedule. For services destined for the United States, it applies technical and organizational measures aligned with HIPAA security and privacy principles.. 

CE marked as a class IIa medical device

Software medical device assessed and certified under Regulation (EU) 2017/745

ISO 13485:2016

Quality Management System specific to medical device companies. 

ISO 27001

Information security is managed systematically, guaranteeing the confidentiality, integrity, and availability of data.. 

ENS High Categorya

Certification under the Spanish National Security Scheme, the most demanding cybersecurity standard for data protection in the healthcare sector. 

NIS2 Directive

Alignment with the risk management and cybersecurity requirements of Directive (EU) 2022/2555 for the healthcare and digital sector.

GDPR

Patient data is handled under the strictest privacy and data protection principles of the European Union. 

HIPAA

Compliance with privacy and security standards for the processing of Protected Health Information (PHI) in contexts of Business Associates

International Compliance (UKCA)

Adapted to meet the regulatory requirements for medical devices in the United Kingdom.

AWS Well-Architected 

Cloud infrastructure aligned with Amazon Web Services’ best practices for security and performance. 

From the camera to clinical practice

Regulatory commitment and clinical safety

ReHub’s AI allows us to see what was previously invisible: how the patient moves, how they perform each exercise, when they compensate, how much they progress, and when they need professional intervention.

Regulatory excellence in telerehabilitation

DyCare has developed ReHub® under the most demanding standards of European health and data protection regulations, guaranteeing a safe, externally audited functional assessment and rehabilitation tool with constant human supervision. 
 

Certified as a Medical Device (MDR Class IIa))

ReHub® is a Class IIa medical device software (MDSW), independently assessed and certified in accordance with Regulation (EU) 2017/745 (MDR). Its purpose of functional movement analysis and rehabilitation monitoring has been validated by the notified body Kiwa Cermet SpA (0476).. 

National and international cybersecurity compliance 

As a Spanish manufacturer, DyCare is authorized by the AEMPS (Spanish Agency for Medicines and Health Products) and has achieved ENS Category High certification, the most rigorous cybersecurity standard in Spain. Furthermore, our architecture complies with GDPR privacy requirements and HIPAA standards for the protection of health information.. 

Continuous improvement and post-market surveillance 

Our Quality Management System (ISO 13485:2016) ensures that ReHub® is actively maintained and strengthened. We conduct regular audits and post-market surveillance to guarantee compliance with evolving regulatory expectations, including the transparency guidelines of the EU AI Regulation (2024/1689).

clinical regulation

Regulatory commitment and clinical safety

ReHub’s AI allows us to see what was previously invisible: how the patient moves, how they perform each exercise, when they compensate, how much they progress, and when they need professional intervention.

The differential principle

More than seeing

privacy and security

Privacy and security

ReHub® protects patient data through an architecture that prioritizes privacy, local processing, and complete control of clinical information.. 

Frequently Asked Questions

Clinical validation

Scientific evidence peer-reviewed.

Every clinical decision regarding AI is supported by publications in indexed journals. Here are the most recent studies.

+k
Patients treated with DyCare
+
Peer-reviewed scientific publications
Randomized clinical trials
Participating hospitals and services
Sensors
· 2024

Validation of computer vision-based rehabilitation in shoulder rehabilitation

Comparative study of accuracy vs. manual clinical measurement in 240 sessions.

BMC Health Services
2023

Telerehabilitation effectiveness in chronic low back pain

RCT with 312 patients — adherence and functional outcome at 12 weeks.

JMIR Rehabilitation
· 2023

Adherence patterns in AI-guided home rehabilitation

Analysis of 35,000 real sessions in a real portfolio of hospital patients.

Respiratory Medicine
· 2024

Pulmonary rehabilitation in COPD via digital platform

Prospective pilot study in COPD stage II-III patients with 4 months of follow-up.

Annals of Oncology
· 2024

Prehabilitation and recovery in breast cancer patients

Prehabilitation protocol + post-mastectomy recovery. 80% adherence.

European Stroke Journal
· 2023

Computer vision for post-stroke motor recovery

Case-control evaluating functional recovery of the affected limb.

Security architecture

Clinical data. Clinical safety.

Security isn’t an add-on—it’s built into every layer of the system. We built it as a healthcare product from day one.

End-to-end encryption

TLS 1.3 in transit (all API + apps)
AES-256 at rest (all clinical data)
Keys rotated and managed with KMS
Encrypted backups with separate key

Certified European Hosting

Infrastructure in AWS EU regions
Guaranteed data residency
AWS Healthcare Competency
Datacenters con ISO 27001 + SOC2

Anonymization by default

pseudonymized clinical data
Identity separate from usage data
We do not use videos of the patient outside of their session
Verifiable deletion on request (GDPR)

Audit and traceability

Immutable logs of each access
Granular roles and permissions
MFA required for professionals
Annual external audit report
Ethical commitment

Five commitments that we don’t negotiate.

AI in healthcare is not neutral—design decisions have clinical and ethical consequences. These are the principles that govern how we built DyCare, set in stone from day one.

We never use patient data to train external models. The data serves the treatment of the patient — period.
Transparent and auditable algorithms. Each clinical decision regarding AI can be explained and reviewed by a professional.
Clinical decision always in the hands of the professional. The AI ​​recommends and corrects; the physiotherapist decides.
Privacy by design. The patient can request its export or deletion at any time — no questions asked.
No ad tracking. No third-party cookies, no pixels, and nothing that is not in service of rehabilitation.
Ethical commitment

Five commitments that we don’t negotiate.

AI in healthcare is not neutral—design decisions have clinical and ethical consequences. These are the principles that govern how we built DyCare, set in stone from day one.

We never use patient data to train external models. The data serves the treatment of the patient — period.
Transparent and auditable algorithms. Each clinical decision regarding AI can be explained and reviewed by a professional.
Clinical decision always in the hands of the professional. The AI ​​recommends and corrects; the physiotherapist decides.
Privacy by design. The patient can request its export or deletion at any time — no questions asked.
No ad tracking. No third-party cookies, no pixels, and nothing that is not in service of rehabilitation.

Do you want to go into detail? technical or regulatory?

We have data sheets, white papers, and regulatory documentation available for your legal, technical, or clinical team. Request them.

Scroll to Top