Sovereign cloud for healthcare
Hospitals, health insurers, diagnostics labs, and medical-AI teams handle the most sensitive personal data in the economy under two hard constraints: GDPR special-category obligations and NIS2 essential-entity duties. The architectural answer is not “a healthcare SaaS in someone else’s cloud” — it’s a sovereign platform where data residency, encryption-key custody, and audit trails are structural. Ænix builds and operates these platforms on Cozystack, running production healthcare workloads on the provider’s own hardware.
Pairs with: Ænix Private Cloud Platform for the regulated cloud foundation; AI Platform for medical imaging, clinical NLP, and decision-support AI on patient data. Free NIS2 Compliance Checklist →.
What healthcare teams come to us for
The four most-common entry points:
- Healthcare data sovereignty — patient records, imaging archives, and genomic data that must stay in-jurisdiction with provider-held keys. See Data sovereignty.
- NIS2 readiness for the health sector — essential-entity risk management, incident reporting, and supply-chain controls. See NIS2 compliance.
- Sovereign AI on clinical data — imaging models, clinical NLP, and decision support that cannot send patient data to a hyperscaler. See Sovereign AI.
- Public / regulated infrastructure alignment — shared patterns with public health bodies and the wider public sector. See Public sector.
Most engagements combine two or more of these triggers.
Why healthcare needs a sovereign architecture, not a compliance checkbox
Health data is the highest-friction data class in European regulation, and two frameworks converge on it.
GDPR special-category data. Under Article 9 of the GDPR, data concerning health is special-category personal data. Processing is prohibited unless a specific condition applies, and even then providers must demonstrate heightened technical and organizational safeguards — encryption, access control, and documented residency. A generic hyperscaler contract asserts these controls; a sovereign platform lets you prove them, because the keys and the audit logs never leave your custody.
NIS2 essential-entity duties. The health sector is an essential-entity sector under NIS2 (Directive (EU) 2022/2555), Annex I. In-scope hospitals and health organizations carry binding risk-management, supply-chain-security, and incident-reporting obligations, with accountability at management level. ENISA provides the reference guidance national authorities build on. A platform whose control plane is auditable open source shortens the distance between “we operate securely” and “here is the evidence.”
Data residency and key custody. On a sovereign platform, workloads are pinned to named EU or DACH regions on hardware the provider owns or contracts directly — there is no default cross-border replication to a US-owned parent company. Encryption uses customer-held keys (BYOK), so the operator has no standing path to plaintext patient data.
Sovereign AI on patient data. Medical AI is where sovereignty and economics collide: imaging and clinical-language models want GPUs, but the data cannot leave the perimeter. Running GPU inference and training inside the same platform as the data — rather than shipping records to an external AI API — keeps special-category data in-jurisdiction while still delivering modern model performance.
What this looks like for the systems you actually run
Healthcare infrastructure is not generic infrastructure, and the platform has to meet the estate where it is.
- PACS and the imaging archive. A PACS is a storage problem wearing a clinical badge: large immutable objects, a long legal retention period, latency that radiologists notice, and a DICOM interface everything speaks. Cozystack gives it S3-compatible object storage for the archive tier with LINSTOR/DRBD block storage for the online tier, both inside the same cluster and the same encryption boundary as the rest of the estate — so imaging is not a separate silo with its own backup story. Retention and immutability are set per bucket; the object store is not shared with a public cloud tenant you cannot name.
- The DICOM and HL7/FHIR path. Modality gateways, DICOM routers, integration engines and FHIR servers are mostly long-lived stateful services, often vendor-supplied as an appliance or a VM image with a support matrix that names an operating system. They run as KubeVirt VMs on the same platform as the containerized services, on the same network, with the same backup class — no second virtualization stack to license and operate alongside Kubernetes.
- Vendor-locked clinical applications. Every hospital has a handful of applications the vendor will only support on a specific OS and a specific hypervisor generation. These are the workloads that block a container-only platform. They stay as VMs, indefinitely, and stop being the reason a modernization stalls.
- Imaging AI next to the imaging data. Because inference runs as a tenant workload on the same cluster as the archive, a segmentation or triage model reads from local object storage rather than a copy shipped somewhere else — the GPU is inside the perimeter that the DPIA already covers.
How Ænix engages with healthcare organizations
The standard engagement runs as a Platform Readiness Assessment with workstreams weighted for the healthcare context:
- Sovereignty + NIS2 workstream — data-residency mapping, GDPR Article 9 safeguards, encryption and key-custody posture, incident-reporting readiness, supply-chain-security review.
- Platform engineering workstream — a multi-tenant Kubernetes-native foundation with isolation between clinical, administrative, and research workloads, plus golden paths for internal delivery teams.
- AI infrastructure workstream (where applicable) — sovereign GPU architecture for imaging, clinical NLP, and decision-support models that must process patient data in-perimeter.
- Cost workstream — an honest TCO model and repatriation candidates for sustained workloads where public-cloud economics no longer fit.
Output is a written report aligned with regulator dialog plus a Phase 2 implementation roadmap.
Evidence pattern
We do not publish named healthcare customers — health engagements are NDA-protected until permissions land. As an architectural evidence pattern, see our anonymized sovereign public cloud case study: a multi-tenant platform running regulated workloads with full data residency and provider-held keys — the same structural pattern a hospital group or health insurer would deploy.
Ænix is the team behind Cozystack — a CNCF project (Sandbox today; Incubating expected late summer 2026), Apache 2.0. Ænix commercializes Cozystack as Ænix Platform, as three platforms on one engine — Public Cloud, Private Cloud and AI — that combine rather than exclude each other.