Official Blog
How Data Sovereignty Is Reshaping Healthcare IT
Sara Wei
September 11, 2026

How Data Sovereignty Is Reshaping Healthcare IT

According to Nutanix’s healthcare report, 72% of healthcare IT professionals now name data sovereignty as a must-include factor in infrastructure decisions. Data sovereignty is becoming an increasingly important consideration for healthcare IT. Traditionally, protecting healthcare data has focused primarily on security: preventing sensitive information from being leaked, altered, or lost. Today, the discussion is expanding beyond security to sovereignty—whether healthcare organizations truly control their data. So what does this shift actually mean for healthcare IT? Let’s take a closer look.

Data sovereignty is redefining how healthcare data is managed

Data sovereignty has gained urgency in recent years as healthcare data is now seen as a highly sensitive asset of national value. Therefore, related issues, such as cross-border cloud providers, foreign authorities being able to legally access data, or whether healthcare data maybe used to train AI models. These discussions have sparked concerns about data sovereignty.

Governments are responding. France now requires its most sensitive health data—including records held by its national Health Data Hub—to be stored with SecNumCloud-qualified providers, shielded from foreign legal reach. In the United States, a Department of Justice rule effective since 2025 restricts certain foreign access to Americans’ health data—including Electronic health records (EHRs) and clinical records. Japan’s Ministry of Health, Labor and Welfare requires healthcare providers outsourcing patient data to external overseas servers to enforce technical safeguards, such as encryption, against unauthorized access.

While requirements may vary, the goal is clear: sensitive healthcare data should remain under the healthcare organization’s control. The following core objectives keep appearing:

  • Data residency: Sensitive information must remain within an approved geographic or legal jurisdiction.
  • Encryption and key control: Data must be encrypted while organizations retain control over the keys required to access it.
  • Access control: Only authorized parties should be able to access healthcare data. The data should not be reused without authorization.
  • Irreversible deletion: Organizations must be able to define data retention periods and ensure data is securely deleted and cannot be recovered.
  • Transparency and auditability: Access and administrative activities must remain traceable.

However, one aspect of data sovereignty that is often overlooked is backup. Most discussions focus on production workloads, but from a sovereignty perspective, backups can contain the same sensitive data as the production environment, creating a potential sovereignty gap. When healthcare organizations build their own data sovereignty strategy, backup architecture needs to be part of that solution.

Beyond security: Building sovereign backup with ActiveProtect

Synology ActiveProtect is an all-in-one backup appliance that delivers strong cyber resilience to help keep healthcare data secure, through features such as immutable protection and air-gapped protection.

Beyond security, ActiveProtect can also help organizations achieve sovereignty, thanks to its on-premises deployment model. It can be deployed entirely within an organization’s own environment, allowing healthcare organizations directly control their backup data. This stands in contrast to storing backups in the cloud, which often relies on contractual assurances —such as who is permitted to access the environment.

For healthcare organizations developing a data sovereignty strategy, an on-premises deployment can help meet the following data sovereignty requirements:

Absolute data residency

As ActiveProtect can be deployed on-premises, the backup data remains with the hospital or a location selected by the organization. This enables healthcare providers to maintain control over where sensitive information is stored.

For example, our customer St. Nikolaus Hospital needed a fully on-premises solution to meet GDPR and NIS2 compliance requirements, keeping patient data recoverable without ever leaving hospital-controlled infrastructure—so they chose to deploy ActiveProtect.

Encryption and independent key control

ActiveProtect protects backup data both in transit and at rest. At rest, it encrypts the entire storage volume with AES, and the recovery key is held solely by the organization—not even Synology can access it. This means control over encrypted backup data stays entirely with the organization. Even if the underlying drives were lost or stolen, the data would remain unreadable, helping organizations maintain control over sensitive information.

Least-privilege access

ActiveProtect provides granular role-based access control (RBAC) based on each user’s responsibilities. Auditors can be limited to read-only access, infrastructure teams to hardware management, and in multi-site environments, administrators can be restricted to managing only the backup servers at their assigned locations.

Automatic and irreversible deletion

ActiveProtect automatically manages recovery points according to predefined retention policies, giving organizations control over how long the data is retained. Once data reaches the end of its required lifecycle, it can be permanently deleted and made unrecoverable, helping organizations meet requirements for irreversible deletion.

Transparent auditing

ActiveProtect is equipped with a comprehensive logging system that captures detailed information on backup, recovery, user connections, and device operations, supporting auditing and governance requirements. For monitoring, APM can also forward abnormal events to mainstream SIEM/SOAR platforms via SMTP email notifications, Syslog forwarding, and SNMP traps.

💡 Good to know

Not all cloud backup is disqualified from meeting data sovereignty requirements. What matters is whether a provider meets the same requirements outlined above. Synology C2 Backup is built to meet these requirements, giving organizations that need an off-premises option a way to extend that same level of control beyond their own infrastructure. Check out the C2 Backup page to see which data center regions are currently available.

Conclusion

Healthcare data sovereignty applies to every copy of the data, including backups. As sovereignty rules around the world grow stricter, healthcare organizations need architecture, not just contracts, to ensure lasting control over their most sensitive information. Building backup infrastructure on premises is one way to address that gap at the architecture level. It keeps data residency, encryption keys, access, retention, and auditability under the organization’s own control.