Aleris

Sweden · aleris.se · 11 vendors

Aleris is a Scandinavian healthcare provider focused on specialist medical care. The company operates clinics throughout Sweden from Malmö in the south to Umeå in the north, serving thousands of patients daily with specialized medical services.

Resilience scores

Technology vendors

Services catalogue

3 services in catalogue across 1 category; runs on 11 sub-vendors.

Insights

Last updated 2026-08-16 · revision 2

11 direct vendors, 198 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 7/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Aleris exhibits a moderate to high level of migration readiness. The company's strong emphasis on digital health, AI, and IoT (e.g., AI-based medical record annotation, Albot, connected hospital-at-home technology, digital psychiatry platforms) suggests a tech stack that is likely modern, modular, and well-suited for cloud migration. Proprietary tools indicate internal control over core intellectual property, potentially simplifying migration for these critical systems. The adoption of SaaS solutions like Teamtailor and Webflow for non-core functions means these services are already cloud-native. ISO 9001 & ISO 14001 certifications suggest structured processes that can aid in managing a complex migration project. However, significant challenges and unknowns exist. The 'Data Residency Requirements: Not specified' is a critical unknown; strict requirements common in healthcare could significantly complicate or restrict migration options. There is no data on financial stability (revenue concentration, growth history) to assess the company's capacity to fund a substantial migration. The 'Vendor Lock-in Risk: Unknown' and the contradictory 'Total Vendors: 0' make it challenging to determine the actual level of vendor lock-in. Finally, the inherently complex regulatory environment of the healthcare industry will add compliance overhead to any migration effort.

Compliance

9 in-scope frameworks identified; showing 3.

GDPR (source) — Assessment Required

Aleris operates as a major Scandinavian healthcare provider processing extremely sensitive special category personal data (health data, patient records, medical histories) under GDPR Article 9. This is among the highest-risk categories of personal data processing. They operate across three EU/EEA countries (Sweden, Norway, Denmark), serve thousands of patients daily across 100+ clinics, and handle data from both public and private patients. Non-compliance with GDPR in the healthcare sector can result in fines up to €20 million or 4% of global annual turnover, whichever is higher. Swedish, Norwegian, and Danish data protection authorities (IMY, Datatilsynet) actively enforce GDPR in healthcare. The combination of sensitive health data, large patient volumes, cross-border Scandinavian operations, and digital/physical care delivery creates a high inherent risk profile. While Aleris likely has GDPR compliance measures in place given their scale and regulatory environment, no public audit evidence of full compliance was found.

Evidence: https://www.aleris.se/integritetspolicy/, https://www.aleris.se/om-aleris/nationella-kvalitetsregister/, https://www.imy.se/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679

CSRD (source) — Assessment Required

CSRD (EU 2022/2464) requires large companies and listed SMEs in the EU to report on sustainability matters. Aleris, as a large Scandinavian healthcare provider with operations across three countries and 100+ clinics, likely meets the size thresholds for CSRD applicability (large company: 250+ employees, €40M+ net turnover, €20M+ balance sheet). Their existing UN Global Compact participation and sustainability reporting demonstrate awareness of ESG obligations. Non-compliance risk is Medium because CSRD is being phased in and enforcement is still developing, but the direction of travel is clear.

Evidence: https://unglobalcompact.org/what-is-gc/participants/25111-Aleris-, https://www.aleris.se/om-aleris/kvalitet-hallbarhet/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2464

Patientsäkerhetslagen — Assessment Required

Patientsäkerhetslagen is the core Swedish patient safety law applicable to all healthcare providers. As a major specialist healthcare provider, Aleris is fully subject to this law and is supervised by IVO. Non-compliance can result in license revocation, fines, and reputational damage. Aleris's published Patient Safety and Quality Report (Årsberättelse Patientsäkerhet & Kvalitet) demonstrates active engagement with patient safety obligations, reducing but not eliminating compliance risk.

Evidence: https://cms.aleris.se/siteassets/om-aleris/aleris_kvalitetsrapport_2024.pdf, https://www.aleris.se/om-aleris/, https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/patientsakerhetslag-2010659_sfs-2010-659/, https://www.ivo.se/

Financials

Three-year financials

Financial Resilience Score: 7/10

Aleris demonstrates solid financial resilience underpinned by its scale as a leading Scandinavian private specialist healthcare provider operating across Sweden, Norway, and Denmark. The group benefits from significant geographic diversification across three Nordic markets, a diversified payer mix (public healthcare contracts, private health insurance, and self-pay), and a broad service portfolio spanning orthopaedics, ophthalmology, psychiatry, primary care, diagnostics, and plastic surgery. Management described FY2024 as a year of 'record growth,' and FY2025 saw patient visits reach approximately 3.8 million, up ~7% YoY, indicating strong operational momentum. The group is backed by Triton Partners, a well-capitalised private equity owner that has funded bolt-on M&A (CT-klinikken in Denmark, Nordiskt Centrum in Linköping) and major capex projects including a new Malmö hospital with Hemsö targeted for 2027. The pending 2025 sale to Finnish healthcare provider Mehiläinen further validates enterprise value and would provide a credible industrial owner post-transaction. However, resilience is tempered by exposure to regulatory and political risk in Nordic private healthcare (particularly the Swedish 'vinster i välfärden' debate), tender concentration in public procurement, ongoing wage inflation and clinical staff shortages, and capex intensity. As a PE-owned group, Aleris likely carries meaningful leverage, though precise figures were not extracted. Deal-closing risk on the Mehiläinen transaction remains pending regulatory approval. Overall, the combination of scale, diversification, and strong owner backing supports an above-average resilience score.

Key strengths: Scale and geographic diversification across Sweden, Norway, and Denmark, Diversified payer mix: public healthcare, private insurance, and self-pay, Broad service portfolio across multiple specialties, Strong Nordic private-health tailwind from public waiting lists and ageing populations, Backing from well-capitalised PE owner Triton Partners, Pending acquisition by Mehiläinen validates enterprise value, Record growth in FY2024 and ~7% YoY patient visit growth in FY2025, Aleris Elisabethsjukhuset ranked Sweden's best hospital 2025

Risk factors: Regulatory/political risk on for-profit healthcare in Nordic countries, Tender concentration and repricing risk in public procurement contracts, Wage inflation and clinical staff shortages across the Nordics, Capex intensity for hospitals and imaging equipment (e.g., Malmö hospital 2027), Likely meaningful leverage as PE-owned group, Deal-closing risk on pending Mehiläinen acquisition

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report