DIPS ASA
Norway · www.dips.com · 6 vendors
DIPS ASA is a Norwegian software company that develops and delivers e-health solutions, including electronic health record (EHR) and electronic patient record (EPR) systems. The company provides digital work tools for clinical documentation, patient administration, and real-time mobile access, primarily serving hospitals and municipal health services in Norway. Its solutions aim to enhance efficiency for healthcare personnel and improve patient care.
Resilience scores
- Digital Sovereignty: 33
- Digital Resilience: 6
- Financial Resilience: 7
Disruption prediction
DIPS ASA has an estimated 11% probability of disruption in the next 6 months.
3 of DIPS ASA's 6 vendors monitored for disruptions.
Technology vendors
- Deepinsight — Norway
- Domeneshop AS — Norway
- HubSpot, Inc. — Technology — United States
- and 3 more
Services catalogue
1 service in catalogue across 1 category; runs on 6 sub-vendors.
- Electronic Health Records
Insights
Last updated 2026-08-15 · revision 2
6 direct vendors, 116 subvendors
Direct vendors by controlling owner country (sample)
- Denmark: 1
- United States: 2
- Poland: 1
Subvendors by controlling owner country (sample)
- France: 6
- Denmark: 2
- Netherlands: 2
Migration Readiness: 5/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
DIPS ASA exhibits medium migration readiness. The company's 'Open Platform Architecture,' use of 'HL7 FHIR,' and 'REST APIs' are strong indicators of a modern, modular, and interoperable system, which significantly aids in potential migration efforts to cloud-native or new environments. The 'third-generation' EHR system also suggests a more contemporary foundation. However, several critical factors reduce overall readiness. 'Data Residency Requirements' are not specified, but given the healthcare industry and operations in Norway, it is highly probable that strict data residency within Norway is a requirement, which adds considerable complexity and cost to any cloud migration strategy. The 'Regulatory Environment' is also not detailed, but healthcare is a heavily regulated industry, implying complex compliance requirements that must be met during migration. Financial stability data (revenue concentration, growth history) is missing, making it impossible to assess the company's capacity to fund a large-scale migration. Furthermore, the 'Vendor Lock-in Risk' is unknown; if there are critical vendor dependencies, their contracts, technologies, or proprietary systems could significantly impede or complicate migration. The actual number of vendors is unclear, making it difficult to assess vendor-related migration complexity.
Compliance
12 in-scope frameworks identified; showing 3.
Helseregisterloven — Assessment Required
The Norwegian Health Registry Act (Helseregisterloven, LOV-2014-06-20-43) governs the establishment and use of health registries in Norway. DIPS provides systems that may interface with national health registries. The risk level is MEDIUM because: (1) DIPS's interoperability and connectivity solutions (Connectivity Suite, Interactor) may process data flowing to/from national health registries; (2) the Act imposes strict requirements on data quality, access, and secondary use of health data; (3) compliance is primarily the responsibility of registry operators (hospital trusts, FHI), but DIPS as a system provider must ensure technical compliance.
Evidence: https://lovdata.no/dokument/NL/lov/2014-06-20-43, https://www.dips.com/losninger/samhandling, https://www.fhi.no/
GDPR (source) — Partially Compliant
DIPS ASA operates as a healthcare IT provider processing highly sensitive special-category personal data (patient health records) on behalf of Norwegian hospitals and municipalities. Norway is an EEA member state, making GDPR directly applicable via the EEA Agreement and implemented through Norway's Personal Data Act (Personopplysningsloven). The company acts as both a data controller (for its own employee, customer, and marketing data) and a data processor (for patient data processed through its electronic health record systems used by 100,000+ healthcare professionals). The risk level is HIGH because: (1) health data is a special category under GDPR Article 9 with stricter requirements; (2) a breach or non-compliance could affect hundreds of thousands of patients; (3) fines can reach €20M or 4% of global annual turnover; (4) Datatilsynet (Norway's DPA) actively enforces GDPR in the healthcare sector; (5) DIPS uses third-party processors (HubSpot, Mailchimp, Google Analytics) which require valid data processing agreements and transfer mechanisms. Positive indicators include: a named Data Protection Officer (Ingrid Egelandsaa), a published privacy policy, and stated data deletion routines. However, the use of US-based processors (HubSpot, Google Analytics, Mailchimp) raises international transfer compliance questions post-Schrems II.
Evidence: https://www.dips.com/personvern, https://www.dips.com/om-oss, https://lovdata.no/dokument/NL/lov/2018-06-15-38, https://www.datatilsynet.no/regelverk-og-verktoy/lover-og-regler/om-personopplysningsloven-og-nar-gjelder-den/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679
NIS2 (source) — Assessment Required
NIS2 (EU Directive 2022/2555) explicitly lists 'health' as an Essential Entity sector (Annex I). DIPS ASA provides mission-critical electronic health record (EHR) systems to Norwegian hospitals — systems described on their own website as 'samfunnskritisk helseteknologi' (society-critical health technology). Norway, as an EEA member, is expected to implement NIS2 equivalent requirements. The risk level is HIGH because: (1) DIPS's EHR systems are used by 100,000+ healthcare professionals across Norwegian hospitals, making them critical digital infrastructure for the health sector; (2) a cybersecurity incident affecting DIPS could cascade to patient safety across multiple hospitals; (3) NIS2 imposes significant obligations including incident reporting within 24 hours, supply chain security, and management accountability; (4) non-compliance penalties can reach €10M or 2% of global annual turnover for Essential Entities; (5) Norway's NSM (Nasjonal sikkerhetsmyndighet) actively enforces cybersecurity requirements in critical sectors. The 'Assessment Required' status reflects that Norway's formal NIS2 transposition timeline and DIPS's formal registration status as an Essential Entity supplier require verification.
Evidence: https://www.dips.com/om-oss, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555, https://www.nsm.no/regelverk/nis2/, https://www.regjeringen.no/no/tema/statlig-forvaltning/ikt-politikk/cybersikkerhet/nis2/id3024/
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 7/10
DIPS AS demonstrates strong financial resilience underpinned by its dominant position as the de-facto EHR standard for Norwegian specialist healthcare. The customer base—Norwegian regional health authorities and municipalities—represents extremely low credit risk, and the switching costs for hospital EHR systems are enormous, providing very sticky multi-year revenue streams. Historical reporting suggests revenues in the NOK 500-700 million range with consistently positive operating results and high single-digit to low double-digit operating margins. The company benefits from PE backing through Norvestor and the Kernel group platform, providing access to capital for M&A and product investment. The recurring revenue mix (licenses, SaaS, support, maintenance, consulting) provides good revenue visibility. However, resilience is tempered by significant customer concentration risk with just a handful of Norwegian regional health authorities, complete single-country exposure to Norway, and competitive risks demonstrated by Helse Midt-Norge's selection of Epic over DIPS. The ongoing product transition from Classic to Arena requires sustained R&D spend that pressures margins, and PE ownership raises the possibility of leveraged balance sheet dynamics and dividend upstreaming.
Key strengths: Dominant domestic position as de-facto EHR standard for Norwegian specialist healthcare, Public-sector customer base with extremely low credit risk, High switching costs creating sticky multi-year revenue, Long product/reference history since 1987 with deep clinical domain expertise, PE-backed group (Kernel/Norvestor) providing access to capital, Recurring revenue mix providing revenue visibility, Consistently profitable with high single-digit to low double-digit operating margins
Risk factors: Customer concentration on handful of Norwegian regional health authorities, Single-country exposure (essentially 100% Norway), Competitive/policy risk - Helse Midt-Norge chose Epic over DIPS, Product transition risk from Classic to Arena requiring sustained R&D spend, PE ownership - possibility of debt on group balance sheet and dividend upstreaming, Regulatory/data-protection burden (GDPR, MDR, Norm for informasjonssikkerhet), National e-health strategy changes could reshape addressable market
Revenue by geography
- Norway: 100%
Workforce by country
- Norway: 380
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.