Skip to main content
Simplify HCS
Menu

Trust & compliance

Everything a buyer checks, in one place

This page states our clinical safety, information governance, security and data protection position. It is written for procurement, not for marketing. Where a value is not yet published it is marked rather than omitted.

Last reviewed

Clinical safety

Our products are developed under DCB0129. We maintain a Clinical Risk Management Plan, Hazard Log and Clinical Safety Case Report, overseen by our Clinical Safety Officer.

Clinical Safety Officer
Nagini Vallamkonda, GDC 190767
Standard applied
DCB0129 (clinical risk management for health IT manufacturers)
Artefacts maintained
Clinical Risk Management Plan, Hazard Log, Clinical Safety Case Report
Reissue cadence
Clinical Safety Case Reports are issued per release
Availability to deploying organisations
Available to deploying organisations to support their DCB0160 obligations, on request

Digital Technology Assessment Criteria (DTAC)

Status
We maintain a completed NHS Digital Technology Assessment Criteria response against the February 2026 form, available to NHS buyers on request.
Form version
February 2026
Last completed
[PLACEHOLDER: DTAC completion date]

Data Security and Protection Toolkit (DSPT)

As an IT supplier we file the standards-based version of the DSPT, not the CAF-aligned version that applies to NHS organisations.

Status
[PLACEHOLDER: DSPT status, e.g. Standards Met]
Toolkit version
[PLACEHOLDER: DSPT version filed]
Publication date
[PLACEHOLDER: DSPT publication date]
ODS code
B8D4Q
Assessment type
Standards-based (IT supplier), not CAF-aligned

Security certification

Certification claims are only meaningful with a certificate number, an expiry date and a named certification body. Undated badges are a red flag, so we publish the detail or we publish nothing.

Security certifications held, with certificate numbers and expiry dates
CertificationCertificate no.ExpiresCertification bodyUKAS-accredited
Cyber Essentials[PLACEHOLDER: certificate number or “not held”][PLACEHOLDER: expiry date][PLACEHOLDER: body][PLACEHOLDER: yes / no]
Cyber Essentials Plus[PLACEHOLDER: certificate number or “not held”][PLACEHOLDER: expiry date][PLACEHOLDER: body][PLACEHOLDER: yes / no]
ISO/IEC 27001[PLACEHOLDER: certificate number or “not held”][PLACEHOLDER: expiry date][PLACEHOLDER: body][PLACEHOLDER: yes / no]

Delete any row for a certification we do not hold rather than leaving it blank. An empty row reads as an expired certificate.

Data protection

We are a controller for the data we collect about our own customers and website visitors, and a processor for the patient data our customers put through our products. The distinction matters because it determines who answers a subject access request.

ICO registration
ZB235652 (Tier 1, renews 11 October 2026)
Where we are a controller
Customer contact details, billing records, support correspondence and website analytics.
Where we are a processor
Patient data entered into our products by a customer. The customer is the controller; we act on their documented instructions.
Hosting region
[PLACEHOLDER: hosting region, e.g. UK South]
Hosting provider
[PLACEHOLDER: hosting provider]
International transfers
[PLACEHOLDER: state whether any data leaves the UK, and under what mechanism]
Data Protection Officer
[PLACEHOLDER: DPO name and contact, or state that none is appointed and why]

Sub-processors

Last updated . We notify customers before adding a sub-processor that handles patient data.

Current sub-processors and what they process
Sub-processorPurposeData region
[PLACEHOLDER: sub-processor name][PLACEHOLDER: purpose][PLACEHOLDER: data region]
[PLACEHOLDER: sub-processor name][PLACEHOLDER: purpose][PLACEHOLDER: data region]

AI and patient data

Buyers ask three questions about AI and patient data: does it reach a model provider, is it used for training, and how long is it kept. Silence on any of them is read as yes, so we answer all three.

Does patient data reach a model provider?
[PLACEHOLDER: yes / no — and if yes, which provider and under what contract]
Is patient data used to train models?
[PLACEHOLDER: yes / no — state the contractual basis for the answer]
Retention period at the model provider
[PLACEHOLDER: retention period, or state zero-retention if contracted]
Retention period in our systems
[PLACEHOLDER: retention period]
Which products use a model provider
[PLACEHOLDER: list products, or state none]
Human review before anything is filed
Yes. Every output is a draft until a clinician or Clinical Safety Officer reviews, edits and approves it.

Documents for buyers

These are available to NHS buyers and deploying organisations on request. A pre-populated DPIA template is provided so your information governance team starts from our answers rather than a blank form.