AI Build Policy
Our Approach to Safe, Private AI
Version: 1.0 · Last Updated: 9 October 2026
Your information is protected before AI ever sees it. This page explains how NowPatient builds and governs AI, in plain language first, with the detail for healthcare organisations and procurement teams further down.
Our approach in brief
- A governed layer, not shortcuts. AI in NowPatient runs through a purpose-built harness. We never paste patient data into public chat tools or wire model calls directly into application code.
- Privacy first. Identifiable details are de-identified or redacted before they reach an AI model.
- No training on your data. Our contracts prohibit third-party AI vendors from training their models on your data.
- Everything is logged and checked. Every AI request and response is recorded in an audit trail, and outputs are checked against clinical-safety and content guardrails.
- People stay in the loop. Human oversight is built in where it matters most.
1. What "the harness" means
The harness is a single governed layer that sits between NowPatient products and the underlying frontier AI models. Every AI feature we build uses it. That means access, data handling, safety checks and monitoring are managed in one place, rather than reinvented, and potentially weakened, in each product.
2. Privacy and data protection
- De-identification before processing. Protected health information (PHI) and patient-identifiable data are de-identified or redacted before they reach a model.
- Minimum necessary. AI features receive only the information they need to do their job.
- Encryption. Data is encrypted in transit and at rest.
- Jurisdiction. Processing is held within agreed jurisdictions: primary UK hosting (AWS London / eu-west-2) for clinical and application workloads; some supporting infrastructure also in other AWS regions including the US; HIPAA-aligned controls and clinician BAAs where US clinicians onboard.
- No vendor training. Contractual terms prohibit third-party model providers from training on your data. Where PHI is processed by a provider, we maintain Business Associate Agreements / zero-retention arrangements.
3. Access control
Access to systems, prompts and data is role-based and follows the minimum-necessary principle. Permissions are managed centrally and reviewed at least every six months.
4. Audit and accountability
Every AI request and response is recorded in a tamper-evident audit trail. This supports HIPAA audit-control expectations and NHS expectations for transparency and accountability, and allows us to investigate and respond if something goes wrong.
5. Safety, guardrails and human oversight
- Outputs are validated against clinical-safety and content guardrails before they reach you.
- Human oversight is built into workflows where AI output could affect care or decisions.
- AI features are tested before release and monitored after it. Models are evaluated before being adopted or changed.
What our AI does, and does not do. NowPatient uses AI to support clinical care, not to replace it. AI does not diagnose, prescribe or make treatment decisions, and no AI output is acted on or shared with another healthcare professional until a registered clinician has reviewed it. Responsibility for every clinical decision remains with the clinician. We do not use AI to make automated decisions that have legal or similarly significant effects on patients. We tell patients when AI has been used in their care.
6. Built to adapt
Because models, prompts and permissions are managed centrally, we can evaluate, update or swap a model, apply policy consistently across every product, and respond quickly to emerging risks without rebuilding each product.
For healthcare organisations: standards and frameworks
NowPatient’s AI is designed around the following.
| Framework | Region | How we approach it |
|---|---|---|
| HIPAA (Privacy, Security and Breach Notification Rules) | US | Minimum-necessary access, encryption, audit controls, de-identification before model processing, BAAs where applicable |
| NHS DTAC (Digital Technology Assessment Criteria) | UK | Designed around DTAC’s clinical safety, data protection, technical security, interoperability and usability criteria. DTAC questionnaire completed; formal assessment at NHS / social care commissioning (NHS England DTAC guidance, May 2024) |
| NHS Information Governance | UK | Governance, accountability and transparency controls. Role-based access, audit logging and clinical safety documentation under DCB0129 |
| Data Security and Protection Toolkit (DSPT) | UK | Infohealth Ltd (P416): Standards exceeded for 2025–26 (v8), published 29 June 2026; https://www.dsptoolkit.nhs.uk/OrganisationSearch/P416 |
| UK GDPR / Data Protection Act 2018 | UK | InfoHealth Limited is controller; lawful bases and rights as in NowPatient Privacy Policy; rights via dpo@nowpatient.com; DPIAs where high risk |
| DCB0129 / DCB0160 (clinical risk management) | UK | Clinical Safety Officer: Navin Khosla; hazard logs and CSCR NowPatient NHS/Global baseline v1.2 (June 2026) |
HIPAA does not offer a formal certification, and DTAC is an assessment rather than a badge. We describe our alignment accurately and are glad to share supporting documentation under NDA.
Your rights and questions
If you have questions about how AI is used in NowPatient, want to see supporting documentation, or wish to raise a concern, contact us:
- Email: dpo@nowpatient.com
- Data Protection Officer: Amish Patel (Data Protection Officer / Compliance)
We review this policy every 6 months and whenever our AI practices materially change.