Not for emergencies. If someone is seriously unwell or in immediate danger, call 999. For urgent medical help use NHS 111 or your local urgent-care route.
Display: Accessibility statement

Healing Process policy suite

Acceptable Use, Messaging and Professional Conduct Policy

StatusWorking draft
Version1.0-draft
OwnerService Operations Lead
Review date23 July 2027 or earlier
Approval status: this is a substantive governance draft for review. It is not evidence that a production control has been implemented, audited or approved. Each live NHS or care deployment must align it with the provider’s policies, law, contract and configured service.

1. Purpose

To set clear standards for safe, respectful and attributable use of Healing Process accounts, images, messages, exports and professional functions.

2. Scope and status

This policy applies to patients, carers, professionals, administrators, support workers, contractors and anyone granted access to the website, app, portal or data.

Core supplier and product policy

3. Policy principles

  • Every user acts under their own identity and only within their role and authority.
  • Messaging supports the configured purpose and is not an emergency channel or a substitute for required assessment.
  • Professional communication is concise, respectful, relevant and documented in the correct record.
  • Users must not copy sensitive information into personal messaging, social media, unapproved AI tools or personal storage.

4. Mandatory requirements

  • Keep credentials confidential, use approved devices and report suspected compromise promptly.
  • Confirm the person, episode and wound/skin area before capturing, messaging, reviewing or exporting.
  • Do not upload unrelated, sexual, abusive, illegal, misleading or third-party content, and avoid including faces or documents unless necessary and authorised.
  • Do not apply filters or external editing to clinical source images. Use only approved in-product processing and preserve originals.
  • Use messages for relevant updates, questions and actions within stated service hours; use urgent alternatives when needed.
  • Professionals must not offer care beyond competence or make an image-only decision where direct assessment is required.
  • Do not share accounts, impersonate another person, browse records without a purpose, bulk export, attempt to defeat security or use data for personal interest.
  • Record clinically significant advice, decisions and escalation in the authoritative record according to provider policy.
  • Treat discriminatory, threatening, harassing or exploitative behaviour as a conduct and potentially safeguarding matter.

5. Procedure and escalation

  • Potential misuse is logged and triaged by severity. Access may be restricted urgently while care continuity and evidence are preserved.
  • Minor first issues may receive education; serious or repeated misuse may lead to suspension, provider/manager notification, safeguarding, professional or legal escalation.
  • A user can challenge a restriction through the applicable provider or product process, but safety controls remain during review where justified.
  • Professional messages use approved templates only as an aid and must be personalised to the concern and next action.

6. Roles and responsibilities

Users

use the service lawfully, accurately and respectfully.

Professionals/managers

maintain competence, supervision and appropriate documentation.

Provider administrators

grant and remove access and investigate local conduct.

Supplier support/security

detect, preserve and escalate misuse without making clinical decisions.

Product team

builds attribution, confirmation, rate limits, export control and reporting tools.

7. Records, confidentiality and retention

Keep terms acceptance, access, messages, exports, misuse reports, decisions, warnings, restrictions, appeals and audit logs according to the approved schedule.

Records created under this policy must be accurate, attributable, access-controlled and linked to the applicable retention schedule. Where a provider is the controller or authoritative record holder, its documented instructions and legal duties apply.

8. Monitoring, assurance and review

Review annually and after significant misuse or workflow change. Monitor shared-account indicators, unauthorised access, inappropriate exports, abusive messages, wrong-record actions and training completion.

Material non-compliance is reported through the relevant clinical-safety, patient-safety, data, security, safeguarding, HR, contractual or whistleblowing route. Corrective actions receive an owner, target date and effectiveness check.

9. Training and communication

The policy owner identifies which roles require awareness, operational or specialist training. Training is accessible, version-controlled, role-specific and refreshed after material change or evidence that understanding is inadequate. Providers communicate local procedures and contact routes before users are granted access.

10. Related documents

11. Approval record

RoleNameDecision/date
Policy ownerTo be completedDraft pending approval
Clinical/technical specialistTo be completedDraft pending approval
Board or delegated committeeTo be completedDraft pending approval
Return to policy centre