Healing Process policy suite
Acceptable Use, Messaging and Professional Conduct Policy
1. Purpose
To set clear standards for safe, respectful and attributable use of Healing Process accounts, images, messages, exports and professional functions.
2. Scope and status
This policy applies to patients, carers, professionals, administrators, support workers, contractors and anyone granted access to the website, app, portal or data.
Core supplier and product policy
3. Policy principles
- Every user acts under their own identity and only within their role and authority.
- Messaging supports the configured purpose and is not an emergency channel or a substitute for required assessment.
- Professional communication is concise, respectful, relevant and documented in the correct record.
- Users must not copy sensitive information into personal messaging, social media, unapproved AI tools or personal storage.
4. Mandatory requirements
- Keep credentials confidential, use approved devices and report suspected compromise promptly.
- Confirm the person, episode and wound/skin area before capturing, messaging, reviewing or exporting.
- Do not upload unrelated, sexual, abusive, illegal, misleading or third-party content, and avoid including faces or documents unless necessary and authorised.
- Do not apply filters or external editing to clinical source images. Use only approved in-product processing and preserve originals.
- Use messages for relevant updates, questions and actions within stated service hours; use urgent alternatives when needed.
- Professionals must not offer care beyond competence or make an image-only decision where direct assessment is required.
- Do not share accounts, impersonate another person, browse records without a purpose, bulk export, attempt to defeat security or use data for personal interest.
- Record clinically significant advice, decisions and escalation in the authoritative record according to provider policy.
- Treat discriminatory, threatening, harassing or exploitative behaviour as a conduct and potentially safeguarding matter.
5. Procedure and escalation
- Potential misuse is logged and triaged by severity. Access may be restricted urgently while care continuity and evidence are preserved.
- Minor first issues may receive education; serious or repeated misuse may lead to suspension, provider/manager notification, safeguarding, professional or legal escalation.
- A user can challenge a restriction through the applicable provider or product process, but safety controls remain during review where justified.
- Professional messages use approved templates only as an aid and must be personalised to the concern and next action.
6. Roles and responsibilities
Users
use the service lawfully, accurately and respectfully.
Professionals/managers
maintain competence, supervision and appropriate documentation.
Provider administrators
grant and remove access and investigate local conduct.
Supplier support/security
detect, preserve and escalate misuse without making clinical decisions.
Product team
builds attribution, confirmation, rate limits, export control and reporting tools.
7. Records, confidentiality and retention
Keep terms acceptance, access, messages, exports, misuse reports, decisions, warnings, restrictions, appeals and audit logs according to the approved schedule.
Records created under this policy must be accurate, attributable, access-controlled and linked to the applicable retention schedule. Where a provider is the controller or authoritative record holder, its documented instructions and legal duties apply.
8. Monitoring, assurance and review
Review annually and after significant misuse or workflow change. Monitor shared-account indicators, unauthorised access, inappropriate exports, abusive messages, wrong-record actions and training completion.
Material non-compliance is reported through the relevant clinical-safety, patient-safety, data, security, safeguarding, HR, contractual or whistleblowing route. Corrective actions receive an owner, target date and effectiveness check.
9. Training and communication
The policy owner identifies which roles require awareness, operational or specialist training. Training is accessible, version-controlled, role-specific and refreshed after material change or evidence that understanding is inadequate. Providers communicate local procedures and contact routes before users are granted access.
10. Related documents
11. Approval record
| Role | Name | Decision/date |
|---|---|---|
| Policy owner | To be completed | Draft pending approval |
| Clinical/technical specialist | To be completed | Draft pending approval |
| Board or delegated committee | To be completed | Draft pending approval |
