Healing Process policy suite
Patient Safety Incidents, Complaints, Candour and Openness Policy
1. Purpose
To provide a clear, fair and learning-focused process for safety incidents, near misses, complaints and concerns involving Healing Process, including timely containment, investigation, communication and corrective action.
2. Scope and status
This policy applies to product defects, incorrect or delayed outputs, data incidents with clinical impact, missed reviews, failed messages, access issues, user harm, complaints and allegations arising from supplier activity or a provider deployment.
Core supplier and product policy
3. Policy principles
- Immediate safety and continuity take priority over determining blame.
- People raising a concern will be treated respectfully and will not suffer retaliation.
- Supplier and provider investigations must coordinate without obscuring each party’s responsibilities.
- Communication should be honest, proportionate and consistent with statutory, contractual, professional and provider duties of candour and notification.
4. Mandatory requirements
- Provide accessible routes for patients, carers, professionals and customers to report a concern, including urgent operational escalation.
- Triage by actual/potential harm, ongoing exposure, affected users, data impact, device/regulatory relevance and need for immediate action.
- Preserve evidence including versions, logs, messages, configuration, images and decisions while restricting unnecessary access.
- Assign an investigation lead independent enough for the seriousness of the matter and use an appropriate human-factors and systems approach.
- Notify customers, regulators, data-protection authorities, device vigilance systems, insurers or affected people where required and document the decision.
- Separate complaint response from technical root-cause work while sharing relevant facts and actions.
- Track corrective and preventive action to verified completion and assess whether similar issues exist elsewhere.
- Feed learning into hazards, training, user information, product design, monitoring and supplier control.
- Publish or share learning in an appropriately anonymised form where this supports safety and trust.
5. Procedure and escalation
- On receipt, the reporter receives acknowledgement and urgent-care advice where relevant, without suggesting that public support is a clinical service.
- Critical issues trigger an incident command process with authority to disable features, stop deployment, issue safety communication or activate continuity arrangements.
- The provider leads clinical care and local patient communication; the supplier supplies evidence, technical analysis and product action and fulfils its own legal duties.
- Closure requires an approved conclusion, recorded uncertainty, completed actions, effectiveness review and communication to the reporter/customer as appropriate.
6. Roles and responsibilities
Patient Safety Lead
owns triage, coordination and learning governance.
Clinical Safety Officer
updates hazards and advises clinical risk action.
Security/DPO/Regulatory leads
manage specialised notification and investigation duties.
Providers
manage patient care, local incident systems and duty-of-candour responsibilities.
All workers
report promptly and preserve evidence.
7. Records, confidentiality and retention
Keep reports, acknowledgements, triage, evidence index, investigation, decisions, communications, notifications, actions, effectiveness checks and learning under controlled access.
Records created under this policy must be accurate, attributable, access-controlled and linked to the applicable retention schedule. Where a provider is the controller or authoritative record holder, its documented instructions and legal duties apply.
8. Monitoring, assurance and review
Review incidents and complaints monthly at an appropriate governance forum and this policy annually. Monitor severity, recurrence, response time, overdue actions, complaints themes and safety-signal detection.
Material non-compliance is reported through the relevant clinical-safety, patient-safety, data, security, safeguarding, HR, contractual or whistleblowing route. Corrective actions receive an owner, target date and effectiveness check.
9. Training and communication
The policy owner identifies which roles require awareness, operational or specialist training. Training is accessible, version-controlled, role-specific and refreshed after material change or evidence that understanding is inadequate. Providers communicate local procedures and contact routes before users are granted access.
10. Related documents
11. Approval record
| Role | Name | Decision/date |
|---|---|---|
| Policy owner | To be completed | Draft pending approval |
| Clinical/technical specialist | To be completed | Draft pending approval |
| Board or delegated committee | To be completed | Draft pending approval |
