Healing Process policy suite
Professional and Clinician Portal Terms
1. Purpose
To set the conditions for authorised professional use of the Healing Process portal and preserve the provider’s responsibility for clinical care, staffing, records, configuration and local deployment safety.
2. Scope and status
These draft terms apply to clinicians, administrators, auditors and other authorised staff accessing a provider-linked portal. They require completion through the customer contract, data-processing terms, service specification and local user policy.
Deployment-specific policy framework
3. Policy principles
- Portal access is role-specific and does not confer competence or authority outside the professional’s scope or provider policy.
- Automated indicators and aligned images support review; professionals remain responsible for assessing the complete context and arranging appropriate action.
- The provider is responsible for operating hours, capacity, queue ownership, escalation, clinical record and continuity.
- The supplier is responsible for the product within its approved specification and for cooperating with safety, security and regulatory duties.
4. Mandatory requirements
- Users access only records needed for their role, use their own credentials, protect devices and report inappropriate access or wrong-patient information.
- Before deciding, the reviewer checks identity, source images, notes, quality, limitations, relevant history and local protocol and seeks direct assessment when needed.
- Clinically significant messages, decisions, referrals, prescriptions and safety-netting are recorded in the authoritative record according to the provider’s approved integration/workflow.
- Exports, screenshots and downloads are limited to authorised purposes, logged and protected under the receiving organisation’s rules.
- Users do not change thresholds, labels, templates or workflow outside controlled administration and change approval.
- The provider maintains users, training, competence, supervision, leavers, emergency access and periodic access review.
- Incidents, complaints, false or misleading output, downtime and suspected device or data issues are reported promptly through the configured routes.
- The portal is not used for unapproved research, model training, worker monitoring or commercial profiling.
- Service levels, liability, indemnity, warranties, jurisdiction and termination are governed by the signed organisation contract and must not be replaced by a click-through clause without legal review.
5. Procedure and escalation
- Professional acceptance records identity, organisation, role, term version and training status.
- Suspicious or inappropriate access may be suspended immediately while the provider maintains safe care and investigation.
- Provider and supplier cooperate on incidents with agreed lead, evidence, notification and corrective action.
- On role or contract end, access is removed, unresolved tasks reassigned and records/export obligations completed.
6. Roles and responsibilities
Professional user
acts within competence, policy and role and documents decisions.
Provider
owns deployment, access, staffing, clinical service and local governance.
Supplier
operates product, support, security, product safety and agreed service levels.
Administrators
apply approved configurations and access controls.
Clinical Safety Officers
coordinate product and deployment risk.
7. Records, confidentiality and retention
Keep acceptance, identity/role, training, access, review/action, configuration, exports, incidents, support and termination records according to contracts and schedules.
Records created under this policy must be accurate, attributable, access-controlled and linked to the applicable retention schedule. Where a provider is the controller or authoritative record holder, its documented instructions and legal duties apply.
8. Monitoring, assurance and review
Review per contract and at least annually, plus after material product, pathway, regulatory or legal change. Audit access, queue ownership, documentation, exports and training.
Material non-compliance is reported through the relevant clinical-safety, patient-safety, data, security, safeguarding, HR, contractual or whistleblowing route. Corrective actions receive an owner, target date and effectiveness check.
9. Training and communication
The policy owner identifies which roles require awareness, operational or specialist training. Training is accessible, version-controlled, role-specific and refreshed after material change or evidence that understanding is inadequate. Providers communicate local procedures and contact routes before users are granted access.
10. Related documents
11. Approval record
| Role | Name | Decision/date |
|---|---|---|
| Policy owner | To be completed | Draft pending approval |
| Clinical/technical specialist | To be completed | Draft pending approval |
| Board or delegated committee | To be completed | Draft pending approval |
