Not for emergencies. If someone is seriously unwell or in immediate danger, call 999. For urgent medical help use NHS 111 or your local urgent-care route.
Display: Accessibility statement

Healing Process policy suite

Professional and Clinician Portal Terms

StatusWorking draft
Version1.0-draft
OwnerLegal, Clinical Safety and Customer Leads
Review date23 July 2027 or earlier
Approval status: this is a substantive governance draft for review. It is not evidence that a production control has been implemented, audited or approved. Each live NHS or care deployment must align it with the provider’s policies, law, contract and configured service.

1. Purpose

To set the conditions for authorised professional use of the Healing Process portal and preserve the provider’s responsibility for clinical care, staffing, records, configuration and local deployment safety.

2. Scope and status

These draft terms apply to clinicians, administrators, auditors and other authorised staff accessing a provider-linked portal. They require completion through the customer contract, data-processing terms, service specification and local user policy.

Deployment-specific policy framework

3. Policy principles

  • Portal access is role-specific and does not confer competence or authority outside the professional’s scope or provider policy.
  • Automated indicators and aligned images support review; professionals remain responsible for assessing the complete context and arranging appropriate action.
  • The provider is responsible for operating hours, capacity, queue ownership, escalation, clinical record and continuity.
  • The supplier is responsible for the product within its approved specification and for cooperating with safety, security and regulatory duties.

4. Mandatory requirements

  • Users access only records needed for their role, use their own credentials, protect devices and report inappropriate access or wrong-patient information.
  • Before deciding, the reviewer checks identity, source images, notes, quality, limitations, relevant history and local protocol and seeks direct assessment when needed.
  • Clinically significant messages, decisions, referrals, prescriptions and safety-netting are recorded in the authoritative record according to the provider’s approved integration/workflow.
  • Exports, screenshots and downloads are limited to authorised purposes, logged and protected under the receiving organisation’s rules.
  • Users do not change thresholds, labels, templates or workflow outside controlled administration and change approval.
  • The provider maintains users, training, competence, supervision, leavers, emergency access and periodic access review.
  • Incidents, complaints, false or misleading output, downtime and suspected device or data issues are reported promptly through the configured routes.
  • The portal is not used for unapproved research, model training, worker monitoring or commercial profiling.
  • Service levels, liability, indemnity, warranties, jurisdiction and termination are governed by the signed organisation contract and must not be replaced by a click-through clause without legal review.

5. Procedure and escalation

  • Professional acceptance records identity, organisation, role, term version and training status.
  • Suspicious or inappropriate access may be suspended immediately while the provider maintains safe care and investigation.
  • Provider and supplier cooperate on incidents with agreed lead, evidence, notification and corrective action.
  • On role or contract end, access is removed, unresolved tasks reassigned and records/export obligations completed.

6. Roles and responsibilities

Professional user

acts within competence, policy and role and documents decisions.

Provider

owns deployment, access, staffing, clinical service and local governance.

Supplier

operates product, support, security, product safety and agreed service levels.

Administrators

apply approved configurations and access controls.

Clinical Safety Officers

coordinate product and deployment risk.

7. Records, confidentiality and retention

Keep acceptance, identity/role, training, access, review/action, configuration, exports, incidents, support and termination records according to contracts and schedules.

Records created under this policy must be accurate, attributable, access-controlled and linked to the applicable retention schedule. Where a provider is the controller or authoritative record holder, its documented instructions and legal duties apply.

8. Monitoring, assurance and review

Review per contract and at least annually, plus after material product, pathway, regulatory or legal change. Audit access, queue ownership, documentation, exports and training.

Material non-compliance is reported through the relevant clinical-safety, patient-safety, data, security, safeguarding, HR, contractual or whistleblowing route. Corrective actions receive an owner, target date and effectiveness check.

9. Training and communication

The policy owner identifies which roles require awareness, operational or specialist training. Training is accessible, version-controlled, role-specific and refreshed after material change or evidence that understanding is inadequate. Providers communicate local procedures and contact routes before users are granted access.

10. Related documents

11. Approval record

RoleNameDecision/date
Policy ownerTo be completedDraft pending approval
Clinical/technical specialistTo be completedDraft pending approval
Board or delegated committeeTo be completedDraft pending approval
Return to policy centre