Healing Process policy suite
Safeguarding Children and Adults at Risk Policy
1. Purpose
To ensure that concerns about abuse, neglect, exploitation, coercion, inappropriate access or unsafe care discovered through Healing Process are recognised, recorded and escalated through the responsible provider’s safeguarding arrangements.
2. Scope and status
This policy applies to staff, contractors, support interactions, research, image review, messaging, carer/proxy access and customer deployments. The product company does not replace statutory agencies or the provider’s designated safeguarding professionals.
Deployment-specific policy framework
3. Policy principles
- The welfare and immediate safety of the child or adult at risk take priority over product process or commercial interest.
- A digital image or message may reveal a concern but cannot establish the full facts. Staff must avoid investigation beyond their role and preserve evidence appropriately.
- Confidentiality is not absolute where disclosure is necessary and lawful to protect a person or others from harm.
- Children and adults who may lack capacity must be heard and supported in a manner appropriate to their communication needs.
4. Mandatory requirements
- Use verified, individual accounts for patients, carers and professionals and record the relationship and authority for proxy access.
- Train relevant workers to recognise indicators in messages, image context, repeated missed care, coercive control, unexplained injury, neglect, fabricated information and inappropriate photography.
- Provide a prominent internal escalation route to the provider safeguarding team and an emergency route where immediate danger is suspected.
- Limit image access and prohibit copying to personal devices, informal messaging or unapproved storage.
- Preserve the original record, access logs and relevant communication when a concern is raised; do not confront an alleged perpetrator through the app.
- Apply safer recruitment, confidentiality and role-based access to workers who can view health images or support accounts.
- Include safeguarding in pilot protocols, incident review, downtime plans and supplier agreements.
5. Procedure and escalation
- A worker who identifies a concern records facts, not speculation, and immediately follows the provider’s safeguarding and emergency procedure.
- The supplier support team receiving a concern contacts the named customer safeguarding/incident route without promising confidentiality or undertaking clinical investigation.
- Access may be restricted urgently where account compromise, coercion or misuse is suspected, while preserving lawful care access and evidence.
- Allegations involving staff are handled under the provider’s safeguarding, HR, professional and regulatory processes.
6. Roles and responsibilities
Safeguarding Lead
maintains this policy, training and customer escalation contacts.
All workers
recognise, record and report concerns promptly.
Support and security teams
preserve evidence and restrict compromised access where authorised.
Providers
own local safeguarding decisions, referrals, clinical care and statutory notifications.
Product team
builds proxy, access and audit controls that support safe practice.
7. Records, confidentiality and retention
Keep safeguarding training records, factual concern reports, referral details, decisions, access changes, audit logs, incident links and learning under restricted access and approved retention.
Records created under this policy must be accurate, attributable, access-controlled and linked to the applicable retention schedule. Where a provider is the controller or authoritative record holder, its documented instructions and legal duties apply.
8. Monitoring, assurance and review
Review annually and after every material safeguarding event or statutory change. Audit referral timeliness, unauthorised proxy access, training completion and corrective actions.
Material non-compliance is reported through the relevant clinical-safety, patient-safety, data, security, safeguarding, HR, contractual or whistleblowing route. Corrective actions receive an owner, target date and effectiveness check.
9. Training and communication
The policy owner identifies which roles require awareness, operational or specialist training. Training is accessible, version-controlled, role-specific and refreshed after material change or evidence that understanding is inadequate. Providers communicate local procedures and contact routes before users are granted access.
10. Related documents
- Consent, Capacity, Carer and Proxy Access Policy
- Patient Safety Incident Policy
- Information Security Policy
11. Approval record
| Role | Name | Decision/date |
|---|---|---|
| Policy owner | To be completed | Draft pending approval |
| Clinical/technical specialist | To be completed | Draft pending approval |
| Board or delegated committee | To be completed | Draft pending approval |
