Clinical safety
Intended use, clinical safety officer, hazard analysis, safety case, release controls, training, incidents and benefit-risk monitoring.
Security, privacy and assurance
This framework sets out the artefacts a provider should be able to inspect before Healing Process processes identifiable health images in a live pathway.
Assurance domains
Intended use, clinical safety officer, hazard analysis, safety case, release controls, training, incidents and benefit-risk monitoring.
Data map, purpose and minimisation, lawful conditions, DPIA, transparency, processor terms, retention and rights handling.
Secure development, architecture, encryption, secrets, access, logging, testing, vulnerability response, continuity and supplier assurance.
Availability, performance, capacity, compatibility, integration, observability, data quality, error handling and support.
Verified identifiers, terminology, APIs, structured export, authoritative record integration and reconciliation.
User-centred design, WCAG 2.2 AA target, assistive-technology testing, accessible information and inclusive service pathways.
Data-flow principles
Security control set
| Control area | Expected implementation | Evidence |
|---|---|---|
| Identity | Strong authentication, verified enrolment, session controls, recovery and appropriate multi-factor authentication. | Identity design, threat model, test results and access-review records. |
| Authorisation | Role- and tenant-based access, least privilege, separation of duties and emergency-access governance. | Permission matrix, automated tests, privileged-access logs. |
| Application security | Secure coding, peer review, dependency control, SAST/DAST, secrets scanning and release approval. | SDLC standard, scan reports, remediation records and software bill of materials. |
| Infrastructure | Hardened environments, network segmentation, managed configuration, patching and monitored cloud controls. | Architecture, configuration baseline, CSP evidence and monitoring reports. |
| Detection and response | Centralised logs, alerting, triage, incident playbooks, breach assessment and provider notification. | SIEM coverage, exercise records, incident metrics and contact matrix. |
| Resilience | Backups, restore tests, redundancy, defined RTO/RPO, downtime workflow and continuity exercises. | BCP/DR plans, restore evidence and exercise actions. |
AI and image processing
Record source image identifier, model or algorithm version, processing parameters, result and timestamp.
Test across skin tones, devices, lighting, body sites, wound types and accessibility needs; publish known failure modes.
Show originals by default, permit override, explain uncertainty and prevent automation from closing or downgrading a concern without authorised review.
The readiness checklist assigns owners, required evidence and approval decisions across product and service deployment.