Skip to main content

Safety and compliance

Trust in clinical technology depends on more than product functionality. Journai Health is developing clinical safety, information governance, security and interoperability processes alongside the platform.

Compliance status

Implementation and assessment status across safety, security, and interoperability requirements.

Clinical safety

DCB0129
Planned before clinical pilot
Clinical risk management documentation in development.
DCB0160 deployment support
Planned before clinical pilot
Deployment guidance to be developed with pilot partners.
Medical-device applicability assessment
Applicability being assessed
Classification assessed as intended purpose and functionality evolve.
Incident management
In implementation
Incident reporting processes being defined.

Interoperability

FHIR UK Core
In implementation
Alignment in progress against UK Core profiles.
SNOMED CT
Planned before clinical pilot
Terminology mapping planned as part of UK Core implementation.
dm+d
Planned before clinical pilot
Medicines terminology support planned for medication-related workflows.

Assessment and assurance

DTAC
Applicability being assessed
Assessment against Digital Technology Assessment Criteria as product scope evolves.
DSPT
Requires internal confirmation
Data Security and Protection Toolkit alignment to be confirmed with pilot organisations.
Cyber Essentials
Planned before clinical pilot
Certification planned as part of pre-pilot security programme.
Cyber Essentials Plus
Planned before clinical pilot
Extended certification under consideration.
Supplier assurance
Planned before clinical pilot
Third-party supplier assessment framework in development.
Business continuity
Planned before clinical pilot
Continuity planning to be finalised before live deployments.

Data protection and security

DPIA support
In implementation
Support for partner DPIAs as part of pilot onboarding.
Information governance
In implementation
IG frameworks being developed with legal and clinical advisors.
Data hosting and residency
Requires internal confirmation
UK data residency approach to be confirmed before live patient data processing.
Encryption
In implementation
Encryption in transit and at rest designed into platform architecture.
Access control
In implementation
Role-based access control concepts implemented in MVP.
Audit logging
In implementation
Audit trail concepts for access and changes in MVP design.
Model governance
In implementation
Version control, review workflows and output monitoring in development.

Accessibility

WCAG 2.2 AA
In implementation
Accessibility improvements ongoing; formal audit planned.

Governance areas

Clinical safety

  • Clinical Safety Officer appointment in progress
  • Hazard-log and safety-case documentation in development
  • Human oversight required for all clinically relevant outputs
  • Incident reporting processes being defined

Data protection

  • Lawful processing aligned with UK GDPR
  • Data minimisation and role-based access
  • DPIA support for pilot partners
  • Patient-identifiable data only under appropriate governance

AI governance

  • Source traceability in summary outputs
  • Hallucination and omission testing in progress
  • Model versioning and output monitoring in development
  • Third-party provider assessment underway

Medical-device applicability

The regulatory classification of software depends on its intended purpose and functionality. Journai Health assesses applicable UK medical-device requirements as product capabilities and intended uses evolve.

Discuss a clinical information workflow.

Speak with Journai Health about evaluating the platform within a defined workflow in your organisation.