As part of the NHS, we operate under the highest standards of safety and security. The ChatHealth central support team consists entirely of NHS staff, working to the same codes of conduct as many of the 80 healthcare organisations and 2,000 healthcare professionals that we support across the UK.
We provide detailed safe standard operating procedures and quality standards for local healthcare teams to use when they are providing ChatHealth messaging services. The standards and procedures have been developed in the long term in partnership with clinical teams, safeguarding experts, governance managers and advisory organisations. Overseen by our dedicated clinical lead, this clinical safety approach is subject to a continuous co-design cycle with all staff users and managers able to input on how we maintain high quality, up-to-date processes that effectively safeguard our most vulnerable service users.
The technology behind ChatHealth is co-designed with clinical teams and managers. Our dedicated clinical lead oversees our compliance with the NHS Digital information standards that are required for developing and maintaining IT systems in the health and care environment. We keep messaging safe with a range of safety features such as staff alerts and automated out-of-hours bounce-backs, which help to ensure no message ever goes unanswered.
ChatHealth is continually assessed and evaluated for its effectiveness in supporting clinical teams to deliver safe, high-quality care. See Evidence of evaluation, accreditations, academic research, case studies and media coverage.
Leicestershire Partnership NHS Trust which operates ChatHealth is registered with the Information Commissioner’s Office in relation to data protection and work within all related compliance frameworks such as the NHS Confidentiality Code of Conduct, Care Records Guarantee, Caldicott Guardianship and the NHS Data Security and Protection Toolkit. We also comply with data protection legislation of the UK GDPR and the Data Protection Act (2018).
ChatHealth operates to industry security standards in relation to access controls, threat countermeasures and tested disaster recovery functionality. We operate countless technical controls to ensure our systems are kept secure, including multi-tiered anti-malware software, anti-ransomware services and multi-vendor firewalls. We also have clearly defined processes for incident response which are a requirement of the many frameworks under which we operate.
We undertake frequent routine security testing of the IT infrastructure and the ChatHealth platform. Testing and audits are undertaken by external partners and our own NHS information security service which is independently accredited by Tigerscheme, EC-Council and other major bodies.
All data at rest is encrypted to AES256 and all data in transit is encrypted to TLS1.2 as a minimum. Patient identifiable information is only ever used to support essential day-to-day messaging transactions and no sensitive information is retained by ChatHealth in the long term. See Privacy and Terms to find out more.
Our key cloud provider, Amazon Web Services (AWS), has one of the most flexible and secure cloud computing environments available and has certification for compliance with ISO/IEC 27001:2022, 27017:2015, 27018:2019, 27701:2019, 22301:2019, 20000-1:2018, 9001:2015, and CSA STAR CCM v4.0.
ChatHealth meets the NHS architecture principle of ‘Public cloud first’ where “Digital services should move to the public cloud unless there is a clear reason not to do so.”
Our key partner for technical delivery is a highly accredited NHS health informatics service which has extensive experience of NHS standards, clinical systems security, procedures, information governance and risk management including ISO 27001 certification for activities as an NHS Information Management & Technology (IM&T) service provider, and NHS England Data Security and Protection Toolkit (DSPT) compliance.
More detailed information about our safety and security approach can be found in the ChatHealth service specification, Data Privacy Impact Assessment (DPIA) and we also have evidence ready to share with prospective organisations assessing our products against NHS England’s Digital Technology Assessment Criteria (DTAC).
See Adopt ChatHealth if you would like more information.