Data, privacy & identity
The patient-facing apps carry no personal data and authenticate no patient — by design, not by policy.
| Area | What we commit to | How Patient Compass meets it | Basis |
|---|---|---|---|
| No personal data (PII) | No accounts, no logins, no email capture. | The patient apps need no sign-in and store no personal data; reading choices are kept on the device only. | Charter §7.2 · UK GDPR data-minimisation |
| No health data (PHI) | No patient-identifiable health information is stored, processed or transmitted. | Patients stay anonymous; the suite is a delivery layer for approved content, not a clinical record system. | Charter §7.2 |
| No patient authentication | Patients are never authenticated — absolute and unchanged. | Only clinicians authenticate, and only on The Helm (never a patient, never patient data). | Charter §7.2 · ADR-0107 |
| No tracking | No advertising trackers, no cross-site tracking, no behavioural profiling. | Cookieless, aggregate-only analytics (Plausible); nothing that can re-identify a user. | Charter §7.2 · ADR-0119 |
Accessibility
Accessibility-first delivery is the central clinical and commercial promise of the suite, not an add-on.
| Area | What we commit to | How Patient Compass meets it | Basis |
|---|---|---|---|
| WCAG conformance | WCAG 2.2 AA minimum; AAA target for text contrast. | Audited against 2.2; reduced-motion respected, 44×44px touch targets, high-contrast support, no autoplaying media. | Charter §11.5 · WCAG 2.2 |
| Dual-track easy-read | Every step exists in both a standard and an easy-read version. | The choice is offered on the first screen and persists across the journey; easy-read is one tap away on every page. | Charter §11.1–§11.2 |
| Predictable structure | Branching is visible and predictable; nothing is hidden without reason. | A persistent progress indicator, plain-language branch labels, and content warnings before any anatomical detail. | Charter §11.4 |
Clinical governance & safety
Nothing reaches a patient until a registered clinician takes professional responsibility for it.
| Area | What we commit to | How Patient Compass meets it | Basis |
|---|---|---|---|
| Informed consent | Built to the Montgomery disclosure standard. | Material risks, options and instructions presented at the patient’s pace, in a form they can genuinely engage with. | Montgomery v Lanarkshire (2015) · §16.1 |
| Clinician sign-off | No content reaches a patient until a registered clinician signs it off. | Sign-off writes an immutable record: name, registration number, document + version, attestation and timestamp. | Charter §14 · ADR-0113 |
| Continuous source alignment | Content reflects the current approved source — no frozen content. | On source reissue, affected content is flagged for review, then realigned and re-signed within a defined workflow window. | Charter §14.1 · §15 |
| No clinical decision logic | The suite presents information; it never advises, triages or recommends. | No decision-making logic anywhere in the patient surfaces — it is not a clinical system. | Charter §7.2 |
| Complication data honesty | Literature-sourced and attributed; never fabricated or averaged. | Single cited values (authority + year + DOI); local-cohort figures only as an audited, clearly-labelled exception. | Charter §14.5 |
| Trust mark (where applicable) | PIF TICK certification, separate from publishing. | An optional clinician-ticked gate lights a patient-facing PIF TICK badge; it de-certifies automatically on source reissue. | ADR-0120 · ADR-0124 |
Hosting, residency & portability
UK-regional today, and movable to a tenant-controlled or NHS-Digital-approved environment at no cost.
| Area | What we commit to | How Patient Compass meets it | Basis |
|---|---|---|---|
| Hosting & residency | UK regional hosting. | Vercel UK configuration with managed TLS; content in a Sanity-hosted dataset. | Charter §7.1 |
| Migration path | Migratable to NHS-Digital-approved hosting at no cost. | Hosting, the content dataset and the domain can move to a tenant-controlled or NHS-D environment without losing licence rights. | Charter §7.3 |
| Audit trail | A medico-legally defensible record. | Provenance metadata per content item plus full Sanity edit history (author and timestamp) constitute the audit trail. | Charter §15.4 |
In plain words
The matrix above, restated as plain statements — each one stands on its own.
Patients never create an account on Patient Compass and are never authenticated. They reach their pathway through a link issued by their own clinical team, and they cannot self-enrol. The patient-facing apps store no personal data and no patient health information. The platform is cookieless, runs no advertising trackers, and uses only aggregate, non-re-identifying analytics.
Nothing patient-facing is published until a registered clinician signs it off; the sign-off records the clinician’s name, registration number, the document and version, and a timestamp. Published content is versioned, so there is a record of exactly what the information said, in which version, on any given date. Every pathway records the approved source document it reflects and is flagged for review when that source is reissued. Complication figures are single values from a cited source — never an averaged range — and figures taken from the literature say so in the patient-facing text.
Every pathway step exists in a standard and an easy-read version, with the choice offered up front and available on every page. The patient surfaces are built to WCAG 2.2 AA, with an AAA target for text contrast. The suite contains no clinical decision logic: it presents information and never advises, triages or recommends. Hosting is UK-regional, and a tenant may migrate hosting, content and domain to a tenant-controlled or NHS-Digital-approved environment without losing licence rights.
On the accessibility duty itself — what the Accessible Information Standard (DAPB1605) requires of a surgical service, and where private practice stands — see the Accessible Information Standard, applied to surgical patient information.
Declared openly
What the suite does not claim.
Because there is no patient sign-in and no patient identifier, the suite does not, on its own, prove that a named individual viewed a given asset. Its defensibility is at the population level: more complete, more accessible, dual-track content, kept aligned to the current approved source, with a clinician sign-off audit trail. That limitation is stated upfront — it is a known boundary, not a hidden defect.
Reviewing us for adoption?
We are glad to walk a clinical-governance or information-governance team through any line of this matrix against your own standards.
Orientation summary for clinical and information-governance reviewers — not legal advice and not a contract. It reflects the platform charter and the architecture decision records; where a signed agreement differs, the signed agreement governs.