Industries

Healthcare AI that knows where the device boundary is

The largest, safest returns in healthcare AI are administrative: the letters, the coding, the referral paperwork and the rota churn that consume clinical time without touching clinical judgement. We work on that side of the line deliberately, and we are explicit about where the line is.

  • DSPT and IG aligned
  • Clinical safety process respected
  • Device boundary made explicit
Working in healthcare
The pressure right now

What we hear from healthcare

  • Clinical time consumed by documentation rather than patients
  • Referral and waiting list administration outgrowing the teams that manage it
  • Coding accuracy affecting both the record and the income
  • Digital tools procured in isolation, each with its own information governance case
  • Staff already using consumer AI tools on work that involves patient information
Where it pays off

Six places AI earns its keep here

Not everything on this list will apply to you. Most organisations start with one and extend once it has been measured.

Clinical correspondence

Discharge summaries and clinic letters drafted from the consultation record into your standard format, checked and signed by the clinician - the highest-volume documentation win in most providers.

Coding support

Suggested codes with the supporting passage from the record shown next to each one, so the coder verifies rather than searches.

Referral administration

Structuring, checking and routing incoming referrals against your acceptance criteria, flagging incomplete ones back immediately rather than at the review meeting.

Patient communications

Appointment, preparation and follow-up communications in accessible language, with reading-age and translation support, and clinical content approved in advance.

Policy and guidance retrieval

Grounded answers from your own local protocols and standard operating procedures, with citations - for staff, not for patients.

Operational reporting

Assembling the weekly operational picture from systems that do not talk to each other, so managers spend the meeting deciding rather than reconciling.

Where we would start

The first three moves

1

Choose an administrative workflow

Correspondence or referral admin. Measurable, high-volume, and outside the clinical decision path.

2

Run the clinical safety process

Even administrative systems in a clinical setting need a clinical safety case, a named officer and a hazard log. We build that in from the start.

3

Prove it in one service line

One specialty, real volume, measured against the baseline before anything is offered trust-wide.

Risk and regulation

The part most suppliers skip

Where the risk sits

  • Anything that diagnoses, triages by clinical risk or recommends treatment is a medical device
  • Data Security and Protection Toolkit obligations and your local information governance
  • Clinical safety standards DCB0129 and DCB0160 and the need for a named clinical safety officer
  • Special category data and the lawful basis for each processing purpose
  • Health inequality: accessibility and language must be designed in, not retrofitted

How we handle it

We stay on the administrative side of the medical device boundary and we say so in writing. Where a genuinely clinical capability is wanted, the route is a UKCA-marked product and an MHRA-aware procurement, not a bespoke build.

Clinical safety is treated as a deliverable, not paperwork: hazard log, safety case and clinical safety officer sign-off accompany the system.

Where patient-identifiable data cannot leave your boundary, the deployment is private, inside your own tenancy or infrastructure, with the IG position documented for approval.

Questions

Questions from healthcare

No, and we would question any supplier who offers to build one outside the medical device regime. Software that triages by clinical risk or supports diagnosis needs conformity assessment and UKCA marking. We work on the administrative side and are explicit about the boundary.
That is the test we design to. We produce the DPIA input, the data flow map and the clinical safety documentation as part of delivery, because a system that cannot clear IG is not a system.
The device boundary and data protection law apply identically. DSPT and the NHS clinical safety standards may not be mandatory for you, but they remain a sensible bar - and your NHS-contracted work will often require them anyway.

Start with an audit of what you already run

Two to four weeks to an evidenced picture of your AI use, spend and risk - and a ranked list of what to do first.