Skip to content

TRUST

What happens to the data, in plain terms.

Medication safety software sits close to patient data. This page sets out what PharmAlert sends, stores, retains and logs — and where we are with each compliance requirement.

Data handling

A check sends the clinical information needed to evaluate the prescription. It does not require a patient identifier. Check payloads are processed in memory and are not retained after the result is returned. Audit records store the decision and its reason, not the patient’s clinical detail.

Follow the data

What is sent
Age, sex, renal and hepatic function, pregnancy status, allergies, conditions and the medicine list.
What is stored
Nothing. The request is not written to disk.
For how long
Not retained.
Who can access
The integrating system only.

Compliance posture

Compliance status
RequirementStatus
UK GDPR / DPA 2018Compliant
DCB0129 clinical risk managementClinical safety case maintained
NHS Data Security and Protection ToolkitIn progress
ISO 27001In progress
Cyber Essentials PlusPlanned

We publish status rather than badges. If something is in progress, this page says so.

The security pack goes into more detail.

Hosting, access control, sub-processors and the clinical safety case.

Request the security pack