TRUST
What happens to the data, in plain terms.
Medication safety software sits close to patient data. This page sets out what PharmAlert sends, stores, retains and logs — and where we are with each compliance requirement.
Data handling
A check sends the clinical information needed to evaluate the prescription. It does not require a patient identifier. Check payloads are processed in memory and are not retained after the result is returned. Audit records store the decision and its reason, not the patient’s clinical detail.
Follow the data
- What is sent
- Age, sex, renal and hepatic function, pregnancy status, allergies, conditions and the medicine list.
- What is stored
- Nothing. The request is not written to disk.
- For how long
- Not retained.
- Who can access
- The integrating system only.
Compliance posture
| Requirement | Status |
|---|---|
| UK GDPR / DPA 2018 | Compliant |
| DCB0129 clinical risk management | Clinical safety case maintained |
| NHS Data Security and Protection Toolkit | In progress |
| ISO 27001 | In progress |
| Cyber Essentials Plus | Planned |
We publish status rather than badges. If something is in progress, this page says so.
The security pack goes into more detail.
Hosting, access control, sub-processors and the clinical safety case.
Request the security pack