At Heidi, we actively collaborate with regulators around the world including NHS England to ensure clinicians are using Heidi safely. Read on to see how we ensure all UK clinicians meet the latest guidance from NHS England.
✅ DTAC: We’ve completed a full internal DTAC assessment aligned to NHS expectations, with supporting evidence available across the five domains. This can be provided again on request.
✅ DSPT: Heidi has a current and fully compliant DSPT submission listed on the NHS portal, addressing all relevant data protection and cyber security obligations.
✅ Security Certifications: Heidi holds ISO 27001, SOC 2 Type II, and ISO 42001 certifications, all globally recognised standards for cybersecurity, information security, data protection, and AI management systems. These certifications are independently audited multiple times per year. We also hold Cyber Essentials certification and are currently undergoing an audit for Cyber Essentials Plus to meet the newly updated requirement in the latest guidance.
✅ Penetration Testing: We conduct annual penetration testing using a CREST-accredited security firm, covering infrastructure, APIs, and application-level vulnerabilities.
✅ DPIA: We’ve completed a comprehensive DPIA for NHS deployments, including lawful basis, risk mitigation, and data flow transparency. Versions have already been used to support ICB governance approvals.