Medflow is designed to meet the highest standards of data governance, clinical safety, and regulatory compliance in UK healthcare. We believe trust is earned through transparency.
Multiple layers of protection for your organisation's data.
AES-256 encryption for stored data, TLS 1.3 for all communications.
Customer platform data is stored in AWS eu-west-2 (London).
30-role RBAC system across 9 tiers, enforced at API and UI level.
Immutable audit logs for every data mutation. Full traceability for CQC inspections.
24/7 infrastructure monitoring via CloudWatch with automated incident alerting.
Automated dependency scanning, code analysis, and infrastructure checks on every deployment.
Our compliance pathway covers the key standards required for NHS and healthcare IT systems.
Control
Implemented / Ongoing
Personal data is processed within Medflow's UK GDPR and data-protection governance framework.
Control
Implemented
Customer platform data is hosted within approved UK cloud infrastructure.
Assessment
Standards Met
Medflow has published its Data Security and Protection Toolkit assessment with a Standards Met status.
Verify this statusCertification
In Progress
Medflow is currently preparing for Cyber Essentials Plus certification as part of our ongoing cybersecurity assurance programme.
Certification
Planned
Our information-security controls and governance are being developed with ISO 27001 principles in mind. Formal certification is planned as Medflow progresses through its assurance roadmap.
Assessment
In Progress
Medflow is progressing its assessment against the NHS Digital Technology Assessment Criteria as part of our wider NHS assurance pathway.
Process
In Progress
Clinical risk management is embedded within our product development lifecycle in line with DCB0129, supported by our Clinical Safety Officer.
Customer support
DCB0160 is the deployer's obligation, not ours. We supply the hazard log and safety documentation customers need for their own assessment.
Dedicated officers and formal governance structures ensuring safety and accountability.
Appointed CSO responsible for maintaining Clinical Safety Case Report, Hazard Log, and safety governance.
Designated DPO overseeing GDPR compliance, DPIAs, and data subject rights.
Comprehensive security policies covering access control, incident response, and business continuity.
Our team is happy to discuss our security practices, compliance pathway, and governance framework in detail.