Privacy and security
Security and Data Protection
Patient data protection is fundamental to how Neravise is designed. Privacy, controlled access, clinical accountability and auditability shape the product architecture.
Patient Data First
Sensitive patient and clinical information is treated as requiring heightened protection throughout referral, assessment, review and reporting workflows.
Authentication and Access
Email OTP authentication and role-based permissions are designed to restrict practitioner, QA and admin actions to authorised workspaces and responsibilities.
Organisation Isolation
Organisation-aware access rules are designed to separate each organisation’s configuration and clinical records according to the configured security model.
Auditability
Important authentication, clinical workflow, review, playback and export actions can be recorded as audit events without placing clinical narrative in the audit record.
Clinical Oversight
Clinicians retain responsibility for reviewing and approving clinical information. AI-assisted content, where authorised, remains a draft and cannot replace professional judgement.
Private Recordings
Recording workflows are designed around consent, private storage, referral-level access checks and short-lived playback links.
UK Data Protection
Neravise Ltd is registered with the Information Commissioner’s Office (ICO). Neravise is designed with UK data-protection obligations in mind. Registration does not mean that the ICO has approved, certified or endorsed the product.
US Healthcare and HIPAA
Neravise is being designed to support secure neurodevelopmental assessment workflows for US healthcare organisations, with HIPAA-aligned privacy and security principles incorporated into the platform architecture.
Software features alone do not establish a healthcare organisation’s compliance. Before real US Protected Health Information is processed, relevant Business Associate Agreements, eligible vendor services, security configuration, organisational policies, risk analysis, legal review and customer responsibilities must be verified.
AI and Patient Data
Clinical information must not be sent to an AI or transcription provider merely because an integration exists. Production use requires documented organisational approval, appropriate consent, controlled access, data-processing and contractual arrangements, retention settings, eligible service configuration and clinician oversight. Clinical AI and transcription should remain disabled until those prerequisites are evidenced.
Shared Responsibility
Neravise provides workflow and security controls, while each customer remains responsible for its users, policies, lawful processing, configuration, training and professional practice. See the Privacy Notice or contact info@neravise.com without including patient-identifiable information.