Compliance & trust

Built for the standards healthcare rightly demands.

This page is maintained by HandoverMed Ltd to answer the questions procurement, IT and information-governance teams ask first. We're an early-stage company: what follows describes how we design and operate, not certifications we hold today.

Our commitments

How we think about security and data

Brand-level assurance, described plainly. Technical detail is shared under NDA during procurement conversations.

Data protection by design

We aim to collect the minimum data needed, keep purposes clearly defined, and make retention and deletion deliberate choices rather than defaults. Privacy considerations are part of design review, not a later stage.

Secure hosting

Our intent is to host on reputable, region-appropriate infrastructure with data residency aligned to the customer's jurisdiction, environment separation, and hardened, monitored deployments.

Encryption & access control

Encryption in transit and at rest is our baseline. Access follows least-privilege principles with role-based controls, strong authentication and clear separation between production and non-production data.

Audit & accountability

We're building a culture of traceability: meaningful audit logging, documented change control, named ownership for security and clinical safety, and honest incident handling.

Regional alignment

Standards we design towards

HandoverMed is being built for healthcare across the UK, Europe and the US. We describe alignment honestly — designed with these standards in mind, and working towards formal assurance as we mature.

United Kingdom / NHS

  • Designed with the NHS Data Security and Protection Toolkit (DSPT) in mind
  • Working towards alignment with the Digital Technology Assessment Criteria (DTAC)
  • Clinical risk management designed around DCB0129 and DCB0160
  • Working towards Cyber Essentials Plus
  • Built with UK GDPR and the Data Protection Act 2018 in mind

Europe

  • Built with EU GDPR principles in mind — lawful basis, data minimisation, purpose limitation
  • Designed to support data residency choices appropriate to European customers
  • Sub-processor transparency as part of our standard approach

United States

  • Designed with HIPAA alignment in mind as the company expands
  • Administrative, technical and physical safeguards considered in architecture decisions
  • Business Associate arrangements to be addressed as US engagement begins

Documentation on request

Our compliance documentation set is growing alongside the company. Assurance materials — including our data protection position, security overview, clinical safety approach and sub-processor list — are available on request and will expand as formal assessments are completed. If your organisation has a specific assurance questionnaire, send it over and we'll answer it honestly, including where we're not there yet.

Security or data protection queries: privacy@handovermed.com

Note: nothing on this page constitutes certification or independent verification. Where we say "designed with" or "working towards", we mean exactly that.

Procurement & IG

Bring us your assurance questions

We'd rather have the difficult compliance conversation early than late. Book a demo and bring your IG lead.