AI systems for healthcare and care providers
There is a clear line in healthcare between administration and clinical judgement. Everything on the administrative side — the letters, the coding suggestions, the evidence packs, the rota juggling, the endless assembling of things for inspection — is work we can take on. Everything on the clinical side stays with the clinician, and we will say no if you ask us to cross that line.
The administrative load nobody trained for
Clinical staff spend a substantial minority of their working time on administration connected to care rather than care itself. In care settings, the burden is evidence: proving what you did, to whom, and when.
Correspondence that has to be read by someone qualified
Discharge summaries and clinic letters arrive as unstructured prose. Someone clinical reads each one, identifies medication changes, extracts follow-up actions, considers coding, and files it. It is genuinely skilled work, and it is also mostly extraction.
Inbound demand arriving through more channels than staff
Online consultation submissions, e-referrals, patient emails, calls. Practices report meaningful workload increases as digital access expanded — the request volume rose faster than the capacity to triage it.
Inspection evidence scattered across a dozen places
Supervision records, competency assessments, training matrices, reflective learning, incident logs. The evidence exists; assembling it into something an inspector can follow is days of a registered manager's time, repeated at every framework change.
And the assessment frameworks are changing again through 2026Rotas and visit schedules rebuilt by hand
In domiciliary and residential care, one absence cascades. Someone rebuilds the schedule around continuity, competencies, travel time and working-time limits, usually at short notice and usually in a spreadsheet.
What we'd build for a healthcare or care provider
Every one of these is administrative by design. None of them make, suggest or influence a clinical decision.
Correspondence structuring
Reads incoming letters and discharge summaries and extracts the actionable content — medication changes, follow-up actions, candidate codes — into a review queue for a clinician to confirm. It surfaces; it never actions.
Extraction for review. Not decision support.Inbound triage and routing
Classifies incoming requests by type and routes them to the right queue with the relevant record attached. Routing by workflow category — explicitly not by clinical priority.
Routing, never clinical prioritisation.Inspection evidence assembly
Pulls supervision records, training completions, competency sign-offs and incident logs into an inspection-ready pack mapped to the current framework, and flags what's missing before an inspector does.
Rota and visit scheduling support
Proposes schedules that respect continuity of carer, competencies, travel time and working-time rules, and re-proposes quickly when someone calls in sick. A manager approves before anything is published.
Policy and procedure gap analysis
Compares your current policy set against updated standards and guidance, and produces a plain list of what needs revising — instead of a manager reading a framework document cover to cover.
Non-clinical correspondence drafting
Appointment logistics, recall invitations, did-not-attend letters, complaints acknowledgements. High volume, entirely administrative, drafted in your tone for a person to send.
What actually governs AI in a healthcare setting
This sector has more overlapping assurance regimes than any other we work in. Here is the honest map, current as of August 2026 — and where our position sits within it.
- <strong>The medical device line is narrower than most vendors imply.</strong> In July 2026 the MHRA confirmed that ambient voice technology used solely for transcription, summarising a consultation, drafting letters or suggesting codes for clinician review is <em>not</em> a medical device. It becomes one where it supports diagnosis or treatment, derives new clinical information, or acts autonomously without clinician review — and the claims a manufacturer makes count as much as the function.
- <strong>Patient data is special category data.</strong> That means a lawful basis under Article 6 <em>and</em> a separate condition under Article 9, plus a Data Protection Impact Assessment. We produce the DPIA as part of the build rather than leaving you to write it.
- <strong>The Data Security and Protection Toolkit deadline was 30 June 2026.</strong> Note the version matters: the CAF-aligned toolkit applies to NHS trusts, ICBs, ALBs and designated operators of essential services. Suppliers, GP practices, dentists, pharmacy, optometry, social care and local authorities complete the non-CAF version.
- <strong>DTAC was updated in February 2026</strong> and the previous form should not be used from 6 April 2026 onwards. Where a build is destined for NHS procurement, we structure the documentation to answer the current criteria.
- <strong>Clinical risk management standards are under national review.</strong> NHS England's consultation on DCB0129 and DCB0160 opened on 29 June 2026 and closes on 11 September 2026 — partly because the existing standards handle deterministic software well but don't clearly address AI transparency or model drift. If a build engages those standards, we say so up front.
- <strong>CQC's assessment frameworks are changing.</strong> Scoring is being removed in favour of rating at key-question level, with sector-specific frameworks replacing the single assessment framework. Final frameworks are expected in summer 2026, with implementation running to the end of the year.
What we will not build for a healthcare provider
This is the shortest conversation we have with clients in this sector, and the least negotiable.
Anything that diagnoses, triages clinically, or recommends treatment
If the intended purpose touches diagnosis, prevention, monitoring, prediction, prognosis or treatment, it is a regulated medical device and it is not the kind of system we build. We will tell you that on the first call rather than after a scoping fee.
Medication reconciliation or prescribing decisions
A system can extract candidate medication changes from a letter and present them. A clinician reconciles and prescribes. There is no version of this we would automate end to end.
Safeguarding decisions
AI may surface a flag from a record. A named professional makes the judgement and owns it. Safeguarding is precisely the domain where an automated inference creates false reassurance, which is worse than no system at all.
Mental capacity, best interests and deprivation of liberty assessments
These are statutory, personal and non-delegable. Software has no role in reaching the conclusion.
Emotion recognition applied to staff or patients
Emotion inference in a workplace is a prohibited practice under the EU AI Act where it applies, subject only to narrow medical and safety exceptions. We don't build it regardless.
Common questions.
Do AI scribes and ambient voice tools need MHRA approval?
+
Not if they only transcribe and summarise. MHRA guidance published in July 2026 confirms that ambient voice technology intended solely for transcription, summarising a clinical conversation, drafting letters or discharge summaries, or suggesting codes from explicitly mentioned terms for clinician review is not a medical device. It becomes a regulated medical device if it supports diagnosis or treatment, derives new clinical information that wasn't in the conversation, or acts autonomously without clinician review — and the claims the manufacturer makes matter as much as what the software does. If a supplier's marketing says a product “guides diagnosis”, that claim alone can bring it into scope.
Can patient data be used with AI safely?
+
Yes, if the deployment model keeps it inside a boundary you already control. Patient data is special category data under UK GDPR, requiring both an Article 6 lawful basis and an Article 9 condition, plus a Data Protection Impact Assessment. That's entirely achievable — but it usually rules out sending records to a general-purpose public model. Most of our healthcare work runs on-premise or in a private tenancy for exactly that reason, so the data never leaves the environment it already sits in.
Is administrative healthcare AI high-risk under the EU AI Act?
+
Usually not, and it's worth being precise because fear sells in this market. AI intended as a medical device or as a safety component of one is high-risk under Annex I of the EU AI Act, with obligations now applying from 2 August 2028 following Regulation (EU) 2026/1744. General administrative automation — letter drafting, rota support, evidence assembly, invoice processing — does not fall into that category. Transparency obligations under Article 50 can still apply where people interact with an AI system. For UK providers the Act only bites where the output is used in the EU.
Can AI write or update care plans?
+
It can draft and assemble; it cannot decide. A system can pull together the evidence a care plan review needs, draft the administrative sections, and flag where records are inconsistent or out of date. Changing what care a person actually receives is a professional judgement that a named person makes and signs. We build the workflow so that signature is a real review step, not a rubber stamp on something already sent.
Can this run entirely inside our own infrastructure?
+
Yes — and in this sector it's usually the right answer. We deploy on-premise, in your own private cloud tenancy, or fully air-gapped with no outbound connection at all, depending on how sensitive the data is and what your information governance team will accept. Air-gapped builds take longer and cost more, and we'll tell you honestly if your use case doesn't need one.
Start on the administrative side of the line.
Tell us which task is eating clinical or management time. If it turns out to be the wrong side of the line, we'll tell you that instead of selling you something.