Two of this month's five free Independent AI Audits are still open — included when you start an AI health check.Check eligibility →
Healthcare & care

Special-category data. A regulator that expects continuous monitoring.

Clinicians and care staff use AI scribes and consumer tools for notes and admin, and the CQC expects continuous monitoring, risk assessment and named accountability for harm.

SECTOR SNAPSHOT Healthcare & care 40%
Healthcare & careGenWA · sector view
40%

of GPs use AI scribes; most started without practice-level support (npj Digital Medicine, 2026)

30%

of health and social care providers use AI, the second lowest of twelve industries (Access, 2025, vendor survey)

CQC

expects continuous monitoring, DPIAs, consent records and named accountability for AI (CQC, 2026)

What your regulator has said

Accountability stays with a named person.

CQC (May 2026): AI “can enhance, but not replace human decision making”; providers need risk assessments, DPIAs and accountability procedures for when AI causes harm. MHRA and NHS England (July 2026): transcription tools are not medical devices, tools that support diagnosis or act on their own are, and NHS organisations remain responsible for deploying them safely.

Regulator statements summarised from the published guidance; see the sources on the Problems page. This supports compliance; it is not legal advice.

Where AI is already used
  • Consultation notes and letters
  • Rota, admission and resource planning
  • Patient and family communications
  • Referral and triage support
What goes wrong
  • Health data in consumer tools without consent
  • Unregulated scribes in clinical use
  • No incident record when an output is wrong
What we do

Audit with a data-flow map for special-category data. Gateway rules that block health data from unapproved tools. Rules naming where AI must not be used. Compliance Mapping to CQC expectations and UK GDPR. Ledger as the incident record.

Built in for this sector

The rules, as controls.

  • CQC AI expectations (May 2026)
  • NHS DSPT and Caldicott
  • MHRA ambient voice guidance (Jul 2026)
  • UK GDPR (special-category data)
The first ninety days
StartSet up with your teamRegister across managed accounts and the systems this sector runs on, set up by our team with your IT lead. Nothing for your people to install.
48 hFirst findingsEvery tool, account and pound. Personal accounts named. Sector rules checked.
Day 10Report and planAudit, evidence pack outline, 90-day plan, and the cost of doing it with us.
Day 90Under controlGateway live, rules enforced, first agent on a job with a named owner, value register running.
insight.genwa.co.uk/overview
Overview · September 2026example data · 310 people
Policy breaches · 30 days143 open · 11 resolved
Data stopped before leaving128items redacted or blocked
Personal AI accounts31 → 4migrating to managed
Spend vs budget£11,240of £14,000 · saved £4,870
Issues detected · needs attention first
Issue Rule Severity Owner Status
Payroll file uploaded to an external AI tool R-15 High HR Director Blocked · reviewed
31 personal AI accounts found in Sales R-02 High Head of Sales Migrating · 27 done
Customer data in a prompt without redaction R-01 High Ops lead Redacted · 0 left
Premium model used for internal drafts · 412 requests R-07 Medium Engineering lead Rerouted
CRM "AI assist" running without a DPIA Policy Medium Head of Sales DPIA in progress
Agent attempted an external email R-12 Low S. Reid Held · approved
Questions we are asked

From this sector.

Is GenWA a medical device?

No. GenWA controls, records and evidences the AI tools you use; it does not make clinical decisions or claims.

Where does our data go?

Nowhere new. Everything runs inside your own cloud account. Nothing routes through GenWA's infrastructure. Sensitive data is removed before a request leaves your environment.

Find out where your AI stands. Then decide.

Under a minute, an upload, or a visit. Something for the board either way.