Confidentiality
Task-, role-, relationship- and application-specific access rather than indiscriminate record disclosure.
CareStrand is designed around minimum-necessary access, source provenance, explicit permissions, meaningful human control and auditable workflow evidence.

The safeguards below are product architecture and demonstration controls. Formal local information governance, cyber-security, clinical-safety, accessibility and regulatory evidence must be completed before any production use.
Task-, role-, relationship- and application-specific access rather than indiscriminate record disclosure.
Defined intended purpose, hazard controls, source authority and human approval for clinically significant action.
Organisation-controlled gateway, managed credentials, least privilege, monitoring and revocable application access.
Clear degraded mode, source-system independence, retry and reconciliation rather than silent partial failure.
CareStrand’s policy and Context Compiler filter the patient information before any approved application or model provider receives it.
Role, purpose, care relationship, organisation and application determine whether access is permitted, limited, denied or emergency.
Only approved information groups and fields are assembled, with sensitivity rules and source provenance retained.
The result is cited, reviewed and converted into a draft, task or approved action according to the permission tier.
CareStrand separates platform assurance from application assurance and local deployment assurance.
A model or permission change invalidates the previous approval evidence and requires review.
Each capability is separately approved and can be suspended or revoked.
Autonomous clinical action, unrestricted ordering, generic prescribing and silent alteration of the authoritative record.
The intended default is no. Any secondary use for model development or research would need a separately defined purpose, governance, data minimisation and approval.
The clinician and clinical service retain responsibility for care, while CareStrand and connected suppliers remain responsible for safe design, reliable context, permissions, provenance, monitoring and their contractual obligations.
Not where identifiable clinical information is involved. Applications must be approved by the organisation and receive only the permissions in their current App Passport.
CareStrand should enter a clear degraded mode: already loaded information remains visible where safe, new remote actions pause, and source systems remain independently accessible.
We want to work with clinical, digital, information-governance, cyber and patient representatives to define a bounded demonstrator and evidence plan.
CareStrand is currently a synthetic prototype for demonstration and product development. It is not connected to production clinical systems and must not be used with identifiable patient information or for clinical decision-making.