Security & Compliance
Protecting patient information and building lasting partnerships with NHS organisations sits at the heart of everything we do.
For clinicians and commissioners considering MedGenix Tech for their GP practice, PCN or ICB, this page details our data handling practices and medical device registration. Additional documentation is available upon request.
Trusted by the NHS
Deep EHR integrations and partnerships



Our Accreditations & Assurances
Registered with the MHRA
Class I Medical Device
MedPrompt is registered with the MHRA as a Class I medical device. The regulated modules include MedPrompt Documents and MedPrompt Scribe, which support clinical workflows in GP practices.
Optum Partner Assurance
Deep integration with Optum's EMIS Web GP system for seamless data exchange.
NHS DSPT
NHS Digital Data Security and Protection Toolkit (DSPT) assured, exceeding standards for NHS suppliers.
Cyber Essentials
Certified under the UK Government's Cyber Essentials scheme, with Cyber Essentials Plus certification.
DPIA
Data Protection Impact Assessment completed, ensuring compliance with GDPR requirements and data protection best practices.
DCB0129 Compliant
Full Clinical Safety Case and Hazard Log maintained by our Clinical Safety Officer (CSO), in line with NHS requirements for software suppliers.
GDPR Compliant
Fully GDPR compliant with clear Data Processing Agreements (DPAs) and full control resting with practices at all times.
How We Protect Your Data
We never sell your data
We never have and we never will.
Encrypted data storage
We encrypt data in extremely secure data centres.
Robust identity controls
Only verified NHS professionals can access your data.
Secure partnerships
We only partner with safe and secure partners who meet our high security standards.
Staff training
We train all staff in data security from week one onwards.
NHS code of conduct
We follow the NHS code of conduct for data driven technology.
Frequently Asked Questions
MedGenix Tech has a commitment to every patient whose data we store to keep it safe and secure. To find out more about how we use your data, take a look at the frequently asked questions below.
Filter by category (3 selected):
MedPrompt is registered with the MHRA as a Class I medical device. It is fully compliant with the DCB0129 standard (UK digital clinical safety and risk management) and is aligned with the NHS Digital Technology Assessment Criteria (DTAC) framework. We also adhere to the NHS Data Security and Protection Toolkit (DSPT) (ODS code D1Z9T). Our clinical safety team is constantly monitoring the latest developments in regulation.
Yes. MedPrompt is registered with the MHRA as a Class I medical device. The regulated functions are the Documents and Scribe modules, which help qualified users in GP practices with clinical correspondence and consultations.
We have partnered with AbedGraham, a leading clinical safety consultancy, to ensure MedPrompt is clinically safe and compliant, including the clinical safety case that supports our Class I medical device registration.
We employ enterprise-grade security including TLS 1.2+, end-to-end encryption for data in transit and at rest, and strict role-based access controls (RBAC). Authentication is secured through multi-factor authentication (MFA) and NHS Care Identity integration. Our servers are hosted in the London Azure Data Centre with automated backup and disaster recovery procedures. We conduct annual penetration testing (with additional testing for major releases) and recently passed a CREST-certified penetration test. We are compliant with Cyber Essentials Plus and have completed a comprehensive Data Protection Impact Assessment. All data processing follows GDPR and NHS Digital standards.
Taking a similar approach to clinical safety, we partnered with Evalian - a data protection consultancy. They provide expert advice to ensure MedPrompt is compliant with GDPR and NHS Digital standards.
MedPrompt processes data for patients registered with your practice, including children and vulnerable individuals where applicable. This includes patient identifiers (name, date of birth, NHS number), demographic information, health and medical information contained in patient documents and consultation transcripts, and metadata generated during processing. All health data is processed under Article 9(2)(h) UK GDPR as special category data, with appropriate safeguards in place.
We carefully vet all third-party vendors and partners to ensure they meet our strict security and compliance requirements. This includes verifying their certifications (such as ISO 27001, Cyber Essentials), reviewing their data processing agreements, conducting regular security assessments, and ensuring they comply with GDPR and NHS Digital standards. We only work with partners who can demonstrate equivalent levels of data protection and security controls.
Find out more about security and privacy
If you have any questions about our security and compliance measures, please feel free to contact us directly and we'll do our best to answer your questions. Email us at info@medgenixtech.co.uk