Trust & Compliance

    We operate inside your
    patient relationships.

    That comes with responsibility. Here's exactly how we handle it. No vague claims, no fine print buried in a footer.

    Request our DPASee our frameworks

    What we commit to

    Three things that are true
    of every Coherent engagement.

    DPA on every engagement

    We enter into a Data Processing Agreement with your clinic before we access a single patient record. No exceptions.

    Reviewed annually

    Our Privacy Notice and DPA are reviewed and updated every year to reflect regulatory changes and how our service evolves.

    Health data handled appropriately

    We use industry standard security as advised by our NCSC approved CHECK accredited independent security advisers, and our trained staff operate within environments that protect and audit all data access.

    Regulatory frameworks

    Frameworks we operate under

    We don't collect certifications for the sake of a badge wall. We operate in compliance with the frameworks that govern the clinics we work with, and we can show our working.

    🇬🇧UK GDPRData Protection Act 2018
    🇺🇸HIPAAHealth Insurance Portability
    🇨🇦PIPEDAPersonal Information Protection
    🇨🇦PHIPAPersonal Health Information Protection

    Security practices

    How we protect patient data

    Encryption in transit and at rest

    All patient data is encrypted using TLS 1.2+ in transit. Data at rest is encrypted on UK/EEA-based infrastructure.

    Minimum access principle

    Role-based access controls ensure team members access only the data required for their specific function.

    Staff vetting

    Every Coherent team member handling patient data undergoes background checks before onboarding.

    Audit logging

    All data access events are logged and available for review. Full audit trail from first access to deletion.

    Breach notification

    Documented incident response procedure with defined escalation paths. Clinic partners notified within regulatory timeframes.

    Data deletion on exit

    On termination of an engagement, we remove your data from our systems within our publicly agreed timeframes.

    Questions

    Your questions, answered

    Questions before you commit?

    Talk to us directly. We'll share our DPA, Privacy Notice, and answer any specific questions about how we handle data.

    Book a callRequest our DPA