Home Trust
We ask you to trust us. Here is the basis.
A company selling verification has to be verifiable itself. This page states how data is handled, how reviewers are credentialed, where we sit in the regulatory picture, and — in plain words — what we do not yet claim.
Data handling
The best protection is not holding it.
Reviewers need clinical context to judge an output. They almost never need to know who the patient is. Our default posture is to minimise identifiable data at the boundary rather than to secure it after collection.
Minimise at source
Integrations are designed so direct identifiers are tokenised or removed before submission. Where a field is not needed for clinical judgement, the correct amount to collect is none.
Least privilege
A reviewer sees only the case assigned to them, only while it is assigned, and only the fields that case requires. Access is logged and attributable.
Bounded retention
Clinical content is retained for the period set in your agreement and then deleted. The verification record can outlive the content it refers to — that is the point of a record.
| Area | Position |
|---|---|
| Business associate agreement | Available for engagements where PHI is processed |
| Encryption | In transit and at rest |
| Access control | Role-based, least privilege, logged and attributable |
| Reviewer confidentiality | Contractual obligations and confidentiality terms for every reviewer |
| Model training on your data | Not used to train models for other customers |
| Sub-processors | Disclosed on request, with notice of material change |
| Data residency | Discussed per engagement — tell us your requirement |
Reviewer integrity
The reviewers are the product.
Nothing else on this page matters if the clinician reading your output is not who they say they are, or is not competent in the area they are judging.
Credentials verified at source
Licence status and board certification are checked against primary sources before a reviewer is activated, and re-verified on a schedule. Expired or restricted licences deactivate the reviewer automatically.
Conflicts declared and enforced
Reviewers declare financial and professional relationships. Routing excludes reviewers with a conflict relevant to the case, the customer or the product under review.
Quality is measured, not assumed
Inter-reviewer agreement is tracked continuously and reviewers periodically receive cases with established answers. Persistent drift results in recalibration or removal.
Attribution, always
Every verdict carries the identity and credentials of the clinician who reached it. There is no anonymous sign-off, because an unattributable judgement is not accountability.
Regulatory context
Where this sits in the rules.
Healthcare AI regulation is moving. The direction of travel is consistent: transparency about how outputs are produced, meaningful human oversight, and evidence that a system performs as claimed.
What the direction of travel demands
Across jurisdictions, the same three obligations recur — and each is a documentation problem before it is a technology problem.
- Transparency — the basis on which an output was produced can be described
- Human oversight — a qualified person can review and override
- Evidence — performance claims are supported by something other than assertion
Verification records are built to be usable as that evidence: attributable, timestamped, source-linked and exportable.
What we are, precisely
Harmony Verify is a clinical quality assurance and verification service provided to the organisations that build healthcare AI. We do not generate clinical recommendations, we do not practise medicine, and we do not establish a clinician–patient relationship.
Whether your product is a regulated medical device, and what obligations follow, depends on its intended use and your markets. That determination is yours. Our records are designed to support the evidence you will need for it — they do not replace your regulatory strategy, your quality management system or your counsel.
Claims discipline
What we do not claim.
Healthcare software marketing is full of certifications implied rather than held and accuracy figures with no stated denominator. We would rather be the company that states the boundary plainly.
We name certifications only once held
Where a formal certification or attestation is in progress rather than complete, we say so and give the stage it is at. Ask us directly and you will get the current status in writing, not a badge.
We do not publish accuracy figures we cannot source
A detection rate without a defined dataset, task and denominator is decoration. Any performance figure we give you will arrive with the conditions that produced it.
Verification is not a guarantee
Expert review substantially reduces the risk of an incorrect output reaching a clinician. It does not reduce it to zero, and any vendor implying otherwise is selling something that does not exist.
Clinical responsibility stays with the clinician
The treating clinician remains responsible for clinical decisions. Harmony Verify improves the evidence available to them; it does not assume their duty of care.
Running diligence on us? Ask for the security questionnaire, sub-processor list and current certification status — request them here.
When something goes wrong
Failure handling, stated in advance.
A reviewer approved an output that was wrong
The record identifies who reviewed it, against which rubric and on what evidence — so the failure can be located rather than inferred. We notify you, re-review the case, examine the reviewer's recent decisions for a pattern, and record the outcome. Systemic issues result in recalibration, routing changes or removal from the network.
A security incident affects data you sent us
Notification obligations and timelines are set out in your agreement and business associate agreement, and we will meet them. Practically: we tell you what happened, what data was involved, what we have done and what we are changing — early, in plain language, and without waiting for a complete picture before making contact.
You disagree with a verification result
Dispute it. Contested records go to independent re-review, and if the original verdict was wrong the record is amended with both the original and the correction preserved. Records are not silently rewritten — an audit trail that can be edited without trace is not an audit trail.
You want your data deleted
Request it and we will delete clinical content within the timeframe in your agreement and confirm in writing. Verification records may be retained in a form stripped of clinical content where we are contractually or legally required to keep evidence that a review occurred.
Diligence
Ask us the hard questions.
Security review, data protection assessment, clinical governance questionnaire — send it over. We would rather answer early than at the end of a procurement cycle.