Clinical AI Exposure Diagnostic™
Find the AI your clinic is already using. See what evidence exists. Know what needs action.
Your clinicians and staff may already be using ChatGPT, Microsoft Copilot, transcription tools, AI-enabled administration platforms or features built into software the clinic already trusts.
Some of that use may be approved. Some of it may not have been seen by leadership.
The exposure is not simply that AI exists in the clinic. It is being unable to show your DPO, board, insurer, medical defence organisation or an inspector:
- What AI is being used
- Where patient data may be involved
- What controls and supplier evidence exist
- Who owns the decisions
- What action is underway
The Clinical AI Exposure Diagnostic™ gives you that position.
Four working days. Nine deliverables. One board-ready evidence pack.
£5,500 + VAT · Delivered remotely · Founder-delivered
What changes after the Diagnostic
Before the Diagnostic, AI use may be spread across personal accounts, informal trials, browser extensions, approved platforms and tools that have never been recorded in one place.
After the Diagnostic, your clinic has a documented view of:
- The declared and shadow AI tools identified
- The workflows in which they are being used
- Where patient data is confirmed, possible or unclear
- What governance and supplier evidence was available
- What could not be evidenced
- Which issues require DPO, legal, clinical safety, insurer or MDO clarification
- Which actions should be addressed first
- Who should own each action
You do not receive a generic report.
You receive a clinic-specific evidence position and a practical 30-day action plan that your board, DPO, clinical leadership and practice management team can work from.
Is this service for your clinic?
The Diagnostic is designed for UK private healthcare providers that are already using, trialling or considering AI.
This includes:
- Private GP and GP-led multidisciplinary clinics
- Dental practices and dental groups
- Doctor-led dermatology, aesthetics and specialist clinics
- Clinics using ChatGPT, Microsoft Copilot or other general AI assistants
- Clinics using AI for transcription, administration, patient communication or clinical documentation
- Clinics concerned that staff may be using AI outside approved routes
- Clinics preparing for questions from their board, DPO, insurer, MDO or another external stakeholder
It is particularly relevant where AI may touch consultation notes, referral wording, patient correspondence, clinical documentation, images, transcripts or administrative records.
The practical test
If someone asked your clinic tomorrow how AI use is controlled, could you produce a clear, evidenced answer?
The Diagnostic establishes what you can show now, what remains uncertain and what needs action.
Before you commission a Diagnostic
Most clinics do not start with a clean AI programme. They start with tools already in use.
The public Clinical AI Exposure Map sets out the exposure themes a board should understand. The map is illustrative. The Diagnostic creates your clinic's own evidence position.
Related evidence guides: AI Evidence Pack Checklist · DPO Evidence Request Guide
What is in the pack
A nine-part board-ready pack. Every deliverable has a specific purpose. Where a part does not apply to your clinic, it is recorded as not applicable with the reason stated, so the pack remains complete as an evidence record.
1. AI Tool and Use Case Inventory
A single record of the AI tools and use cases identified through leadership input, staff reporting and the evidence review.
It shows who is using each tool, what it is being used for, whether patient data may be involved, its approval position, the evidence available and the next action.
2. Board Findings Report
A plain-English account of what was found, why it matters and which decisions need leadership attention.
Written for board members, partners and clinic leaders who do not work in AI governance or data protection every day.
3. RAG Exposure Map
A one-page board view across thirteen governance dimensions.
It covers areas including governance ownership, shadow AI discovery, patient-data exposure, DPIA readiness, supplier evidence, human oversight, patient transparency, staff guidance, incident arrangements and external readiness.
Red, Amber, Green and TBC ratings show the evidence position and priority for action. They are not legal findings or regulatory outcomes.
4. Ambient Scribe Assessment Sheet
For a Standard Diagnostic, this is recorded as not applicable because ambient scribes and consultation transcription tools require a separate assessment route.
Where an ambient scribe, AI transcription or consultation note-generation tool is in use, in trial or planned, the clinic is routed to the six-working-day Ambient Scribe Diagnostic.
A pack that records what was considered and ruled out is stronger evidence than one that leaves it unmentioned. That is why the not-applicable position is stated rather than omitted.
5. DPIA Readiness and Patient Data Exposure Note
A structured view of where patient data may be involved, what privacy evidence exists and which matters require DPO review.
The note identifies whether DPIA screening is needed or whether a DPIA is likely required or strongly indicated. The final determination remains with your DPO.
6. Vendor Data Position and Evidence Tracker
A supplier-by-supplier view of the evidence your clinic holds.
This may include contractual and data-processing material, hosting and transfer information, retention and deletion positions, sub-processors, security evidence and statements about model training or data reuse.
ELSA AI assesses the evidence available to the clinic. It does not rank, endorse or criticise suppliers.
7. MDO, PMI and Insurer Disclosure Readiness Note
A clear view of what your clinic could currently evidence if an insurer, private medical insurer, medical defence organisation or adviser asked about its AI use.
It separates:
- What can be shown now
- What evidence is missing
- What requires clarification with the relevant organisation or adviser
ELSA AI does not determine coverage, underwriting, disclosure obligations or indemnity support.
8. 30-Day Priority Action Plan
A prioritised plan with owners, target dates, dependencies and the evidence needed to close each action.
Red and Amber findings are converted into practical actions. Nothing is left as a vague recommendation.
9. Source and Guidance Mapping Appendix
A traceable record showing how material findings and recommendations relate to the clinic's evidence and to relevant authoritative guidance.
The status of each source is stated. Guidance and recognised frameworks are not presented as universal legal mandates.
What the Standard Diagnostic covers
The Standard Diagnostic is designed for a defined clinic profile so that the work can be completed properly within four working days.
The standard fee covers:
- One clinic site
- Up to 60 staff
- Up to five AI tools or use cases
- Up to five suppliers requiring evidence review
- Up to 25 evidence documents
- One clinical specialty: GP, dental, dermatology or a comparable single regulated care area. Mixed-specialty and multidisciplinary clinics are outside the standard scope.
- No NHS contract or NHS data-sharing arrangement in scope
- No ambient scribe, AI transcription or consultation note-generation tool in use, in trial or planned
The fixed scope, fee and delivery window are confirmed in writing before the delivery clock starts.
Larger or more complex scopes
Six to eight AI tools are assessed at an additional £500 + VAT per tool. Whether that fits the four-working-day route depends on the other scope conditions, and is confirmed in writing at intake, before the delivery clock starts.
Nine or more tools, multiple sites, larger teams, mixed clinical specialties, larger evidence sets or NHS arrangements are scoped separately.
You see the confirmed position before work starts. Once the delivery clock begins, the agreed fee does not change.
Using or planning an ambient scribe?
Ambient scribes and consultation transcription tools require a different level of assessment.
The review needs to consider matters including:
- Consultation audio and transcript handling
- Retention and deletion
- Supplier clinical safety evidence
- Patient information and objection routes
- Clinician review before information enters the patient record
- DPIA readiness
- Model-training and data-reuse statements
- Relevant clinical safety responsibilities
These issues do not fit responsibly inside the four-day Standard Diagnostic.
The Clinical AI Exposure Diagnostic™ with Ambient Scribe Assessment is a separate six-working-day engagement at £8,500 + VAT.
A separate six-working-day engagement. The ambient scribe assessment runs through the full evidence pack, not as a standalone addition.
See what is actually in use. Know what you can prove. Act on what is missing.
When your board, DPO, insurer or CQC inspector asks how AI use is governed, the answer is either a documented position or an improvised one. The Diagnostic gives you the documented position before the question arrives.
Every engagement is delivered personally by Faisal Ali, AAISM, CISM, CRISC. No junior handoff. No automated output. No template with your logo on it.
We combine leadership intake, a confidential, role-level and non-disciplinary staff survey, clinic-held evidence and structured analysis to show:
What AI is in use
A controlled inventory of declared and staff-reported tools, embedded AI features and use cases, including uses leadership may not have seen.
What your clinic can evidence
For each material use case, we record what evidence was available, what was partial and what could not be shown. This includes patient-data exposure, supplier evidence, DPIA readiness, human review and external disclosure readiness.
What happens next
We convert every Red and Amber finding into an owned action with a target date and the evidence needed to close it.
Where another accountable person or specialist must make a decision, we identify:
- who needs to consider it
- the question they need to answer
- what evidence ELSA AI has prepared
- what would demonstrate that the action has been closed
See the assessment structure
The Clinical AI Exposure Map shows the governance questions commonly created by AI use in a private clinic.
It is an illustrative guide, not an assessment of your clinic.
Your Diagnostic applies this structure to your actual tools, workflows and clinic-held evidence. It shows where evidence is available, where uncertainty remains and which actions require priority attention.
Explore the Clinical AI Exposure Map
After the readout
You can brief your board in plain English, send your DPO the DPIA readiness note directly, send focused evidence questions to each supplier, act on immediate staff guidance priorities and route every remaining decision to the correct accountable person with the question they need to answer.
By the end of the readout, your clinic has a documented starting position it owns. You know what is in use, what can be evidenced and what needs attention first.
You are not left with a generic report or an unstructured list of concerns.
A standalone assessment
The Diagnostic is a complete standalone engagement.
You may implement the action plan internally, use your existing advisers, appoint independent specialists or ask ELSA AI to scope further support. Nothing in the pack requires you to buy another ELSA AI service.
No surprise repricing
Your scope, delivery period and fixed fee are confirmed in writing after intake and before delivery starts.
If additional AI use is identified after the clock starts, every use identified during the assessment is recorded. The fee does not change. The Board Findings Report states which items received full-depth review and which were registered for later assessment.
£5,500 plus VAT. Four working days from the start of delivery. Remote. Subject to the published scope envelope.
Delivery starts after the engagement paperwork is signed, payment is confirmed, the staff survey window has closed, available evidence has been submitted or formally confirmed absent, and we have issued your written scope and fee confirmation.
What happens if we find AI you did not know about?
We often identify tools or use cases that were not declared at the start.
That is not a failure of the clinic or of the engagement. It is one of the reasons the Diagnostic exists.
Every identified tool is recorded in the Inventory with:
- Its use case
- A patient-data indicator
- Its approval position
- An advisory RAG rating
- An owner where known
- A next action
Where the number of tools discovered is larger than the agreed full-depth scope, the most significant patient-data exposures are assessed first.
The remaining tools are still recorded and clearly marked for further review. Nothing is quietly excluded to make the scope appear smaller.
The Board Findings Report states what was assessed in full and what requires follow-on review.
The agreed delivery date and fee do not change because additional shadow AI is found after the work has started.
The Staff AI Use Survey
Leadership usually knows which tools the clinic has purchased. It may not see personal accounts, browser extensions, free transcription tools, informal trials or AI features added inside software approved for another purpose.
The survey is confidential, role-level and non-disciplinary. Responses are never attributed to named individuals, and no staff-identifying information appears in the deliverables. A written non-disciplinary commitment from clinic leadership is required before the survey runs.
The purpose is not to identify individual staff. It is to establish the clinic's actual AI footprint, and whether staff have a clear approved route for using AI safely.
How we deliver
Delivered remotely
Every Diagnostic is delivered remotely. The work assesses your evidence, staff-reported AI use, described workflows and supplier documentation. It is not an onsite inspection and does not claim to verify operational practice through observation.
Remote delivery also supports the independence of the Staff AI Use Survey.
Nothing in the nine deliverables requires ELSA AI to be present in the clinic.
Founder-delivered
Every Diagnostic is delivered personally by Faisal Ali, AAISM, CISM, CRISC, Founder and Principal Consultant, ELSA AI.
The assessment, the nine deliverables and the readout are his work. There is no junior delivery team, offshore handover or reseller involvement in delivery.
Faisal brings more than two decades in cybersecurity, information risk and governance across healthcare, financial services and national infrastructure, and holds AAISM, CISM, CRISC and CISSP.
The experience and credentials support the governance assessment. They do not imply legal advice, statutory audit opinion, regulatory approval or certification.
What the Diagnostic is not
The Clinical AI Exposure Diagnostic™ is an advisory governance and evidence-position assessment.
It does not provide:
- Legal advice or legal sign-off
- CQC, ICO or NHS approval
- A completed or signed DPIA
- Clinical safety case sign-off
- DCB0160 authorship
- Appointment as your Clinical Safety Officer
- Medical device or SaMD classification
- Insurer coverage or underwriting decisions
- MDO indemnity decisions
- Penetration testing or security testing
- Vendor certification or endorsement
- Certification or any guarantee of compliance
RAG ratings identify evidence positions and priorities for action.
A Red rating does not mean that a breach, illegality, regulatory failure or loss of indemnity support has been confirmed.
A Green rating does not provide a clean bill of health.
Final legal, data protection, clinical safety, regulatory, insurer and indemnity decisions remain with your DPO, legal counsel, Clinical Safety Officer, accountable officers, insurers, medical defence organisation and clinicians as applicable.
ELSA AI says what it found, what it means and what to do about it. You decide.
Next engagements
Clinical AI Safe Usage Launchpad™ converts findings into lasting policy, registers, transparency wording and briefing packs.
AI Exposure Sentinel™ keeps your evidence refreshed as tooling, insurer questions or regulatory expectation shifts.
Advisory boundary
ELSA AI provides advisory governance support only. It does not provide: legal advice or legal sign-off; CQC, ICO or NHS approval; insurer coverage or underwriting decisions; MDO indemnity decisions; a completed or signed DPIA; clinical safety case sign-off, DCB0160 authorship or appointment as Clinical Safety Officer; medical device or SaMD classification; certification or any guarantee of compliance. Final legal, data protection, clinical safety, regulatory, insurer and indemnity decisions remain with the client's DPO, legal counsel, Clinical Safety Officer, accountable officers and clinicians.
Faisal Ali, AAISM, CISM, CRISC
The next step
The 20-minute discovery call establishes:
- Whether the Diagnostic is the right service for your clinic
- The likely scope
- Whether the Standard or Ambient Scribe route applies
- The likely fee
- What would be needed to begin
It is a fit-and-scope conversation. It does not include document review or governance advice.
The discovery call is a scoping conversation. If the Diagnostic is the right fit, Faisal delivers the engagement.