A patient asks the receptionist whether the consultation was recorded. Or whether the letter was written by ChatGPT. Or where the transcript went afterwards. The clinician gives one answer. The practice manager gives another. Nobody can point to a document.
That is not a public relations problem. It is a governance evidence gap. The same gap becomes material when a DPO requests evidence on AI processing of patient data, when an insurer or MDO renewal questionnaire asks which AI tools are in use, or when a CQC inspector asks how AI use is controlled and who approved it.
What you are buying: for a fixed £5,500 + VAT, in four working days, a board-ready evidence pack that answers one question with evidence: what AI is in use across your clinic, what patient data it touches, and how that use is governed. The pack is what you put in front of your DPO, a CQC inspector, your MDO, your insurer or your board when the question lands.
Evidence guides: AI Evidence Pack Checklist for Private Clinics · Shadow AI in Clinics
Pages tailored to your setting: Private GP and GP-Led Clinics · Dental Practices and Groups · Specialist Clinics · Clinics Using Ambient Scribes
Why UK private clinics need a documented governance position
1. CQC inspection applies across private healthcare
Private clinics providing regulated activities are required to register with and be inspected by CQC under the Health and Social Care Act 2008. CQC's key questions include whether a service is safe and well-led. Where AI affects clinical records, care workflows, data processing or human oversight of clinical output, the clinic needs a documented position it can show an inspector.
2. UK GDPR creates specific obligations where AI processes health data
Consultation audio, clinical notes, patient images, correspondence and identifiers are all special category health data under UK GDPR. Where AI tools process any of them, a DPIA is likely required or strongly indicated. That determination is the clinic's DPO's to make. In many private clinics, DPIA screening has not started before AI tools are already in live use.
3. Professional accountability for AI-generated output rests with the clinician
The consistent theme across medical defence organisation guidance is that the clinician remains responsible for the accuracy of the clinical record, including where the first draft was AI-generated, and that AI use outside organisational approval and governance may carry personal risk. The current position should be confirmed with your own MDO or indemnity organisation.
4. Shadow AI is present in most clinics before governance is
The premise of the Diagnostic is that leadership does not see the full picture. Clinicians and support staff adopt tools that are useful, not tools that have been approved. An ambient scribe goes live before the DPIA is screened. ChatGPT is used to draft referral letters on a personal device. A marketing platform writes recall messages and nobody has checked whether it has access to clinical data. The governance gap is not a failure of intent. It is a gap between what is in use and what is documented.
What a clinic needs to be able to show
Six things answer most of what a DPO, inspector, MDO or insurer will ask.
An AI tool and use case inventory.
Declared and shadow AI use across clinical, admin and marketing workflows. Not a policy. A list, with names, purposes and patient-data indicators on it.
A patient-data exposure position.
Which tools touch consultation audio, notes, images, correspondence or identifiers, and which do not.
A DPIA readiness position.
Whether screening has been done, whether a DPIA is in progress or complete, and what determination or review remains with the clinic's DPO.
Vendor evidence.
Data processing agreement, hosting and residency, retention and deletion, sub-processors, model-training position. Held centrally, not scattered across individual inboxes.
A human-review workflow.
Written down, owned by a named person: who reads the AI-generated note before it reaches the clinical record, and what the process is when it is wrong.
Patient transparency wording.
The same explanation from every clinician, at every site, on every day, with a clear route for patients to decline or raise a concern.
The typical governance position we find
Across private GP clinics, dental practices and specialist clinics, the recurring pattern is an evidence gap rather than a single failure.
Common findings include:
- AI tools are in use, but there is no single inventory covering which tools, which users, which workflows or what patient data is involved.
- Ambient scribes or transcription tools are live before DPIA screening has been completed.
- Free-tier accounts or personal devices are in use with no patient-data boundary in place.
- Vendor data processing agreements are absent, incomplete or held in a clinician's inbox rather than centrally.
- Marketing automation reaches into patient contact data with no documented boundary between marketing and clinical records.
- Staff have not received a written position on which AI tools are approved, conditional or prohibited.
- Incident reporting covers clinical events but not AI-specific scenarios: hallucinated clinical content, transcription errors, wrong-patient attribution or accidental data exposure.
- There is no board or partnership-level view of AI risk.
None of this is a legal conclusion. It means there is an evidence gap. That gap becomes urgent when a DPO, insurer, MDO, CQC inspector, board member or patient asks how AI use is controlled.
Common triggers for engaging ELSA AI
- A DPO requesting evidence on AI processing of patient data.
- CQC inspection scheduled or anticipated.
- An AI tool under consideration, in pilot or recently adopted without a governance review.
- An insurer, PMI or MDO renewal questionnaire including AI questions.
- A practice manager or principal discovering informal ChatGPT or Copilot use among staff.
- A patient question, subject access request or complaint involving AI-generated content.
- A board, partnership or investor review of AI exposure.
- Staff, referrer or patient concern about AI use in the clinic.
What you get for £5,500, in four working days
The Clinical AI Exposure Diagnostic™ produces a board-ready governance pack. It establishes:
- which AI tools are in use across clinical, admin, marketing and support functions, including declared and shadow AI;
- whether patient or clinical data is being processed, and at what level of sensitivity;
- whether use is approved, conditional, tolerated, shadow or unknown, and whether any tools are running on personal devices or free-tier accounts;
- whether DPIA screening, privacy notice, data processing agreement and vendor evidence are in place, and where gaps exist;
- whether patients are informed consistently and have a clear route to raise concerns or decline use;
- whether staff have a documented and approved AI use position;
- whether MDO, PMI or insurer disclosure needs review;
- what should be done in the next 30 days.
You receive nine deliverables in one pack
- Board Findings Report
- One-page RAG Exposure Map
- AI Tool and Use Case Inventory
- DPIA Readiness and Patient Data Exposure Note
- Vendor Data Position and Evidence Tracker
- Ambient Scribe Assessment Sheet, where applicable
- MDO, PMI and Insurer Disclosure Readiness Note
- 30-Day Priority Action Plan
- Source and Guidance Mapping Appendix
Where a deliverable does not apply to your clinic, it is recorded as not applicable with the reason stated, so the pack stands as a complete evidence record.
Fee and timeline
Fixed fee: £5,500 + VAT. Delivered within four working days from the start of delivery.
This standard fixed fee covers a single-site clinic of up to 60 staff, in a single clinical specialty, with no NHS contract or NHS data-sharing arrangement in scope. Larger clinics, multi-site groups and mixed-specialty practices are scoped individually at intake.
Where an ambient scribe, AI transcription or consultation note-generation tool is in use, in trial or planned, the engagement routes to the Clinical AI Exposure Diagnostic™ with Ambient Scribe Assessment at £8,500 + VAT, delivered in six working days.
A separate six-working-day engagement. The ambient scribe assessment runs through the full evidence pack, not as a standalone addition.
No platform subscription. No retainer required to start.
For clinics that want to convert the Diagnostic into a board-adopted governance baseline, the Clinical AI Safe Usage Launchpad™ follows over four to six weeks. For clinics that want their governance evidence kept current as tools, staff use, vendor terms and regulatory expectations change, the AI Exposure Sentinel™ retainer is available at £950 per month, £2,850 per quarter in advance, or £10,500 per year prepaid, + VAT. Annual prepaid is preferred.
What ELSA AI does not do
ELSA AI provides advisory governance support only. We do not:
- determine legal compliance with UK GDPR, the Data Protection Act 2018 or any other legislation;
- provide CQC, ICO or MHRA approval, certification or sign-off;
- complete or sign a DPIA;
- determine insurer coverage, underwriting or MDO indemnity support;
- approve AI tools or certify a vendor's position;
- make medical device or SaMD classification decisions;
- replace the clinic's DPO, legal counsel, clinical lead or accountable officers.
Final legal, data protection, clinical safety, regulatory, insurer and MDO decisions remain with the clinic's own accountable officers and advisers. Where useful, ELSA AI structures evidence so it can be reviewed, adopted and signed off by those advisers. We say what we found, what it means and what to do about it. You decide, and you adopt.
Founder-delivered
Engagements are led by Faisal Ali, AAISM, CISM, CRISC, Founder and Principal Consultant of ELSA AI. Faisal brings more than two decades in cybersecurity, information risk and governance across healthcare, financial services and national infrastructure.
Senior-led. No junior delegation. No template-and-invoice model.