AI Governance for Dermatology, Aesthetics and Specialist Clinics

A documented governance position for doctor-led dermatology, aesthetics, diagnostics, fertility and ophthalmology clinics using AI with patient images, notes, correspondence or clinical workflows.

What you are buying: for a fixed £5,500 + VAT, in four working days, a board-ready evidence pack that answers one question with evidence: what AI is in use across your clinic, what patient data it touches, and how that use is governed. The pack is what you put in front of your DPO, a CQC inspector, your MDO, your insurer or your board when the question lands.

Specialist clinics hold some of the most sensitive data in private healthcare: clinical photographs, aesthetic before-and-after images, fertility records, ophthalmic scans, intimate consultation notes. AI is now involved in how much of that data is captured, processed and communicated: image analysis, AI-assisted triage, online consultation summaries, transcription, marketing platforms that reach into the patient journey.

The problem is not that these tools exist. It is that a patient photograph can pass through a tool nobody registered, under terms nobody read, and the clinic has no documented position when its DPO, a CQC inspector, its MDO or its insurer asks how that use is controlled.

Evidence guides: AI Evidence Pack Checklist for Private Clinics · Shadow AI in Clinics

Why a documented governance position matters for specialist clinics

  1. 1. CQC-regulated specialist activities are subject to inspection

    Specialist clinics providing regulated activities are required to register with and be inspected by CQC under the Health and Social Care Act 2008. CQC's key questions include whether a service is safe and well-led. Where AI affects clinical records, imaging workflows, data processing or human oversight of clinical output, the clinic needs a documented position it can show an inspector.

  2. 2. AI imaging and diagnostic support tools may require medical device review

    AI software used for image analysis, triage, diagnosis support or risk scoring in dermatology, ophthalmology, diagnostics or fertility may meet the MHRA's definition of software as a medical device. Where it does, specific regulatory obligations apply to the supplier and to the clinic deploying it. ELSA AI flags where SaMD review may be warranted and what supplier evidence should be requested; it does not make the classification decision.

  3. 3. Specialist clinics process some of the most sensitive health data in the sector

    Clinical photographs, aesthetic before-and-after images, fertility records, ophthalmic scans and intimate consultation notes are all special category health data under UK GDPR. Where AI processes any of them, a DPIA is likely required or strongly indicated. That determination is the clinic's DPO's to make, and screening should come before live use, not after.

  4. 4. Confidentiality expectations in these settings are not average

    Dermatology, aesthetics and fertility patients expect discretion as a baseline condition of the service. Uncontrolled AI processing images, consultation audio, transcription or patient communications creates a professional accountability question alongside the data protection one. The clinic needs to show that patient data passed only through tools it approved, under terms it reviewed.

  5. 5. Insurers, MDOs, acquirers and boards are starting to ask

    The consistent theme across medical defence organisation guidance is that the clinician remains responsible for the accuracy of the clinical record, including where the first draft was AI-generated, and that AI use outside organisational approval and governance may carry personal risk. The current position should be confirmed with your own MDO or indemnity organisation. Where a clinic is subject to investor, acquirer or franchise due diligence, the AI governance position is increasingly part of what gets examined.

The typical governance position we find

In specialist clinics, the recurring pattern is an evidence gap rather than a single failure.

Common findings include:

  • AI imaging or analysis tools are in use, but the clinic holds no supplier evidence: no data processing agreement, sub-processor list, hosting information or retention terms.
  • Patient images are processed by AI tools with no documented patient transparency position and no information given to patients about how their images are used.
  • Online triage or consultation-summary tools have been adopted without DPIA screening.
  • Marketing AI runs across the patient journey with no documented boundary between marketing data and clinical records.
  • Clinicians are drafting letters, reports and treatment notes in ChatGPT on personal devices with no patient-data boundary in place.
  • Incident reporting does not cover misclassification by an AI imaging tool, hallucinated clinical content, wrong-patient attribution or accidental image exposure as reportable events.
  • There is no single board-level view of which tools are in use, what patient data they touch, or what governance evidence exists.

None of this is a legal conclusion. It means there is an evidence gap. That gap becomes urgent when a DPO, insurer, MDO, CQC inspector, board member or patient asks how AI use is controlled.

Common triggers for engaging ELSA AI

  • A DPO requesting evidence on AI processing of patient images, records or special category data.
  • CQC inspection scheduled or anticipated.
  • An AI imaging, triage or diagnostic support tool under consideration, in pilot or recently adopted.
  • An insurer, PMI or MDO renewal questionnaire including AI questions.
  • A clinician or practice manager discovering informal ChatGPT or Copilot use.
  • A patient query, subject access request or complaint involving AI-generated content or images.
  • Investor, acquirer or franchise due diligence requiring a view of AI governance exposure.
  • Marketing automation introduced across the patient journey with no clinical-data boundary.

What you get for £5,500, in four working days

The Clinical AI Exposure Diagnostic™, scoped to a specialist clinic setting, produces a board-ready governance pack. It establishes:

  • which AI tools are in use across clinical, imaging, admin, marketing and patient-facing workflows, including declared and shadow AI;
  • whether clinical images, patient identifiers, notes, correspondence or special category data are being processed, and at what level of sensitivity;
  • whether use is approved, conditional, tolerated, shadow or unknown, and whether any tools are running on personal devices or free-tier accounts;
  • whether DPIA screening, privacy notice, data processing agreement and vendor evidence are in place, and where gaps exist;
  • whether AI imaging or diagnostic support tools raise SaMD questions, and what supplier evidence should be requested;
  • whether patients are informed consistently and have a clear route to raise concerns or decline use;
  • whether a qualified clinician reviews AI output before it enters the clinical record or is relied on;
  • whether incident reporting covers AI-specific scenarios, including misclassification, hallucinated content, wrong-patient attribution and accidental image exposure;
  • whether staff have a documented and approved AI use position;
  • whether MDO, PMI or insurer disclosure needs review;
  • what should be done in the next 30 days.

You receive nine deliverables in one pack

  • Board Findings Report
  • One-page RAG Exposure Map
  • AI Tool and Use Case Inventory
  • DPIA Readiness and Patient Data Exposure Note
  • Vendor Data Position and Evidence Tracker
  • Ambient Scribe Assessment Sheet, where applicable
  • MDO, PMI and Insurer Disclosure Readiness Note
  • 30-Day Priority Action Plan
  • Source and Guidance Mapping Appendix

Where a deliverable does not apply to your clinic, it is recorded as not applicable with the reason stated, so the pack stands as a complete evidence record.

Fee and timeline

Fixed fee: £5,500 + VAT. Delivered within four working days from the start of delivery.

This standard fixed fee covers a single-site specialist clinic of up to 60 staff, in a single clinical specialty, with no NHS contract or NHS data-sharing arrangement in scope. Multi-site groups and clinics spanning more than one specialty are scoped individually at intake.

Where an ambient scribe, AI transcription or consultation note-generation tool is in use, in trial or planned, the engagement routes to the Clinical AI Exposure Diagnostic™ with Ambient Scribe Assessment at £8,500 + VAT, delivered in six working days.

A separate six-working-day engagement. The ambient scribe assessment runs through the full evidence pack, not as a standalone addition.

View pricing details

No platform subscription. No retainer required to start.

For clinics that want to convert the Diagnostic into a board-adopted governance baseline, the Clinical AI Safe Usage Launchpad™ follows over four to six weeks. For clinics that want their governance evidence kept current as tools, staff use, vendor terms and regulatory expectations change, the AI Exposure Sentinel™ retainer is available at £950 per month, £2,850 per quarter in advance, or £10,500 per year prepaid, + VAT. Annual prepaid is preferred.

What ELSA AI does not do

ELSA AI provides advisory governance support only. We do not:

  • determine legal compliance with UK GDPR, the Data Protection Act 2018 or any other legislation;
  • provide CQC, ICO or MHRA approval, certification or sign-off;
  • complete or sign a DPIA;
  • determine insurer coverage, underwriting or MDO indemnity support;
  • approve AI tools or certify a vendor's position;
  • make medical device or SaMD classification decisions;
  • replace the clinic's DPO, legal counsel, clinical lead or accountable officers.

Final legal, data protection, clinical safety, regulatory, insurer and MDO decisions remain with the clinic's own accountable officers and advisers. Where useful, ELSA AI structures evidence so it can be reviewed, adopted and signed off by those advisers. We say what we found, what it means and what to do about it. You decide, and you adopt.

Founder-delivered

Engagements are led by Faisal Ali, AAISM, CISM, CRISC, Founder and Principal Consultant of ELSA AI. Faisal brings more than two decades in cybersecurity, information risk and governance across healthcare, financial services and national infrastructure.

Senior-led. No junior delegation. No template-and-invoice model.

Get a documented AI governance position before the next question lands.

Find out whether your clinic has meaningful AI governance exposure in 20 minutes.

Advisory governance support only. Not legal advice; CQC or MHRA approval; insurer coverage advice; MDO indemnity advice; a completed or signed DPIA; or medical device or SaMD classification. References to CQC, MHRA, UK GDPR and MDO guidance are governance-standard signals; they do not constitute, and are not a substitute for, the clinic's own legal, regulatory or clinical safety review.