Security and compliance: No patient records. A source for every statement.

Wardside is a clinical assistant that holds no patient records. The servers and databases are in the EU, personal data in a question are masked before they reach the model, and every answer is kept in an audit log together with its sources.

Personal data

Patient data stay outside Wardside

Wardside is a reference tool for medicines and clinical questions. It is not a hospital information system and holds no patient records.

  • Names, national identification numbers and phone numbers are masked before the question reaches the classifier, the search, the model and the audit log.
  • Wardside does not answer questions about a named patient.
  • The calculators store neither the values entered nor the result.
  • The application and the databases are in Belgium (europe-west1). The language model that composes the answers is operated by an external sub-processor, named in the privacy policy. Before a question reaches it, any names, ID numbers and phone numbers in it are replaced with placeholders.

Access

Access control by role and department

Access to Wardside is through the institution: single sign-on (SSO) or a work email domain, with roles and departments managed centrally from the administration console.

By invitation or domain only

Registration is possible only with an invitation or through the organisation’s work email domain. When an account is not approved automatically, the professional registration number is checked against the national professional register.

SSO with the institution’s accounts

Log-in through the organisation’s identity provider (SAML or OIDC), with automatic approval or approval by the administrator.

Roles and departments

Doctor, nurse, pharmacist, by department. Permissions are read from the signed session, never from the request itself.

60-minute sessions

The session is a protected cookie that the server checks on every request. A deactivated account loses access on its next request.

Computers on the network

A shared computer on the hospital network can be used without a personal account: register, interactions and calculators, with no chat and no history.

Revoking access

On deactivation, a change of role or an expired membership, sessions are revoked. Membership for a student cohort expires at the end of its term.

Audit and retention

Every answer stays in the log

Every chat turn is written to an audit log before the answer is shown. The log keeps every answer with its sources, so the institution can trace how the AI assistant has been used. Log entries are not modified.

  • Each entry keeps the question after masking, the cited passages, the answer and the versions of the model and of the data.
  • Interaction checks are recorded too, with the pairs recalculated on the server.
  • The organisation’s audit log is available only to its administrator and its pharmacist. Wardside’s operator sees only metadata.
  • The monthly PDF report shows usage by department. Small groups are hidden so that no individual can be identified.

Citations

A refusal instead of a guess

Wardside shows what the sources state. When it cannot confirm something, it does not answer.

  • Every sentence carries a citation. Text without a citation is not shown.
  • Citations from the safety sections of the SmPC (sections 4.3 to 4.6) are checked verbatim. A sentence that cannot be confirmed is dropped; if nothing confirmed remains, there is no answer.
  • Prices, reimbursement, interaction severities and the doses in SmPC tables are read from the database. The model does not paraphrase them.
  • The only link outside the platform is the document itself, at the European Medicines Agency (EMA) or the national regulator.
Not a clinical decision support system and not a medical device

In regulatory terms, Wardside is an information service. It is not a clinical decision support system and is not a medical device within the meaning of Regulation (EU) 2017/745. It does not choose a therapy, make a diagnosis or invent a severity, dose or mechanism. Every answer in the chat ends with “Not a treatment recommendation.”

Questions

About security

Where the data that Wardside searches come from: Sources and data
Who is behind Wardside: About us

Where are the data physically located?

The servers and databases are in the European Union, in Belgium (europe-west1). The language model that composes the answers is operated by an external sub-processor, named in the privacy policy. Before a question reaches it, any names, national identification numbers and phone numbers in it are replaced with placeholders.

Do staff need to enter patient data?

No. Wardside is a reference tool for medicines and clinical questions and holds no patient records. If a question contains a name, a national identification number or a phone number, these are masked before the question reaches the model, the search and the audit log.

Can Wardside’s operator read our questions?

No. For the organisation’s records, the operator sees only metadata. Their content is available only to the organisation’s administrator and pharmacist.

How long is a session valid?

The session is a protected cookie valid for 60 minutes, and the server checks it on every request. While the page is open, it renews itself. A deactivated account loses access on its next request.

Is Wardside a medical device?

No. In regulatory terms, Wardside is an information service. It is not a clinical decision support system and is not a medical device within the meaning of Regulation (EU) 2017/745. It shows what the sources state and does not recommend treatment.

Show Wardside to your security team

In the demo we will answer the questions of your IT team, your legal team and your data protection officer.