Security and compliance: No patient records. A source for every statement.
Wardside is a clinical assistant that holds no patient records. The servers and databases are in the EU, personal data in a question are masked before they reach the model, and every answer is kept in an audit log together with its sources.
Personal data
Patient data stay outside Wardside
Wardside is a reference tool for medicines and clinical questions. It is not a hospital information system and holds no patient records.
- Names, national identification numbers and phone numbers are masked before the question reaches the classifier, the search, the model and the audit log.
- Wardside does not answer questions about a named patient.
- The calculators store neither the values entered nor the result.
- The application and the databases are in Belgium (europe-west1). The language model that composes the answers is operated by an external sub-processor, named in the privacy policy. Before a question reaches it, any names, ID numbers and phone numbers in it are replaced with placeholders.
Access
Access control by role and department
Access to Wardside is through the institution: single sign-on (SSO) or a work email domain, with roles and departments managed centrally from the administration console.
By invitation or domain only
Registration is possible only with an invitation or through the organisation’s work email domain. When an account is not approved automatically, the professional registration number is checked against the national professional register.
SSO with the institution’s accounts
Log-in through the organisation’s identity provider (SAML or OIDC), with automatic approval or approval by the administrator.
Roles and departments
Doctor, nurse, pharmacist, by department. Permissions are read from the signed session, never from the request itself.
60-minute sessions
The session is a protected cookie that the server checks on every request. A deactivated account loses access on its next request.
Computers on the network
A shared computer on the hospital network can be used without a personal account: register, interactions and calculators, with no chat and no history.
Revoking access
On deactivation, a change of role or an expired membership, sessions are revoked. Membership for a student cohort expires at the end of its term.
Audit and retention
Every answer stays in the log
Every chat turn is written to an audit log before the answer is shown. The log keeps every answer with its sources, so the institution can trace how the AI assistant has been used. Log entries are not modified.
- Each entry keeps the question after masking, the cited passages, the answer and the versions of the model and of the data.
- Interaction checks are recorded too, with the pairs recalculated on the server.
- The organisation’s audit log is available only to its administrator and its pharmacist. Wardside’s operator sees only metadata.
- The monthly PDF report shows usage by department. Small groups are hidden so that no individual can be identified.
Citations
A refusal instead of a guess
Wardside shows what the sources state. When it cannot confirm something, it does not answer.
- Every sentence carries a citation. Text without a citation is not shown.
- Citations from the safety sections of the SmPC (sections 4.3 to 4.6) are checked verbatim. A sentence that cannot be confirmed is dropped; if nothing confirmed remains, there is no answer.
- Prices, reimbursement, interaction severities and the doses in SmPC tables are read from the database. The model does not paraphrase them.
- The only link outside the platform is the document itself, at the European Medicines Agency (EMA) or the national regulator.
In regulatory terms, Wardside is an information service. It is not a clinical decision support system and is not a medical device within the meaning of Regulation (EU) 2017/745. It does not choose a therapy, make a diagnosis or invent a severity, dose or mechanism. Every answer in the chat ends with “Not a treatment recommendation.”
Questions
About security
Where the data that Wardside searches come from: Sources and data
Who is behind Wardside: About us
Where are the data physically located?
The servers and databases are in the European Union, in Belgium (europe-west1). The language model that composes the answers is operated by an external sub-processor, named in the privacy policy. Before a question reaches it, any names, national identification numbers and phone numbers in it are replaced with placeholders.
Do staff need to enter patient data?
No. Wardside is a reference tool for medicines and clinical questions and holds no patient records. If a question contains a name, a national identification number or a phone number, these are masked before the question reaches the model, the search and the audit log.
Can Wardside’s operator read our questions?
No. For the organisation’s records, the operator sees only metadata. Their content is available only to the organisation’s administrator and pharmacist.
How long is a session valid?
The session is a protected cookie valid for 60 minutes, and the server checks it on every request. While the page is open, it renews itself. A deactivated account loses access on its next request.
Is Wardside a medical device?
No. In regulatory terms, Wardside is an information service. It is not a clinical decision support system and is not a medical device within the meaning of Regulation (EU) 2017/745. It shows what the sources state and does not recommend treatment.
Show Wardside to your security team
In the demo we will answer the questions of your IT team, your legal team and your data protection officer.