commvitaConnected care platform
Regulatory compliance

Compliance frameworks are configured, not compiled in.

The regulator, the inspection framework and the statutory clock all change by jurisdiction. None of them is hardcoded.

Configurable compliance

Compliance frameworks are configured, not hardcoded

The regulator, the inspection framework, the background-check scheme, the professional register and the statutory clocks are all per-jurisdiction values resolved from a governed record.

AreaWhat commvita does
Clinical safetyDCB0129 and DCB0160 hazard log, clinical risk management and a safety case, with the hazard raised alongside the change it assesses
Audit trailsAppend-only, SHA-256 hash-chained and re-verified on every read, so tampering is evident rather than merely prohibited
Information governanceAsset register, records of processing, retention and disposal with legal hold, and data lineage
Data protectionLawful basis per purpose, special-category handling, and impact assessments as a register rather than a folder
Consent managementRecorded, versioned and withdrawable, with withdrawal shown rather than the record hidden
Access controlRole hierarchy, organisation scope, delegation with expiry, and default deny on special-category domains
Cyber securityCyber Essentials controls, ISO 27001 Annex A mapping and a remediation roadmap that states its own gaps
Regulatory reportingA registry of every statutory return with deadlines computed on the correct working-day or calendar basis
Research governanceEthics approval, access requests, an extract ledger and re-identification risk controls
Data residencyRecorded per jurisdiction and surfaced in the API — and the API states plainly that recording is not enforcement
Governance

The information governance operating modelThree columns — know what you hold, control how it is used, prove it on demand — over a note that statutory clocks are computed rather than typed.Know what you holdInformation asset registerRecords of processingData flows and lineageRetention schedulesControl how it is usedLawful basis per purposeConsent and opt-outsAccess control and scopeSharing agreementsProve it, on demandTamper-evident auditSubject access and FOI clocksBreach managementEvidence packsStatutory clocks are computed, never typedA working-day duty counts working days. A calendar duty counts calendar days. Getting that wrong understates a deadline by about a week.Information governance as an operating model, not a folder of policies.

Know what you hold, control how it is used, prove it on demand.