top of page
Search
All Posts


Deepfakes: An Increasing Risk for our customers
The strongest protections are controls that prevent a single convincing communication from causing harm. We have written on this topic before but it warrants revisitng. I think deepfakes should now be treated as a medium and increasing risk for sectors like healthcare, finance or IT. The technology is becoming more accessible, convincing and much easier to use. These are not always sophisticated fake videos. In many cases, a cloned voice, manipulated image or impersonation ca
1 day ago4 min read


AI Assurance for Clinical Safety Officers - Online Training
While the webinar is designed with Clinical Safety Officers in mind, it is also valuable for CCIOs, CNIOs, Digital Leads, Information Governance professionals, AI Leads and anyone responsible for assuring AI technologies within healthcare. A practical session exploring the governance, legal and information risks associated with AI in healthcare, designed for CSOs 18th August 2026, 12pm to 2pm Online via Teams For Clinical Safety Officers, AI presents new challenges. Traditi
Jul 22 min read


Managing Subject Access Requests in Health and Care
Applying the 'serious harm - health' exemption It is important to remember that the harm exemption is time limited. This article relates only to subject access requests (SARs) made under UK GDPR and the Data Protection Act 2018. It does not cover disclosures made under court orders, police investigations, safeguarding processes, litigation, insurance requests, statutory powers, or any other legal basis for sharing information. A SAR is a request by an individual, or someone
Jul 14 min read


Managing Subject Access Requests in Health and Care
Applying the 'third party confidential ' exemption The ICO makes clear that you should not automatically redact information simply because it mentions another person. This article relates only to subject access requests (SARs) made under UK GDPR and the Data Protection Act 2018. It does not cover disclosures made under court orders, police investigations, safeguarding processes, litigation, insurance requests, statutory powers, or any other legal basis for sharing information
Jun 304 min read


Human Oversight in AI: Why “A Human Reviews It” Is Not Enough
This is the paradox. The more carefully every AI output is reviewed, the less productivity the AI may deliver. The more productivity the AI delivers, the less likely it is that every output is being carefully reviewed. From AI scribes and service user triage to decision support and administrative automation, AI has the potential to reduce workload and improve efficiency for all our customers. However, a very common phrase in supplier materials is: “A human reviews every AI ou
Jun 294 min read


Why Good Suppliers Still Lose Public Sector Tenders
One consequence of widespread AI use is that many tender responses are beginning to sound very similar. Many suppliers assume that if they have a strong product, competitive pricing and relevant experience, they should perform well in public sector procurement exercises. In practice, good suppliers score poorly for reasons that have little to do with the quality of their service. At Kafico, we regularly support organisations assessing suppliers, reviewing governance arrangeme
Jun 203 min read


Preparing Your HealthTech Product for the UK Market: What International Suppliers Need to Know
NHS procurement and healthcare procurement processes place significant emphasis on assurance and governance. For a decade now we have supported our NHS and charity customers to assess HealthTech products before adoption, reviewing supplier assurances, data protection arrangements, AI governance, DPIAs, risk assessments, clinical safety considerations and wider compliance evidence. For many HealthTech and AI suppliers, the UK healthcare market can appear highly attractive. The
Jun 204 min read


What Our Customers Look For When Assessing AI Systems
Many suppliers spend effort trying to prove their AI is accurate, powerful or innovative but in our experience, customers understand that no system is perfect. We support around 150 healthcare, charity and tech customers as their DPO or AI Compliance Lead and perform AI governance assessments routinely. Over the last few years we've worked on both sides of the procurement journey; with organisations developing AI products and trying to bring them to market and with organisati
Jun 204 min read


Lasting Power of Attorney: What Should Care Providers Check?
For healthcare providers, the important point is that not every LPA gives the attorney the same rights. Healthcare providers are often contacted by relatives, carers or attorneys asking for access to a patient / service user information. Sometimes this is straightforward. Sometimes it is not. A Lasting Power of Attorney, often called an LPA, is a legal document that allows someone to make decisions on behalf of another person if they are unable to make those decisions themsel
Jun 194 min read


Health or Care Subject Access Requests from Solicitors: How do we treat them?
A solicitor acting on behalf of a patient is exercising the patient's right of access. The solicitor effectively stands in the patient's shoes. It is common for GP practices or care homes to receive Subject Access Requests (SARs) from solicitors acting on behalf of patients / residents. These requests are often linked to personal injury claims, clinical negligence cases, employment disputes, insurance claims or family court proceedings. A common question we hear is: "Do we pr
Jun 195 min read


The Rise of Digital Coercive Control
"The world in which domestic abuse is perpetrated is changing, but domestic abuse persists at worrying levels. Perpetrators of domestic abuse now routinely use technology and social media to control and instil fear in those they victimise." All-Party Parliamentary Group on Domestic Violence Safeguarding professionals have long been trained to recognise physical abuse, emotional abuse, financial exploitation and coercive control, but digital coercise control is a rapidly growi
Jun 174 min read


Medical Records Are Not Personal Health Records: Managing Increasing Requests to Rewrite Clinical Records
The EHR is not a personal health record, it is a professional record containing personal data We have noticed a big increase in requests to amend, remove or add information to clinical records since the expansion of patient access to online medical records, and while some requests relate to genuine inaccuracies and should be corrected, others are not appropriate and can be tricky to manage for customers. Practices report patients asking for large sections of narrative to be a
Jun 53 min read


Deceased Patient Records: Who Can Access Them and When?
Being someone's spouse, child, relative or next of kin does NOT automatically give them the right to access a deceased patient's medical records. We often get asked.. ✓ Who can legally request deceased patient records ✓ What "intestate" means ✓ When records can be released to family members ✓ How to handle contested will requests ✓ When discretionary disclosure may be appropriate ✓ Common mistakes to avoid Probably, one of the most common questions we receive from practices
Jun 45 min read


AI-generated requests are increasing, and I don't think it's a bad thing
Organisations should not dismiss or treat requests differently because AI may have been involved. Anyone who knows me knows that I am super passionate about information rights and the role they play in protecting people. At their core, both FOIs and SARs are about empowerment. They are intended to give people the ability to understand decisions, challenge organisations, access their own information, and hold public bodies to account - often where there is a pronounced power i
May 212 min read


The LENS Journey #2: Clinical Safety Is a Team Sport
One of the things that has become really obvious while building LENS is that AI governance cannot realistically sit with one person. We’ve spent the last few months talking to Clinical Safety Officers, DPOs, digital leads, GP practices and suppliers, and the recurring theme that keeps coming up is that the amount of coordination involved is huge. People are trying to pull together supplier information, governance concerns, workflow understanding, technical limitations, clinic
May 143 min read


The Disappearing First Step: The Experience Ladder Is Breaking
“Are we still creating the conditions through which experience and judgement are formed?” A recent Deloitte article on the growing “experience gap” really fascinated me. It discussed what happens when organisations automate the very work people once learned from. For decades, most careers followed a predictable structure. Entry-level roles provided exposure, repetition, and low-risk responsibility. People learned by doing. They made mistakes in contained environments, gradual
May 114 min read


The LENS Journey #1: Why We’re Piloting a New Approach to AI Governance in Healthcare
After more than a year of development, testing, discussion, and redesign, we’re now approaching go live for our NHS pilot of LENS (previously CleanAI), a platform designed to support practical AI governance and clinical safety oversight in healthcare settings. LENS stands for Lawful, Explainable, Necessary and Safe. The pilot is focused on a question that feels increasingly important across healthcare: How do organisations safely understand, assess, and oversee AI systems in
May 93 min read


Introducing Our Tech, Rights and Risks Forum for GP Practices and PCNs
We’re launching a new quarterly forum for our GP practices and PCNs, designed to support with the real-world challenges of data protection, digital tools, and risk management. Each session will bring together practices from across our network to explore practical, relevant topics in a structured and accessible way. A simple format that works Every forum follows the same three core themes: 💻 Tech – the tools and systems you’re using (including AI) ✊🏼 Rights – patient rights
Mar 312 min read


External IT Support: Risks and Issues
Over the past few months, I’ve been looking more closely at something that raises concerns for me. How much real, practical control organisations retain when their IT service is delivered by an external provider. The relationship may be great and the SLA met, but three patterns keep surfacing: Concentrated privileged access (single points of failure) Remote access to sensitive data without meaningful friction Customers being charged for access to their own governance informat
Feb 273 min read


How much does ISO 27001 Cost?
Achieving ISO 27001 certification is a significant step for any organisation aiming to strengthen its information security management system (ISMS). However, one of the most common questions businesses ask is: how much does ISO 27001 cost? The answer is not straightforward because the total cost depends on various factors including the size of the organisation, the scope of certification, and the existing security posture. This post breaks down the different cost components
Feb 185 min read
bottom of page