Who in our organisation needs to own this?
In practice three people together: communications spots it first, the board decides, and the DPO looks on the moment data is involved. That is not bureaucracy — it is why the approval flow sits in the code rather than in an understanding.
| Who | Who decides | What keeps them up at night |
|---|---|---|
| Hospital, clinic or care group | Communications and the board together, with the DPO alongside | Medical claims, privacy, and what happens when it goes wrong at the weekend |
| Residential care home | The director, together with whoever handles communications | Residents' privacy, and a family forming its picture elsewhere |
What exactly can go wrong in an AI answer about care?
Four risks, and the first is the strangest: an engine can say something about you that exists nowhere. Not quoted, not copied — assembled from two half-facts. That is measurable, because we keep the answer and the sources underneath it, and the gap between those two IS the finding.
| Driver | What ceeme measures underneath | What stays dark without a connection |
|---|---|---|
| Hallucination risk | invented and outdated facts about you, counted by type | We see what an engine invents about you, and we follow the media coverage around it through the press feed. |
| Compliance / deontology risk | claims your sector does not allow you to make | Your professional body's rulepack is not fully formalised yet; what is there is strict, not complete. |
| Governance risk | who may publish what, and whether it can be undone | We show who may do what. Enforcing it per channel needs an operator flag and an adapter. |
| Reputation risk | misquotes, sliding reviews and where they come from | Reviews and social are read live. Print and paywalled media are not in there. |
| Local trust | GBP, reviews and whether your details match everywhere | We read your Google profile. Changing anything in it needs a GBP connection. |
Do you look inside our patient records or our systems?
No, and that is not a matter of settings. What we read is what an AI assistant reads too: your public pages, your Google profile, the press, the guides and the reviews. From your systems there is at most a read connection to the web statistics, and that is optional.
| Source | Kind |
|---|---|
| GBP | public — we read it, you connect nothing |
| press and news | public — we read it, you connect nothing |
| reviews and directories | public — we read it, you connect nothing |
| public — we read it, you connect nothing | |
| GA4 | connected — only after your approval, read-only unless agreed otherwise |
| GSC | connected — only after your approval, read-only unless agreed otherwise |
| CMS (read→scoped) | connected — only after your approval, read-only unless agreed otherwise |
| GBP (read) | connected — only after your approval, read-only unless agreed otherwise |
| GA4 (optional) | connected — only after your approval, read-only unless agreed otherwise |
Do you write medical content for us?
No. If an engine says something medically wrong, we trace it to the source and tackle that — a page being misread, a guide with an outdated department name. The medically correct wording comes from you, because that is where it belongs.
| Rule | Kind |
|---|---|
| Not a single sentence that could read as a medical claim or a promise of treatment, not even in passing. | hard rule — the build refuses output that crosses it |
| The measurement runs on public sources. No path exists that brings personal data from your practice into a measurement. | hard rule — the build refuses output that crosses it |
| Every finding, every approval and every change is logged with time and person, and can be read back afterwards. | hard rule — the build refuses output that crosses it |
| We do not write medical content. If something medically wrong is circulating, we tackle the source and not the text. | forbidden — we do not do this, not even on request |
| Patient data is not read, not stored and not processed, in any route. | forbidden — we do not do this, not even on request |
| Residents' data stays entirely outside the measurement — no connection, no import, no setting that enables it. | hard rule — the build refuses output that crosses it |
| Nothing goes out without the person authorised to sign off at your organisation having seen it — the flow sits in the code, not in an understanding. | hard rule — the build refuses output that crosses it |
| Every claim about the care you provide must trace back to something you confirmed yourselves. | hard rule — the build refuses output that crosses it |
| Residents' names, files and data are not read, not stored and not processed. | forbidden — we do not do this, not even on request |
| Not a single sentence promising an outcome or a quality of care, not even if that sentence already sits on your own site. | forbidden — we do not do this, not even on request |
How does approval work when something wrong is circulating?
A finding arrives with its source and a proposal. Communications assesses, the board approves, and only then does anything go out. For urgent cases there is a shorter path with the same steps — faster, not fewer. Every step is logged, and there is always a way back.
Frequently asked questions
Can you force ChatGPT to correct our waiting times?
Nobody can, and anyone promising it is selling something they do not own. What does work is changing the source the engine leans on. If your own page shows a waiting time nobody maintains any more, that is the fix — and the answer follows on its own, next time the engine looks.
How quickly do we know when something serious is circulating?
As fast as the measurement runs, and you set that frequency. What you do not get today is full media coverage: reviews and social are read live, print and paywalled media are not. The table above says so, because an alerting system that acts as if it sees everything is more dangerous than no alerting at all.
We already have a spokesperson protocol. Does this clash with it?
It should fit inside it, not sit beside it. The approval flow is configurable to whoever may sign off at your organisation, and nothing goes out without that person seeing it. What we add is not a second protocol but the piece that was missing: seeing what is said about you in a place where no journalist calls.
Read on
Free, no account and no card.