Compliance and Accreditations

Compliance and Accreditations

Header graphic for Cyber Essentials section

Cyber Essentials

 

Cyber Essentials Plus

PKB has been tested against the Cyber Essentials Scheme Test Specification. Certification date: 26th June 2025 Recommended re-assessment date: 26th June 2026 Certificate no.: cc4b6d9t-5452-4f36-9098-ec34f5fcea1e Verification: Cyber Essentials Certificate Validator.
Header graphic for ISO Standards section

ISO Standards

ISO 27001 - Information Security Management (ISMS)

Google Cloud Platform (GCP) Our cloud hosting partner GCP is ISO 27001 certified. For full details on GCP’s compliance please see their dedicated webpage. Download certificate PKB PKB is fully compliant with the ISO27001 standard, we have implemented an Information Security Management System and we maintain up-to-date policies, practices and documentation to support this. Please see: PKB Information Security Management Plan EU PKB Information Security Management Plan UK

ISO 27017 - Cloud Security

Our cloud hosting partner Google Cloud Platform (GCP) is ISO 27017 certified. For full details on GCP’s compliance, please see their dedicated webpage.

ISO 27018 - Protecting PII in Public Clouds

ISO 27018 is the international standard for protecting personal information in cloud storage. Our cloud hosting partner Google Cloud Platform (GCP) is ISO 27018 certified. For full details on GCP’s compliance, please see their dedicated webpage.

ISO 27701 - Privacy Information Management

ISO/IEC 27701 is a global privacy standard that focuses on the collection and processing of personally identifiable information (PII). Our cloud hosting partner Google Cloud Platform (GCP) is ISO 27701 certified. For full details on GCP’s compliance, please see their dedicated webpage.

ISO 9001 - Quality Management System

ISO 9001 is the global standard, which companies implement to help ensure the quality of products brought to market.  Patient Know Best’s quality management system is detailed here. Our cloud hosting partner Google Cloud Platform (GCP) is ISO 9001 certified. For full details on GCP’s compliance, please see their dedicated webpage.


Header for NHS Standards section

NHS Standards

DSPT - Data Security and Protection Toolkit

DTAC - Digital Technology Assessment Criteria

The Digital Technology Assessment Criteria for health and social care (DTAC) gives staff, patients and citizens confidence that the digital health tools they use meet our clinical safety, data protection, technical security, interoperability and usability and accessibility standards. Purpose and Scope The DTAC brings together legislation and good practice across clinical safety, data protection, technical security, interoperability and usability and accessibility standards and is designed to be used by healthcare organisations to assess suppliers at the point of procurement or as part of a due diligence process, to make sure new digital technologies meet our minimum baseline standards. Patients Know Best (PKB) passed NHS England’s DTAC assessment in February 2022. PKB have an ongoing commitment to developing and running the platform with the required security, governance and accessible standards for our users. The DTAC is a living document and is reviewed periodically to ensure that the most up to date information is provided in relation to the five core components. Product Overview Patients Know Best is a Personal Health Record system. PKB facilitates borderless, integrated care. The system connects information from primary, secondary, social and mental health care providers, to create a single, unified copy of patient data accessible by patients and their carers. Patients can also upload their own data to help them self-manage their health and wellbeing. This includes a symptom tracker and uploading measurements for patients to see their trends. Organisations can choose what data to release to patients, including diagnoses, allergies, medications, dynamic care plans, test results, measurements and documents. The PKB platform does not suggest actions to patients, it is a data store to allow patients to both see and save their data securely. Where organisations choose to, asynchronous messaging allows a patient to contact their clinical teams for shared decision making. DTAC PKB’s DTAC can be accessed here: DTAC Supporting Documentation B4 / D1.1: User Journey & Data Flows C1.2.3 / C1.2.4: - Clinical Safety Case Report C1.2.4: Hazard Log C2.1: DSPT C2.2.1: ICO registration C2.2.2: DPIA (UK / NHS) C2.2.3: Transparency information C2.2.4: Privacy Notice & User Agreements C3.1: Cyber Essentials Certification C3.3: External Penetration Test Summary Report - available on request. A request can be made here. D1.4.3: Accessibility Statement

Data Security and Protection Toolkit

SOC2

Other Compliance

NEN 7510

ODS, ICO, etc.

DCB0129 / DCB0160