Hi,
We’ve built an AI-powered platform for medical professionals that listens to consultations, transcribes them, and converts them into structured clinical notes.
The product itself is working well.
Before we release this as an MVP to real users, we want to make sure it is secure, compliant, and set up properly for the UK market.
At the moment, we have a developer who can help implement changes, but we need someone with the right expertise to guide us on what actually needs to be done.
⸻
What the Platform Does:
• Records consultations via microphone
• Transcribes conversations into text
• Converts transcripts into structured clinical notes
• Stores transcripts and notes
This involves sensitive patient data, so we need to get this right before launch.
⸻
What We Need Help With:
We’re looking for someone experienced in GDPR, healthcare data, and SaaS security to advise and guide on:
1. GDPR Compliance (UK)
• What is required before going live
• Consent requirements for recorded consultations
• Data storage and processing considerations
• Data retention and deletion policies
• Key legal risks we should be aware of
2. Security & Infrastructure
• How secure the current setup likely is (high-level review)
• What needs to be improved or implemented
• Encryption requirements
• Best practices for storing audio and transcripts
• Hosting guidance (e.g. where servers should be based, UK/EU considerations)
3. Clear Action Plan
• A simple, practical checklist of what we need to do before launch
• What is essential vs what can wait
• Avoiding overengineering while still being safe and compliant
⸻
Ideal Candidate:
• Experience with GDPR in healthcare or health-tech SaaS
• Strong understanding of data security and infrastructure
• Has helped take a product from MVP → compliant launch
• Able to give clear, practical advice, not just theory
⸻
Scope:
Initially:
• Consultation + audit + action plan
Potentially:
• Ongoing support with implementation alongside our developer
⸻
To Apply:
Please include:
1. Relevant experience (especially healthcare/GDPR projects)
2. How you would approach this
3. Any immediate risks or considerations based on the description
Apply tot his job
Apply To this Job