Skip to content
Ortho Outcomes

AI transparency

AI use notice

Last updated 21 August 2026.

Users are told when they are using AI. AI output is a draft for human verification, not a clinical decision, diagnosis, treatment recommendation or emergency alert. The public personal beta should be evaluated with synthetic or properly de-identified information.

Where AI is used

  • Theatre-list extraction: digital files use deterministic local parsing first and supported desktop photo OCR is attempted locally. Cloud Gemini fallback is off by default and requires a per-import choice.
  • Ask: a labelled Anthropic-powered analytical assistant. It can work with aggregates and pseudonymised case-level tool results after common direct identifiers are removed.

Core case recording, PROM scoring and ordinary filtering do not require generative AI.

Data sent and provider retention

An opted-in extraction may send list text or an image containing names, dates of birth, identifiers, procedures and layout information to the configured Gemini API. Ask can send a scrubbed question and aggregate or pseudonymised operation details, but users must not type patient identifiers into prompts. Pseudonymised data remains personal data where re-identification is possible.

Provider terms, retention and location depend on the account and configuration. Paid business API terms do not automatically mean zero retention. Operators must verify the current DPA, training restriction, abuse-monitoring retention and any approved Zero Data Retention arrangement before use; consumer or free AI accounts are unsuitable for identifiable health data.

Limitations and human oversight

Models can hallucinate, omit rows, confuse columns, infer the wrong procedure or produce a fluent but unsupported answer. Every imported patient, identifier, procedure, side, date, score and AI response must be checked against the source and clinical record. Confidence is not proof. AI output must not be the sole basis for treatment, access, employment, insurance or another significant decision.

EU AI Act and organisational duties

In August 2026 the operator must assess whether it is an AI provider, deployer, importer or distributor; provide applicable Article 50 transparency; maintain proportionate AI literacy under Article 4; inventory systems and models; document instructions, limitations and human oversight; and assess whether a changed purpose creates high-risk or medical-device obligations. The supported intended purpose excludes automated or patient-specific clinical decision-making.

Governance, incidents and questions

Before live use, approve a DPIA, processor/transfer assessment, AI risk assessment, clinical-safety review, access controls, audit retention, staff training and incident route. Record provider/model versions and review evidence. Report wrong-patient matches, unsafe output or unexpected disclosure immediately and stop the affected workflow until assessed. Questions can be raised through the contact page.