MICKAI®ArticlesClinical Records Review Without S…
Article · 31 July 2026

Clinical Records Review Without Sending Patients to the Cloud

NHS trusts can use modern AI on referral letters, discharge summaries and clinical audit records entirely on hardware they own, air gapped, with a clinician signing every disposition.

Author
Micky Irons
Published
31 July 2026
Follow Micky Irons
LinkedInX
sovereign-ainhshealthcare-datauk-gdpron-premise-ai
Clinical Records Review Without Sending Patients to the Cloud

NHS trusts and independent healthcare providers can use modern AI on referral letters, discharge summaries and clinical audit records without a single patient record leaving the building. The review runs on hardware the organisation owns, on premise and air gapped, and a clinician signs every disposition. That is the defensible shape for AI in health administration, and it is the shape we build.

The regulatory ground here is strict and settled. Health records are special category data under UK GDPR. NHS bodies also operate under the Data Security and Protection Toolkit, the annual self assessment completed by organisations with access to NHS patient data, and the health sector remains among the most represented in data breach reports to the Information Commissioner's Office. Any conversation about AI and patient records starts from that reality, not from what the technology can do.

Why are patient records treated differently from other data?

Because the law layers protections on them that ordinary business data never attracts. UK GDPR classes data concerning health as special category data, so a provider needs both a lawful basis and a separate condition before processing it at all. On top of that sit the common law duty of confidentiality, owed directly to the patient, and the Caldicott principles, which require every use of confidential patient information to be justified, minimised and overseen by a Caldicott Guardian. A mental health referral is not an input to be optimised. It is a confidence the patient placed in a clinician, and every system that touches it inherits that duty.

What does the Data Security and Protection Toolkit expect of a trust?

It expects the organisation to demonstrate, every year, that its people, processes and technology protect patient data against the National Data Guardian's standards. That includes knowing where confidential data flows, which suppliers process it, and on what terms. Every external service added to the chain is another data flow to map, another processor to assure and another entry in the evidence base. When the review runs on hardware the trust owns, the data flow map stays short and the assurance question stays answerable. We build for that shape deliberately, because the simplest honest answer to where the patient data goes is nowhere.

Can a trust use cloud AI on patient records at all?

Sometimes, with enough contractual and assurance work, but every transfer has to be justified and defended, and the honest question is whether the trust wants that burden at all. A cloud AI service must receive the record in a form it can read, which places identifiable or weakly pseudonymised health data with a third party processor, often with subprocessors behind it. Each hop needs an impact assessment, a contract and an incident plan. None of that is impossible. All of it is weight. An air gapped deployment removes the transfer question rather than answering it. The record never leaves the building, so there is no disclosure to justify and the duty of confidentiality is never tested against a supplier's infrastructure.

What does sovereign review of clinical records look like in practice?

It looks like a system inside the trust's own estate doing the first pass that administrative teams currently do by hand, with people keeping every judgement. Our document review capability reads a package of records, cross references what is claimed against what is evidenced, drafts routine paperwork and holds anything anomalous for a person. In health administration, that means:

  • Referral letters checked for completeness against the receiving service's criteria before triage time is spent on them
  • Discharge summaries cross referenced against the episode's records, with gaps and inconsistencies surfaced for the clinical team
  • Clinical audit packs assembled from the records themselves rather than by hand, with every source traceable
  • Anomalies held for a named person to review, never silently corrected or waved through
  • Every action sealed to the Open Audit Record before it runs, so the trust can prove afterwards exactly what was reviewed, by whom and under what policy

One boundary is absolute. Anything touching clinical reasoning is reference material only. The system can gather, cross reference and present, but a diagnosis or treatment decision belongs to the treating clinician, who reviews and signs it. We hold that line because it is the right line.

Who is accountable when AI touches a patient record?

A named person, always, and the record proves it. Every consequential action in Mickai waits for a person's clearance before it executes, and the Open Audit Record seals what was proposed, what policy permitted it and who cleared it before the action runs. The record is cryptographically signed, tamper evident, post quantum secure and verifiable offline, years later, without any connection to us. For a Caldicott Guardian or an information governance team, that changes the character of assurance. Instead of asking a supplier what happened, the trust holds standing evidence.

A patient record is a confidence, not a dataset. The machine can be patient enough to check every page, but the duty of confidentiality stays with people, on hardware the trust owns, with a sealed record of every action.

Mickai

Where does AI in health administration go from here?

Toward the estate, not away from it. The pressure on health administration is real, and the temptation to relieve it by sending records outward will keep arriving in polished form. We think the durable answer runs the other way. Bring the capability to the data, keep the clinician's signature on every judgement, and hold evidence rather than assurances. Mickai runs fully offline on the customer's own hardware, with a hardware held root of trust, voice biometric gating on privileged operations and a cooperative multi model consensus substrate that cross checks its own reading before a person sees it. As the toolkit and the ICO continue to raise expectations on health data, the strongest position belongs to organisations whose answer to where the record went has always been nowhere.

Frequently asked questions

Does patient data leave the trust with an on premise deployment?

No. Mickai runs on hardware the organisation owns, on premise and air gapped where required. Records are read, cross referenced and reviewed inside the trust's own estate, and nothing is transmitted to us or any third party.

Does the system make clinical decisions?

No. Anything touching clinical reasoning is reference material only, prepared for the treating clinician, who reviews and signs it. The system's work is administrative: completeness checks, cross referencing, drafting and evidence assembly.

How does this help with the Data Security and Protection Toolkit?

The toolkit asks organisations to evidence how patient data is protected, where it flows and who processes it. An on premise deployment keeps the data flow map short, and the Open Audit Record provides signed, tamper evident evidence of every review and action.

What is the Open Audit Record?

It is Mickai's accountability layer. Before a consequential action runs, the record seals what was proposed, what policy permitted it and who cleared it. It is cryptographically signed, post quantum secure, tamper evident and verifiable offline, so a trust can prove what happened years later without relying on anyone's recollection.

Can the review run with no internet connection at all?

Yes. Mickai is built to operate fully offline. Air gapped deployment is the intended shape, not a degraded mode, and every capability, including verification of the audit record, works without a connection.

What is MICKAI?

MICKAI is a Sovereign Intelligence Operating System, a SIOS that runs on the customer's own hardware, on premise and air gapped. Every action is sealed to the Open Audit Record, a cryptographically signed, tamper evident record that can be verified offline. It comprises 87 studios, with ten production ready at launch and 77 in development, and is protected by 104 filed UK patent applications across 2,340 claims, filed rather than granted.

Subscribe
Get every new Mickai article by email.

Long-form essays on sovereign AI from Micky Irons. One email per article. No tracking, no marketing, no third parties. Every email includes a one-click unsubscribe link.

Prefer RSS? Subscribe at /articles/feed.xml.

Originally published at https://mickai.co.uk/articles/clinical-records-review-without-the-cloud. If you operate in a regulated sector or want sovereign AI on your own hardware, the audit form on mickai.co.uk is the entry point.
More articles