User Access & Acceptable Use Policy

Product: Caresoft eICU  •  For: all clinical and administrative users  •  Effective:01/04/2026

This policy applies to everyone who signs in to the Caresoft eICU platform — intensivists, doctors, nurses, command centre staff, hospital administrators, biomedical and IT personnel. It is a condition of holding an account.

Two things above all else.

1. The Platform is an adjunct. It is not a primary alarm system and not a substitute for bedside monitoring or direct patient assessment. Where the Platform and the bedside disagree, the bedside prevails.

2. Everything you do here is logged against your name — every sign-in, every patient record you open, every entry and every export. Opening a record you have no care reason to open is detectable, and is a disciplinary matter.

Contents
  1. Your account
  2. Passwords and authentication
  3. Minimum necessary access
  4. Clinical use rules
  5. Documentation and amendments
  6. Reading integrity indicators
  7. Alerts and escalation
  8. Handling patient information
  9. Exports, screens and printing
  10. Devices and workstations
  11. Remote and home access
  12. Prohibited conduct
  13. During downtime
  14. What you must report
  15. Monitoring and audit
  16. Enforcement
  17. When you leave or change role
  18. Acknowledgement

1. Your account

Shared logins destroy the audit trail. If two people use one account, no one can establish afterwards who saw what, who entered what, or who missed what. In a patient safety investigation that is not a technicality — it can make the sequence of events unreconstructable and leave everyone who touched the account exposed.

2. Passwords and authentication

3. Minimum necessary access

Open a patient's record only when you have a current care relationship with that patient, or a defined operational reason within your role.

Curiosity is not a reason. Looking up a colleague, a relative, a neighbour, a public figure, a friend's family member, or your own record is prohibited, even if you would be entitled to know the information some other way, and even if you tell no one.

4. Clinical use rules

5. Documentation and amendments

6. Reading integrity indicators

A flat or empty trend does not mean the patient is stable. It may mean no data is arriving.

Always check the sync health indicator before drawing any conclusion from the absence of data. Silence from the Platform is never reassurance.

IndicatorWhat it meansWhat you do
Device offline / no syncNo data flowing from that bedConfirm bedside monitoring is intact; report to [IT/biomed]
Data gapA period with no recorded dataDo not interpret that period; note in handover
Stale value warningLast reading is older than expectedVerify at the bedside
Clock drift flagTimestamps may be unreliableReport; treat timing of that data with caution
Unattributed / quarantined dataData could not be matched to a patientCheck the bed–patient mapping; report to [client admin]

7. Alerts and escalation

8. Handling patient information

9. Exports, screens and printing

10. Devices and workstations

11. Remote and home access

Remote access is permitted only where your hospital has authorised it for your role, and always subject to the same rules as on-site access.

12. Prohibited conduct

13. During downtime

14. What you must report

Report immediately to [charge nurse / Clinical Owner / hospital IT] and, where clinical, through your hospital's incident system:

Report early and report honestly. Reporting a mistake is expected and protected. Concealing one is the serious offence. Investigations look for system weaknesses first — most incidents in clinical systems have a design or process cause rather than an individual one.

15. Monitoring and audit

16. Enforcement

ConductTypical response
Minor or first breach, self-reportedRetraining and a documented discussion
Repeated breach, or failure to reportAccess restriction; formal disciplinary process
Account sharingImmediate suspension of access pending review
Unauthorised access to recordsImmediate suspension; disciplinary process; possible referral to professional council
Disclosure or removal of patient dataImmediate suspension; disciplinary process; regulatory notification; possible referral to police
Falsifying recordsImmediate suspension; disciplinary process; referral to professional council
Concealing a patient safety incidentTreated as a serious matter irrespective of the underlying event

Enforcement is the hospital's responsibility. Caresoft supports investigations by providing audit records, and may restrict access where there is a credible security threat to the Platform or to other hospitals.

17. When you leave or change role

Retain the signed acknowledgement in the hospital's training and access record. Access must not be provisioned before it is signed.

Home Book a Demo