User Access & Acceptable Use Policy
Product: Caresoft eICU • For: all clinical and administrative users • Effective:01/04/2026
This policy applies to everyone who signs in to the Caresoft eICU platform — intensivists, doctors, nurses, command centre staff, hospital administrators, biomedical and IT personnel. It is a condition of holding an account.
Two things above all else.
1. The Platform is an adjunct. It is not a primary alarm system and not a substitute for bedside monitoring or direct patient assessment. Where the Platform and the bedside disagree, the bedside prevails.
2. Everything you do here is logged against your name — every sign-in, every patient record you open, every entry and every export. Opening a record you have no care reason to open is detectable, and is a disciplinary matter.
1. Your account
- Your account is personal to you. Never share it, never let anyone else use it, never use anyone else's — not "just this once", not for a colleague who is busy, not for a consultant who has not been set up yet.
- If someone needs access, they get their own account. Ask your hospital administrator.
- You are accountable for everything done under your account.
- Access is granted by role and unit. If you need more access to do your job, request it; do not work around the limits.
- Accounts are issued only after training is completed and recorded.
Shared logins destroy the audit trail. If two people use one account, no one can establish afterwards who saw what, who entered what, or who missed what. In a patient safety investigation that is not a technicality — it can make the sequence of events unreconstructable and leave everyone who touched the account exposed.
2. Passwords and authentication
- Choose a strong, unique password. Do not reuse a password from any other system.
- Never write it down where others can find it, never store it in a shared file, never send it by message or email.
- Do not save credentials in a browser on a shared clinical workstation.
- Enable multi-factor authentication where offered, and always for administrative roles.
- If you think anyone knows your password, change it immediately and report it (Section 14).
- Never authenticate on behalf of someone else, including for a phone request you cannot verify.
3. Minimum necessary access
Open a patient's record only when you have a current care relationship with that patient, or a defined operational reason within your role.
Curiosity is not a reason. Looking up a colleague, a relative, a neighbour, a public figure, a friend's family member, or your own record is prohibited, even if you would be entitled to know the information some other way, and even if you tell no one.
- Access only the units and beds your role covers.
- Do not browse records for teaching, audit or research without your hospital's approval and, where required, ethics committee clearance.
- If you open a record in error, close it and report it — a self-reported error is treated very differently from one found in an audit.
4. Clinical use rules
- Verify before you act. Confirm any value against the bedside device or direct assessment before making a clinical decision on it.
- Confirm patient identity before interpreting data, and again after any transfer. Data is attributed by bed; if a move has not been recorded, the display can be wrong.
- Never rely on the Platform to detect deterioration. Bedside alarms do that. The Platform helps you see and review; it does not watch for you.
- Do not use the Platform for a purpose outside the Intended Use Statement.
- Early warning scores are screening aids. A normal score does not exclude deterioration and never replaces examination.
- Do not attempt to change, silence or configure a bedside device through the Platform. It cannot do this, and any apparent ability to do so must be reported immediately.
5. Documentation and amendments
- Document contemporaneously, accurately and legibly. Entries carry your name and timestamp.
- Do not document care you did not provide or observations you did not make.
- Entries cannot be deleted. Corrections are recorded as amendments showing the original, the change, who made it and why. This is a medical-records requirement, not a system limitation.
- Never backdate. If you are documenting late, say so and record the actual time of the observation and the time of entry.
- Write as though the record will be read in a coroner's court or a complaint investigation, because it may be.
6. Reading integrity indicators
A flat or empty trend does not mean the patient is stable. It may mean no data is arriving.
Always check the sync health indicator before drawing any conclusion from the absence of data. Silence from the Platform is never reassurance.
7. Alerts and escalation
- Platform notifications are secondary. They may be delayed, duplicated or not delivered at all. Never build a workflow that depends on one arriving.
- Acknowledge alerts you receive, and follow your unit's written escalation protocol.
- Do not silence, suppress or redirect alerts to reduce noise without going through your clinical governance process. If the volume is unmanageable, say so — alarm fatigue is a patient safety hazard and thresholds can be tuned properly.
- Never disable a bedside alarm because the Platform is "watching".
8. Handling patient information
- Discuss patients only with those involved in their care, and only where you cannot be overheard.
- Do not send patient identifiers or clinical detail over personal WhatsApp, personal email, SMS or social media. Use the Platform, or your hospital's approved channel.
- Notifications you receive are minimised and masked deliberately. Do not forward them.
- Never photograph a screen showing patient data, including for teaching or a quick second opinion. Use the Platform's own sharing and export functions.
- Do not copy patient data into personal notes, personal cloud storage, or a personal device.
- Confidentiality continues after the patient is discharged, after the patient dies, and after you leave the hospital.
9. Exports, screens and printing
- Export only what you need, for a defined purpose, and handle the file as you would a paper medical record.
- Exports are logged with your name, the patient, the scope and the time.
- Save exports only to hospital-approved storage. Never to a personal device, personal drive or unencrypted USB.
- Delete exported files when the purpose is complete.
- Collect printouts immediately and dispose of them in confidential waste.
- Position and lock screens so patient data is not visible to visitors or passers-by. Lock your session whenever you step away — the automatic timeout is a safety net, not a substitute.
10. Devices and workstations
- Use hospital-managed workstations and devices for clinical access wherever available.
- Keep the operating system and browser current; do not disable security software.
- Do not install unapproved software on clinical workstations or on edge agent hardware.
- Never plug personal storage into clinical or edge systems.
- Report a lost or stolen device that had Platform access immediately (Section 14).
11. Remote and home access
Remote access is permitted only where your hospital has authorised it for your role, and always subject to the same rules as on-site access.
- Use a private, trusted network. Avoid public or open Wi-Fi.
- Ensure no one else can see your screen — family members included.
- Multi-factor authentication is mandatory for remote access.
- Do not access the Platform from a shared or public computer, an internet café, or a device you do not control.
- Lock or sign out the moment you finish.
12. Prohibited conduct
- Sharing accounts or credentials, or using another person's account.
- Accessing records without a care or defined operational reason.
- Disclosing patient information to anyone not entitled to it, including family, media, insurers, employers or law enforcement without hospital authorisation.
- Photographing, screenshotting or recording screens containing patient data.
- Removing, copying or transmitting patient data outside approved channels.
- Falsifying, backdating or fabricating any entry.
- Attempting to bypass access controls, escalate privileges, disable logging, or test the Platform's security without written authorisation.
- Using the Platform for any non-clinical, personal or commercial purpose.
- Connecting unauthorised devices to the clinical or device network.
- Concealing an error, a near miss or an access made in error.
13. During downtime
- Follow your unit's downtime procedure immediately. You should know where it is without looking.
- Revert to bedside monitoring and paper or HIS documentation. Bedside alarms are unaffected by Platform downtime.
- In the command centre, loss of data flow is itself an escalation trigger — absence of alerts does not mean absence of events.
- When service is restored, review the outage period: buffered data arrives with its original timestamps and may reveal events you did not see live.
- Transcribe paper documentation into the record promptly, marked as retrospective with the actual observation times.
14. What you must report
Report immediately to [charge nurse / Clinical Owner / hospital IT] and, where clinical, through your hospital's incident system:
- Data shown against the wrong patient, or any suspicion of it.
- A value that does not match the bedside device.
- An alert that should have fired and did not, or one that fired wrongly.
- Any event where the Platform may have contributed to harm or a near miss.
- Suspected unauthorised access, a shared or compromised password, or a lost device.
- Data you can see that you should not be able to see.
- Any record you opened in error.
- Anything that looks like the Platform influencing a bedside device.
Report early and report honestly. Reporting a mistake is expected and protected. Concealing one is the serious offence. Investigations look for system weaknesses first — most incidents in clinical systems have a design or process cause rather than an individual one.
15. Monitoring and audit
- Sign-ins, record access, entries, amendments, exports and configuration changes are logged with your identity and timestamp.
- Logs are retained as part of the medical record and for legally mandated periods, and are reviewed by your hospital.
- Access patterns may be audited routinely and will be examined after any complaint or incident.
- Caresoft personnel accessing patient data are logged in exactly the same way, with a stated reason, and that log is available to your hospital.
- This monitoring exists for patient safety, medical-records integrity and confidentiality — not to assess your clinical performance.
16. Enforcement
Enforcement is the hospital's responsibility. Caresoft supports investigations by providing audit records, and may restrict access where there is a credible security threat to the Platform or to other hospitals.
17. When you leave or change role
- Tell your administrator before your last working day, or as soon as your role changes.
- Your access is revoked within [24] hours of leaving or of a role change. This is the hospital's responsibility — Caresoft cannot know when you leave.
- Delete any exports held locally and return or securely dispose of any printed material.
- Your confidentiality obligations continue indefinitely after you leave.
- Do not attempt to access the Platform after your access should have ended, even if your login still works. If it does still work, report it.
Retain the signed acknowledgement in the hospital's training and access record. Access must not be provisioned before it is signed.