Skip to main content

Security, safety & compliance

At Reach Health Technologies (RHT), we are on a mission to bridge the gap between clinic and home. As the dedicated technology and innovation arm of the Cortera Health Group—working alongside our sister clinical brands Ascenti and Six Physio, we connect an intuitive digital front door directly to a nationwide network of over 300 expert clinicians. Instead of trying to replace human medicine with algorithms, we believe in "human-led, digitally enabled" recovery.

We understand that NHS clinical directors, private medical insurers, and enterprise employers require clear, verified evidence of software safety, interoperability, and data governance. That is why our products, clinical pathways, and clinician networks are held to the highest national healthcare and cybersecurity standards.

Clinical Governance & Patient Safety

At RHT, clinical quality is built directly into our software design, ensuring that technology acts as an amplifier of human expertise rather than a replacement.

  • HCPC-Registered Clinicians: Every single digital patient pathway, including assessments completed within the patient-facing Reach application, is reviewed and supervised by Health and Care Professions Council (HCPC) registered physiotherapists. The clinical engine remains our responsibility, ensuring consistent and expert clinical oversight regardless of how our platform is white-labeled or co-branded by a B2B partner.
  • HCPC-Registered Clinicians: Our self-guided digital assessments are designed to actively mitigate risk. The Reach AI PhysiScore system evaluates clinical questionnaires to generate a risk score for every presentation. This ensures high-risk or "red flag" cases are instantly prioritized in the clinician's Omega dashboard, while lower-risk presentations are safely routed into structured, self-managed care pathways.
  • HCPC-Registered Clinicians: We maintain strict clinical standards across our national employed network of over 300 physiotherapists through continuous clinical quality audits, defined sessional averages (<4.5 sessions per episode of care), and rigorous internal Learning & Development (L&D) programs.
A person wearing a smartwatch scrolling on their phone

Industry Accreditations & Standards

Our platforms are rigorously and continuously audited to meet the strict digital healthcare benchmarks required by national health systems and private medical insurance (PMI) networks:

  • DTAC (Digital Technology Assessment Criteria): RHT software is fully assessed against the NHS Digital Technology Assessment Criteria, demonstrating total compliance across clinical safety, data protection, technical security, interoperability, and usability.
  • ISO 27001 Certification: We operate an Information Security Management System (ISMS) certified to ISO 27001 standards, ensuring corporate data security protocols are consistently applied across all product lines.
  • Cyber Essentials: Certified under the UK government-backed Cyber Essentials scheme to guard against common cyber threats and maintain robust perimeter technical security.

"At RHT, you aren't just writing code for another abstract software product. Knowing that a feature you build in the morning is actively helping a patient recover from an injury that afternoon gives your work a genuine human purpose."

SALLY SMITH Operations Lead, Reach Healthtech

Data Protection & GDPR Compliance

Protecting sensitive patient data is our highest priority. RHT implements strict data controls to ensure complete compliance with privacy laws:

  1. End-to-End Encryption: All clinical data, patient records, and secure chat interactions are protected using industry-standard, end-to-end encryption both in transit and at rest.
  2. GDPR-Compliant Processing: Every data transaction within the Reach patient app and the Omega clinician dashboard is fully compliant with the General Data Protection Regulation (GDPR) and UK data protection laws.
  3. Unified & Auditable Electronic Health Records (EHR): Omega maintains a single, structured patient record that follows the patient seamlessly from digital triage through to face-to-face treatment, eliminating fragmented medical history and ensuring a secure, comprehensive clinical audit trail.

Secure API Interoperability

We build clinical technology to connect care pathways securely, not to isolate them.

Our platforms integrate seamlessly via secure APIs with industry-leading systems, enabling the secure electronic transfer of member clinical records with no manual double-entry, reducing data input errors and ensuring record parity:

  • DTAC (Digital Technology Assessment Criteria): RHT software is fully assessed against the NHS Digital Technology Assessment Criteria, demonstrating total compliance across clinical safety, data protection, technical security, interoperability, and usability.
  • ISO 27001 Certification: We operate an Information Security Management System (ISMS) certified to ISO 27001 standards, ensuring corporate data security protocols are consistently applied across all product lines.
  • Bupa
  • Health Partners
  • AXA
  • Vitality
  • NHS
  • Circle Health Group