HANA Trust Centre

Responsible AI for healthcare Last updated: July 2026  ·  Version 1.0

Welcome to the HANA Trust Centre. HANA is the artificial intelligence built into HealthAccess, and this page is here to help your organisation understand how we develop, deliver and govern AI responsibly — and how we protect the information you trust us with. It works alongside our Privacy Policy and Support & Security Policy, which remain the authoritative sources for our privacy and security practices.

What is HANA?

HANA is the artificial intelligence platform within HealthAccess, providing AI features designed to help organisations work more efficiently while keeping people in control. AI features are optional and are not switched on by default: your organisation chooses whether to enable them and who can use them.

HANA Today

Current AI Feature

  • HANA Scribe (Beta) — HANA Scribe assists healthcare professionals by converting recorded consultations into draft clinical documentation for review.

As additional HANA AI features are released, they will be added to this Trust Centre together with feature-specific information where appropriate.

Responsible AI

Everything we build within HANA is guided by seven principles, applied consistently across every AI feature:

  • Human oversight — HANA produces drafts and suggestions for a person to review; a human stays in control.
  • Transparency — we show when content is AI-assisted or AI-generated, and we keep this Trust Centre up to date.
  • Privacy by design — AI features are off by default, and we use only the information needed for a task.
  • Security by default — HANA runs inside the same secure HealthAccess platform, protected by the same controls.
  • Fairness and reliability — we know AI accuracy can vary, so every feature is designed to be reviewed before it is relied on.
  • Accountability — we take responsibility for how we build and operate our AI features.
  • Continuous improvement — we keep improving HANA over time through testing, development and your feedback.

The sections below explain what these principles mean in practice.

Human Oversight and Clinical Safety

HANA is built to support healthcare professionals, not to replace them. Anything HANA produces is a draft until an appropriate person has reviewed it and, where needed, approved it.

HANA is designed as an AI-assisted documentation and workflow tool. It does not diagnose, prescribe, or make clinical decisions on its own; it is not intended for emergency, time-critical or life-threatening decision making; and it must not replace appropriate professional judgement or the informed consent process.

Where output will be used for clinical or other regulated purposes, an appropriately qualified healthcare professional must review it first, in line with their professional and regulatory obligations (for example those of the HPCSA or SANC where relevant). The healthcare professional remains responsible for the accuracy and completeness of the final clinical record.

Roles and Responsibilities

Using HANA responsibly is a shared effort:

  • HealthAccess provides the AI features and, for the Personal Information processed through them, acts as the Operator — handling data on your organisation's documented instructions.
  • Your organisation is the Responsible Party for its patient or client information. You decide which AI features to enable and for whom, set your own internal AI and review policies, and make sure there is a lawful basis for the information you process.
  • Authorised users use AI features only within their role, review AI output before relying on it, and keep their login details secure.

If you enable features that record or transcribe consultations, your organisation is responsible for obtaining and recording any consent needed from the individual beforehand, and for letting people know that AI may be in use. Our Privacy Policy explains this in full.

Transparency

We believe AI should be transparent. When AI has helped produce content, we show that it is AI-assisted or AI-generated, and we remind users that this output is a draft to review before relying on it. This Trust Centre is part of that openness: we keep it current and version controlled, so you can see how our AI features and practices change over time.

Privacy and Data Handling

This is a short, plain-language summary; our Privacy Policy is the complete and authoritative source.

When your organisation turns on AI features, Personal Information entered into or created within the platform may be processed by AI — for example to transcribe, summarise, generate or respond to information. Some of this may be Special Personal Information (health information), which POPIA protects more strictly. Your organisation is the Responsible Party for this information and decides how long it is kept; HealthAccess acts as the Operator.

We do not use identifiable patient or client information to train AI or foundation models unless your organisation has given a lawful basis and any required consent, and this has been recorded. We may use de-identified and aggregated data, and feedback, to improve our services.

AI Providers and Data Location

To deliver HANA, information may be processed by one or more AI sub-processors — the foundation models, AI providers and orchestration layers behind the AI features — which may change over time as the technology develops. These providers work under contract and may not use your information for their own purposes.

Some processing may take place outside your jurisdiction, with appropriate safeguards, as explained in the International Transfers section of our Privacy Policy. A current list of approved sub-processors, including AI providers where relevant, is available on request.

Security

HANA is protected by the same platform security controls as the rest of HealthAccess. A short summary is below; our Support & Security Policy is the complete and authoritative source.

  • Encryption of data in transit and, where applicable, at rest.
  • Authentication controls, including multi-factor authentication where available.
  • Role-based, least-privilege access, limited to what each person needs.
  • Audit logging and continuous monitoring for availability, performance and unusual activity.
  • Secure development, controlled releases, change management and vulnerability management.
  • Hosting with reputable cloud providers, and daily encrypted backups kept in geographically separate locations.
  • An incident-response approach, with affected customers notified without undue delay.

We describe these controls at a high level and do not publish sensitive detail. We work to keep the platform available and secure, though no online service can be free of all risk.

How We Govern AI

HANA sits within a clear governance framework:

  • The use of HANA AI features is subject to the applicable agreement between HealthAccess and your organisation.
  • AI features are optional and role-based — they are enabled by choice and can be made available differently depending on plan, organisation, role, permissions and regulatory requirements.
  • A person stays involved — we do not use AI to make decisions about someone by automated means alone where those decisions would significantly affect them, except where the law allows.
  • We keep pace with regulation — we follow developments in data protection, AI regulation and professional guidance, and may adjust, restrict or pause a feature as needed to stay compliant.

Within this framework, your organisation governs how HANA is used day to day and may set its own internal AI policies for your team.

AI Limitations

Being open about limitations is part of building trust. Like all AI, HANA can produce output that is inaccurate, incomplete, outdated, biased or invented, and its accuracy can vary with language, accent, terminology, context and audio quality. In practice, it may occasionally mishear speech, mistake who is speaking, miss an important detail, misunderstand specialist terms, or generate wording that was not actually said.

For this reason, AI output should always be reviewed — and corrected where needed — by an appropriate person before it is relied on, shared or saved.

Frequently Asked Questions

Does HANA replace healthcare professionals?

No. HANA assists by producing drafts and suggestions. Professional judgement and responsibility always stay with the appropriate person.

Can HANA be used for urgent or clinical decisions?

No. HANA is designed as an AI-assisted documentation and workflow tool and is not intended for emergency or time-critical decision making. Clinical decisions and professional judgement always remain with an appropriate healthcare professional.

Are AI features switched on automatically?

No. AI features are optional and off by default. Your organisation chooses whether to enable them and who can use them.

Can AI make mistakes?

Yes. AI output can be inaccurate or incomplete, so it should always be reviewed before it is relied on or saved.

Is consent needed to record a consultation?

Your organisation, as the Responsible Party, is responsible for obtaining and recording any consent needed before recording, and for letting people know AI may be in use.

Do you use our data to train AI models?

We do not use identifiable patient or client information to train AI or foundation models unless a lawful basis and any required consent are in place and recorded. We may use de-identified and aggregated data, and feedback, to improve our services.

Which AI providers do you use, and where is data processed?

HANA relies on AI sub-processors that may change over time, and some processing may happen outside your jurisdiction with appropriate safeguards. See our Privacy Policy, and request our current sub-processor list at any time.

Who owns the notes and records created with HANA?

Your organisation keeps ownership of its own data and of the final content of the records and documents your team reviews, adopts and saves.

Contact and Feedback

We welcome your questions and feedback about HANA — it helps us improve. For support, to report inaccurate output, or to request our sub-processor list, please contact the HealthAccess support team via the Contact Us page. For privacy questions and data requests, see the Contact & Complaints section of our Privacy Policy; HealthAccess has an appointed Information Officer registered with the Information Regulator.

Related Information

The HANA Trust Centre complements our existing documentation. For more detail, please see: