Compliance
This page is for registered managers and coordinators. It covers the four rules that shaped how WholeVisit is built, and what each one means for what you see on screen.
Home care is regulated on its records. That is why WholeVisit’s record is the product rather than a module bolted to the side of it. The pages in this section describe what the platform actually does. What it does not do is on What WholeVisit does not claim.
CQC Regulation 17: good governance
Section titled “CQC Regulation 17: good governance”Regulation 17 asks for records that are accurate, complete, contemporaneous and securely kept, and for a provider who can show what happened and when.
In WholeVisit that means every change to a care record writes a line saying who made it, when, and what moved. Records are written at the point of care rather than typed up later: check-in, checklist ticks and medication answers all carry the server’s clock, and there is no box to type a time into. A correction never writes over the thing it corrects. It becomes a new entry pointing back at the old one, with a reason, so an inspector reads both.
NHS DSCR: the core capabilities
Section titled “NHS DSCR: the core capabilities”The Digital Social Care Record standard sets out what a care record system has to be able to do. The one that shapes WholeVisit hardest is capability 4, the audit trail: the system has to record every change and every access, and keep that record safe from editing.
WholeVisit logs reads as well as writes. Opening a client’s record writes a line. So does opening a list of care records, along with the filter that was on screen. The trail is append-only in the application, in the database itself, and by sealing each line against the one before it. The audit trail covers how to read it.
NICE NG67: managing medicines
Section titled “NICE NG67: managing medicines”NG67 says what a medicines record has to carry and how it has to behave. A medication line records the name, strength, form, dose, route, quantity, timing and any special instructions, whether it is taken as needed, and how much support the person needs to take it. Controlled drugs need a second person to witness.
A dose is recorded against a visit somebody has checked in to, and a dose that was not given records why. Answers are never overwritten: recording again supersedes, and voiding an answer needs a reason. Every client has a monthly medication chart you can read and print.
UK GDPR Article 9: special-category data
Section titled “UK GDPR Article 9: special-category data”Health data gets stronger protection than ordinary personal data. WholeVisit treats every care record as health data.
Access is scoped to the role: support workers see their own published visits and only the clients they visit, and every coordinator surface is closed to them in the navigation, in the URL and at the API. Every read is logged. Photographs and documents sit behind an authorised route, never a public address. Emails and logs never name a client or say what happened on a visit; they say a visit needs attention and link into the platform.
Nothing that is care data is deleted outright. A removal is a removal, retention runs for eight years, and destruction afterwards is a separate act with a reason and its own log. Retention and removal covers it, and Subject access covers answering a request for a copy of somebody’s record.