RESILIENCE
Business continuity at MedTalk
How MedTalk maintains continuity of the MedTalk AI service, and plans, tests, and governs its ability to recover from a disruption.
Purpose
This policy sets out how MedTalk maintains continuity of the MedTalk AI service for its customers in the event of a disruption, and how MedTalk plans, tests, and governs its ability to recover. It is owned by the Chief Executive Officer and overseen by MedTalk's Executive Steering Committee under MedTalk's Enterprise Governance Framework.
Business impact analysis
MedTalk maintains a Business Impact Analysis (BIA) that identifies critical service components, the impact of their disruption, and the Maximum Tolerable Downtime (MTD) for each.
| Critical service component | Impact if disrupted | Maximum tolerable downtime |
|---|---|---|
| Ambient capture and transcription | Clinicians revert to manual documentation; no clinical data loss | 4 hours |
| Clinical note generation and review UI | Clinician workflow delayed; manual documentation fallback available | 4 hours |
| Identity and access (SSO) | Clinicians unable to authenticate to MedTalk AI | 2 hours |
| Data storage and backup infrastructure | No new data loss risk while degraded; recovery time critical | 4 hours |
Recovery priorities
Recovery follows a fixed priority order:
- 1Restore clinician authentication and platform availability
- 2Restore ambient capture and note generation
- 3Restore full reporting and administrative functions
This order reflects the fact that MedTalk AI is a documentation support tool, not a system of record, so clinical operations can continue using existing manual documentation processes while MedTalk AI is restored.
Alternate operating arrangements
Because MedTalk AI operates alongside, rather than in place of, a customer's existing clinical documentation processes, clinicians retain the ability to document manually at all times. This means a MedTalk AI service disruption does not interrupt clinical care, only the efficiency benefit MedTalk AI provides. This significantly reduces the clinical continuity risk associated with any single point of failure in the MedTalk AI platform.
Pandemic and workforce disruption planning
MedTalk's operations, engineering, and support functions are structured for remote delivery, so a localised event affecting a single office or region does not materially affect MedTalk's ability to support its customers. Key operational roles, including the CISO, Clinical Safety Officer, and Operations Lead, have documented delegates who can act in their absence.
Crisis management and communications
- Crisis Management Team: A disruption affecting MedTalk AI availability activates MedTalk's crisis management process, led by the CEO or delegate, with the CISO and Operations Lead as standing members.
- Communications: Customers are notified in line with the severity and communication timeframes set out in MedTalk's Service Level Agreements and Incident Response Tiers, with a single named point of contact for the duration of the disruption.
- Post-Incident Review: Every activation of the crisis management process is followed by a documented post-incident review, with findings tracked to closure and reported to the Executive Steering Committee.
Recovery governance
Business continuity governance sits with MedTalk's Executive Steering Committee, with operational ownership held by the Chief Executive Officer and technical execution led by the Chief Information Security Officer. This mirrors the governance structure set out in MedTalk's Enterprise Governance Framework.
Testing and review
- Annual Exercise: MedTalk commits to exercising this Business Continuity Management Policy at least annually, using a scenario-based walkthrough of a significant service disruption.
- Quarterly Component Testing: Underlying recovery mechanisms, including backup restoration, are tested quarterly as set out in MedTalk's Disaster Recovery Plan.
- Policy Review: This policy is reviewed at least annually, and following any activation of the crisis management process, to incorporate lessons learned.
Contact
Security & Compliance: support@medtalk.co
Legal / compliance: legal@medtalk.co