Data and privacy
This is a local developer example, not a clinical application. Use only synthetic patient data.
- Every valid search sends your criteria and a Base64-encoded audit identity to the NHS Wales public sandbox. There is no offline mock mode or local fallback. API authentication is optional and disabled by default; when enabled, an application bearer token is sent and authentication failures stop the query.
- API authentication uses a server-side RSA private key to obtain access tokens. Tokens are cached in server memory, not sent to the browser or stored in a database. This authenticates the application, not the person using it.
- Public sandbox responses may use fixed message IDs. The app displays a warning when these differ from the request; results are always labelled demonstration fixtures.
- No patient records, searches, credentials or audit identities are deliberately written to application logs or a database. Logs include result counts, message IDs and safe error codes.
- Searches use POST and responses include no-store headers. Patient data still exists in server memory and the displayed browser page; these headers are not a guarantee of secure deletion.
- The manual audit identity is for demonstrations only. A deployed app must derive it from authenticated user claims and enforce access authorization.
- Before real use, add approved authentication, authorization, provider-approved auditing, retention controls, operational monitoring and information-governance review.