Solutions — Digital Health · GDPR

The patient field that never hit the logs

How a digital-health team survived hotfix pressure without Article 9 data ever reaching a plaintext log — because the check doesn't get tired on a Tuesday.

EU AI Act Annex III high-risk obligations for health-adjacent AI systems now apply from December 2, 2027. The deadline moved — the excuse to wait didn't. Start tracking compliance now.

TUESDAY, 09:15 — HOTFIX

Under pressure to ship a hotfix, someone flips a logger to debug. Patient-record fields start flowing into plaintext logs — in staging today, production on Friday. The diff is 4 lines; the review takes 40 seconds.

TUESDAY, 09:15:04 — CI

The gate fails the pull request: unmasked patient identifier in log output, Article 9 data, rule and line cited — masked evidence only. The hotfix ships 20 minutes later, without the logger.

The hotfix still shipped that morning. The patient data didn't.

The problem we kept living

Before the gate, there was the incident report

If you process health data, you already know this document:

  • Logging discipline lived in a code-review checklist — reliable right up until the first urgent hotfix.
  • Article 9 data has no "minor leak" category. One patient field in a log file is a reportable event, a 72-hour clock, and a very long week.
  • Review caught what reviewers had time to read. A 4-line hotfix diff at 09:15 gets 40 seconds, not scrutiny.
  • Every audit asked the same question — "how do you prevent PHI in logs?" — and the honest answer was "we ask people to be careful."

So "be careful" stopped being the control and the merge check became it.

What it does

The guided tour — from commit to evidence

01

A rule your DPO can read

Compliance rules are plain declarations — what to detect, where to look, what happens on a hit. The GDPR detective pack ships ready; your org adds its own patient-identifier signatures without asking us.

RULE · DC-MED-007BLOCKS MERGE
Detectpatient identifier in log output
Wheresrc · logging config
CitesGDPR Art. 9, 32
02

The merge that fails politely

A hit fails the check with the file, line, and rule — and masked evidence only. The reviewer sees enough to fix it; the value itself never leaves your CI runner.

PR #904 · CHECK RESULTFAILED
src/billing/logger.ts:88patient_id=P-2***
RuleDC-MED-007 · critical
Evidencemasked · runner-local
03

Drift, scored between releases

Hourly process rules score review coverage, incident hygiene and documentation habits against your Jira and GitHub activity — so slipping standards show up as a trend, not as the next incident report.

COMPLIANCE · BY DOMAINTHIS SPRINT
Patient-data handling97%
Incident hygiene93%
Review coverage89% ↘
04

Sign-off that stays locked

What needs human judgment — the clinical-risk checklist, the DPIA confirmation — gets a named reviewer and a locked gate. The result exports signed and timestamped: evidence, not screenshots.

RELEASE GATE · PATIENT PORTAL 2.4LOCKED
CI scan — 9 reposPASSING
DPIA confirmation · Dr. Brandtawaiting sign-off
Audit exportsigned · sha256:4be1…
What changed

The same audit, one release later

Before

  • —"How do you prevent PHI in logs?" — "We ask people to be careful"
  • —Every hotfix was a coin flip under a 72-hour clock
  • —Logging discipline was a checklist item
  • —Audit evidence was screenshots assembled the week before

After

  • ✓It's a blocking check — the answer is a rule ID and a scan ledger
  • ✓The hotfix path has the same gate as everything else
  • ✓It's a named rule that fails the merge
  • ✓Point-in-time snapshots export signed, in one click
Is this for you

An honest fit check

This fits if

  • ✓You process patient or health data under GDPR Article 9
  • ✓Your team merges through pull requests on GitHub or GitLab
  • ✓Hotfix pressure is real and reviews get thin exactly when risk is highest
  • ✓You'd rather block a merge than start a 72-hour notification clock

And honestly, if

  • ·You need semantic judgment — "is this clinical logic safe?" is a human's call. PulseCheck routes it to a locked, role-restricted attestation instead of pretending to detect it.
  • ·You don't merge through CI — the gate has nothing to hook into.
  • ·You want developer-level scorecards — deliberately not built, and it won't be.
NewExpert Review

Put the judgment calls to an independent lawyer

Some questions stay a human's call. With Expert Review you can also put them to an independent, licensed lawyer, and their verdict appears next to each rule.

How Expert Review works →

Digital health compliance FAQ

Can PulseCheck block a pull request?

Yes. The CI Action runs your organization's ruleset against every diff and fails the check when a defined signature (a plaintext patient identifier, a hardcoded credential) is present — configure it as a required status check and the PR cannot merge.

Does PulseCheck read our source code?

The scan runs inside your own CI runner. Findings are masked before they ever leave it — PulseCheck's servers see a match/no-match result and a masked snippet, never your raw source or patient data.

Does it detect flawed consent logic or clinical-safety issues?

No — honestly. That's a judgment call, not a pattern match. PulseCheck routes it to a locked sign-off task a named reviewer must explicitly attest, with the attestation recorded in an audit-ready export. With Expert Review you can also put that question to an independent, licensed lawyer.

How does PulseCheck help with GDPR Article 9?

PulseCheck ships a GDPR rule template pack covering special-category (health) data handling, evaluated hourly against your Jira/GitHub activity, plus a compliance gate with a locked sign-off task and a signed, timestamped export for your audit trail.

Which compliance frameworks ship as templates?

GDPR, EU AI Act, DORA, and a general QA/incident-management pack ship as ready-to-install rule templates — install one and PulseCheck starts scoring your existing data against it immediately.

Bring us your riskiest hotfix path

A 20-minute walkthrough is enough to see your own repository scanned. First rule live the same day — before the next 09:15 hotfix.