This is a planning framework, not a promise. Every clinic’s ninety days will run differently depending on how tidy its data is, how much time its team can give, and what it chooses to do first.

What follows is a sensible shape for the work, in five movements: understand, select, pilot, measure, expand.

Weeks 1 to 3: understand

Resist the urge to pick a tool. Spend the first weeks finding out how the clinic actually runs, which is rarely how anyone describes it.

  • Walk the journey as a patient. Fill in your own form at 7pm. Send a WhatsApp on Saturday. Time the replies. Read them as a stranger would.
  • Map the systems. Practice management, website forms, messaging, email, payments, marketing CRM, lab portals, spreadsheets. Note where the same fact is typed twice.
  • Sample the record. Take one month of enquiries and follow each to its end: replied, booked, attended, followed up, or lost, and at which point.
  • Ask the team what they would drop first if enquiries doubled tomorrow. The answer is usually immediate, and usually the right place to look.

The output is a short document: where work and patients are being lost, roughly how often, and what information the clinic already holds about each.

Weeks 3 to 4: select

Choose one workflow. Two at most. Good first candidates share six properties:

  1. It happens often, so there is enough volume to learn from.
  2. The team can describe the normal path in one sentence.
  3. Success can be observed in a system, not inferred.
  4. There is a safe route for exceptions, and it leads to a named person.
  5. The information it needs already exists and is reasonably clean.
  6. Someone in the clinic wants it and will own it.

Internal knowledge can use approved operational documents without patient records; business reporting needs its own assessment of the data involved. Enquiry handling and follow-up score well on volume but need more care. Write down the trigger, the owner, the timing, the definition of done and the stop condition before anything is built.

Weeks 5 to 9: pilot

Run small and visible. A pilot nobody can see is not a pilot.

  • Draft first, send later. Begin with every action prepared for a person to approve. Move to automatic sending only for the categories that have proven boringly reliable.
  • Small cohort. One clinician’s list, one channel, or one appointment type.
  • Log everything. Trigger, source data, action prepared, who approved, what happened next. Exceptions and their reasons.
  • Weekly review with the owner: a sample of routine items and every exception.
  • Test the stop. Pause it deliberately, once, and confirm nothing leaks out while it is paused.

Weeks 9 to 12: measure

Compare the same numbers, defined the same way, before and after. If the baseline was not captured in the first three weeks, capture it now and extend the pilot; a claim without a baseline is a story.

Quantitative measures depend on the workflow: time to first meaningful reply, enquiry-to-booking rate, attendance, follow-ups booked within the window, hours of manual work removed. Qualitative measures matter as much: what the team says has changed, what patients say, what the clinician noticed in the room. Then decide, explicitly, one of three things: expand it, adjust it, or stop it. Stopping is a legitimate outcome, and a cheap one at this stage.

Beyond 90 days: expand

Expansion means two things. Widening the proven workflow (more clinicians, more channels, automatic sending for the categories that earned it), and starting a second workflow using what the first taught you about your data and your team. Later projects can reuse what the first taught you about the clinic’s data, working methods and review process.

Running throughout: governance

Health data is special category data under UK GDPR. Assess the proposed processing against the ICO’s DPIA criteria, including its guidance on innovative technology and high-risk processing. Complete a required assessment before the relevant processing starts. Agree the data responsibilities, access and processor arrangements, and explain the use of personal data to the people affected. The timetable must accommodate these decisions rather than assume a fixed launch date makes them complete.

One more boundary. Keep everything in the first ninety days operational. Software that interprets clinical information to inform a diagnosis or treatment decision can be a medical device under the MHRA’s guidance, with a regulatory path to match. That is a different project, for a different day.

What good looks like at day 90

One workflow running, visible, with numbers beside it. A team that trusts it because they can see it and stop it. The applicable data responsibilities documented. A short list of what to do next, written by the people who did the first one. That is not a transformed clinic. It is the beginning of one, on a foundation that will hold.

Sources

  1. ICO, Special category data
  2. ICO, When do we need to do a DPIA?
  3. ICO, Accountability and governance implications of AI
  4. MHRA, Medical devices: software applications (apps)