New: BookedSolid is now ISO 27001 Certified! Learn about our certification
Blog
announcementAugust 26, 2026·6 min read

BookedSolid Is Now ISO 27001 Certified: What It Means for Your Clinic

BookedSolid is now ISO 27001 certified. What the standard covers, how it goes beyond GDPR, and what certification means for clinics and multi-site groups.

By Oliver Crockett
securitycompliancehealthcare

Independently audited against the industry standard for information security, so clinics do not have to take BookedSolid's word for it.

BookedSolid, the AI receptionist for healthcare clinics, is now certified against ISO/IEC 27001, the international standard for information security management. Certification followed an independent audit of how BookedSolid manages information security across the whole business: not just the software, but the people, processes and suppliers behind it.

For practice managers and clinic owners, the announcement answers a simple question: can this company be trusted with patient data? Until now, the honest answer from any software supplier rested on its own claims. An accredited auditor has now examined how BookedSolid protects that data, and certified that its security management meets the standard.

This article covers what was certified, what ISO 27001 actually involves, why BookedSolid pursued it, and what it changes for clinics of every size, from single-practitioner practices to multi-site and enterprise groups.

In short BookedSolid is now ISO 27001 certified, following an independent audit by an accredited certification body. GDPR, the Australian Privacy Principles and the New Zealand Privacy Act are the legal floor for handling patient data; ISO 27001 is voluntary proof of going further, with audited security processes and annual surveillance audits. A copy of the certificate is available to any clinic that requests it.

BookedSolid Achieves ISO 27001 Certification

BookedSolid is now ISO 27001 certified: GDPR is the legal minimum, ISO 27001 is independently audited proof of going beyond it

BookedSolid has been certified against ISO/IEC 27001:2022 following an independent audit by British Assessment Bureau Limited. The certificate was issued on 04/08/2026 under certificate number 272627.

The certified scope is “Provision of AI communication and appointment management software for the healthcare and clinical sectors, including integration with practice management systems and automated patient engagement services from the UK”. In plain terms, it covers the management system BookedSolid uses to protect clinic and patient information across its platform and operations.

Certification is not a one-off badge. It is maintained through annual surveillance audits, covered later in this article, and the current certificate details are kept on the BookedSolid security page. A copy of the certificate is available to any clinic that needs it for its records, and can be downloaded directly here (PDF).

What Is ISO 27001?

ISO/IEC 27001 is the international standard for information security management, published jointly by the International Organization for Standardization and the International Electrotechnical Commission. It is widely described as the industry standard for information security.

The standard certifies an information security management system: the policies, risk assessments, controls, documentation and evidence that govern how an organisation protects information day to day. An auditor examines how risks are identified, how access is controlled, how staff are trained, how suppliers are vetted and how incidents would be handled, then verifies that the organisation actually operates the way its documentation says it does.

That makes certification a matter of processes and documentation rather than a plaque on the wall. It cannot be bought or self-declared; it has to be earned through an independent audit and defended at every surveillance audit that follows.

GDPR Is the Legal Floor: ISO 27001 Goes Further

Every company handling patient data in the UK or EU already has to comply with GDPR. That compliance is required by law, so it tells a clinic nothing about which suppliers take security seriously; it is the floor every supplier must stand on.

The same logic applies in BookedSolid's other markets. Australian clinics are covered by the Australian Privacy Principles, and New Zealand clinics by the Privacy Act 2020. Each sets the legal minimum for handling personal information in its country, and BookedSolid builds to all three.

ISO 27001 sits above that floor. No law requires it. A company pursues it by choice, and invites an external body to test its security management every year.

GDPR, the APPs and the NZ Privacy ActISO 27001
Legal statusRequired by law for any company handling personal dataVoluntary: pursued and paid for by choice
Who checksA regulator, usually after something has gone wrongAn accredited certification body, before certification and at every annual audit
What it coversHow personal data is collected, used and protectedThe whole information security management system: people, processes, suppliers and technology
What it signalsThe supplier meets the legal minimumThe supplier chose to be audited against the industry standard
"GDPR is the legal minimum; every provider has to meet it. ISO 27001 is choosing to be audited, every year, against the industry standard for information security. We wanted patient data protection to be something clinics can verify, not something they have to take on trust." — Oliver Crockett, co-founder, BookedSolid

Why BookedSolid Pursued Certification

The push came from BookedSolid's enterprise pipeline. A large multi-site group had been in conversation with BookedSolid for some time. The product fit was there; the group's investors were not prepared to approve a supplier without ISO 27001. Certification was the condition of the deal being possible at all.

That pattern is not unusual. Larger healthcare groups increasingly run supplier decisions through formal due diligence, and information security certification is one of the first boxes on the list. For a buyer's finance director, IT lead or investor, a certificate from an accredited auditor settles in one line what a security questionnaire takes weeks to establish.

"Enterprise customers want proof, not promises. We kept seeing ISO 27001 come up as the tipping point in enterprise decisions: the point where a security conversation either moves forward or stops," says Thomas Wojtowicz, co-founder of BookedSolid.

What It Means for Your Clinic

For most clinics, nothing changes on day one. Calls are answered, bookings land in the diary, and reminders go out exactly as before. The audit did not change how the product works; it examined and certified the way BookedSolid already works.

What changes is assurance. A clinic no longer has to weigh a supplier's security claims on trust, because an accredited third party has audited them. In practical terms, every clinic on BookedSolid can now point to:

  • Independently audited security processes, re-examined at every annual surveillance audit
  • A certificate that drops straight into practice governance and compliance records
  • A standard Data Processing Agreement, available on request
  • Confidence and trust for whoever signs off on suppliers
How BookedSolid protects patient data Certification sits on top of the security model BookedSolid was built with: an in-house platform rather than one assembled on third-party agent tools, data minimisation throughout, encryption in transit and at rest, role-based and fully auditable access, and UK and EU clinic data kept within the UK and EU. Patient data is never sold or shared. Read the full security overview

What It Means for Multi-Site and Enterprise Groups

For larger groups, the certification lands where buying decisions actually happen: procurement and due diligence. Security questionnaires can reference a certified information security management system rather than a stack of self-declared answers, the Data Processing Agreement is standard, and the certificate is available up front.

For large and growing clinic groups in the UK, Australia, and New Zealand, ISO 27001 shortens the path from security review to sign-off, because the hardest questions have already been answered by an auditor.

In the UK, the certification sits alongside the NHS Data Security and Protection Toolkit, the standard NHS-affiliated organisations use to assess how patient data is handled.

What Happens Next

ISO 27001 certification is an ongoing process. The certification body returns for a surveillance audit every year, with full recertification on a three-year cycle, so the certificate only stays valid while the security management keeps passing.

Continual improvement is itself a requirement of the standard, and a value that is core to BookedSolid. Risks are reassessed as the product and the threat landscape change, and processes are updated to match. BookedSolid will keep the security page current with certification details, so clinics and procurement teams always have one place to check.

Patient data, handled properly

BookedSolid answers every patient call with security that has now been independently audited and certified. Read how patient data is protected, or see the platform for yourself.

BookedSolid ISO 27001 FAQs

Is BookedSolid ISO 27001 certified?

Yes. BookedSolid is certified against ISO/IEC 27001:2022, following an independent audit by an accredited certification body. The certificate covers BookedSolid's information security management system, and a copy is available to any clinic or procurement team that requests one.

What does ISO 27001 cover?

ISO 27001 covers an organisation's information security management system: the policies, processes, controls and evidence that govern how information is protected, including risk assessment, access control, supplier vetting and incident handling. Certification means an accredited auditor has verified the system works as documented.

Is ISO 27001 required for healthcare clinics?

There is no legal requirement for a clinic, or its software suppliers, to hold ISO 27001. It is a voluntary data security standard rather than a healthcare-specific one. A clinic's legal duties sit under GDPR, the Australian Privacy Principles or the New Zealand Privacy Act, and choosing certified suppliers is one way to support them.

Does ISO 27001 replace GDPR compliance?

ISO 27001 complements GDPR rather than replacing it. GDPR is the legal requirement for handling personal data; ISO 27001 is a voluntary standard that audits the security management behind it. BookedSolid maintains both, alongside the Australian Privacy Principles, the New Zealand Privacy Act and the NHS Data Security and Protection Toolkit.

Where is patient data stored?

UK and EU clinic data stays within the UK and EU. Access to patient data is role-based and fully auditable, every interaction is encrypted in transit and at rest, and BookedSolid applies data minimisation throughout, accessing only the details needed for the specific call, message or booking. Patient data is never sold or shared.

Can clinics see the certificate or get a DPA?

Yes. A copy of the ISO 27001 certificate and a standard Data Processing Agreement are available on request, and both are designed to drop straight into a clinic's compliance records. The security page carries the current certification details, and the certificate can also be downloaded directly (PDF).

Summarise with AI

Open this article pre-loaded into an AI assistant for a quick summary.