The patient field that never hit the logs
How a digital-health team survived hotfix pressure without Article 9 data ever reaching a plaintext log — because the check doesn't get tired on a Tuesday.
EU AI Act Annex III high-risk obligations for health-adjacent AI systems now apply from December 2, 2027. The deadline moved — the excuse to wait didn't. Start tracking compliance now.
TUESDAY, 09:15 — HOTFIX
Under pressure to ship a hotfix, someone flips a logger to debug. Patient-record fields start flowing into plaintext logs — in staging today, production on Friday. The diff is 4 lines; the review takes 40 seconds.
TUESDAY, 09:15:04 — CI
The gate fails the pull request: unmasked patient identifier in log output, Article 9 data, rule and line cited — masked evidence only. The hotfix ships 20 minutes later, without the logger.
The hotfix still shipped that morning. The patient data didn't.
Before the gate, there was the incident report
If you process health data, you already know this document:
- Logging discipline lived in a code-review checklist — reliable right up until the first urgent hotfix.
- Article 9 data has no "minor leak" category. One patient field in a log file is a reportable event, a 72-hour clock, and a very long week.
- Review caught what reviewers had time to read. A 4-line hotfix diff at 09:15 gets 40 seconds, not scrutiny.
- Every audit asked the same question — "how do you prevent PHI in logs?" — and the honest answer was "we ask people to be careful."
So "be careful" stopped being the control and the merge check became it.
The guided tour — from commit to evidence
A rule your DPO can read
Compliance rules are plain declarations — what to detect, where to look, what happens on a hit. The GDPR detective pack ships ready; your org adds its own patient-identifier signatures without asking us.
The merge that fails politely
A hit fails the check with the file, line, and rule — and masked evidence only. The reviewer sees enough to fix it; the value itself never leaves your CI runner.
Drift, scored between releases
Hourly process rules score review coverage, incident hygiene and documentation habits against your Jira and GitHub activity — so slipping standards show up as a trend, not as the next incident report.
Sign-off that stays locked
What needs human judgment — the clinical-risk checklist, the DPIA confirmation — gets a named reviewer and a locked gate. The result exports signed and timestamped: evidence, not screenshots.
The same audit, one release later
Before
- —"How do you prevent PHI in logs?" — "We ask people to be careful"
- —Every hotfix was a coin flip under a 72-hour clock
- —Logging discipline was a checklist item
- —Audit evidence was screenshots assembled the week before
After
- ✓It's a blocking check — the answer is a rule ID and a scan ledger
- ✓The hotfix path has the same gate as everything else
- ✓It's a named rule that fails the merge
- ✓Point-in-time snapshots export signed, in one click
An honest fit check
This fits if
- ✓You process patient or health data under GDPR Article 9
- ✓Your team merges through pull requests on GitHub or GitLab
- ✓Hotfix pressure is real and reviews get thin exactly when risk is highest
- ✓You'd rather block a merge than start a 72-hour notification clock
And honestly, if
- ·You need semantic judgment — "is this clinical logic safe?" is a human's call. PulseCheck routes it to a locked, role-restricted attestation instead of pretending to detect it.
- ·You don't merge through CI — the gate has nothing to hook into.
- ·You want developer-level scorecards — deliberately not built, and it won't be.
Put the judgment calls to an independent lawyer
Some questions stay a human's call. With Expert Review you can also put them to an independent, licensed lawyer, and their verdict appears next to each rule.
How Expert Review works →Digital health compliance FAQ
Can PulseCheck block a pull request?
Yes. The CI Action runs your organization's ruleset against every diff and fails the check when a defined signature (a plaintext patient identifier, a hardcoded credential) is present — configure it as a required status check and the PR cannot merge.
Does PulseCheck read our source code?
The scan runs inside your own CI runner. Findings are masked before they ever leave it — PulseCheck's servers see a match/no-match result and a masked snippet, never your raw source or patient data.
Does it detect flawed consent logic or clinical-safety issues?
No — honestly. That's a judgment call, not a pattern match. PulseCheck routes it to a locked sign-off task a named reviewer must explicitly attest, with the attestation recorded in an audit-ready export. With Expert Review you can also put that question to an independent, licensed lawyer.
How does PulseCheck help with GDPR Article 9?
PulseCheck ships a GDPR rule template pack covering special-category (health) data handling, evaluated hourly against your Jira/GitHub activity, plus a compliance gate with a locked sign-off task and a signed, timestamped export for your audit trail.
Which compliance frameworks ship as templates?
GDPR, EU AI Act, DORA, and a general QA/incident-management pack ship as ready-to-install rule templates — install one and PulseCheck starts scoring your existing data against it immediately.