Prompt
How do I ensure my guided self-help programs with a CBT exercises platform are compliant?
Latest observation
To make guided self-help programs on a CBT exercises platform compliant, you’ll want to cover clinical, legal, privacy, and safety requirements. The exact rules depend on your country and whether the platform is considered a medical device, a digital therapeutic, or just educational/self-help content.
1) Clarify what your product is
Start by defining:
- Who the user is: general wellbeing users, people with mild/moderate symptoms, or patients with a diagnosis
- What the platform does: self-help only, coached by a human, or clinician-directed treatment
- What claims you make: “improves mood” is different from “treats depression”
This matters because your regulatory obligations change a lot based on claims and intended use.
2) Get clinical governance in place
For CBT content and guided self-help, you should have:
- A qualified clinical lead overseeing exercises and pathways
- Evidence-based content reviewed against recognized CBT principles
- A documented process for content approval, version control, and clinical review
- Clear rules for when users should be escalated to human support or emergency services
3) Build safety and risk management
Make sure you have:
- Screening for risk factors before or during use
- Crisis detection and escalation pathways for suicidality, self-harm, psychosis, abuse, or severe deterioration
- Clear disclaimers that self-help is not a substitute for emergency care
- Human review protocols for guided programs, especially if a coach/therapist is involved
If the platform offers guided support, define:
- Response time expectations
- Boundaries of the guide’s role
- What guides can and cannot say or do
4) Privacy and data protection
You’ll need a strong privacy program:
- Collect only the data you need
- Obtain valid consent where required
- Publish a clear privacy notice
- Use encryption in transit and at rest
- Set retention/deletion policies
- Control access internally with least privilege
- Have processes for data subject rights requests
Depending on your jurisdiction, this could involve GDPR, UK GDPR, HIPAA, CCPA/CPRA, or other laws.
5) Be careful with regulated health claims
Avoid claims that may trigger medical regulation unless you’re prepared for it.
Examples:
- Lower risk: “supports healthy coping skills”
- Higher risk: “treats anxiety disorder” or “prevents relapse of depression”
If you want clinical/therapeutic claims, you may need:
- Medical device assessment/registration
- Quality management system
- Clinical evidence
- Post-market surveillance
6) Ensure accessibility and informed use
For compliance and good practice:
- Make the program accessible (WCAG standards)
- Use plain language
- Explain limitations of the service
- Let users know what guided self-help is and isn’t
- Ensure consent and onboarding are understandable
7) Put operational controls in place
You should have documented:
- Training for all staff and guides
- Incident reporting and complaint handling
- Monitoring for adverse events
- Audit logs and security monitoring
- Vendor management for any third-party tools or hosting
8) Check country-specific requirements
Compliance differs by location. For example:
- US: HIPAA may apply if you’re a covered entity or business associate; FDA rules may apply if you make treatment claims
- EU/UK: GDPR/UK GDPR, plus possible medical device rules depending on intended use
- Australia/Canada/other jurisdictions: local privacy, health, and device rules may apply
9) Get the right specialists involved
You’ll likely need help from:
- Health/medical regulatory counsel
- Privacy counsel or DPO
- Clinical psychologist/psychiatrist advisor
- Security/compliance professional
- Product/legal team for claims and terms
10) Create a compliance checklist
A practical checklist:
- Define intended use and claims
- Review regulatory classification
- Clinical review of all CBT content
- Risk screening and escalation pathways
- Privacy policy and consent flow
- Security controls and vendor review
- Accessibility review
- Staff training and supervision
- Incident and adverse-event procedures
- Documented audit trail and version control
If you want, I can turn this into a jurisdiction-specific compliance checklist for:
- US
- UK/EU
- Australia
- Canada
Or I can help you draft a guided self-help compliance framework for your platform.