Prompt

How do I ensure my guided self-help programs with a CBT exercises platform are compliant?

Latest observation

Jul 22, 2026 · OpenAI APIWeb search: off

To make guided self-help programs on a CBT exercises platform compliant, you’ll want to cover clinical, legal, privacy, and safety requirements. The exact rules depend on your country and whether the platform is considered a medical device, a digital therapeutic, or just educational/self-help content.

1) Clarify what your product is

Start by defining:

  • Who the user is: general wellbeing users, people with mild/moderate symptoms, or patients with a diagnosis
  • What the platform does: self-help only, coached by a human, or clinician-directed treatment
  • What claims you make: “improves mood” is different from “treats depression”

This matters because your regulatory obligations change a lot based on claims and intended use.

2) Get clinical governance in place

For CBT content and guided self-help, you should have:

  • A qualified clinical lead overseeing exercises and pathways
  • Evidence-based content reviewed against recognized CBT principles
  • A documented process for content approval, version control, and clinical review
  • Clear rules for when users should be escalated to human support or emergency services

3) Build safety and risk management

Make sure you have:

  • Screening for risk factors before or during use
  • Crisis detection and escalation pathways for suicidality, self-harm, psychosis, abuse, or severe deterioration
  • Clear disclaimers that self-help is not a substitute for emergency care
  • Human review protocols for guided programs, especially if a coach/therapist is involved

If the platform offers guided support, define:

  • Response time expectations
  • Boundaries of the guide’s role
  • What guides can and cannot say or do

4) Privacy and data protection

You’ll need a strong privacy program:

  • Collect only the data you need
  • Obtain valid consent where required
  • Publish a clear privacy notice
  • Use encryption in transit and at rest
  • Set retention/deletion policies
  • Control access internally with least privilege
  • Have processes for data subject rights requests

Depending on your jurisdiction, this could involve GDPR, UK GDPR, HIPAA, CCPA/CPRA, or other laws.

5) Be careful with regulated health claims

Avoid claims that may trigger medical regulation unless you’re prepared for it.

Examples:

  • Lower risk: “supports healthy coping skills”
  • Higher risk: “treats anxiety disorder” or “prevents relapse of depression”

If you want clinical/therapeutic claims, you may need:

  • Medical device assessment/registration
  • Quality management system
  • Clinical evidence
  • Post-market surveillance

6) Ensure accessibility and informed use

For compliance and good practice:

  • Make the program accessible (WCAG standards)
  • Use plain language
  • Explain limitations of the service
  • Let users know what guided self-help is and isn’t
  • Ensure consent and onboarding are understandable

7) Put operational controls in place

You should have documented:

  • Training for all staff and guides
  • Incident reporting and complaint handling
  • Monitoring for adverse events
  • Audit logs and security monitoring
  • Vendor management for any third-party tools or hosting

8) Check country-specific requirements

Compliance differs by location. For example:

  • US: HIPAA may apply if you’re a covered entity or business associate; FDA rules may apply if you make treatment claims
  • EU/UK: GDPR/UK GDPR, plus possible medical device rules depending on intended use
  • Australia/Canada/other jurisdictions: local privacy, health, and device rules may apply

9) Get the right specialists involved

You’ll likely need help from:

  • Health/medical regulatory counsel
  • Privacy counsel or DPO
  • Clinical psychologist/psychiatrist advisor
  • Security/compliance professional
  • Product/legal team for claims and terms

10) Create a compliance checklist

A practical checklist:

  • Define intended use and claims
  • Review regulatory classification
  • Clinical review of all CBT content
  • Risk screening and escalation pathways
  • Privacy policy and consent flow
  • Security controls and vendor review
  • Accessibility review
  • Staff training and supervision
  • Incident and adverse-event procedures
  • Documented audit trail and version control

If you want, I can turn this into a jurisdiction-specific compliance checklist for:

  1. US
  2. UK/EU
  3. Australia
  4. Canada

Or I can help you draft a guided self-help compliance framework for your platform.

Observation history

Unlock observation history
Create a free Obsurfable account to unlock historical responses, model comparisons, and deeper brand intelligence.

How did Obsurfable measure this prompt?

Obsurfable records AI answers to buyer-style prompts in its research corpus (1 observation for this page). Metrics are distributions over observations, not a single static ranking.

Which AI systems does Obsurfable collect answers from?

OpenAI, ChatGPT, Google, Gemini, Google AI Mode, Anthropic, Claude, Perplexity, Grok, DeepSeek, Mistral, Copilot, and Meta AI.