Romford, London · United Kingdom
Consent-first healthcare data sharing

Secure healthcare technology, built for the UK.

Tan Tech AI helps NHS trusts, private providers and regulated organisations modernise across cloud, AI and Oracle — underpinned by our own method for sharing patient data safely.

2025UK-founded & registered
3Core practices: Cloud, AI & Oracle
UKBased team & data residency
What we do

Consulting across the technologies that run your organisation

We work as an extension of your team — advising, building and operating across cloud, data, AI and enterprise systems, with security and compliance designed in from the start.

Cloud Transformation

Migration, landing zones, FinOps and managed operations across AWS, Azure and OCI — built for UK data residency.

  • Strategy & readiness
  • Migration & modernisation
  • FinOps & cost control
  • 24/7 managed cloud

AI & Data Engineering

Practical, governed AI — from data platforms to machine learning and generative AI that earns its place in production.

  • Data platforms
  • ML & GenAI delivery
  • AI governance
  • BI & reporting

Oracle Services

Deep expertise across the Oracle estate — Database, E-Business Suite, Fusion Cloud and OCI — with licensing and upgrades.

  • Database & Exadata
  • EBS → Fusion
  • OCI architecture
  • Licence & audit support

Security & Compliance

Security architecture, identity and access, and regulatory alignment — UK GDPR, NHS DSP Toolkit and FCA resilience.

  • Security architecture
  • Identity & access
  • UK GDPR
  • Audit-ready assurance
How it works

Patient data stays put. Only permission travels.

Records never leave their source systems. Access is granted through short-lived, cryptographically signed tokens — and every request is written to a tamper-evident ledger.

  • 1
    Consent is encodedPatients set granular rules — data types, institutions, duration, emergency access — held in smart contracts.
  • 2
    Requests are evaluated automaticallyProvider identity, credentials and context are checked before anything is released.
  • 3
    A scoped token is issuedSigned, time-limited and recorded on the ledger — usable only within its defined scope.
  • 4
    Every access is loggedGranted or refused, each request is immutable and auditable for UK GDPR compliance.
Validator Nodes Provider Systems Access-Token Gen. Smart Contract Patient Devices Off-chain Repository

Reference architecture — keeping patient data in place (Fig. 1).

Healthcare practice

Patient data, shared safely.

Healthcare is our flagship practice. We help NHS trusts, private providers and health-tech companies exchange patient information across organisational boundaries — without it ever leaving the safety of its source systems.

The sequence is simple and verifiable: request, evaluate consent, issue a signed token, verify on the ledger, release only the permitted data — every step logged immutably.

Developed in-house

This approach to consent, access tokens and tamper-evident auditing was developed by our own team — and it shapes how we design access control and compliance for every healthcare engagement.

Clinician Consent engine Record store Request access Evaluate consent Issue signed token Present token Verify on ledger Release permitted data

Operational sequence — request, consent, token, verify, release (Fig. 2).

Who we work with

Sector knowledge that shortens the conversation

Our team brings years of UK delivery across regulated sectors — so we already speak your regulator's language.

Flagship practice

Healthcare & Life Sciences

NHS trusts, private providers and health-tech. Consent-led data sharing, DSP Toolkit alignment, interoperability across care settings.

Regulated

Financial Services

Cloud and data programmes built around FCA operational resilience, outsourcing rules and audit expectations.

Public

Public Sector

G-Cloud-experienced delivery for central and local government, with UK data residency as standard.

Commercial

Retail & Utilities

Customer data platforms, demand forecasting and Oracle-backed ERP modernisation for asset-heavy businesses.

How we work

A straightforward path from first call to steady state

1

Discover

A short, structured assessment of your estate, constraints and regulatory position. Findings you can act on.

2

Design

Target architecture and roadmap, costed and sequenced, with security and compliance made explicit.

3

Deliver

Blended teams working alongside yours. We transfer knowledge as we go, so you're never locked in.

4

Run & improve

Optional UK-based managed services, continuous optimisation and quarterly value reviews.

By the numbers
UK
Based team, with data residency as standard
2025
Founded and registered in England & Wales
3
Core technology practices: cloud, AI and Oracle
<1 day
Typical response to a new enquiry
Insights

Thinking from the team

FAQs

Questions we're often asked

How does your healthcare data-sharing approach work?
Patient data stays in its source system. Only short-lived, consent-checked access tokens move between parties, and every request — granted or refused — is logged to a tamper-evident trail. We design real engagements around this model.
How does it handle UK GDPR and NHS requirements?
Patient data stays in its source repository; only short-lived, consent-evaluated access tokens move between parties, and every request is logged immutably. The design supports UK GDPR accountability and the NHS Data Security & Protection Toolkit, and we'll walk your information-governance team through it directly.
Do you work with our existing cloud provider?
Yes — we're partner-accredited across AWS, Azure and OCI and regularly optimise an existing commitment rather than insisting on a rebuild.
Where is your team based?
We're a UK-based team headquartered in Romford, London, with delivery and managed support across the UK.
Get in touch

Tell us what you're trying to achieve

A 30-minute call with a senior consultant — not a salesperson — to understand your situation and tell you honestly whether we can help.

Address21 Jarrow Road, Romford, RM6 5RH, United Kingdom
HoursMon–Fri, 8:30–18:00 GMT

We aim to respond within one working day.