
Your patients trust you with the most intimate details of their lives. Their records deserve storage that takes that seriously.
Bigby gives doctors, clinicians, and private health practitioners encrypted, UK-based cloud storage built around the data protection obligations that come with holding health records.
Health data is the most protected category under UK law. The platform you store it on should reflect that.
When a patient shares their medical history, test results, or clinical notes with you, they have no choice but to trust you entirely. That trust is both personal and legal: health data sits at the top of the GDPR special categories, carrying the strongest protection obligations the law provides.
Most private practitioners use whatever cloud storage was convenient at the time. Consumer platforms, free tiers, tools borrowed from general business use. None of them were designed with clinical records in mind, and the data handling terms that govern them don’t reflect the obligations you carry.

Where standard cloud storage falls short for clinical practice
Storing patient records on general-purpose cloud platforms creates professional, regulatory, and legal exposure that is worth understanding clearly.
Health data and UK GDPR special categories
Under UK GDPR and the Data Protection Act 2018, health data is a special category requiring a higher standard of protection and a lawful basis beyond ordinary personal data. As a data controller, you are responsible for ensuring any processor you use, including your cloud storage provider, meets those standards. A breach affecting patient records triggers mandatory ICO notification obligations and can carry substantial fines and reputational consequences.
GMC, NMC, and HCPC expectations
The GMC, NMC, HCPC, and equivalent bodies all set expectations around the security and confidentiality of patient records. Storing clinical notes, referral letters, or diagnostic reports on a platform with opaque data handling practices, or one that retains rights to scan or analyse stored content, is difficult to reconcile with those standards. In the event of a regulatory complaint or fitness-to-practise investigation, your choice of storage provider becomes a matter of record.
Platforms that can access what you store
Standard cloud services are not designed to be blind to your content. Content scanning, AI training provisions, and broad data usage rights are common across the major platforms. For personal photos or general documents those terms may be acceptable. For clinical records identifying a patient by name, condition, or treatment history, they represent a category of risk that sits directly against your duty of confidentiality.
US jurisdiction and patient data
The major cloud providers are US companies subject to US law. The CLOUD Act creates mechanisms by which US authorities can compel access to data held by those companies, regardless of where the data is physically stored. Patient records, the most sensitive category of personal data, sitting under US jurisdiction is an exposure that, once explained, most practitioners would not knowingly accept.
How Bigby works
Unlike the major cloud platforms, Bigby does not scan, analyse, or profit from the files you store. Here is how that works.
01. Encrypted in transit and at rest
Your files are encrypted on the way to us and while they sit on our UK servers, so they are protected in transit and never stored as readable plain text. We hold the encryption keys, which is what allows features like editing documents in your browser to work.
02. No access to file contents
Bigby does not open, scan, or read the contents of what you store. We have no business reason to and our data processing terms prohibit it.
03. No AI training or secondary use
Your stored content is not used for AI training, advertising targeting, or any analysis of any kind. The subscription fee covers the cost of running the service. That is the entire arrangement.
04. Patient data stays in the UK
All data is stored on UK-based infrastructure. UK GDPR applies. There is no transfer to US servers and no exposure to US jurisdiction. What your patients share with you does not leave the UK.
Frequently asked questions
Storage that reflects the seriousness of what your patients share with you
Private, encrypted, UK-based cloud storage from £3.99 per month. Built for clinicians who understand that a data controller’s obligations don’t stop at the consulting room door.
See all plansAnnual or monthly billing · All prices in GBP · UK data residency · GDPR compliant