Skip to main content

Help us improve the Digital Marketplace - send your feedback

CARDIOSCAN LTD

BeatBox Cloud Platform

CardioScan provides a secure, cloud-based clinical diagnostic software service for managing, analysing and reporting cardiac monitoring data. The service supports healthcare providers in delivering efficient, high-quality cardiac diagnostics through web-based access, without the need to manage infrastructure, hosting or software maintenance.

Features

  • Secure web-based access to cardiac diagnostic software
  • Cloud-based upload and processing of cardiac monitoring data
  • Structured clinical reporting and diagnostic outputs
  • Role-based user access and permissions
  • Audit logging and activity tracking
  • Integration-ready interfaces for clinical systems
  • Automated software updates and maintenance
  • Data encryption in transit and at rest

Benefits

  • improve efficiency of cardiac diagnostic workflows
  • Reduce turnaround times for clinical reporting
  • Support consistent, high-quality diagnostic outcomes
  • Enable remote access without local infrastructure management
  • Reduce operational burden on internal IT teams
  • Support secure handling of sensitive clinical data
  • Scale diagnostic capacity without additional hardware
  • Maintain compliance with healthcare governance requirements

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at ian.cunningham@cardioscan.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

1 7 8 7 4 2 3 3 9 6 9 4 8 2 9

Contact

CARDIOSCAN LTD Ian Cunningham
Telephone: 07876147496
Email: ian.cunningham@cardioscan.co.uk

About your service

Service categories

Applications

Production and operations

Service industry and public sector operations

  • Healthcare
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
The service requires a reliable internet connection and access via a modern web browser. Planned maintenance may occur periodically and is normally scheduled outside core UK business hours, with advance notice provided. The service is delivered as a managed SaaS offering and does not support buyer-managed hosting or on-premise deployment. Integration with third-party clinical systems may be subject to technical feasibility and information governance requirements.
System requirements
  • Modern Chromium-based web browser with JavaScript enabled
  • Reliable internet connection
  • Supported desktop or laptop operating system
  • Secure user authentication credentials
  • Ability to access HTTPS web applications

User support

Email or online ticketing support
Yes
Support response times
Support requests submitted by email or online ticketing are typically acknowledged within one UK business day. Responses are provided during UK business hours, Monday to Friday, excluding public holidays. Response times may vary depending on the nature and complexity of the request. Out-of-hours support is not guaranteed unless otherwise agreed.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes
Support levels
The service includes a standard level of support as part of the service price. Support is provided via email or online ticketing during UK business hours, Monday to Friday, excluding public holidays.

Support covers incident management, fault resolution, and general service queries related to the operation and use of the service. Issues are prioritised and managed by CardioScan based on impact and clinical risk.

The service does not include a dedicated technical account manager or named support engineer as standard. Enhanced or bespoke support arrangements, including extended hours or named contacts, may be agreed separately where required and priced accordingly.
Support available to third parties
No

Onboarding and offboarding

Getting started
CardioScan supports users in getting started through a structured onboarding process. This typically includes account setup, user access configuration, and an introduction to the service features relevant to the buyer’s use case. Users are provided with guidance and documentation to support day-to-day use of the service.

Where required, remote training sessions or walkthroughs can be provided to support initial adoption. Ongoing assistance is available via standard support channels to help users become familiar with the service. Onsite training or bespoke onboarding activities can be discussed and agreed separately if required.
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
At the end of the contract, buyers can request extraction of their service data by contacting CardioScan through the standard support channels. Data is provided in commonly used, structured formats appropriate to the data held, such as CSV files or clinical report documents, to support onward use or migration.

Data exports are delivered securely using agreed transfer methods. Reasonable assistance is provided to support data extraction as part of the offboarding process. The scope, format, and delivery method of exported data are agreed with the buyer to ensure the data can be accessed and reused outside the service.
End-of-contract process
At the end of the contract, access to the service is maintained for an agreed period to allow completion of offboarding activities. Buyers can request extraction of their data in line with the agreed end-of-contract data extraction process.

Standard offboarding support, including coordination of data export and confirmation of service closure, is included within the contract price. Where additional support is required, such as bespoke data formats, extended access periods, or significant professional services effort, this can be provided by agreement and may incur additional cost.

Following completion of offboarding and confirmation from the buyer, service access is withdrawn and customer data is securely handled in accordance with contractual and regulatory requirements.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Onboarding and offboarding documentation is provided in PDF format and can be viewed using standard document reader software. Users can make use of reader features such as zoom, text resizing, and screen display settings to support readability. Where required, documentation can be supplemented with guidance delivered through email, remote walkthroughs, or verbal explanation. CardioScan will consider reasonable adjustments to documentation format or delivery method where specific accessibility needs are identified by the buyer.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Chrome
Application to install
No
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
The service is accessed through a secure, web-based user interface. The interface provides authorised users with role-based access to view, manage, and interact with service data and functionality. It is designed to be intuitive and accessible via modern web browsers, with no local software installation required. Access is controlled through secure user authentication and permissions.
Accessibility standards
None or don’t know
Description of accessibility
The service is accessed through a web-based interface using standard browser controls. Users can adjust browser settings such as zoom and text size to support readability. The interface supports keyboard and mouse navigation for core functions. Some complex data visualisations or workflows may be less suitable for assistive technologies, and full compatibility with screen readers is not guaranteed. Users requiring specific accessibility adjustments are encouraged to discuss requirements with CardioScan.
Accessibility testing
Formal usability testing with users of assistive technology has not been undertaken to date. Accessibility considerations have been informed through general usability testing and feedback from service users. CardioScan recognises the importance of accessibility and will consider reasonable adjustments or future testing where specific user requirements are identified through customer engagement.
API
Yes
What users can and can't do using the API
The service supports system-to-system integration using secure, supplier-managed interfaces. Integrations are typically implemented using healthcare messaging standards such as HL7, with connectivity via secure protocols including HTTPS, SFTP, or VPN-based connections. APIs and integration endpoints are configured and managed by CardioScan as part of agreed implementations and are not provided as open, self-service developer APIs.
API documentation
No
API sandbox or test environment
No
Customisation available
No

Scaling

Independence of resources
The service is delivered using a scalable, multi-tenant cloud architecture hosted on AWS. Resources are logically isolated between customers using account-level separation, access controls, and tenant-aware application design. Capacity is monitored and scaled to manage demand, and usage limits and throttling are applied where appropriate to prevent any single tenant impacting others. This approach ensures that customer performance and availability are not adversely affected by other users’ activity under normal operating conditions.

Analytics

Service usage metrics
Yes
Metrics types
The service can provide agreed usage and operational metrics, such as system usage volumes, user activity, processing throughput, availability, and performance indicators. Metrics are defined in collaboration with the buyer based on operational requirements. Standard metrics are included where available; additional or bespoke metrics may require configuration, development, or reporting effort and may incur additional costs, subject to agreement.
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure

Data importing and exporting

Data export approach
Users can export their data via standard export functions within the service or by request through support. Data exports can also be provided via secure file transfer or API-based integration where required. Exports are performed in accordance with agreed security controls and data protection requirements. Support is available to assist with data export requests as part of normal service operation, with additional assistance available by agreement if required.
Data export formats
  • CSV
  • Other
Other data export formats
JSON (via API), PDF (clinical reports)
Data import formats
  • CSV
  • Other
Other data import formats
JSON (via API integration)

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
The BeatBox Cloud Platform is designed for high availability using resilient cloud infrastructure hosted on AWS. We target 99.9% service availability, measured monthly, excluding planned maintenance and force majeure events. Availability is monitored continuously, and incidents are managed in line with agreed support processes.

Planned maintenance is scheduled outside of core clinical hours wherever possible and communicated in advance. The service architecture includes redundancy, automated monitoring, and failover mechanisms to minimise disruption.

Formal service level agreements (SLAs), including any availability commitments, reporting, and remedies, are agreed with the buyer at contract award. Where guaranteed availability levels are not met, remedies such as service credits or other commercial adjustments may be applied as defined in the call-off contract, rather than through automatic refunds.

Availability commitments can be tailored to buyer requirements, subject to agreement.
Approach to resilience
The BeatBox Cloud Platform is designed using resilient, cloud-native architecture hosted on Amazon Web Services (AWS). The service uses redundant infrastructure components, automated monitoring, and fault-tolerant design patterns to minimise single points of failure and reduce the impact of component or service outages.

Core services are deployed across multiple availability zones where appropriate, with automated recovery mechanisms to support continuity of service. System health is continuously monitored, and alerts are raised to support teams to enable rapid investigation and remediation of incidents.

Data is protected through regular backups and tested recovery procedures to support service restoration in the event of failure. Planned maintenance and updates are managed through controlled release processes designed to minimise user disruption.

Detailed information on the underlying datacentre resilience, backup schedules, and disaster recovery capabilities can be provided to buyers on request, subject to security and commercial considerations.
Outage reporting
Service availability is continuously monitored using automated monitoring and alerting tools. When an outage or significant service degradation is identified, it is logged and investigated by the support team as a priority.

Buyers are notified of confirmed outages and material incidents via email alerts to nominated contacts. Where appropriate, follow-up communications are provided to keep buyers informed of progress, expected resolution times, and post-incident outcomes.

Outage details, including cause, impact, and remedial actions, can be shared with buyers on request as part of incident reporting or service review discussions. A public status dashboard or public API for outage reporting is not currently provided.

Planned maintenance activities that may impact availability are communicated in advance wherever possible to minimise disruption.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is restricted using role-based access controls and the principle of least privilege. Administrative access is limited to authorised personnel only and protected by strong authentication, including multi-factor authentication for privileged accounts. User access rights are granted based on job role and reviewed regularly. Support access to customer environments is controlled, time-limited where required, and logged for audit purposes. All access is revoked promptly when no longer required or when staff leave the organisation.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
CardioScan operates a proportionate, risk-based security governance framework aligned with NHS and public sector expectations. Security responsibilities are clearly defined, with oversight from senior management and regular review of policies, risks and controls. The service is hosted on AWS, inheriting certified physical and infrastructure security controls, while CardioScan manages application-level security, access control, change management and monitoring. Regular external penetration testing, vulnerability management and incident response processes are in place, with findings tracked to remediation. CardioScan is working towards ISO 27001 certification, with target completion by end of 2026, and has aligned its information security management practices to support this.
Information security policies and processes
CardioScan maintains a documented set of information security policies and operational processes covering access control, data protection, incident management, vulnerability management, change control and supplier security. Policies are aligned with NHS DSP Toolkit expectations, GDPR, and ISO 27001 principles, and are reviewed regularly by senior management.

Security responsibilities are clearly defined, with escalation routes to technical leads and executive oversight where required. Compliance with policies is enforced through role-based access controls, least-privilege principles, mandatory staff training, and documented procedures for onboarding, offboarding and change management.

Operational controls include secure AWS configuration, audit logging, monitoring, regular backups, and external penetration testing, with findings tracked through to remediation. Security incidents and risks are logged, assessed and managed using a formal incident and risk management process, with post-incident reviews conducted where appropriate.

Policy adherence is supported through periodic internal reviews, third-party assessments, and customer assurance activities. CardioScan is working towards ISO 27001 certification by the end of 2026, and its information security policies and processes are structured to support ongoing compliance and continuous improvement.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Configuration items across the service (application components, infrastructure and integrations) are tracked throughout their lifecycle using version control, change records and environment inventories. All changes follow a defined change management process, including impact and security risk assessment prior to approval. Changes are tested in non-production environments before deployment and logged for audit purposes. Access to make changes is restricted and role-based. Emergency changes follow an expedited approval process and are reviewed retrospectively. Rollback procedures are documented to minimise service disruption.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
We assess vulnerabilities through regular third-party penetration testing, vulnerability scanning, internal reviews, and continuous monitoring of our cloud environment. Threats are prioritised based on risk, impact, and exploitability. Patches for critical vulnerabilities are deployed as soon as practicable, with high-risk issues prioritised and tracked to resolution through change management. Information on emerging threats is obtained from our penetration testing partners, AWS security advisories, vendor notifications, and recognised industry sources. Remediation actions are documented, reviewed, and validated following deployment.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Protective monitoring is implemented using cloud-native monitoring, logging, and alerting tools to identify unusual activity, errors, or potential security events. System logs, access logs, and security alerts are reviewed to detect potential compromises. When a potential issue is identified, it is investigated promptly, contained where necessary, and escalated internally according to severity. Incident response actions are initiated without undue delay, with priority given to suspected security incidents. Monitoring configurations and response procedures are reviewed regularly to ensure continued effectiveness.
Incident management type
Supplier-defined controls
Incident management approach
We operate defined incident management processes for common events, including service disruption, security incidents, and data issues. Incidents are detected through monitoring or reported by users via email or agreed support channels. All incidents are logged, triaged, and prioritised according to impact and severity. Customers are kept informed through timely updates during resolution. Post-incident reports are provided on request and include root cause analysis, remediation actions, and preventative measures. Processes are regularly reviewed and aligned with our wider security and operational governance framework.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
SAI GLOBAL
ISO 9001 accreditation date
Monday 15 August 2016
What the ISO 9001 doesn’t cover
NA
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
Dd98714c-bfbe-4d57-a7ca-3340393e81af
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
Yes
Any other security certifications
DSPT

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Ensuring new workers are informed of their right to join a trade union
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Activities to cascade good practice on fair working conditions throughout the supply chain
    • Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
    • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
    • How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
    • Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
    • Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
    • Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
    • Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
    • Introducing transparency to pay and reward processes
    • Working conditions which promote an inclusive working environment and promote retention and progression
    • Other measures to provide equality of opportunity for disabled people and those with health conditions into employment, including becoming a Disability Confident employer and inclusion of supported businesses in the contract supply chain
    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
    • Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Understanding of the issues affecting the development of new skills by target cohort
    • Understanding of issues relating to entering the contract workforce
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
    • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
    • Actions to invest in the physical and mental health and wellbeing of the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at ian.cunningham@cardioscan.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.