Bleepa
Bleepa® is an easy-to-use collaboration platform for all patient referrals, diagnostic requests, clinical communication and patient pathways. It is a secure, fully compliant UKCA-marked medical device certified for review of medical grade images.
Features
- Patient-centred clinical communication with shared view of patient information
- Facilitates remote multidisciplinary team working
- Clinical pathway and referral management within and across care providers
- Diagnostic quality image review including annotation
- Full photo and document capture including patient consent
- Web application for on-the-go access from any device
- Interoperable with National, Primary and Secondary healthcare systems
- Dashboard view of patient status and management
- Auditable clinical chat forms part of patient record
- Zero footprint with no data stored on end user devices
Benefits
- Reduces RTT by 63% compared to the national target
- Reduces outpatient appointments by 90% driving cost savings
- 76% of users surveyed identified time savings
- 80% of staff identified an improvement in staff communication
- Expedites and enhances collaboration care settings supporting neighbourhood health delivery
- Unites essential data from existing systems
- Expedites patient care through more efficient digital pathways
- Delivers greater productivity to support elective care recovery
- Fully auditable, compliant and secure (UKCA, ISO13485, ISO27001, DTAC, DCB0129)
- Reduces travel and use of resources supporting carbon reduction plans
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 1 0 7 1 1 7 1 4 9 0 2 5 4 4
Contact
FEEDBACK MEDICAL LIMITED
Richard Dulcamara
Telephone: +44 (0) 20 3997 7634
Email: sales@fbkmed.com
About your service
- Service categories
-
Applications
Collaborative
- Enterprise community
- Team collaboration
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- Bleepa will be hosted in AWS London datacentre
- System requirements
- Bleepa will require a data source for patient demographics
User support
- Email or online ticketing support
- Yes
- Support response times
-
Support levels are negotiated based on customer needs.
Our basic service level agreement (SLA) is during normal UK office hours (Monday to Friday 9am - 5pm, excluding bank holidays).
Response SLA is 1 hour response for critical faults, rising to 4 hours for minor or cosmetic issues. - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- No
- Support levels
-
Bleepa provides a standard support service as part of the off-the-shelf offering.
Standard support:
Standard support is provided Monday to Friday, 09:00 to 17:00 UK time, excluding UK public holidays. It includes incident reporting, fault investigation, issue resolution, and support with service configuration and usage. Support is delivered by experienced cloud support engineers.
All support calls are triaged, and prioritised according to impact and severity.
Cost:
Standard support is included in the service cost.
Additional support options:
Where customers require additional support, such as out-of-hours or weekend cover, these arrangements can be agreed during the contracting process based on customer needs. Any additional support requirements are optional and are defined in advance, with pricing set out transparently in the G-Cloud pricing schedule.
Customers are supported by a designated service contact who coordinates onboarding and ongoing service engagement. This role does not provide consultancy or bespoke development. - Support available to third parties
- No
Onboarding and offboarding
- Getting started
-
Bleepa supports users to start using the service through a standard, repeatable onboarding process that forms part of the off-the-shelf service offering.
Implementation includes structured configuration of the platform in collaboration with local clinical and operational teams to reflect existing pathways and governance arrangements. This configuration uses existing platform functionality and does not require software development or custom code.
Training is primarily delivered virtually and is included as standard. Role-based training is provided for clinical users, administrators, and operational leads through live online sessions. Where required, onsite training can be provided by agreement, for example to support large-scale deployments.
Training is supported by user documentation, quick-reference guides, and in-application support. A train-the-trainer approach can be used to support ongoing local onboarding.
Following go-live, users have access to standard support services, including technical support, issue resolution, and assistance with configuration changes as services evolve. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
Bleepa is designed to manage individual patient episodes, and information relating to that episode automatically exported to external systems at the end of each episode. When used in this way, it can reduce or even avoid the need for bulk export of data at the contract end.
Bleepa uses industry standard interfaces for data export, including DICOM (for medical images and clinical photographs) HL7 (for structured patient centric information) and PDF.
If there is a requirement for bulk export, this can also be accommodated, in line with customer need. Data can be transferred to a file system of your choice, using the following formats:
• Clinical image data retained in the system is stored in DICOM Part 10 format.
• Document scans, etc. are stored as a zip file with patient identifiers in a JSON file.
• Bleepa permits a ‘conversation around the patient’ in the form of messages related to the patient, which can be exported as PDF.
• Remaining data is retained in our SQL database. A backup of the database tables can be provided with a documented schema to enable reconstruction. - End-of-contract process
-
End of contract process
Contracts operate for the term defined in the NHS Call-Off Agreement or Order Form, in line with G-Cloud framework requirements. Where applicable, contracts may include extension periods in accordance with NHS procurement rules. Any auto-renewal provisions are superseded by NHS call-off terms. If the contract is not renewed, it ends automatically at the expiry of the agreed term. On expiry or termination, access to the service is withdrawn in a controlled manner. At the customer’s written request within 90 days, customer data is securely returned or securely deleted in accordance with contractual and data protection requirements. Data is not retained beyond this period unless required by law.
Pricing and additional costs:
The contract price includes licensed use of the service, secure hosting, routine maintenance updates, and standard support for the duration of the contract. Any additional costs are only incurred where explicitly agreed in advance, such as one-off implementation or integration activities, additional licences or usage above agreed thresholds, or optional enhancements provided under a separate written agreement. There are no charges for contract exit or standard data return at the end of the contract. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
Documentation is delivered to the customer key stakeholders, as part of the implementation process, and also as part of customer training.
Training is discussed and considered during deployment planning, as part of the process of compliance with the DCB0129/DBC0160 clinical safety standards.
In addition, relevant documentation is made available at point of use, via dedicated links within the application itself.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
Bleepa provides the same core functionality across mobile and web browser interfaces. Differences are limited and relate to security and device interaction.
Document and image viewing differs slightly due to screen size and interaction methods. Mobile users zoom and navigate images using touch gestures such as pinch-to-zoom and swiping, while desktop users use mouse and keyboard controls.
Photo capture is optimised for mobile devices, with access to camera controls. Once uploaded, images can be viewed from the patient record on any device. - Service interface
- No
- User support accessibility
- None or don’t know
- API
- No
- Customisation available
- Yes
- Description of customisation
-
Bleepa is an off-the-shelf clinical collaboration platform that can be configured to align with local workflows, pathways, and organisational requirements.
What can be customised:
Users can configure referral pathways, workflow stages, user roles and permissions, notification rules, escalation processes, and service and team structures. Message templates and information capture fields can also be configured using standard platform functionality.
How users can customise:
Customisation is achieved through administrative configuration within the live service, without bespoke development or code changes. Configuration is typically completed during onboarding and can be updated over time using existing tools and controls.
Who can customise:
Configuration is performed by authorised customer administrators and local clinical or operational leads. Bleepa provides guidance and support to enable safe and effective configuration in line with NHS governance requirements, including DCB0129.
Scaling
- Independence of resources
-
Bleepa is designed to ensure that demand from one customer does not adversely affect other users. The service operates on a scalable cloud-based platform that supports concurrent use across multiple organisations.
Capacity and performance are monitored centrally to maintain consistent service levels as demand changes. Customer data and workloads are logically separated to support reliable and secure operation.
Standard operational controls, including performance monitoring and incident management processes, are used to maintain service availability and responsiveness across the platform.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Bleepa provides service metrics to support operational oversight and service monitoring. Metrics typically include service availability and performance indicators, usage and adoption metrics, and activity volumes aligned to local use of the service.
Metrics are provided through scheduled periodic reports based on agreed key performance indicators (KPIs). The scope, content, and frequency of reporting are agreed with the customer in advance.
Service metrics are generated using existing features of the service and standard reporting processes and are provided in a format suitable for clinical, operational, and digital teams. - Reporting types
-
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
-
Bleepa is designed to manage individual patient episodes, and information relating to that episode automatically exported to external systems at the end of each episode.
Customers can request data exports for their organisation’s data, provided using standard service processes and delivered securely in line with information governance and UK GDPR requirements.
Bleepa provides scheduled periodic reports based on agreed key performance indicators (KPIs). These reports support service monitoring, operational oversight, and ongoing service review.
Exports and reports are generated using existing features of the service and standard support processes. The scope, frequency, and content of reports are agreed in advance. - Data export formats
-
- CSV
- Other
- Other data export formats
-
- DICOM
- HL7
- Via NHS APIs
- FHIR
- Data import formats
- Other
- Other data import formats
-
- HL7
- DICOM
- FIHR
- HL7
- JPG
- NHS API
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
Bleepa is designed to provide a reliable and resilient service suitable for use in operational clinical environments. The service is hosted on cloud infrastructure with monitoring, backup, and recovery processes in place to support service continuity and availability.
Availability is supported through regular system monitoring, defined operational support processes, and structured backup and recovery arrangements. Different data types are backed up at frequencies appropriate to their role, ranging from hourly snapshots to continuous database replication with defined recovery point objectives. These measures support restoration of service and data in the event of incidents or failures.
Service availability targets and any associated service level agreements (SLAs) are defined contractually and form part of the standard service terms provided to customers. Availability is measured and reviewed as part of routine service monitoring and reporting.
Where guaranteed levels of availability are not met, customers are entitled to service remedies as set out in the contract. This may include service credits or other agreed adjustments, applied in accordance with the contractual terms rather than ad hoc arrangements.
This approach provides customers with clear, contractually defined availability commitments, supported by appropriate technical and operational controls. - Approach to resilience
- Available on request
- Outage reporting
-
Bleepa reports service outages and significant service issues through established communication channels agreed with customers.
Where an outage or degradation is identified, customers are notified via direct communications, such as email alerts to authorised customer contacts. Updates are provided as appropriate during incident investigation and resolution, with follow-up information shared once normal service is restored.
At present, outage information is not provided through a public status dashboard or a customer-facing API. Incident communication and reporting are managed through standard operational and support processes to ensure information is accurate, timely, and appropriately targeted.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Other
- Other user authentication
-
Bleepa utilises Single Sign-On (SSO) widely among our existing Bleepa customer base. It is simple to set up between the Customer Technical Team and Bleepa Technical Team.
The preferred SSO mechanism is Azure Active Directory (Azure AD) but a similar process can be used to integrate with Active Directory via Active Directory Federation Services (ADFS) or LDAP. Bleepa uses the industry standard OpenID Connect for authentication and OAuth for service authentication. These standards also provide compatibility with NHS mail or CIS2. - Access restrictions in management interfaces and support channels
-
Bleepa is hosted in a public cloud environment (typically AWS) with security built in. Application servers are all located within a Virtual Private Cloud (VPC), with end user access from the internet through a Web Application Firewall (WAF) to an application load balancer.
Access to management functions and for our support team, is controlled by use of a dedicated VPN, using MFA protected user accounts. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Bleepa follows formal information security policies and processes aligned to recognised industry standards. The organisation is ISO/IEC 27001 certified and holds Cyber Essentials Plus, demonstrating that information security risks are identified, managed, and independently assessed.
Information security policies cover areas including access control, data protection, incident management, asset management, supplier management, and business continuity. Policies are documented, maintained, and reviewed regularly to ensure they remain effective and aligned with UK GDPR and NHS information governance requirements.
Information security is supported by a defined governance and reporting structure, with responsibility assigned to senior leadership and oversight maintained through established management processes. Compliance with policies is monitored through internal controls, operational checks, and external audits associated with ISO 27001 and Cyber Essentials Plus.
The organisation also operates an ISO 13485–certified quality management system, which supports controlled change management, risk management, document control, and corrective action processes across regulated software products.
Staff are required to follow information security policies as part of their roles, with access restricted based on role and authorisation. Issues identified through monitoring or audit are logged, reviewed, and addressed through agreed actions. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Feedback Medical have implemented change management processes in line with the Information Technology Infrastructure Library (ITIL) framework. This process is externally audited to ensure it complies with the requirements of both our ISO13485 and ISO27001 certifications.
We have adopted an Infrastructure as Code (IaC) methodology, allowing full version control of customer site Configuration, as well as automated deployment into separate Development, Test and Live environments.
All changes are formally risk assessed prior to implementation by a multidisciplinary team, considering both clinical safety and security risks. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Our approach to vulnerabilities begins at the software development stage, by constructing a Software Bill of Materials, which allows us to identify and understand any vulnerabilities in our software products.
The system undergoes external CREST approved penetration tests at least once per year, or when a new major release is produced.
All systems include vulnerability monitoring software, to identify and understand any vulnerabilities which may arise in the live environment. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- All live systems are proactively monitored using Remote Monitoring and Management (RMM), Vulnerability Management and Endpoint detection and Response (EDR) software tools. This information is fed back to centralised dashboards, allowing Feedback Medical to monitor activities across our entire estate. Unexpected activities result in alerts that our internal support team respond to, in line with our published Support Level Agreements.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
Bleepa operates standard, pre-defined incident management processes as part of the live service.
Users report incidents through agreed support channels, typically via authorised customer contacts. Incidents are logged, tracked, and managed by the support team in line with standard operational procedures.
For common service events, established response and resolution processes are followed to restore normal service operation. Customers are kept informed of progress through agreed communication channels.
Following incident resolution, incident information and summaries can be provided to customers where appropriate, supporting transparency and service review. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
- Other
- Other public sector networks
- NHS England API platform (eRS, MESH, GPConnect, PDS)
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- SGS United Kindom Limited. Certificate number GB20/967638
- ISO/IEC 27001 accreditation date
- Friday 11 December 2020
- What the ISO/IEC 27001 doesn’t cover
- Nothing
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 13863f21-1e0c-424b-b211-ee2d62edd63b
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- C20b871d-43d3-4002-969c-3fe66cae196d
- Other security certifications
- Yes
- Any other security certifications
- ISO 13485:2016, SGS certificate number GB14/91947
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
-