Heart Rhythm International
Heart Rhythm International is a cloud-based cardiac rhythm management platform supporting implant workflows, implantable cardiac device tracking, follow-up management, Field Safety Notice management, and regulatory compliance for NHS cardiac services. It integrates with major device manufacturers and hospital systems to support safe, efficient clinical and governance workflows.
Features
- Structured implant and follow-up workflows for cardiac device services
- Implantable cardiac device and lead tracking with full traceability
- Automated ingestion of device data, including remote transmissions, from manufacturers
- Appointment scheduling and follow-up management for cardiac device patients
- Clinical dashboards with DNA tracking and follow-up status reporting
- Field Safety Notice management with affected patient identification
- Secure patient and device registry with role-based access control
- Integration with hospital systems to reduce manual data entry
- Audit trails and reporting for safety, quality, and oversight
- Cloud-hosted SaaS platform accessible via secure web browser
Benefits
- Improve patient safety through accurate device and follow-up tracking
- Support regulatory compliance with complete, auditable device records
- Reduce missed follow-up appointments using DNA tracking and reporting
- Ensure accurate data capture from manufacturers and clinical workflows
- Streamline appointment scheduling for cardiac device patients
- Improve clinic efficiency with centralised clinical dashboards
- Reduce administrative workload through automated data ingestion
- Respond quickly to Field Safety Notices and affected patients
- Reduce data entry errors via system and manufacturer integrations
- Increase clinic capacity without additional administrative staff
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 7 8 5 0 0 2 3 5 4 8 5 8 3 5
Contact
Heart Rhythm International
Robert Kelly
Telephone: +353833325468
Email: robert@heartrhythmintl.com
About your service
- Service categories
-
Application Development and Deployment
Data management
Database management systems
- Relational Database Management Systems
Data integration and intelligence
- Data Ingestion and Transformation Software
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- The service can integrate with and extend hospital patient administration systems, electronic patient records, cardiology information systems, and implantable device manufacturer platforms to support cardiac device workflows, scheduling, governance, and reporting. It can also operate independently where required.
- Cloud deployment model
- Public cloud
- Service constraints
- The service requires internet connectivity and access via a supported, up-to-date web browser. Planned maintenance is scheduled in advance and, where possible, outside core clinical hours. Integration availability may depend on third-party hospital systems and device manufacturers. Service performance may be affected during planned maintenance windows or external system outages.
- System requirements
-
- Modern web browser (Chrome, Edge, Firefox, Safari)
- Secure internet connectivity
- NHS-standard desktop or laptop device
- Role-based user accounts provided by the service
- Multi-factor authentication for user access
- Email access for notifications and account management
User support
- Email or online ticketing support
- Yes
- Support response times
- Support requests submitted via email or the online ticketing system are acknowledged during business hours, Monday to Friday. Initial responses are typically provided within one business day. Critical issues impacting service availability are prioritised and responded to as quickly as possible. Response times may vary outside of standard business hours.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
HRI provides tiered support aligned to NHS operational needs.
Standard Support (included):
Email and ticket-based support during UK business hours (9am–5pm, Monday to Friday). This includes incident management, user support, configuration assistance, and guidance on clinical and administrative workflows. Response times are prioritised based on severity, with critical issues escalated immediately.
Enhanced Support (optional, additional cost):
Enhanced support packages can include extended hours, faster response times, scheduled health checks, and named technical contacts. Onsite support for onboarding, training, go-live assistance, or workflow optimisation is available at additional cost.
Account and technical support:
Each customer is assigned a named account contact. Technical support is provided directly by HRI engineers with domain expertise in cardiac services, device data, and NHS clinical workflows. Where required, HRI provides a dedicated technical lead for complex integrations or larger deployments.
Support levels and service credits are defined in the contract or SLA agreed at call-off stage. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- HRI provides structured onboarding to support users getting started quickly and safely. This includes remote onboarding sessions, optional onsite training where required, and role-based training for clinical, administrative, and governance users. Users are supported with written user guides, quick reference materials, and configuration support during initial setup. Ongoing support is available via email, phone, and scheduled check-ins to ensure adoption and correct use of the service.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
At the end of the contract, buyers can extract their data in commonly used, open formats such as CSV or structured data files. Data extracts can include patient records, device and implant data, follow-up history, audit logs, and configuration data, subject to role-based access and data protection requirements.
The HRI team supports customers during the data extraction process to agree scope, format, and secure transfer method. Where required, data can also be provided via secure file transfer or API-based export.
Following confirmation of successful data extraction, data is securely retained or deleted in line with contractual terms, data protection obligations, and agreed retention schedules. - End-of-contract process
-
At the end of the contract, the service will continue to operate until the agreed contract end date. During this period, buyers can request data extraction and agree the scope, format, and secure transfer method with the HRI team.
Standard offboarding support, including coordination of data extraction and confirmation of successful handover, is included within the contract price.
Where additional support is required beyond standard offboarding, such as bespoke data extracts, extended access periods, complex migrations, or additional technical assistance, these services may be provided at an agreed additional cost.
Following contract completion and confirmation of data handover, access to the service is withdrawn and data is securely retained or deleted in accordance with contractual terms, data protection obligations, and agreed retention policies. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Onboarding and offboarding documentation is provided digitally in clear, structured formats and written in plain language. Documentation is accessible via standard web browsers and common document formats, and can be enlarged or used with browser-based accessibility tools. Recorded demonstrations and live walkthroughs are also provided by the HRI team to support different user needs and ensure all users can complete onboarding and offboarding activities effectively.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The service is accessed via a responsive web interface. Core functionality is the same on mobile and desktop, with layouts optimised for smaller screens. On mobile devices, complex data entry and detailed reporting are best viewed on larger screens, while mobile access supports secure viewing, review, and basic interactions.
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- The service is provided through a secure, web-based user interface accessed via standard browsers. The interface supports clinical and administrative users to manage cardiac device records, appointments, dashboards, and reporting. Role-based access controls ensure users only see information relevant to their role. The interface is designed for use in clinical environments and supports desktop and mobile devices.
- Accessibility standards
- None or don’t know
- Description of accessibility
- The service is accessed through a standard web browser and is designed to be usable across desktop and mobile devices. Users can navigate the interface using standard browser controls, adjust zoom levels, and use built-in operating system accessibility features such as screen magnification. The interface uses clear layouts and consistent navigation to support clinical workflows. Some advanced clinical dashboards and data-dense views may be more challenging for users who rely solely on assistive technologies. Accessibility is actively considered in ongoing product development, with improvements delivered iteratively based on user feedback and service requirements.
- Accessibility testing
- The service has not yet undergone formal usability testing with users of assistive technologies such as screen readers or alternative input devices. User feedback has been gathered through routine use by clinical and administrative staff in live healthcare environments, and this feedback informs ongoing usability and design improvements. Accessibility considerations are included in product development planning, and formal accessibility testing can be undertaken as part of future enhancements or specific customer requirements.
- API
- Yes
- What users can and can't do using the API
-
Heart Rhythm International provides secure RESTful APIs to support integration with hospital systems and approved third parties. The API allows authorised systems to ingest and retrieve patient, device, procedure, and follow-up data, supporting automated data flows and reducing manual data entry.
APIs are typically used for data exchange and integration rather than full system configuration. Core system setup, clinical configuration, and workflow management are performed via the web interface to maintain governance and patient safety.
API access is role-based, audited, and subject to contractual and information governance controls. Certain clinical actions and safety-critical changes are intentionally restricted from API access. - API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Buyers can configure the service to meet local clinical and operational requirements. Customisation includes workflow configuration, follow-up schedules, appointment types, clinical dashboards, reporting views, and role-based user access. Configuration is carried out by authorised customer administrators, with support from HRI where required.
Scaling
- Independence of resources
- The service is delivered as a multi-tenant cloud platform with logical tenant separation and dedicated resource controls. Performance is protected through elastic scaling, workload isolation, and continuous monitoring. Fair-use safeguards such as API rate limiting and background job queuing prevent abnormal or unintended workloads from impacting other users. Automated scaling and proactive monitoring ensure consistent performance during peak clinical activity, so demand from one organisation does not affect others.
Analytics
- Service usage metrics
- Yes
- Metrics types
- The service provides operational and clinical usage metrics including patient volumes, device counts, follow-up activity, appointment attendance and DNA rates, remote transmission volumes, and data ingestion status. Metrics also include user activity, audit logs, and workflow completion status to support service oversight, reporting, and capacity planning.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Other
- Other data at rest protection approach
- Data at rest is protected using industry-standard encryption provided by the underlying cloud platform. All databases and storage volumes are encrypted by default, with encryption keys securely managed by the cloud provider. Access to data is restricted through strict role-based access controls and least-privilege principles. Administrative access is logged and monitored, and production data is segregated by tenant to prevent unauthorised access.
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
- Users can export their data by requesting a data extract from the HRI support team. Data is provided in agreed standard formats using secure transfer methods. Where supported, users can also export reports and datasets directly from the service via built-in reporting and export functions. Data exports are coordinated to ensure completeness, accuracy, and compliance with data protection and information governance requirements.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- JSON
- Secure API extract
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- JSON (via secure API)
- HL7 messages (where supported through integration)
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
The service is provided with a target availability of 99.9%, excluding scheduled maintenance. Availability commitments are defined in the Service Level Agreement (SLA) provided as part of the contract.
If service availability falls below the agreed SLA threshold, service credits may be applied in accordance with the contract terms. Refunds are provided in the form of service credits against future fees rather than direct financial reimbursement.
Planned maintenance is excluded from SLA calculations and is communicated to users in advance. The service is not intended for real-time life-critical use, and temporary service interruptions do not impact immediate patient care delivery. - Approach to resilience
- The service is hosted in a UK-based cloud environment using enterprise-grade infrastructure provided by a major cloud provider. The underlying platform includes built-in resilience across physical facilities, power, and networking. Data is protected through regular, automated backups, including air-gapped, immutable backups to protect against data corruption, accidental deletion, and ransomware events. Backups are retained and tested in line with defined recovery objectives, enabling secure restoration of service within the UK if required.
- Outage reporting
- Service availability is monitored continuously by the HRI operations team and underlying cloud provider monitoring services. In the event of a service disruption, affected customers are notified via email with details of the issue, expected impact, and progress updates. Where appropriate, follow-up communications are issued once service is restored, including a summary of the incident and any remedial actions taken. Outage information can also be provided on request as part of service reporting.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
-
Access to management interfaces is restricted to authorised personnel only and enforced through role-based access control and least privilege principles. Administrative access requires individual user accounts with strong authentication and multi-factor authentication. Access is reviewed regularly and removed promptly when no longer required.
Support channels are access-controlled, with customer-specific data only accessible to approved support staff on a need-to-know basis. All administrative and support access is logged and monitored for audit and security purposes. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- Security governance is overseen at board level, with clear accountability for information security and data protection. The organisation maintains documented security policies and procedures covering access control, data protection, incident management, and secure development practices. Risk is reviewed on an ongoing basis, with security considered as part of product design, change management, and supplier selection. Regular vulnerability management, penetration testing, and staff security awareness form part of the governance approach. Compliance with applicable regulatory and contractual requirements is reviewed periodically and updated as the service evolves.
- Information security policies and processes
-
HRI follows documented information security policies and operational processes aligned with UK government guidance and industry best practice. These include access control, data protection, incident management, vulnerability management, secure development practices, and change control.
Overall responsibility for information security sits with a named board-level director. Day-to-day security operations are managed by senior technical staff, with clear reporting lines and escalation procedures for security incidents or risks.
Policies are enforced through technical controls within the cloud environment, role-based access controls, audit logging, regular vulnerability scanning, and periodic penetration testing by external providers. Staff with access to systems handling sensitive data are trained on security and data protection obligations.
Compliance with policies is monitored through regular reviews, security audits, and operational checks. Where issues are identified, corrective actions are tracked and implemented. The organisation follows the UK Software Security Code of Practice and works closely with trusted cloud providers whose infrastructure meets recognised security and resilience standards. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Configuration and change management is managed through defined internal controls. All application code, infrastructure configuration, and deployment artefacts are version-controlled and tracked throughout their lifecycle. Changes are logged, reviewed, and approved before deployment. Security impact is assessed as part of change review, including access controls, data handling, and potential service impact. Changes are tested in non-production environments prior to release, with controlled deployment to production and rollback procedures in place. Access to production systems is restricted to authorised personnel, and changes are auditable.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Vulnerability management is handled through a combination of automated scanning, monitoring, and controlled patching processes. Cloud-native vulnerability scanning tools are used to continuously assess infrastructure and application components for known vulnerabilities. Alerts are reviewed and prioritised based on severity and potential impact. Security patches and updates are applied promptly through managed deployment pipelines, with urgent fixes expedited where required. Threat intelligence is informed by cloud provider security advisories, vendor notifications, CVE databases, and regular review of industry security guidance. Changes are tested prior to deployment to minimise operational risk.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Protective monitoring is implemented using cloud-native monitoring and security tooling. System activity, access logs, application logs, and infrastructure metrics are continuously monitored for abnormal behaviour or indicators of compromise. Automated alerts are generated for suspicious activity and reviewed by authorised personnel. Where a potential issue is identified, access can be restricted, affected components isolated, and corrective action taken. Incidents are assessed promptly, with investigation and remediation initiated in line with internal incident response procedures. Customers are notified where required, and lessons learned are used to improve controls and monitoring.
- Incident management type
- Supplier-defined controls
- Incident management approach
-
HRI operates defined incident management processes aligned with ISO 27001 principles. Pre-defined response procedures are in place for common security and operational incidents. Incidents can be reported via email or designated support channels and are logged, assessed, and prioritised based on impact and severity.
Customers are notified of relevant incidents in a timely manner, with updates provided throughout resolution. Post-incident reports are made available on request, including root cause analysis and corrective actions taken. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 7%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 12%
- Over £5,000,001
- 15%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- B38a2398-917c-41bb-b1f0-c00994f327f3
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-