Skip to main content

Help us improve the Digital Marketplace - send your feedback

Heart Rhythm International

Heart Rhythm International

Heart Rhythm International is a cloud-based cardiac rhythm management platform supporting implant workflows, implantable cardiac device tracking, follow-up management, Field Safety Notice management, and regulatory compliance for NHS cardiac services. It integrates with major device manufacturers and hospital systems to support safe, efficient clinical and governance workflows.

Features

  • Structured implant and follow-up workflows for cardiac device services
  • Implantable cardiac device and lead tracking with full traceability
  • Automated ingestion of device data, including remote transmissions, from manufacturers
  • Appointment scheduling and follow-up management for cardiac device patients
  • Clinical dashboards with DNA tracking and follow-up status reporting
  • Field Safety Notice management with affected patient identification
  • Secure patient and device registry with role-based access control
  • Integration with hospital systems to reduce manual data entry
  • Audit trails and reporting for safety, quality, and oversight
  • Cloud-hosted SaaS platform accessible via secure web browser

Benefits

  • Improve patient safety through accurate device and follow-up tracking
  • Support regulatory compliance with complete, auditable device records
  • Reduce missed follow-up appointments using DNA tracking and reporting
  • Ensure accurate data capture from manufacturers and clinical workflows
  • Streamline appointment scheduling for cardiac device patients
  • Improve clinic efficiency with centralised clinical dashboards
  • Reduce administrative workload through automated data ingestion
  • Respond quickly to Field Safety Notices and affected patients
  • Reduce data entry errors via system and manufacturer integrations
  • Increase clinic capacity without additional administrative staff

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at robert@heartrhythmintl.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

2 7 8 5 0 0 2 3 5 4 8 5 8 3 5

Contact

Heart Rhythm International Robert Kelly
Telephone: +353833325468
Email: robert@heartrhythmintl.com

About your service

Service categories

Application Development and Deployment

Data management

Database management systems

  • Relational Database Management Systems

Data integration and intelligence

  • Data Ingestion and Transformation Software
Multi cloud support
No

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
The service can integrate with and extend hospital patient administration systems, electronic patient records, cardiology information systems, and implantable device manufacturer platforms to support cardiac device workflows, scheduling, governance, and reporting. It can also operate independently where required.
Cloud deployment model
Public cloud
Service constraints
The service requires internet connectivity and access via a supported, up-to-date web browser. Planned maintenance is scheduled in advance and, where possible, outside core clinical hours. Integration availability may depend on third-party hospital systems and device manufacturers. Service performance may be affected during planned maintenance windows or external system outages.
System requirements
  • Modern web browser (Chrome, Edge, Firefox, Safari)
  • Secure internet connectivity
  • NHS-standard desktop or laptop device
  • Role-based user accounts provided by the service
  • Multi-factor authentication for user access
  • Email access for notifications and account management

User support

Email or online ticketing support
Yes
Support response times
Support requests submitted via email or the online ticketing system are acknowledged during business hours, Monday to Friday. Initial responses are typically provided within one business day. Critical issues impacting service availability are prioritised and responded to as quickly as possible. Response times may vary outside of standard business hours.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
HRI provides tiered support aligned to NHS operational needs.

Standard Support (included):
Email and ticket-based support during UK business hours (9am–5pm, Monday to Friday). This includes incident management, user support, configuration assistance, and guidance on clinical and administrative workflows. Response times are prioritised based on severity, with critical issues escalated immediately.

Enhanced Support (optional, additional cost):
Enhanced support packages can include extended hours, faster response times, scheduled health checks, and named technical contacts. Onsite support for onboarding, training, go-live assistance, or workflow optimisation is available at additional cost.

Account and technical support:
Each customer is assigned a named account contact. Technical support is provided directly by HRI engineers with domain expertise in cardiac services, device data, and NHS clinical workflows. Where required, HRI provides a dedicated technical lead for complex integrations or larger deployments.

Support levels and service credits are defined in the contract or SLA agreed at call-off stage.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
HRI provides structured onboarding to support users getting started quickly and safely. This includes remote onboarding sessions, optional onsite training where required, and role-based training for clinical, administrative, and governance users. Users are supported with written user guides, quick reference materials, and configuration support during initial setup. Ongoing support is available via email, phone, and scheduled check-ins to ensure adoption and correct use of the service.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
At the end of the contract, buyers can extract their data in commonly used, open formats such as CSV or structured data files. Data extracts can include patient records, device and implant data, follow-up history, audit logs, and configuration data, subject to role-based access and data protection requirements.

The HRI team supports customers during the data extraction process to agree scope, format, and secure transfer method. Where required, data can also be provided via secure file transfer or API-based export.

Following confirmation of successful data extraction, data is securely retained or deleted in line with contractual terms, data protection obligations, and agreed retention schedules.
End-of-contract process
At the end of the contract, the service will continue to operate until the agreed contract end date. During this period, buyers can request data extraction and agree the scope, format, and secure transfer method with the HRI team.

Standard offboarding support, including coordination of data extraction and confirmation of successful handover, is included within the contract price.

Where additional support is required beyond standard offboarding, such as bespoke data extracts, extended access periods, complex migrations, or additional technical assistance, these services may be provided at an agreed additional cost.

Following contract completion and confirmation of data handover, access to the service is withdrawn and data is securely retained or deleted in accordance with contractual terms, data protection obligations, and agreed retention policies.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Onboarding and offboarding documentation is provided digitally in clear, structured formats and written in plain language. Documentation is accessible via standard web browsers and common document formats, and can be enlarged or used with browser-based accessibility tools. Recorded demonstrations and live walkthroughs are also provided by the HRI team to support different user needs and ensure all users can complete onboarding and offboarding activities effectively.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The service is accessed via a responsive web interface. Core functionality is the same on mobile and desktop, with layouts optimised for smaller screens. On mobile devices, complex data entry and detailed reporting are best viewed on larger screens, while mobile access supports secure viewing, review, and basic interactions.
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
The service is provided through a secure, web-based user interface accessed via standard browsers. The interface supports clinical and administrative users to manage cardiac device records, appointments, dashboards, and reporting. Role-based access controls ensure users only see information relevant to their role. The interface is designed for use in clinical environments and supports desktop and mobile devices.
Accessibility standards
None or don’t know
Description of accessibility
The service is accessed through a standard web browser and is designed to be usable across desktop and mobile devices. Users can navigate the interface using standard browser controls, adjust zoom levels, and use built-in operating system accessibility features such as screen magnification. The interface uses clear layouts and consistent navigation to support clinical workflows. Some advanced clinical dashboards and data-dense views may be more challenging for users who rely solely on assistive technologies. Accessibility is actively considered in ongoing product development, with improvements delivered iteratively based on user feedback and service requirements.
Accessibility testing
The service has not yet undergone formal usability testing with users of assistive technologies such as screen readers or alternative input devices. User feedback has been gathered through routine use by clinical and administrative staff in live healthcare environments, and this feedback informs ongoing usability and design improvements. Accessibility considerations are included in product development planning, and formal accessibility testing can be undertaken as part of future enhancements or specific customer requirements.
API
Yes
What users can and can't do using the API
Heart Rhythm International provides secure RESTful APIs to support integration with hospital systems and approved third parties. The API allows authorised systems to ingest and retrieve patient, device, procedure, and follow-up data, supporting automated data flows and reducing manual data entry.

APIs are typically used for data exchange and integration rather than full system configuration. Core system setup, clinical configuration, and workflow management are performed via the web interface to maintain governance and patient safety.

API access is role-based, audited, and subject to contractual and information governance controls. Certain clinical actions and safety-critical changes are intentionally restricted from API access.
API documentation
Yes
API documentation formats
Open API (also known as Swagger)
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Buyers can configure the service to meet local clinical and operational requirements. Customisation includes workflow configuration, follow-up schedules, appointment types, clinical dashboards, reporting views, and role-based user access. Configuration is carried out by authorised customer administrators, with support from HRI where required.

Scaling

Independence of resources
The service is delivered as a multi-tenant cloud platform with logical tenant separation and dedicated resource controls. Performance is protected through elastic scaling, workload isolation, and continuous monitoring. Fair-use safeguards such as API rate limiting and background job queuing prevent abnormal or unintended workloads from impacting other users. Automated scaling and proactive monitoring ensure consistent performance during peak clinical activity, so demand from one organisation does not affect others.

Analytics

Service usage metrics
Yes
Metrics types
The service provides operational and clinical usage metrics including patient volumes, device counts, follow-up activity, appointment attendance and DNA rates, remote transmission volumes, and data ingestion status. Metrics also include user activity, audit logs, and workflow completion status to support service oversight, reporting, and capacity planning.
Reporting types
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with another standard
  • Encryption of all physical media
  • Other
Other data at rest protection approach
Data at rest is protected using industry-standard encryption provided by the underlying cloud platform. All databases and storage volumes are encrypted by default, with encryption keys securely managed by the cloud provider. Access to data is restricted through strict role-based access controls and least-privilege principles. Administrative access is logged and monitored, and production data is segregated by tenant to prevent unauthorised access.
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure

Data importing and exporting

Data export approach
Users can export their data by requesting a data extract from the HRI support team. Data is provided in agreed standard formats using secure transfer methods. Where supported, users can also export reports and datasets directly from the service via built-in reporting and export functions. Data exports are coordinated to ensure completeness, accuracy, and compliance with data protection and information governance requirements.
Data export formats
  • CSV
  • Other
Other data export formats
  • JSON
  • Secure API extract
Data import formats
  • CSV
  • Other
Other data import formats
  • JSON (via secure API)
  • HL7 messages (where supported through integration)

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
The service is provided with a target availability of 99.9%, excluding scheduled maintenance. Availability commitments are defined in the Service Level Agreement (SLA) provided as part of the contract.

If service availability falls below the agreed SLA threshold, service credits may be applied in accordance with the contract terms. Refunds are provided in the form of service credits against future fees rather than direct financial reimbursement.

Planned maintenance is excluded from SLA calculations and is communicated to users in advance. The service is not intended for real-time life-critical use, and temporary service interruptions do not impact immediate patient care delivery.
Approach to resilience
The service is hosted in a UK-based cloud environment using enterprise-grade infrastructure provided by a major cloud provider. The underlying platform includes built-in resilience across physical facilities, power, and networking. Data is protected through regular, automated backups, including air-gapped, immutable backups to protect against data corruption, accidental deletion, and ransomware events. Backups are retained and tested in line with defined recovery objectives, enabling secure restoration of service within the UK if required.
Outage reporting
Service availability is monitored continuously by the HRI operations team and underlying cloud provider monitoring services. In the event of a service disruption, affected customers are notified via email with details of the issue, expected impact, and progress updates. Where appropriate, follow-up communications are issued once service is restored, including a summary of the incident and any remedial actions taken. Outage information can also be provided on request as part of service reporting.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces is restricted to authorised personnel only and enforced through role-based access control and least privilege principles. Administrative access requires individual user accounts with strong authentication and multi-factor authentication. Access is reviewed regularly and removed promptly when no longer required.

Support channels are access-controlled, with customer-specific data only accessible to approved support staff on a need-to-know basis. All administrative and support access is logged and monitored for audit and security purposes.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
Security governance is overseen at board level, with clear accountability for information security and data protection. The organisation maintains documented security policies and procedures covering access control, data protection, incident management, and secure development practices. Risk is reviewed on an ongoing basis, with security considered as part of product design, change management, and supplier selection. Regular vulnerability management, penetration testing, and staff security awareness form part of the governance approach. Compliance with applicable regulatory and contractual requirements is reviewed periodically and updated as the service evolves.
Information security policies and processes
HRI follows documented information security policies and operational processes aligned with UK government guidance and industry best practice. These include access control, data protection, incident management, vulnerability management, secure development practices, and change control.

Overall responsibility for information security sits with a named board-level director. Day-to-day security operations are managed by senior technical staff, with clear reporting lines and escalation procedures for security incidents or risks.

Policies are enforced through technical controls within the cloud environment, role-based access controls, audit logging, regular vulnerability scanning, and periodic penetration testing by external providers. Staff with access to systems handling sensitive data are trained on security and data protection obligations.

Compliance with policies is monitored through regular reviews, security audits, and operational checks. Where issues are identified, corrective actions are tracked and implemented. The organisation follows the UK Software Security Code of Practice and works closely with trusted cloud providers whose infrastructure meets recognised security and resilience standards.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Configuration and change management is managed through defined internal controls. All application code, infrastructure configuration, and deployment artefacts are version-controlled and tracked throughout their lifecycle. Changes are logged, reviewed, and approved before deployment. Security impact is assessed as part of change review, including access controls, data handling, and potential service impact. Changes are tested in non-production environments prior to release, with controlled deployment to production and rollback procedures in place. Access to production systems is restricted to authorised personnel, and changes are auditable.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Vulnerability management is handled through a combination of automated scanning, monitoring, and controlled patching processes. Cloud-native vulnerability scanning tools are used to continuously assess infrastructure and application components for known vulnerabilities. Alerts are reviewed and prioritised based on severity and potential impact. Security patches and updates are applied promptly through managed deployment pipelines, with urgent fixes expedited where required. Threat intelligence is informed by cloud provider security advisories, vendor notifications, CVE databases, and regular review of industry security guidance. Changes are tested prior to deployment to minimise operational risk.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Protective monitoring is implemented using cloud-native monitoring and security tooling. System activity, access logs, application logs, and infrastructure metrics are continuously monitored for abnormal behaviour or indicators of compromise. Automated alerts are generated for suspicious activity and reviewed by authorised personnel. Where a potential issue is identified, access can be restricted, affected components isolated, and corrective action taken. Incidents are assessed promptly, with investigation and remediation initiated in line with internal incident response procedures. Customers are notified where required, and lessons learned are used to improve controls and monitoring.
Incident management type
Supplier-defined controls
Incident management approach
HRI operates defined incident management processes aligned with ISO 27001 principles. Pre-defined response procedures are in place for common security and operational incidents. Incidents can be reported via email or designated support channels and are logged, assessed, and prioritised based on impact and severity.

Customers are notified of relevant incidents in a timely manner, with updates provided throughout resolution. Post-incident reports are made available on request, including root cause analysis and corrective actions taken.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
7%
Between £1,000,001 and £2,500,000
10%
Between £2,500,001 and £5,000,000
12%
Over £5,000,001
15%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
B38a2398-917c-41bb-b1f0-c00994f327f3
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at robert@heartrhythmintl.com. Tell them what format you need. It will help if you say what assistive technology you use.