h-trak Scan4Safety System
h-trak Scan4Safety delivers barcode-based tracking of implants, consumables, procedures, stock, staffing, and timings at the point of care. It enables accurate patient-level costing, automated replenishment, improved theatre efficiency, informed clinical, finance and procurement decisions, and enhanced patient safety through full track-and-trace, expiry alerts, and data reuse across systems securely nationwide.
Features
- Cloud-hosted SaaS solution supporting secure, scalable deployment.
- GS1-certified barcode scanning using GS1 and HIBC identifiers.
- End-to-end track and trace to patient level.
- Real-time capture of devices, implants, consumables and materials.
- Centralised product master data management maintained by supplier.
- Automated inventory, stock and materials management including stock takes.
- Consumption-based replenishment with expired, obsolete and waste stock identification.
- Procedure and patient-level costing across materials, staff and time.
- Private patient billing supported by accurate usage data.
- Interoperable with hospital systems via APIs, reporting and analytics.
Benefits
- Improves patient safety through accurate patient-level traceability.
- Reduces expired, obsolete, and wasted stock.
- Automates stock replenishment using real-time consumption data.
- Frees clinical staff time for direct patient care.
- Reduces manual data entry at point of care.
- Enables accurate procedure and patient-level costing analysis.
- Improves purchasing efficiency and contract compliance.
- Supports informed decision making through integrated reporting.
- Enables benchmarking of procedures across specialties.
- Improves collaboration across clinical, procurement, and finance teams.
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 9 5 7 0 6 9 3 6 6 4 6 3 6 1
Contact
h-trak
Nick Roots
Telephone: 0330 127 6240
Email: info@htrak.com
About your service
- Service categories
-
Applications
Supply chain management
- Warehousing and inventory management
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
- H-trak is delivered as a secure, cloud-hosted SaaS service and normally requires network connectivity. During temporary outages, handheld devices can capture data offline and store it locally until connectivity is restored and the data is synchronised. Use of the service requires compatible barcode scanning hardware, supplied separately. The service is configurable to support customer workflows but does not allow unrestricted bespoke development. Integration with existing hospital systems is supported through standard APIs and interfaces and is delivered as a separately scoped implementation activity.
- System requirements
-
- Users access via standard browsers: E.g. Chrome, Firefox, Safari, Edge.
- Internet connectivity is required for normal system operation.
- No local software installation on user PCs.
- Compatible handheld barcode scanning devices required.
- Handheld devices support offline data capture.
- Local device storage used until data synchronisation.
- Standard APIs required for system integrations.
- System integrations require separate setup and configuration.
User support
- Email or online ticketing support
- Yes
- Support response times
-
Severity level 1: Respond 1 hour | (1.5 hours outside Standard Business Hours) | resolve within 4 hours for Software & Web Services
/2 Business Days for hardware.
Severity level 2: Respond 2 hours | (2.5 hours outside Standard Business Hours) | resolve within 8 hours.
Severity level 3: Respond 1.5 days | resolve the date of next New Release (no earlier than 2.5 days)
Severity 4:Respond 2 days | resolve the date of the next New Release (no earlier than 4.5 days)
Severity 5:Respond 5 days | resolve 3 weeks - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Ongoing support from the Customer Services team is offered by telephone, email and through an online Freshdesk ticketing system.
Availability: Monday to Friday during 08.30 – 17.00 hours excluding nationally observed holidays.
On-site support is offered when required by users, during core office hours
though most customers do not require it, after a detailed onboarding
programme. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
H-trak helps users start using the service through a structured onboarding and implementation approach that reduces risk and supports rapid adoption. The supplier works closely with customer teams to configure the service to local clinical and operational workflows before go-live, ensuring the system aligns with existing working practices. Onsite, role-based training is provided for clinical, operational, procurement, finance and administrative users, and is delivered in live environments using real tasks users perform as part of their daily work. This ensures users are confident and productive from day one.
The supplier provides clear user documentation and guidance materials to support ongoing use of the service and enable users to self-serve routine tasks. During deployment, implementation specialists support data setup, workflow validation and system configuration to ensure the service operates as intended. Following go-live, ongoing support is provided to resolve issues, answer queries and help embed the service into routine working practices. This approach reduces onboarding risk, supports sustained user adoption, and enables organisations to realise operational, financial and patient safety benefits quickly. - Service documentation
- Yes
- Documentation formats
-
- Other
- Other documentation formats
- Online video
- End-of-contract data extraction
-
At the end of the contract, h-trak supports users to extract their data in a structured and controlled manner. The supplier works with the customer to agree the scope, format and method of data extraction based on the customer’s requirements. Data can be provided in commonly used, open formats to support reuse, reporting or migration to another system.
The extraction process is planned and managed to minimise disruption to live services and ensure data integrity. The supplier provides guidance on the content and structure of the exported data to help customers understand and use it effectively.
Following successful data extraction and customer confirmation, h-trak securely deletes customer data from the live service in line with contractual obligations, data protection requirements and information governance standards. This approach ensures customers retain access to their data at contract end while supporting secure and compliant service exit. - End-of-contract process
-
At the end of the contract, h-trak works with the customer to support an orderly service exit. This includes agreeing timelines, supporting data extraction in an agreed format, and confirming completion of contractual obligations. Once data extraction has been completed and validated by the customer, h-trak securely deletes customer data from the live service in line with data protection, information governance and contractual requirements.
The contract price includes access to the cloud-hosted SaaS service, use of the core application features, system maintenance, security updates, and standard support services. Configuration of workflows and data capture options required to use the service as intended is also included.
Additional costs may apply for optional services outside the standard offering. These can include handheld scanning hardware, bespoke integration work with third-party systems, enhanced reporting or business intelligence tools, additional training beyond the agreed onboarding scope, and customer-specific data extraction requests beyond standard exit support. All additional costs are agreed in advance with the customer. - Documentation accessibility standard
- WCAG 2.2 A
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Linux or Unix
- MacOS
- Windows
- ChromeOS
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The mobile devices are used for data collection and for accessing functionality on the move where the users are actively moving about locations. This works well for Operating theatre and ward environment. The administrative functions are undertaken from a PC interface as they require more detailed information.
- Service interface
- No
- User support accessibility
- None or don’t know
- API
- No
- Customisation available
- Yes
- Description of customisation
- The h-trak Scan4Safety system has many options that customers can choose from, to meet their individual needs. These include the types of products captured and stock types, timing points used, staffing categories, anaesthetic lists and procedure details. Handhelds can be customised to capture specific data such as OPCS codes, various reasons for timing points or reasons for delays. h-trak staff will collaborate with the customer to facilitate the customisation.
Scaling
- Independence of resources
-
The service is designed to ensure that users are not adversely affected by demand generated by other users.
The platform uses UK-based virtual servers that support multiple concurrent users and are monitored regularly. Periodic capacity testing is undertaken to confirm the service can operate effectively under expected and peak loads. As user numbers and system demand increase, server resources can be scaled to maintain performance.
An enterprise-grade database supports large datasets and high transaction volumes, ensuring consistent performance. Ongoing monitoring and resource management help prevent any single user or workload from impacting the experience of others.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
The service provides comprehensive reporting on system usage, including the time users spend accessing the service. A range of standard reports is available within the h-trak service, covering procedures, purchasing activity, and stock management.
These reports provide accurate measurement of service usage and operational performance, including costs, procedure duration, staff involved, tracking of implantable devices, and stock replenishment activities. Reporting data supports oversight, audit, and operational efficiency.
Where required, this information can be compared with data from existing theatre management systems or integrated directly with those systems to provide a consolidated view of activity and performance. - Reporting types
-
- API access
- Real-time dashboards
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with another standard
- Other
- Other data at rest protection approach
- User access to the application is controlled through unique usernames and passwords, which are stored in encrypted form. Role-based access controls and permissions are used to ensure users can only access data and functionality appropriate to their role. Backup data is encrypted to protect information at rest and support data security and confidentiality.
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
-
Using the h-trak Resource System, users can export their data by requesting an agreed data extract from the supplier. h-trak works with the customer to define the scope, format and delivery method of the export based on the customer’s needs. Data is provided in commonly used, open formats to support reporting, analysis or migration to another system. Exports are managed securely and in line with data protection and information governance requirements, ensuring data integrity and confidentiality throughout the process. If the dataset is too large
for email, assistance can be provided to produce an export dataset via secure file transfer. - Data export formats
-
- CSV
- Other
- Other data export formats
-
- XML
- TXT
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Other
- Other protection between networks
- The buyer’s network and the h-trak network are logically and physically separated. Each environment is protected by its own firewalls and security controls. Communication between the two parties is managed through secure interface services at both ends, ensuring there is no direct connectivity between buyer systems and h-trak databases or servers. This approach reduces risk and helps maintain clear security boundaries between the two environments.
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Other
- Other protection within supplier network
- Strict firewall rules, anti-intrusion software and anti-virus software protect the network.
Availability and resilience
- Guaranteed availability
-
The service is designed to be available 24 hours a day, 7 days a week, excluding scheduled maintenance. Planned system upgrades or maintenance are communicated to buyers at least 72 hours in advance and are normally carried out outside standard business hours. Maintenance activities typically take place once or twice per month and may result in service unavailability for one to two hours.
Telephone support is available Monday to Friday, 08:30 to 17:00, excluding public holidays. Calls received outside these hours are directed to an answerphone service and responded to on the next working day. Monitored email support is available 24/7.
Support requests are logged, triaged, and prioritised based on urgency and impact, with resolution activities carried out during standard support hours.
If the customer’s network or the hosted service is temporarily unavailable, data capture at the point of care is not affected. Information can continue to be collected on handheld devices and securely synchronised with the central system once connectivity is restored. As clinical data capture is not interrupted during outages, service continuity is maintained and compensation is not required. - Approach to resilience
- H-trak Limited servers are hosted by Carelink, a Redcentric company. The service is hosted within secure, UK-based data centre facilities designed to provide high levels of security and resilience. The infrastructure is supported and monitored 24×7×365 from a UK operations centre. This hosting environment supports a service availability target of 99.95% uptime.
- Outage reporting
-
The h-trak Scan4Safety service is designed to support continued operation during temporary service or connectivity issues. Handheld mobile devices used at the point of care periodically synchronise with the central host server but are able to continue capturing data locally if the host service or network is unavailable. This ensures that clinical workflows are not interrupted during outages.
Data captured on handheld devices is stored securely and synchronised with the central system once connectivity is restored. This approach supports service continuity and protects against data loss.
If a handheld device experiences a fault, the issue can be investigated by the h-trak support team using remote access tools, where appropriate. Additional devices can be provided to replace faulty units and minimise disruption to users.
In the event of planned or unplanned service outages affecting non-critical functionality, such as reporting or administrative features, users are informed by the h-trak Customer Services team via email. This ensures customers are kept informed while core data capture activities continue to operate.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
-
Access to the h-trak service is strictly controlled and restricted based on role and authority. Registered users are issued with unique usernames and passwords, which are stored in encrypted form using Salted MD5. The system can also be configured to require a 4-digit PIN on handheld devices. All access is secured over a VPN connection.
The service is split into separate functional components, each requiring authentication. Management interfaces are accessible only to authorised h-trak personnel. Customer users have no access to management interfaces or administrative functions. Support access is similarly restricted to authorised staff only. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Other
- Description of management access authentication
-
Management access to the h-trak service is tightly controlled and authenticated. Users are only added following approval from the buyer’s management. Access to management functions within the application requires a unique username and password and is restricted to specific privileged access levels.
Access to the underlying server infrastructure is heavily restricted and available only to authorised personnel. Server access is provided via a secure VPN connection and requires username and password authentication, supplemented by two-factor authentication (2FA). These controls ensure that management access is limited, auditable, and protected against unauthorised use.
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
-
• Cyber Essentials Plus
• NHS Data Security and Protection Toolkit - Information security policies and processes
-
H-trak Limited follows defined information security processes supported by an Information Security Policy aligned with GDPR requirements.
The policy ensures the protection of all information systems and the mitigation of risks associated with misuse or unauthorised access. Access to the service is restricted to authorised users through unique usernames and passwords. User passwords are stored in encrypted form using Salted MD5 hashing, which provides strong protection against password disclosure and automated attacks. Role-based permissions are applied to ensure users can only access data appropriate to their role.
Technical and organisational controls provide a secure information systems working environment for authorised users. Backup data is encrypted to protect information at rest.
Users are made aware of the Information Security Policy and their responsibilities for protecting the confidentiality and integrity of the data they handle.
Information security incidents must be reported to the IT/Operations Director by emailing info@htrak.com or custserviceuk@htrak.com. Where appropriate, the Data Protection Officer is involved to oversee escalation, investigation, and resolution in line with regulatory obligations. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
The service follows a defined configuration and change management process to maintain security and stability. Configuration of service components is restricted to authorised personnel only. All components and configuration changes are managed through a source control system (TFS), which records version history and provides full traceability of changes, including who made them.
When changes are proposed, the development team performs an impact assessment, including a security impact analysis, to identify any additional security requirements. New or updated components are thoroughly tested before deployment to ensure they do not negatively affect service performance, availability, or security. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
H-trak Limited follows a defined vulnerability management process to identify and mitigate security risks.
Potential threats are assessed using security alerts, system monitoring, and endpoint protection tools. All h-trak computers are protected by Windows Defender and Bitdefender Endpoint Security, with on-access scanning enabled. Bitdefender automatically quarantines or removes malware and spyware.
Information on emerging threats is obtained from security tooling, vendor advisories, and operating system updates. Bitdefender Update Manager checks regularly for updates.
Security patches are applied based on severity. Critical updates are deployed as soon as practicable, with lower-risk patches applied during routine maintenance. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Protective monitoring is used to detect and respond to security incidents.
The service uses automated logging, monitoring, and alerting to identify potential compromises, including unusual access patterns, failed login attempts, configuration changes, or abnormal system behaviour. Access logs are reviewed to detect unauthorised activity. Infrastructure is monitored continuously, and firewall intrusion alerts are generated by the hosting provider.
When a potential compromise is identified, it is assessed to determine severity and impact. Immediate actions may include isolating affected systems, restricting access, applying mitigations, and blocking IP addresses.
High-severity incidents are responded to immediately. Lower-severity incidents are handled within agreed timescales. - Incident management type
- Supplier-defined controls
- Incident management approach
-
Incident management processes ensure incidents are handled consistently and effectively. Pre-defined procedures exist for common incident types, including service outages, performance issues, and security events, with defined escalation routes and responsibilities.
Users can report incidents via telephone, email, or directly to the project management team when on-site. Incidents are logged, prioritised, and tracked through to resolution. Issues are managed by the project team, customer service team, and/or development team depending on severity and type. Issue logs are maintained, and software incidents are tracked using Freshdesk.
Significant incidents are investigated, documented, and reported to customers where required. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 7.5%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 12.5%
- Over £5,000,001
- 15%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- F54426b4-ee86-4f2c-8cc7-8c873d693904
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- A67a0a20-f5d2-4ca8-8869-9fe790d08164
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Introducing transparency to pay and reward processes
- Working conditions which promote an inclusive working environment and promote retention and progression
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of issues relating to entering the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
-