iGROW
iGROW is a digital growth chart solution designed to record, monitor, and analyse the growth and development of children and young people. It offers an alternative to traditional paper-based charts with an electronic, data-driven tool integrated into the organisation’s EPR or EDMS system.
Features
- System will work both anonymously or with individual patient details
- Data is stored in a standard SQL database
- Data recorded can be as simple or detailed as required
- Standalone or seamlessly integrated with all EPRs
- Supports data import and export, and Excel analysis
- Export data in various formats
- Hosted in a secure Cloud environment inside HSCN
Benefits
- Charts and notes can be shared within authorised user group
- Only system in the UK which utilises the UK data
- Provides clinicians with accurate, up-to-date growth information
- Offers an alternative to traditional paper-based charts
- Supports organisation’s transition to fully digital clinical documentation
- Full history view of growth supports clinical decision-making
- Ensures consistent monitoring of patient growth trajectories across services
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 5 9 6 9 5 1 4 2 7 0 8 5 8 0
Contact
HARLOW PRINTING LIMITED T/A HARLOW SOLUTIONS
Jack Harrison
Telephone: 01914554286
Email: bidteam@harlowprinting.co.uk
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Electronic Patient Records (EPR) or Electronic Document Management System (EDMS)
- Cloud deployment model
- Hybrid cloud
- Service constraints
- Service constraints are bound by agreed Service Levels
- System requirements
- No specific requirements
User support
- Email or online ticketing support
- Yes
- Support response times
- Support agreement are tailored to agreements. Typically response times are based on priority. Ranging from urgent priority target response time of 4 hours where there is a severe system malfunction to low priority (an issue that is inconvenient but does not require immediate attention) is 5 working days. Medium priority where there is a workaround is 2 working days.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Support is made available under an annual agreement. This support is made available via the helpdesk contact routes and will be accessible:
Monday - Friday, 9am – 5pm, UK working hours (excluding UK Bank Holidays). Additionally, a dedicated account manager is assigned as standard within our offering. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Our technical team works closely with the organisation's service teams and third-party suppliers to implement the solution. With the appropriate support package selected, we support with project plans and Project Initiation Documents (PID). Online training includes train the trainer, user guides and videos. Onsite training is also available at an additional charge.
- Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- Given the integrations and data, an offboarding project is agreed with organisation at an additional charge
- End-of-contract process
- Raw data is securely returned to the data controller by a means mutually agreed upon. Additional costs may be incurred depending on the complexity of work. Access to the service is terminated upon end of contract. Organisation is to provide access for the offboarding process to complete.
- Documentation accessibility standard
- WCAG 2.2 A
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- MacOS
- Windows
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- User interface differs across the two services
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 A
- Description of service interface
- Interface is designed for use by paediatricians and clinicians
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- Test team has tested interface
- API
- Yes
- What users can and can't do using the API
- API changes are recommended to be discussed with our technical team
- API documentation
- Yes
- API documentation formats
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- A limited set of options are customisable subject to requirements and are chargeable.
Scaling
- Independence of resources
- Our service ensures users are not affected by demand from other users through strict resource isolation and capacity management. For cloud deployments, each customer operates within a logically segregated environment with defined compute, storage, and database limits, proactive monitoring, and scalable resources to manage peak demand. For on-premise deployments, the service is installed within the organisation’s own infrastructure, providing full physical and logical separation and dedicated capacity. In all deployment models, secure connectivity is delivered via HSCN, ensuring resilient, prioritised access independent of other organisations’ usage. Service availability is continuously reviewed and capacity adjusted accordingly.
Analytics
- Service usage metrics
- Yes
- Metrics types
- For cloud installs, uptime, downtime and reporting
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Physical access control, complying with CSA CCM v4.0
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Data Erasure
Data importing and exporting
- Data export approach
- Growth chart data can be exported directly by users via role-based self-service in the system; if a managed export service is required for large or complex data exports, this can be provided at an additional cost and will be quoted to requirements.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- Uptime is greater than 99.9%
- Approach to resilience
- Available on request
- Outage reporting
- Email alerts
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Multi-Factor Authentication (MFA)
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is restricted using role-based access controls and the principle of least privilege. Administrative access is limited to authorised staff. Access is restricted to trusted networks. User access rights are formally authorised, regularly reviewed, and promptly removed when no longer required. Support channels are authenticated to ensure only approved users can raise or manage requests. All administrative and support activity is logged and monitored in line with NHS DSPT and ISO 27001 requirements.
- Access restriction testing frequency
- At least once a year
- Management access authentication
- Multi-Factor Authentication (MFA)
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
-
Cyber Essentials Plus
NHSE Data Security and Protection Toolkit - Information security policies and processes
- Full details available on request. In summary we use structured policies, risk assessments and documented procedures to govern how data is received, processed, anonymised and stored. Access to systems is role-based, logged and restricted to authorised staff only. Security controls such as encryption, monitoring, incident management and change control are all implemented as part of our certified ISMS. We review risks regularly through internal audits, management review meetings, and continuous improvement processes. Overall, our approach ensures that all information (identifiable or anonymised) is handled consistently, securely and in line with the NHS and ICO expectations.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
We operate a formal configuration and change management process aligned to ITIL best practice. All service components (infrastructure, application, and configuration items) are uniquely identified and recorded in a configuration management system, with version control and audit history maintained throughout their lifecycle.
Changes are raised, assessed, approved, implemented, and reviewed through a controlled change process. Each change is subject to impact and risk assessment, including consideration of confidentiality, integrity, and availability. Security-relevant changes are reviewed by technical and information security leads and, where required, supported by testing and rollback plans. Emergency changes follow an expedited but fully auditable process. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- We operate a structured vulnerability management process aligned with ISO 27001. Potential threats are identified through regular vulnerability scanning, penetration testing, system monitoring, and formal risk assessments. Vulnerabilities are assessed and risk-rated based on their potential impact to confidentiality, integrity, and availability. Remediation actions are prioritised accordingly. Critical and high-risk vulnerabilities are patched promptly, following testing and change control procedures to minimise operational impact. Lower-risk issues are addressed through planned maintenance cycles. Threat intelligence is obtained from trusted sources including vendor security advisories, operating system and application suppliers, the National Cyber Security Centre (NCSC), and recognised industry security alerts.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- We operate protective monitoring controls aligned with ISO 27001 to detect and respond to potential security incidents. System, application, and access logs are collected and reviewed to identify indicators of compromise, including unauthorised access attempts, unusual user behaviour, and unexpected system activity. Alerts are generated for security-relevant events and reviewed by authorised personnel. When a potential compromise is identified, incidents are triaged, contained, and investigated in line with our incident management procedures, with corrective actions implemented as required. Security incidents are responded to promptly based on severity, with high-risk incidents investigated immediately and escalated to minimise impact and restore service.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- We operate a formal incident management process aligned with ISO 27001 and ITIL best practice. Pre-defined procedures are in place for common operational and security events, including service outages, security incidents, and data-related issues, ensuring consistent and timely handling. Users can report incidents via agreed support channels, including email and service desk, with incidents logged, prioritised, and tracked through to resolution. Incidents are assessed based on impact and urgency and escalated where required. Incident reports are provided to customers following significant incidents, detailing root cause, actions taken, and any preventative measures implemented to reduce the likelihood of recurrence.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
- Health and Social Care Network (HSCN)
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- A free version of the service is available for clinicians. It provides limited access to core functionality. The free version does not include full configuration, integrations, live data use, service levels, or ongoing support. Access is time-limited typically to 14 days and provided by agreement.
- Link to free trial
- https://www.igrow-software.co.uk/register
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 1%
- Between £2,500,001 and £5,000,000
- 2%
- Over £5,000,001
- 2%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Management Systems Certification Ltd
- ISO/IEC 27001 accreditation date
- Wednesday 3 December 2025
- What the ISO/IEC 27001 doesn’t cover
- N/a
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Management Systems Certification Ltd
- ISO 9001 accreditation date
- Friday 21 June 2024
- What the ISO 9001 doesn’t cover
- N/a
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Ea3c770a-df8f-4cf0-a770-3ce0458cab10
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 15293816-46b8-46a0-9ac2-5fab25408c08
- Other security certifications
- Yes
- Any other security certifications
- NHS Data Security and Protection Toolkit
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Other measures to offer development opportunities for the target cohort(s) in the contract workforce
-