Skip to main content

Help us improve the Digital Marketplace - send your feedback

RAPID HEALTH LTD

Smart Triage

Smart Triage is a Software as a Service AI-triage and online consultation platform for UK primary care. It uses automated assessment within clinician-defined protocols to capture patient-reported information, prioritise and route requests, manage demand and capacity, and enable online navigation and appointment booking across practices, PCNs and integrated care settings.

Features

  • AI-triage using automated assessment within clinician-defined protocols
  • Online consultation capturing structured patient-reported information
  • Automated prioritisation and routing of patient requests
  • Configurable triage pathways aligned to local practice rules
  • Real-time appointment booking based on available capacity
  • Demand and capacity management across practices and PCNs
  • Integration with EMIS, SystmOne, NHS Login and NHS App
  • Multi-channel access supporting online, phone and in-person requests
  • Secure multi-tenant SaaS hosted in the UK public cloud
  • Aggregated operational datasets supporting demand analysis and service configuration

Benefits

  • Reduce administrative workload by automating triage and booking
  • Improve patient access through consistent online consultations
  • Manage demand effectively during peak periods
  • Route patients to appropriate care without manual handling
  • Protect clinical capacity through effective prioritisation
  • Standardise access processes across practices and PCNs
  • Reduce phone congestion and inbox backlogs
  • Enable staff to focus on patient care
  • Provide clear visibility of demand and capacity
  • Support compliance with primary care access requirements

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at hello@rapidhealth.ai. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

5 9 7 5 1 4 4 9 2 9 8 6 1 4 4

Contact

RAPID HEALTH LTD Carmelo Insalaco
Telephone: 03301335610
Email: hello@rapidhealth.ai

About your service

Service categories

Applications

Production and operations

Service industry and public sector operations

  • Healthcare
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
N/A
System requirements
Modern web browser with internet connectivity

User support

Email or online ticketing support
Yes
Support response times
Support is provided via the Rapid Health Service Desk during business hours, 09:00–18:00 GMT/BST, Monday to Friday. Service tickets are prioritised based on business impact. Target response times are within 2 business hours for Priority 1 issues, 4 business hours for Priority 2, 16 business hours for Priority 3 and 40 business hours for Priority 4. Resolution targets range from 8 business hours for Priority 1 issues to inclusion in a future release for low-impact issues.
User can manage status and priority of support tickets
No
Phone support
No
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Rapid Health provides standard support as part of the service subscription via email and an online service desk during business hours, 09:00–18:00 GMT/BST, Monday to Friday. Support requests are prioritised based on business impact in line with the published SLA.
Standard support is included at no additional cost and covers incident management, service requests and configuration support. Response and resolution targets are defined by priority level, ranging from rapid response for critical issues to scheduled resolution for low-impact requests.
Enhanced support services, including onsite support, implementation assistance, training sessions and bespoke configuration support, are available at additional cost and agreed at call-off.
Rapid Health does not provide a dedicated technical account manager or named cloud support engineer as standard. Account management and service oversight are provided by the Rapid Health delivery and support team, with escalation routes available where required.
Support available to third parties
No

Onboarding and offboarding

Getting started
Rapid Health supports customers through a structured onboarding process designed to enable users to start using the service quickly and effectively. Following contract award, customers are provided with onboarding guidance covering account setup, user access, and initial configuration.
User training is delivered through e-learning materials that allow users to learn at their own pace. This is supported by scheduled live online Q&A sessions, giving users the opportunity to ask questions, clarify workflows, and understand how to use the service in their operational context.
User documentation and guidance materials are provided to support ongoing use of the platform. During onboarding and live operation, customers have access to the Rapid Health service desk for support and issue resolution. Where additional onboarding support is required, this can be agreed with the customer as part of the implementation approach.
Service documentation
Yes
Documentation formats
  • PDF
  • Other
Other documentation formats
  • Video guidance
  • Email-based guides
  • E-learning materials
End-of-contract data extraction
At the end of the contract, customers can request extraction of their data by contacting the Rapid Health service desk. Data extraction is managed as a supplier-assisted process to ensure data is provided securely, accurately, and in line with contractual and data protection obligations.
Following a valid request, Rapid Health works with the customer to confirm the scope of data required and the appropriate format for delivery. Data is then prepared and provided securely using agreed transfer methods. Any reasonable assistance required to support data extraction is handled in accordance with the applicable contract terms.
Once data extraction has been completed and confirmed by the customer, data retained within the service is managed in line with agreed retention and deletion requirements set out in the contract and data processing arrangements.
End-of-contract process
At the end of the contract, Rapid Health will work with the buyer to ensure an orderly, low-risk exit in line with the agreed call-off contract and Call-Off Schedule 10 (Exit Management), where applied.
Where the call-off contract includes automatic renewal, this will be set out in the agreed contract terms. The buyer retains the right to terminate the contract or prevent renewal in accordance with the notice and termination provisions agreed at call-off stage.
All buyer data remains the property of the buyer. At contract end, data will be returned to the buyer in a commonly used, machine-readable format or securely deleted in line with the buyer’s instructions and applicable data protection requirements. Written confirmation of deletion can be provided on request.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Rapid Health provides onboarding and offboarding documentation in formats designed to be accessible to a wide range of users. Documentation is primarily provided in digital PDF format and shared electronically via email, allowing users to access content using standard assistive technologies such as screen readers and text resizing tools where supported by the user’s device.
Supporting guidance is also provided through video content and e-learning materials, which enable users to consume information in different ways according to their needs. Live online Q&A sessions provide an additional opportunity for users to ask questions and clarify onboarding or offboarding steps.
Where customers have specific accessibility requirements, Rapid Health will work with them to provide information in an alternative format or offer additional support on request, ensuring onboarding and offboarding activities can be completed effectively.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The service provides different user experiences depending on user role. The patient-facing interface is designed to work on mobile devices and desktops, supporting online consultation and request submission through a responsive web interface. The practice-facing administrative interface is optimised for desktop use, providing access to triage workflows, dashboards, configuration and integrations that benefit from larger screens and keyboard-based interaction. Core functionality and data are shared across interfaces, with role-based access controls applied.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
Smart Triage is accessed through a secure, browser-based service interface. Patients access a responsive web interface to submit online consultations and requests using structured, guided questions. Practice users access a separate administrative interface designed for desktop use, providing tools for reviewing submissions, prioritising and routing requests, managing workflows, configuring pathways and viewing operational dashboards. Interfaces are role-based and secured through authentication and access controls. The service does not require local installation and is accessed via standard web browsers on approved devices.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
Accessibility considerations are incorporated into the design and ongoing development of the service interface. The patient-facing interface is designed to support use with common assistive technologies, including screen readers and browser accessibility features. Testing is carried out as part of routine quality assurance using accessibility tooling and manual checks, with feedback from users and customers used to inform improvements. Accessibility issues identified are prioritised through the product backlog and addressed as part of continuous service improvement.
API
No
Customisation available
Yes
Description of customisation
Configuration supports local adoption while maintaining a standardised, clinically safe core platform.

Scaling

Independence of resources
Smart Triage is delivered as a multi-tenant Software as a Service platform designed to manage variable demand across users. Logical separation, role-based access controls and tenant-aware configuration ensure customer data and workflows are isolated. The service is hosted on scalable cloud infrastructure with capacity management, monitoring and throttling controls to prevent individual usage patterns adversely affecting other users. Performance and availability are actively monitored, with proactive management and operational controls applied to maintain consistent service levels as demand fluctuates.

Analytics

Service usage metrics
Yes
Metrics types
Smart Triage provides service usage metrics to support operational oversight and demand management. Metrics include volumes of patient submissions, submission trends over time, triage outcomes, workflow routing and request resolution, response and handling times, appointment utilisation, pathway usage and administrative workload indicators. Metrics support practices, PCNs and commissioners to understand demand, capacity and service performance and to inform service improvement and planning activities.
Reporting types
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CHECK service provider
Protecting data at rest
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure

Data importing and exporting

Data export approach
Users can export their data from Smart Triage by submitting a request to Rapid Health support or their nominated account contact. Data exports are provided securely following buyer authorisation and identity verification.
Exports are carried out in line with the agreed call-off contract and data protection requirements. Where required, exports can be scheduled or provided as part of contract exit activities.
Buyer data remains the property of the buyer at all times. Exported data is transferred securely using agreed methods and access controls to ensure confidentiality and integrity.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
Rapid Health does not contractually guarantee a fixed uptime percentage. Instead, the service is provided on a 24 hours a day, 7 days a week basis using commercially reasonable efforts, excluding planned maintenance and permitted emergency maintenance.
Planned maintenance is scheduled in advance where possible and communicated to customers with notice, and is designed to minimise disruption to service availability.
Availability is supported by defined support and maintenance arrangements set out in the Rapid Health Platform Support and Service Level Agreement. Incidents are prioritised by business impact from Priority 1 to Priority 4, with target response and resolution times applied during normal business hours. Priority 1 incidents, where the service is unavailable and no workaround exists, have a target response within 2 business hours and a target resolution within 8 business hours.
Service availability is monitored and incidents are managed through the Rapid Health service desk, with customers kept informed of progress and resolution.
Where availability expectations are not met, any remedies, service credits or refunds are handled in accordance with the applicable Order Form, SLA schedule and Master Services Agreement.
Approach to resilience
Rapid Health designs the service to be resilient in line with the government’s cloud security principle on asset protection and resilience. The service is hosted on secure cloud infrastructure designed to protect customer data and maintain availability in the event of component failure.
Resilience is achieved through infrastructure redundancy and fault isolation to reduce single points of failure. Service components are monitored continuously, with automated alerts triggering investigation and incident response where availability or performance thresholds are breached. Planned maintenance is controlled, tested in advance, and scheduled to minimise disruption.
Customer data and service configuration are protected through regular backup processes, enabling restoration to a known good state in the event of data loss, corruption, or a security incident. Backup and recovery procedures are documented and tested as part of operational assurance activities.
Details of the underlying data centre controls, physical security, and geographic resilience are managed by the cloud infrastructure provider and are available to customers on request. Incidents affecting resilience are managed in line with defined incident management procedures and support service levels, with post-incident reviews used to drive continuous improvement.
Outage reporting
Rapid Health reports service outages directly to affected customers via email. Where a service disruption is identified, customers are notified as soon as reasonably practicable and provided with information on the nature of the outage, expected impact, and progress towards resolution. Follow-up communications are issued as appropriate until the incident is resolved.
The service does not currently provide a public status dashboard or outage reporting API. All outage communications are managed through direct customer notifications and the Rapid Health service desk to ensure accurate, timely and controlled communication. Post-incident summaries can be provided on request in line with incident management procedures.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is restricted through role-based access control, least-privilege principles and separation of duties. All users authenticate using unique credentials with enforced multi-factor authentication. Administrative access is limited to approved personnel and subject to regular access reviews. Support access to customer data is strictly controlled, logged and provided only where operationally necessary. Management interfaces are secured using network-level restrictions and application controls. All privileged and support actions are comprehensively logged, monitored and retained to support security monitoring, audit requirements and incident response.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
Rapid Health applies a risk-based security governance approach aligned to the UK Software Security Code of Practice. Senior leadership is accountable for software security and resilience, with clear ownership of secure design, development, deployment and maintenance activities. Secure by design and secure by default principles are applied throughout the software lifecycle. We use controlled build and deployment processes, regular vulnerability scanning and independent penetration testing, supported by documented vulnerability management and incident response processes. Security controls and risks are reviewed regularly, and findings are tracked to remediation. This approach ensures proportionate, consistent governance without reliance on formal certification.
Information security policies and processes
Rapid Health operates a documented information security management approach proportionate to the nature of the Smart Triage service. Core policies cover information security, access control, data protection, secure development, incident management, vulnerability management, change management and business continuity.
Security governance is owned by senior management, with day-to-day responsibility delegated to designated technical leads. Risks, incidents and control effectiveness are escalated through defined reporting lines to senior leadership as required.
Policies are embedded into operational processes, including role-based access control, least-privilege administration, secure build and deployment practices, logging and monitoring, and controlled change processes. Compliance is reinforced through mandatory staff onboarding, ongoing security awareness, and technical controls such as automated monitoring, vulnerability scanning and regular independent penetration testing.
Security incidents and vulnerabilities are managed through documented response procedures, with root cause analysis and tracked remediation. Policies and processes are reviewed periodically and updated to reflect changes in risk, technology and regulatory expectations.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Configuration items including application code, infrastructure, integrations and system configurations are version-controlled and tracked throughout their lifecycle. Changes follow a formal change management process with documented impact and risk assessment, including security, data protection and patient safety considerations. Changes are reviewed, tested and approved prior to deployment, with segregation between development, test and production environments. Emergency changes follow an expedited but auditable approval process. These controls operate within our quality management system, which is undergoing external certification as part of our CE Class IIb medical device conformity assessment.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
We operate a risk-based vulnerability management process aligned with our secure development lifecycle and medical device QMS. Potential threats are identified through automated vulnerability scanning, dependency monitoring, penetration testing, code review, and threat modelling. We monitor sources including vendor security advisories, CVE/NVD feeds, cloud provider alerts, and results from independent penetration tests. Vulnerabilities are triaged based on severity, exploitability, and patient safety impact. Critical and high-risk issues are prioritised and remediated promptly, with patches deployed via controlled change management and tested before release. Remediation actions are tracked to closure and reviewed as part of ongoing security and risk management.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
We operate continuous protective monitoring using centralised logging and automated alerting across application, infrastructure and security components. Logs cover authentication, privileged access, configuration changes and data access. Alerts for anomalous activity are triaged by trained staff, with containment actions such as access revocation or system isolation where required. Incidents are investigated and remediated in line with our incident management process, with initial response typically within hours based on severity.
Incident management type
Supplier-defined controls
Incident management approach
Rapid Health operates defined incident management procedures aligned to UK government operational security principles. Pre-defined playbooks exist for common events, including service outages, security incidents and data protection incidents. Incidents are detected through system monitoring or reported by users via a dedicated support email and service desk during support hours. All incidents are logged, triaged by severity, investigated, and resolved with documented actions and timelines. Where required, customers receive timely incident notifications and status updates. Post-incident reports are provided on request and include root cause analysis, impact assessment, corrective actions and lessons learned to support continuous improvement.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
Yes
Connected networks
Health and Social Care Network (HSCN)

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
2%
Between £500,001 and £1,000,000
5%
Between £1,000,001 and £2,500,000
8%
Between £2,500,001 and £5,000,000
10%
Over £5,000,001
12%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
862698d4-ece6-45ef-b3f3-593764bdc609
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at hello@rapidhealth.ai. Tell them what format you need. It will help if you say what assistive technology you use.