Smart Triage
Smart Triage is a Software as a Service AI-triage and online consultation platform for UK primary care. It uses automated assessment within clinician-defined protocols to capture patient-reported information, prioritise and route requests, manage demand and capacity, and enable online navigation and appointment booking across practices, PCNs and integrated care settings.
Features
- AI-triage using automated assessment within clinician-defined protocols
- Online consultation capturing structured patient-reported information
- Automated prioritisation and routing of patient requests
- Configurable triage pathways aligned to local practice rules
- Real-time appointment booking based on available capacity
- Demand and capacity management across practices and PCNs
- Integration with EMIS, SystmOne, NHS Login and NHS App
- Multi-channel access supporting online, phone and in-person requests
- Secure multi-tenant SaaS hosted in the UK public cloud
- Aggregated operational datasets supporting demand analysis and service configuration
Benefits
- Reduce administrative workload by automating triage and booking
- Improve patient access through consistent online consultations
- Manage demand effectively during peak periods
- Route patients to appropriate care without manual handling
- Protect clinical capacity through effective prioritisation
- Standardise access processes across practices and PCNs
- Reduce phone congestion and inbox backlogs
- Enable staff to focus on patient care
- Provide clear visibility of demand and capacity
- Support compliance with primary care access requirements
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 9 7 5 1 4 4 9 2 9 8 6 1 4 4
Contact
RAPID HEALTH LTD
Carmelo Insalaco
Telephone: 03301335610
Email: hello@rapidhealth.ai
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- N/A
- System requirements
- Modern web browser with internet connectivity
User support
- Email or online ticketing support
- Yes
- Support response times
- Support is provided via the Rapid Health Service Desk during business hours, 09:00–18:00 GMT/BST, Monday to Friday. Service tickets are prioritised based on business impact. Target response times are within 2 business hours for Priority 1 issues, 4 business hours for Priority 2, 16 business hours for Priority 3 and 40 business hours for Priority 4. Resolution targets range from 8 business hours for Priority 1 issues to inclusion in a future release for low-impact issues.
- User can manage status and priority of support tickets
- No
- Phone support
- No
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Rapid Health provides standard support as part of the service subscription via email and an online service desk during business hours, 09:00–18:00 GMT/BST, Monday to Friday. Support requests are prioritised based on business impact in line with the published SLA.
Standard support is included at no additional cost and covers incident management, service requests and configuration support. Response and resolution targets are defined by priority level, ranging from rapid response for critical issues to scheduled resolution for low-impact requests.
Enhanced support services, including onsite support, implementation assistance, training sessions and bespoke configuration support, are available at additional cost and agreed at call-off.
Rapid Health does not provide a dedicated technical account manager or named cloud support engineer as standard. Account management and service oversight are provided by the Rapid Health delivery and support team, with escalation routes available where required. - Support available to third parties
- No
Onboarding and offboarding
- Getting started
-
Rapid Health supports customers through a structured onboarding process designed to enable users to start using the service quickly and effectively. Following contract award, customers are provided with onboarding guidance covering account setup, user access, and initial configuration.
User training is delivered through e-learning materials that allow users to learn at their own pace. This is supported by scheduled live online Q&A sessions, giving users the opportunity to ask questions, clarify workflows, and understand how to use the service in their operational context.
User documentation and guidance materials are provided to support ongoing use of the platform. During onboarding and live operation, customers have access to the Rapid Health service desk for support and issue resolution. Where additional onboarding support is required, this can be agreed with the customer as part of the implementation approach. - Service documentation
- Yes
- Documentation formats
-
- Other
- Other documentation formats
-
- Video guidance
- Email-based guides
- E-learning materials
- End-of-contract data extraction
-
At the end of the contract, customers can request extraction of their data by contacting the Rapid Health service desk. Data extraction is managed as a supplier-assisted process to ensure data is provided securely, accurately, and in line with contractual and data protection obligations.
Following a valid request, Rapid Health works with the customer to confirm the scope of data required and the appropriate format for delivery. Data is then prepared and provided securely using agreed transfer methods. Any reasonable assistance required to support data extraction is handled in accordance with the applicable contract terms.
Once data extraction has been completed and confirmed by the customer, data retained within the service is managed in line with agreed retention and deletion requirements set out in the contract and data processing arrangements. - End-of-contract process
-
At the end of the contract, Rapid Health will work with the buyer to ensure an orderly, low-risk exit in line with the agreed call-off contract and Call-Off Schedule 10 (Exit Management), where applied.
Where the call-off contract includes automatic renewal, this will be set out in the agreed contract terms. The buyer retains the right to terminate the contract or prevent renewal in accordance with the notice and termination provisions agreed at call-off stage.
All buyer data remains the property of the buyer. At contract end, data will be returned to the buyer in a commonly used, machine-readable format or securely deleted in line with the buyer’s instructions and applicable data protection requirements. Written confirmation of deletion can be provided on request. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
Rapid Health provides onboarding and offboarding documentation in formats designed to be accessible to a wide range of users. Documentation is primarily provided in digital PDF format and shared electronically via email, allowing users to access content using standard assistive technologies such as screen readers and text resizing tools where supported by the user’s device.
Supporting guidance is also provided through video content and e-learning materials, which enable users to consume information in different ways according to their needs. Live online Q&A sessions provide an additional opportunity for users to ask questions and clarify onboarding or offboarding steps.
Where customers have specific accessibility requirements, Rapid Health will work with them to provide information in an alternative format or offer additional support on request, ensuring onboarding and offboarding activities can be completed effectively.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The service provides different user experiences depending on user role. The patient-facing interface is designed to work on mobile devices and desktops, supporting online consultation and request submission through a responsive web interface. The practice-facing administrative interface is optimised for desktop use, providing access to triage workflows, dashboards, configuration and integrations that benefit from larger screens and keyboard-based interaction. Core functionality and data are shared across interfaces, with role-based access controls applied.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Smart Triage is accessed through a secure, browser-based service interface. Patients access a responsive web interface to submit online consultations and requests using structured, guided questions. Practice users access a separate administrative interface designed for desktop use, providing tools for reviewing submissions, prioritising and routing requests, managing workflows, configuring pathways and viewing operational dashboards. Interfaces are role-based and secured through authentication and access controls. The service does not require local installation and is accessed via standard web browsers on approved devices.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- Accessibility considerations are incorporated into the design and ongoing development of the service interface. The patient-facing interface is designed to support use with common assistive technologies, including screen readers and browser accessibility features. Testing is carried out as part of routine quality assurance using accessibility tooling and manual checks, with feedback from users and customers used to inform improvements. Accessibility issues identified are prioritised through the product backlog and addressed as part of continuous service improvement.
- API
- No
- Customisation available
- Yes
- Description of customisation
- Configuration supports local adoption while maintaining a standardised, clinically safe core platform.
Scaling
- Independence of resources
- Smart Triage is delivered as a multi-tenant Software as a Service platform designed to manage variable demand across users. Logical separation, role-based access controls and tenant-aware configuration ensure customer data and workflows are isolated. The service is hosted on scalable cloud infrastructure with capacity management, monitoring and throttling controls to prevent individual usage patterns adversely affecting other users. Performance and availability are actively monitored, with proactive management and operational controls applied to maintain consistent service levels as demand fluctuates.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Smart Triage provides service usage metrics to support operational oversight and demand management. Metrics include volumes of patient submissions, submission trends over time, triage outcomes, workflow routing and request resolution, response and handling times, appointment utilisation, pathway usage and administrative workload indicators. Metrics support practices, PCNs and commissioners to understand demand, capacity and service performance and to inform service improvement and planning activities.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
-
Users can export their data from Smart Triage by submitting a request to Rapid Health support or their nominated account contact. Data exports are provided securely following buyer authorisation and identity verification.
Exports are carried out in line with the agreed call-off contract and data protection requirements. Where required, exports can be scheduled or provided as part of contract exit activities.
Buyer data remains the property of the buyer at all times. Exported data is transferred securely using agreed methods and access controls to ensure confidentiality and integrity. - Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
Rapid Health does not contractually guarantee a fixed uptime percentage. Instead, the service is provided on a 24 hours a day, 7 days a week basis using commercially reasonable efforts, excluding planned maintenance and permitted emergency maintenance.
Planned maintenance is scheduled in advance where possible and communicated to customers with notice, and is designed to minimise disruption to service availability.
Availability is supported by defined support and maintenance arrangements set out in the Rapid Health Platform Support and Service Level Agreement. Incidents are prioritised by business impact from Priority 1 to Priority 4, with target response and resolution times applied during normal business hours. Priority 1 incidents, where the service is unavailable and no workaround exists, have a target response within 2 business hours and a target resolution within 8 business hours.
Service availability is monitored and incidents are managed through the Rapid Health service desk, with customers kept informed of progress and resolution.
Where availability expectations are not met, any remedies, service credits or refunds are handled in accordance with the applicable Order Form, SLA schedule and Master Services Agreement. - Approach to resilience
-
Rapid Health designs the service to be resilient in line with the government’s cloud security principle on asset protection and resilience. The service is hosted on secure cloud infrastructure designed to protect customer data and maintain availability in the event of component failure.
Resilience is achieved through infrastructure redundancy and fault isolation to reduce single points of failure. Service components are monitored continuously, with automated alerts triggering investigation and incident response where availability or performance thresholds are breached. Planned maintenance is controlled, tested in advance, and scheduled to minimise disruption.
Customer data and service configuration are protected through regular backup processes, enabling restoration to a known good state in the event of data loss, corruption, or a security incident. Backup and recovery procedures are documented and tested as part of operational assurance activities.
Details of the underlying data centre controls, physical security, and geographic resilience are managed by the cloud infrastructure provider and are available to customers on request. Incidents affecting resilience are managed in line with defined incident management procedures and support service levels, with post-incident reviews used to drive continuous improvement. - Outage reporting
-
Rapid Health reports service outages directly to affected customers via email. Where a service disruption is identified, customers are notified as soon as reasonably practicable and provided with information on the nature of the outage, expected impact, and progress towards resolution. Follow-up communications are issued as appropriate until the incident is resolved.
The service does not currently provide a public status dashboard or outage reporting API. All outage communications are managed through direct customer notifications and the Rapid Health service desk to ensure accurate, timely and controlled communication. Post-incident summaries can be provided on request in line with incident management procedures.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is restricted through role-based access control, least-privilege principles and separation of duties. All users authenticate using unique credentials with enforced multi-factor authentication. Administrative access is limited to approved personnel and subject to regular access reviews. Support access to customer data is strictly controlled, logged and provided only where operationally necessary. Management interfaces are secured using network-level restrictions and application controls. All privileged and support actions are comprehensively logged, monitored and retained to support security monitoring, audit requirements and incident response.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- Rapid Health applies a risk-based security governance approach aligned to the UK Software Security Code of Practice. Senior leadership is accountable for software security and resilience, with clear ownership of secure design, development, deployment and maintenance activities. Secure by design and secure by default principles are applied throughout the software lifecycle. We use controlled build and deployment processes, regular vulnerability scanning and independent penetration testing, supported by documented vulnerability management and incident response processes. Security controls and risks are reviewed regularly, and findings are tracked to remediation. This approach ensures proportionate, consistent governance without reliance on formal certification.
- Information security policies and processes
-
Rapid Health operates a documented information security management approach proportionate to the nature of the Smart Triage service. Core policies cover information security, access control, data protection, secure development, incident management, vulnerability management, change management and business continuity.
Security governance is owned by senior management, with day-to-day responsibility delegated to designated technical leads. Risks, incidents and control effectiveness are escalated through defined reporting lines to senior leadership as required.
Policies are embedded into operational processes, including role-based access control, least-privilege administration, secure build and deployment practices, logging and monitoring, and controlled change processes. Compliance is reinforced through mandatory staff onboarding, ongoing security awareness, and technical controls such as automated monitoring, vulnerability scanning and regular independent penetration testing.
Security incidents and vulnerabilities are managed through documented response procedures, with root cause analysis and tracked remediation. Policies and processes are reviewed periodically and updated to reflect changes in risk, technology and regulatory expectations. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Configuration items including application code, infrastructure, integrations and system configurations are version-controlled and tracked throughout their lifecycle. Changes follow a formal change management process with documented impact and risk assessment, including security, data protection and patient safety considerations. Changes are reviewed, tested and approved prior to deployment, with segregation between development, test and production environments. Emergency changes follow an expedited but auditable approval process. These controls operate within our quality management system, which is undergoing external certification as part of our CE Class IIb medical device conformity assessment.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- We operate a risk-based vulnerability management process aligned with our secure development lifecycle and medical device QMS. Potential threats are identified through automated vulnerability scanning, dependency monitoring, penetration testing, code review, and threat modelling. We monitor sources including vendor security advisories, CVE/NVD feeds, cloud provider alerts, and results from independent penetration tests. Vulnerabilities are triaged based on severity, exploitability, and patient safety impact. Critical and high-risk issues are prioritised and remediated promptly, with patches deployed via controlled change management and tested before release. Remediation actions are tracked to closure and reviewed as part of ongoing security and risk management.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- We operate continuous protective monitoring using centralised logging and automated alerting across application, infrastructure and security components. Logs cover authentication, privileged access, configuration changes and data access. Alerts for anomalous activity are triaged by trained staff, with containment actions such as access revocation or system isolation where required. Incidents are investigated and remediated in line with our incident management process, with initial response typically within hours based on severity.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Rapid Health operates defined incident management procedures aligned to UK government operational security principles. Pre-defined playbooks exist for common events, including service outages, security incidents and data protection incidents. Incidents are detected through system monitoring or reported by users via a dedicated support email and service desk during support hours. All incidents are logged, triaged by severity, investigated, and resolved with documented actions and timelines. Where required, customers receive timely incident notifications and status updates. Post-incident reports are provided on request and include root cause analysis, impact assessment, corrective actions and lessons learned to support continuous improvement.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
- Health and Social Care Network (HSCN)
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 2%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 8%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 12%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 862698d4-ece6-45ef-b3f3-593764bdc609
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
-