Graphnet Remote Monitoring
Graphnet Remote Monitoring, powered by Luscii, is a cloud-based virtual care platform enabling clinicians to remotely monitor long-term, chronic and episodic conditions at home. Integrated apps, patient questionnaires and clinical dashboards support prevention-first care across 150+ conditions, reducing admissions and improving outcomes.
Features
- Interoperable with GP, Population Health and Shared Care Record systems
- Home-based patient support remotely measure vitals and symptoms
- Automatic alerts warn clinicians when a patient's condition deteriorates
- Contact patients when needed via chat or video calling
- Deliver digital coaching, education and self management tools
- Open: simple APIs based on international standards enable EHR integrations
- Modular and flexible platform adapts to local clinical pathways
- Remote management and help desk support for patients and clinicians
- Full regulatory compliance with UK healthcare and data protection requirements
- Intuitive dashboards for management information, reporting and healthcare data exports
Benefits
- Cost optimisation, reduces hospital admissions and readmissions, increasing home-based care
- Supports early discharge, freeing up hospital beds rapidly
- Empowers proactive monitoring and coaching across 150+ clinical pathways
- Reduces A&E attendances through targeted, data-driven interventions
- Improves patient self-management, enhancing confidence and independence
- Supports timely intervention via intelligent, real-time clinical alerts
- Fully compliant with NHS information governance and data security
- Clinician dashboards support efficient, safe prioritisation of caseloads
- Embedded in Shared Care Records and Population Health platforms
- Proven measurable outcomes in multiple NHS Integrated Care Systems
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
6 1 4 3 8 2 3 2 2 9 7 1 4 8 4
Contact
GRAPHNET HEALTH LIMITED
Lisa Haslam
Telephone: 03330771988
Email: salesandbids@graphnethealth.com
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Adult Social Care
- Children's Social Care
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Graphnet Shared Care Record and Population Health solutions
- Cloud deployment model
- Public cloud
- Service constraints
-
Patients access the service via either an Android or iOS device (phone or tablet). Our policy is to always support the current and previous versions of each operating system. Clinicians access the service via a secured website that is supported by all modern web browsers (web based clinical access) or through an EHR integration that can be implemented. To initiate a video call to a patient the clinician must use an iOS device.
Browser-based access is optimised for standard NHS IT infrastructure.
Access and data transfer comply with NHS IG policies; deployment may depend on local network and security arrangements. - System requirements
-
- Clinicians require internet access for our Pro web portal
- Our Pro app is compatible with iOS and Android devices
- Patient app available on Apple App Store and Google Play
- Web access supports Chrome, Edge (Chromium), Firefox latest versions
- Secure connection required; HTTPS protocols must be enabled
- Integration possible with NHS Shared Care Record infrastructure
- Real-time data requires consistent network and Wi-Fi connectivity
- Devices must support video consultations through our apps
- Configuration may vary based on local NHS IT policies
User support
- Email or online ticketing support
- Yes
- Support response times
- Support is available from project initiation, with multiple support packages offered. Each package outlines ticket prioritisation and corresponding response times, which are agreed with the customer during onboarding. Typically, our team responds to all queries within the same working day.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- Our web chat functionality initial trouble shooting response is via AI. Depending on the subject area this will then switch to an appropriate member of the team for further investigation. This is a process that has been tested with several assistive technology professionals.
- Onsite support
- Yes, at extra cost
- Support levels
- Options to suit customer's need. Typically 9 - 5.30pm or other daily times possible subject to agreed SLA and commercials. Costings depend on the number of product and user licences required. Support engineers are supplied as part of the Service Desk provision as specified under the Service Level T&Cs for each customer.
- Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
We provide comprehensive onboarding support to help users start using the service effectively. We offer a structured implementation process, tailored to local service needs, which includes initial setup, pathway configuration, and user role assignment.
Training is delivered via a combination of onsite sessions, live online webinars, and self-paced e-learning modules. These are designed for both clinical and operational users, ensuring confidence in using the Professional dashboard, mobile apps, and reporting tools.
We provide extensive user documentation, including guides, FAQs, and video tutorials, accessible through our Help Centre. Clinical leads also receive configuration support to tailor care pathways, question sets and alerts to their specific service models.
Our implementation team works collaboratively with customers to embed remote monitoring into daily practice, supported by project plans, checklists, and pathway templates. Ongoing account management and optional superuser training further enhance adoption.
Our intuitive interface helps reduce the learning curve, and our support team is available to assist during and after go-live. - Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
-
- HTML, PDF, video tutorials, e-learning modules, and slide decks
- Used in both remote and onsite training for user support
- Comprehensive knowledge base available via our online Help Centre
- Includes FAQs, walkthroughs, and step-by-step practical guidance resources
- API documentation provided through OpenAPI (Swagger) and developer portal
- Supports technical onboarding for developers and integration partners effectively
- End-of-contract data extraction
- The patient data is shared with the healthcare organisation as part of the service delivery. The healthcare organisation, as data controller, specifies the terms of service to their patients. A patient gives consent to these terms and the privacy statement upon onboarding. Organisations can integrate with their local EHR system through API / webhook integrations based on the FHIR standards. If there is no integration the data is available for download by the organisation admin.
- End-of-contract process
-
6 to 12 months prior to the contract expiry, Graphnet will work with the customers senior leadership, finance and contract management teams to discuss what options are available. Options to discuss would include.
Non-Renewal: Clearly we hope that all contracts are renewed, but in some rare cases contracts do expire. In such cases where appropriate provisions are made such that any information entered into the solution is returned in a format agreed with the customer and that here is a managed transition to a new system.
Renewal: Contract is renewed. Contracted components and/or participant organisations may alter, terms and conditions will be agreed via a CCN.
Should the contract actually no longer be required Graphnet will offer the provision of other reasonable termination assistance at the Authority’s request at the Supplier’s standard rates (e.g. to assist with data migration to the replacement contractor’s system). In addition, if necessary, a “read only licence” for historic data is offered. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- MacOS
- Windows
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Patients access the service via a mobile device (iOS or Android, phone or tablet). Clinicians can access via an iOS app or via the desktop web service. For a clinician to initiate a video call to a patient they need to use the iOS app.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Our solution, provides a clean, user-friendly interface for clinicians and patients. The clinician portal and Pro app offer real-time dashboards, alerts, and configurable care plans to support efficient caseload management. The patient app, available on iOS and Android, features simple navigation for entering symptoms, vital signs, and accessing video consultations. Interfaces are responsive and designed to support accessibility across devices. Both views present essential information clearly, enabling rapid access and personalised engagement. The consistent layout and intuitive design ensure users can quickly interpret data and take appropriate action within their role.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
Our platform is built on the Luscii Design System and undergoes accessibility audits and user research, capturing the user experience with a wide range of different cognitive and physical abilities and considering digital inclusion, visual impairment and literacy.
– We carry out regular checks against WCAG 2.2 AA standards, and record known non compliances.
– The interface supports keyboard navigation, includes labelled controls, and is compatible with screen readers on desktop and mobile.
– We have worked with users of assistive technologies to review key flows and incorporate feedback into design updates.
– Contrast, layout clarity and iconography are part of our accessibility metrics monitored during development. - API
- Yes
- What users can and can't do using the API
- Our solution provides a fully documented integration platform including REST endpoints, FHIR webhooks and SDKs. You can onboard patients via APIs, send data into Graphnet Remote Monitoring, and receive alerts or measurements programmatically. Single sign‑on (SSO) enables clinicians to access the dashboards seamlessly.
- API documentation
- Yes
- API documentation formats
- Other
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
We provide extensive customisation options to tailor remote monitoring services to local care models. Clinical teams can configure patient pathways, question sets, measurement schedules, threshold alerts, and escalation protocols. Users can adjust the frequency and content of health questionnaires, define trigger values for alerts, and create automated rules for symptom review and clinical response.
Customisation is carried out via our Professional dashboard by authorised administrators or in collaboration with our implementation team. Users can also request pathway adaptations based on specific clinical conditions or patient cohorts.
Access roles and permissions are customisable using Role-Based Access Control (RBAC), ensuring appropriate visibility of patient data for different staff groups. Dashboards and views are configurable to focus on specific patient groups, data fields or metrics.
Our open integration model allows further personalisation through APIs, enabling local system linkage, automatic enrolment, and data exchange between platforms.
This flexibility ensures the platform meets the clinical, operational, and technical needs of NHS services while enabling rapid iteration based on feedback.
Scaling
- Independence of resources
-
Our managed AWS infrastructure scales elastically to support increased demand while maintaining performance and availability.
As more patients are onboarded and demand increases, scalability is achieved through automated compute scaling, ensuring capacity is provisioned as usage grows. Traffic is distributed via managed load balancing, avoiding bottlenecks.
Data storage and databases use managed AWS services scaling automatically to support growing volumes of patient data, measurements, alerts. Services deploy across availability zones to ensure availability and resilience.
Infrastructure performance is continuously monitored, with scaling triggered automatically by predefined thresholds. This keeps the platform responsive, reliable as patient numbers grow, without customer intervention.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
System metrics are surfaced via the Analytics Dashboard within the platform. These metrics include:
Patient status, including active, stopped, added, cancelled
New patient onboarding by date
Breakdown of active vs discharged patients by date
Cumulative number of patients by date
Volume of alerts and alert types by date
Volume of measurements triggering alerts by date
The platform also provides public APIs to export datasets on patients and system insights to client data warehouses, enabling clients to maintain service-level metrics.
Additionally, the platform displays operational status of all services, uptime over the past 60 days, and summaries of known issues, resolutions. - Reporting types
-
- API access
- Real-time dashboards
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- Luscii Healthtech B.V.
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Other
- Other data at rest protection approach
- Data is stored on Amazon AWS databases located in the UK and Germany. Storage on these servers is encrypted to protect data at rest. The databases make use of redundancy to ensure availability and are automatically backed up. Each day a full snapshot is backed up and each 5 minutes a transaction log, meaning at most 5 minutes of data is lost after a catastrophic event.
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
-
Users export their data through a user-friendly interface provided by Graphnet. Upon accessing the designated export feature, users can select the specific datasets they wish to export, choosing from various formats such as CSV, Excel, or PDF. The software offers options to customize the export settings, allowing users to tailor the output to their requirements.
These extracts can be ad-hoc or scheduled. Patients can view their data at any time within the app. - Data export formats
-
- CSV
- Other
- Other data export formats
-
- FHIR
- JSON
- Data import formats
-
- CSV
- Other
- Other data import formats
- FHIR
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
The platform operates with an uptime of 99.9%.
When deployment issues are logged via JIRA, they are immediately triaged to assess the extent to which service availability has been affected. Incident severity levels and associated response and resolution times are outlined below.
P1 (Critical)
A critical issue with Graphnet Remote Monitoring that has a severe impact on patients’ use of the services.
Response time: within 1 extended working hour
Resolution time: within 8 hours
P2 (Major)
A major issue with Graphnet Remote Monitoring that has a significant impact on patients’ use of the services.
Response time: within 8 working hours
Resolution time: within 12 working hours
P3 (Restricted)
An issue with Graphnet Remote Monitoring that causes significant inconvenience to patients’ use of the services.
Response time: within 1 working day
Resolution: an agreed workaround will be provided within 72 hours, and a permanent resolution will be delivered within 10 working days
P4 (Minor)
An issue causing moderate inconvenience to users, with no risk to patient safety.
Response time: within 5 working days
Resolution time: at the discretion of the Supplier
Where service credits apply, details of any repayment are set out in the customer contract. - Approach to resilience
-
Our remote monitoring platform, built on AWS managed services, is designed for resilience by eliminating single points of failure and using services with built-in high availability and automated recovery.
Core application components are deployed across multiple AWS Availability Zones, ensuring continuity if a single zone becomes unavailable. Managed load balancers and health checks route traffic only to healthy components. Compute capacity scales automatically to meet demand and replaces failed instances without manual intervention.
The data layer uses managed databases configured for high availability, with synchronous replication and automated failover. Patient data and documents are stored in highly durable managed storage services.
Regular backups are performed using AWS-managed backup mechanisms. Databases are backed up automatically with point-in-time recovery, and stored data is protected through versioning and defined retention policies. Backups are encrypted and regularly tested to ensure recoverability.
Decoupled architectures, such as managed queues and messaging services, isolate components and reduce the impact of failures. Continuous monitoring and alerting provide visibility into system health and support rapid operational response. Infrastructure is deployed using repeatable, automated processes, enabling efficient recovery. Disaster recovery configurations can be implemented to meet agreed recovery time and recovery point objectives. - Outage reporting
-
The platform includes a dashboard displaying the operational status of each component, which is visible to all users logged into the system.
All outages are recorded as part of the incident management process. If an issue is detected, the service desk will notify the customer by phone and email, and via the automated Jira alerting system, which also provides a link to the dashboard.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Other
- Other user authentication
- Account access is protected with multi-factor authentication by sending a login token to the user’s email address.
- Access restrictions in management interfaces and support channels
- Access to our system is controlled using role-based access control (RBAC) and the principle of least privilege. Users are assigned roles based on their job function, with permissions limited to the minimum required to perform their duties. Clinical, administrative and support access is segregated, and privileged access is restricted to authorised personnel only. Access rights are managed by authorised customer contacts. All access and permission changes are logged and monitored to support audit, security oversight and data protection compliance.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
- Multi-Factor Authentication (MFA)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
We have ISO 27001 and Cyber Essentials Plus certification a range of policies to ensure we adhere to IG and Information Security arrangements. These include:
-Access Control
-Information Governance
-Project and Security Coding
-Clean Screen and Clear Desk
-PID
-Secure Software
-Solution Development Procedure
-Data Transfer (Encryption)
-Secure Disposal
-Acceptable Use
-Network Control.
We have other specific guidance and polices available to provide assurance with our Data Processor and internal responsibilities.
We have a Governance Board which our CFO and SIRO, Director of Information Governance, Cyber and Compliance (Data Protection Officer), Information Security Manager, ISO Compliance Manager, all sit on. Through these key roles we ensure policies are reviewed and amended in light of any issues arising, audit reviews and process changes etc.
Policies are available to all staff via our employee hub system which requires staff to read all required policies.
We incorporate the Crown Commercial Service’s Generic Standard GDPR clauses in all our contracts where we process personal data; we process in compliance with Article 32. Where services use the “cloud” this processing adheres to the fourteen National Cyber Security Centre cloud service security principles as applicable to UK OFFICIAL and the cloud host complies with ISO27018. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
All changes implemented under our EN13485 Medical Device QMS and our ISO27001
To ensure the security and reliability of Graphnet's solutions, Graphnet follow a 5 phase configuration and change management process.
• Development and QA and internal only proof of concept (POC) activities
• Customer facing POC work.
• Build of all pre-production systems that may go on to hold customer or Graphnet data (deployment phase work)
• BAU customer systems provided by Graphnet including all UAT, Sandpit, Training, Testing, Production or Live systems.
• Exit planning defines all data management activities - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- We use a combination of internal vulnerability scanners, system monitoring and industry sources to monitor for possible threats, applying patches within 14 days of their release. Additionally, we use NHS CARE-cert, US-Cert and industry publications to assess threats weekly and respond accordingly. Out Of Band patch releases are investigated and installed immediately if appropriate.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- AWS applies continuous protective monitoring to our application hosted on its infrastructure. Network traffic, system activity and access patterns are monitored to detect unauthorised or anomalous behaviour. Managed services such as CloudTrail log API activity, CloudWatch monitors system metrics and logs, and GuardDuty identifies potential security threats using threat intelligence. AWS Shield provides monitoring and protection against DDoS attacks. Security events trigger automated alerts and are handled through 24/7 incident response processes. These controls are independently assessed against recognised standards, including ISO/IEC 27001.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- We follow ISO 27001-aligned incident management procedures. Security events are monitored 24/7, and incidents are categorised by severity. All incidents trigger investigation, root cause analysis, and remediation. High-risk incidents are escalated immediately and reported to affected stakeholders in line with GDPR and NHS DSPT requirements. Lessons learned are documented and reviewed to prevent recurrence. Incident handling includes predefined response playbooks and traceability via internal ticketing and audit logs. Regular drills and post-incident reviews ensure the process remains robust. Customers receive timely updates and final reports, with support for coordinated response if required.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- Trial services for our remote monitoring solution and other G-Cloud products are available where practical. Live trials using real data may be impractical due to significant third-party costs. However, we can usually provide test versions using dummy data where this adequately meets customer requirements during early-stage evaluation and procurement discussions.
- Link to free trial
- We don't have a generic link as each customer's requirements are slightly different. We make test systems available on request with them configured as per the customer's requirements.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- BSI Assurance UK Limited
- ISO/IEC 27001 accreditation date
- Monday 15 July 2024
- What the ISO/IEC 27001 doesn’t cover
- Our 27001 covers the full business operation without exclusions. Graphnet holds Certification number IS 614375 and operates Information Management Systems which comply with the requirements of ISO/IEC 27001:2022 for: All automated information systems under the direct control of Graphnet Health Ltd. All employees and agents of Graphnet Health Limited. All employees and agents of other organisations who directly or indirectly make use of or support the use of information systems under the direct control of Graphnet Health Limited.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- BSI Assurance UK Limited
- ISO 9001 accreditation date
- Monday 11 March 2024
- What the ISO 9001 doesn’t cover
- Our 9001 covers the full business operation without exclusions. Graphnet holds Certification number FS 614373 and operates a Quality Management System which complies with the requirements of ISO/IEC 9001:2015 with no exceptions.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 51f753d9-3a05-43aa-90d0-054a83d271a4
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 9a259fc6-6ab9-413e-aa1d-c1968dbc6f89
- Other security certifications
- Yes
- Any other security certifications
-
- Data Security and Protection Toolkit (NHS Digital ODS code 8GX89)
- Data Protection Act 1998 (DPA)
- Level 3 compliance with NHS IGSoC
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Volunteering opportunities for staff
-