Skip to main content

Help us improve the Digital Marketplace - send your feedback

HARLOW PRINTING LIMITED T/A HARLOW SOLUTIONS

MiRecord

MiRecord is a cloud based paperless electronic maternity record. It supports online and offline working which includes mother and clinician portals.

Features

  • Emergency Access to ensure risks available when other solutions used
  • Allows live data capture and offline working
  • Ability for Trusts / regions to customise solution
  • Includes / Prompts risk alerts, clinical referrals and management plans
  • Content is regularly updated inline with national guidance
  • Diabetes module for care planning and blood glucose monitoring
  • Mother write access for personal care pages
  • Mother app with information for care planning and informed choice
  • Cloud based application
  • Online application available in language native to mother

Benefits

  • Removes paper requirement for duplicate data-entry
  • Increase in patient safety with risk alerts and prompts
  • Compliance with national / regional reporting requirements
  • Increase in data integrity and completion
  • Accessibility to records for any care provider
  • Releases time to care with streamlined workflows
  • Easy navigation, thus reducing training burden
  • Mother centred approach
  • Centralised monitoring
  • Reducing inequalities in care: complete information for all women

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at bidteam@harlowprinting.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

8 4 5 7 0 7 2 8 0 9 9 5 7 0 3

Contact

HARLOW PRINTING LIMITED T/A HARLOW SOLUTIONS Jack Harrison
Telephone: 01914554286
Email: bidteam@harlowprinting.co.uk

About your service

Service categories

Applications

Production and operations

Service industry and public sector operations

  • Healthcare
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Software services available to extend to meet DCF
Cloud deployment model
Private cloud
Service constraints
The service constraints are bound by the Service Level Agreement
System requirements
  • Buyers purchase a license to use the SaaS
  • Online Web App: modern browser (Chrome/Firefox/Safari) and internet access
  • Online Web App: HTTPS over port 80/443
  • Online Web App: Whitelist URLs or domains
  • Online REST API: Modern web browser (Chrome/Firefox/Safari) and internet access
  • Online REST API: HTTPS over port 80/443
  • Online REST API: Integration interface local to the site
  • Online REST API: Whitelist URLs or domains
  • Mobile App: Modern phone with iOS or Android
  • Mobile App: Internet to download the application

User support

Email or online ticketing support
Yes
Support response times
Response times dependant upon priority.
Low priority questions are responded to in normal working hours whereas priority 1 concerns are responded to within 30mins. Service management is outlined in SLA.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Dedicated clinical support helpdesk.
Support available via email / phone / video call. Response time is dependant upon priority level- all outlined in SLA.
Support timescales as follows- For priority 1, system down or clinical risk incidents we aim to resolve the incident within 4 hours. Priority 2 incidents within 24 hours, P3 incidents within 30 days and P4 incidents in the next available software release
Support available to third parties
Yes

Onboarding and offboarding

Getting started
The Perinatal Institute's clinical and technical team will work closely with the customer’s service teams and/ or third-party suppliers to implement the solution. Full project plans and a Project Initiation Document (PID) is provided. We also provide on-site training (train the trainer, user guides, teaching videos and on site support can also be available (at an additional charge)
Service documentation
Yes
Documentation formats
  • PDF
  • Other
Other documentation formats
Online
End-of-contract data extraction
A full data extract is provided in an agreed format
End-of-contract process
End of contract - raw data is securely returned to the data controller by a means both parties agree upon.
Additional costs may be incurred depending on the complexity for what is agreed upon.

Customer access to the service will be terminated upon end of contract.
Documentation accessibility standard
WCAG 2.2 A

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
Yes
Compatible operating systems
  • Android
  • IOS
  • Linux or Unix
  • MacOS
  • Windows
  • ChromeOS
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Maternity information gathering is the same on mobile and desktop service. Desktop service contains added administrative functionality concerning user management
Service interface
Yes
User support accessibility
WCAG 2.2 A
Description of service interface
SaaS. Users authenticate with MFA to the online software. The interface is clinically designed for use by clinicians, midwives, and mothers.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
None
API
Yes
What users can and can't do using the API
Open API can be integrated with various systems to populate data items
API documentation
Yes
API documentation formats
PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Examples of items which can be configured include (but are not limited to):
• Structured clinical documentation forms
• Free text fields.
• Lookup tables and values, and dropdown lists.
• User favourites and tailored homepages
• Reports and dashboards
• Role Based Access Control (RBAC) permissions

Scaling

Independence of resources
The AWS infrastructure hosting is fully cloud based and fully scalable. The RDS database automatically scales based on usage. The EC2 server can be upgraded with zero downtime if required (advanced metrics and automated alerts in place for high recourse usage).

Analytics

Service usage metrics
Yes
Metrics types
Uptime, downtime and reporting
Reporting types
Reports on request
Resource tagging
Yes
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Other
Other data at rest protection approach
TLS 1.2+ / TLS 1.3 for all web traffic
HTTPS enforced (no HTTP fallback)
Encrypted API traffic (mTLS where appropriate)
Certificate rotation and expiry management
AWS KMS and vault keys (centralised key management)
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
Data Erasure

Data importing and exporting

Data export approach
We will provide support to the customer in performing data extraction activities, and if required, we will be happy to provide services to more actively assist the customer in undertaking these tasks. This would be at additional cost and a quote for this would be provided by the vendor
Data export formats
  • CSV
  • Other
Other data export formats
SQL
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • Other
Other protection between networks
Encryption at REST 256bit AES.
Network/security logging that are audited.
HTTPS is forced over port 443.
MFA authentication to login.
Data protection within supplier network
  • TLS (version 1.2 or above)
  • Other
Other protection within supplier network
Subnetting VPC

Availability and resilience

Guaranteed availability
99.5%
Approach to resilience
Further information is available upon request.
The SaaS is hosted in AWS, London (globally leading provider).
Resilience includes:
* ISO27001 certified (MiRecord is governed by this standard)
* Availability zones
* Fully cloud-based (fast and efficient restore)
* AWS Backup (continuous backups and backups that follows son/father/grandfather scheme) - for short term & long term backups/restore
* Advanced monitoring (CloudWatch) with automated alerts
* Zero downtime (blue/green) deployments for the majority of updates.
Outage reporting
Automated CloudWatch monitoring with automated alerts setup internally for various warning, such as service downtime, high CPU/RAM usage, TLS or HTTPS alerts.

Outages reported through email to key contacts listed in the SLA.

Identity and authentication

User authentication needed
Yes
User authentication
Multi-Factor Authentication (MFA)
Access restrictions in management interfaces and support channels
Username and password. For activation DOB is also required
Access restriction testing frequency
At least once a year
Management access authentication
Multi-Factor Authentication (MFA)

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
DSP Toolkit
ICO registered
Cyber Essentials
Information security policies and processes
Full details available here: https://perinatal.org.uk/information/governance

Through recognised frameworks like ISO27001. We use structured policies, risk assessments and documented procedures to govern how data is received, processed, anonymised and stored. Access to systems is role-based, logged, and restricted to authorised staff only. Security controls such as encryption, monitoring, incident management and change control are all implemented as part of our certified ISMS. We review risks regularly through internal audits, management review meetings, and continuous improvement processes. Overall, our approach ensures that all information (identifiable or anonymised) is handled consistently, securely, and in line with NHS and ICO expectations.

Policies include: Acceptable Use Policy; Activity Logging, Retention and Classification Policy; AWS Access Key Management Policy; Change Management Policy; Cryptography Policy; Data Handling Policy; Data Warehouse Policy; DES Checklist; Handling of DES Certificates Information Policy; Health and Safety Management System; HLT Policy; Hybrid WFH Policy ; IG Policy; Information Classification Policy; Information Security Management Policy; Malware Detection and Prevention Policy; Patch Management Policy; Potential Suspected Outage Policy; Privacy Policy; Recruitment of Offenders Policy; Risk Assessment; Security Incident and Event Management Policy; Security Policy; Software Development Policy; Storage Media Policy; Subject Access Request Policy; Vulnerability Management Policy.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
ITIL change management process mantained through ISO27001 certification.

Change management process includes clinical safety impact assessment, CSO review, and hazards in compliance with DCB0129 and 0160.

Change management policy put in place as part of ISO27001, detailing the purpose, scope, change types, role and responsbilities, change management process, impact/risk assessment, approval, testing/validation, implementation, post-implementation review, emergency change management, documentation/records, monitoring/audit, and continous improvment - reviewed at least anually.

Examples of evidence includes: change policy, logged approval/authorisation, risk assessment, testing results, segregation of duties, deployment controls/documentation, and audit logging.

Change management process is managed through Atlassian JIRA software.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
In compliance with Cyber Essentials (certified).
Threats are assessed through an ISO27001 aligned risk based security management approach.
Security updates are applied within 14 days of release, with critical updates implemented without delay.
Trusted external sources monitored include:
•Cloud provider advisories (e.g., AWS bulletins)
•NCSC guidance and alerts
•Vendor advisories for operating systems, frameworks, and dependencies
•CVE/NVD vulnerability feeds
•Penetration test reports and vulnerability scans
•Security monitoring from hosted environments
•Industry best practice, including ISO27001 and NHS guidance
MiRecord undergoes annual third party CREST approved penetration testing.
The Institute also performs regular internal and hybrid penetration tests.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
MiRecord applies protective monitoring aligned with Cloud Security Principle 5, ISO/IEC 27001, Cyber Essentials, and the NHS DSP Toolkit.

Monitoring combines centralised logging, automated alerts, and defined incident response processes proportionate to service risk.

Logged activity includes system, application, authentication, administrative, and configuration events.

Audit logs provide traceability to detect misuse. Cloud infrastructure is monitored for performance, availability, and security events, with alerts for failed logins, privilege changes, or unusual behaviour.

Authorised personnel review logs routinely. Incident management handles triage, investigation, escalation, and resolution.

Monitoring outputs feed into operational oversight, with data retained per policy and protected from unauthorised access.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
MiRecord operates a formal incident management process aligned with ISO27001, the NHS DSP Toolkit, and UK Government Cloud Security Principles.

Incidents are detected, reported, assessed, resolved, and reviewed in a controlled manner.

Pre‑defined procedures cover security incidents, service outages, performance issues, data integrity problems, deployment or configuration errors, and vulnerability or patch‑related events.

Incidents are categorised by severity and escalated as required, with senior or clinical safety review for security‑relevant cases.

Emergency incidents receive immediate containment and restoration.

All incidents are logged in a central system, triaged by authorised staff, and communicated to affected customers with updates and post‑incident reports.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
Yes
Connected networks
Health and Social Care Network (HSCN)

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
1%
Between £2,500,001 and £5,000,000
2%
Over £5,000,001
2%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Management Systems Certification Ltd
ISO/IEC 27001 accreditation date
Wednesday 3 December 2025
What the ISO/IEC 27001 doesn’t cover
N/a
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
Management Systems Certification Ltd
ISO 9001 accreditation date
Friday 21 June 2024
What the ISO 9001 doesn’t cover
N/a
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
Ea3c770a-df8f-4cf0-a770-3ce0458cab10
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
15293816-46b8-46a0-9ac2-5fab25408c08
Other security certifications
Yes
Any other security certifications
NHS Data Security and Protection Toolkit

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Other measures to offer development opportunities for the target cohort(s) in the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at bidteam@harlowprinting.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.