MiRecord
MiRecord is a cloud based paperless electronic maternity record. It supports online and offline working which includes mother and clinician portals.
Features
- Emergency Access to ensure risks available when other solutions used
- Allows live data capture and offline working
- Ability for Trusts / regions to customise solution
- Includes / Prompts risk alerts, clinical referrals and management plans
- Content is regularly updated inline with national guidance
- Diabetes module for care planning and blood glucose monitoring
- Mother write access for personal care pages
- Mother app with information for care planning and informed choice
- Cloud based application
- Online application available in language native to mother
Benefits
- Removes paper requirement for duplicate data-entry
- Increase in patient safety with risk alerts and prompts
- Compliance with national / regional reporting requirements
- Increase in data integrity and completion
- Accessibility to records for any care provider
- Releases time to care with streamlined workflows
- Easy navigation, thus reducing training burden
- Mother centred approach
- Centralised monitoring
- Reducing inequalities in care: complete information for all women
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 4 5 7 0 7 2 8 0 9 9 5 7 0 3
Contact
HARLOW PRINTING LIMITED T/A HARLOW SOLUTIONS
Jack Harrison
Telephone: 01914554286
Email: bidteam@harlowprinting.co.uk
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Software services available to extend to meet DCF
- Cloud deployment model
- Private cloud
- Service constraints
- The service constraints are bound by the Service Level Agreement
- System requirements
-
- Buyers purchase a license to use the SaaS
- Online Web App: modern browser (Chrome/Firefox/Safari) and internet access
- Online Web App: HTTPS over port 80/443
- Online Web App: Whitelist URLs or domains
- Online REST API: Modern web browser (Chrome/Firefox/Safari) and internet access
- Online REST API: HTTPS over port 80/443
- Online REST API: Integration interface local to the site
- Online REST API: Whitelist URLs or domains
- Mobile App: Modern phone with iOS or Android
- Mobile App: Internet to download the application
User support
- Email or online ticketing support
- Yes
- Support response times
-
Response times dependant upon priority.
Low priority questions are responded to in normal working hours whereas priority 1 concerns are responded to within 30mins. Service management is outlined in SLA. - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Dedicated clinical support helpdesk.
Support available via email / phone / video call. Response time is dependant upon priority level- all outlined in SLA.
Support timescales as follows- For priority 1, system down or clinical risk incidents we aim to resolve the incident within 4 hours. Priority 2 incidents within 24 hours, P3 incidents within 30 days and P4 incidents in the next available software release - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- The Perinatal Institute's clinical and technical team will work closely with the customer’s service teams and/ or third-party suppliers to implement the solution. Full project plans and a Project Initiation Document (PID) is provided. We also provide on-site training (train the trainer, user guides, teaching videos and on site support can also be available (at an additional charge)
- Service documentation
- Yes
- Documentation formats
-
- Other
- Other documentation formats
- Online
- End-of-contract data extraction
- A full data extract is provided in an agreed format
- End-of-contract process
-
End of contract - raw data is securely returned to the data controller by a means both parties agree upon.
Additional costs may be incurred depending on the complexity for what is agreed upon.
Customer access to the service will be terminated upon end of contract. - Documentation accessibility standard
- WCAG 2.2 A
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Linux or Unix
- MacOS
- Windows
- ChromeOS
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Maternity information gathering is the same on mobile and desktop service. Desktop service contains added administrative functionality concerning user management
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 A
- Description of service interface
- SaaS. Users authenticate with MFA to the online software. The interface is clinically designed for use by clinicians, midwives, and mothers.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- None
- API
- Yes
- What users can and can't do using the API
- Open API can be integrated with various systems to populate data items
- API documentation
- Yes
- API documentation formats
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Examples of items which can be configured include (but are not limited to):
• Structured clinical documentation forms
• Free text fields.
• Lookup tables and values, and dropdown lists.
• User favourites and tailored homepages
• Reports and dashboards
• Role Based Access Control (RBAC) permissions
Scaling
- Independence of resources
- The AWS infrastructure hosting is fully cloud based and fully scalable. The RDS database automatically scales based on usage. The EC2 server can be upgraded with zero downtime if required (advanced metrics and automated alerts in place for high recourse usage).
Analytics
- Service usage metrics
- Yes
- Metrics types
- Uptime, downtime and reporting
- Reporting types
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Other
- Other data at rest protection approach
-
TLS 1.2+ / TLS 1.3 for all web traffic
HTTPS enforced (no HTTP fallback)
Encrypted API traffic (mTLS where appropriate)
Certificate rotation and expiry management
AWS KMS and vault keys (centralised key management) - Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Data Erasure
Data importing and exporting
- Data export approach
- We will provide support to the customer in performing data extraction activities, and if required, we will be happy to provide services to more actively assist the customer in undertaking these tasks. This would be at additional cost and a quote for this would be provided by the vendor
- Data export formats
-
- CSV
- Other
- Other data export formats
- SQL
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- Other
- Other protection between networks
-
Encryption at REST 256bit AES.
Network/security logging that are audited.
HTTPS is forced over port 443.
MFA authentication to login. - Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
- Subnetting VPC
Availability and resilience
- Guaranteed availability
- 99.5%
- Approach to resilience
-
Further information is available upon request.
The SaaS is hosted in AWS, London (globally leading provider).
Resilience includes:
* ISO27001 certified (MiRecord is governed by this standard)
* Availability zones
* Fully cloud-based (fast and efficient restore)
* AWS Backup (continuous backups and backups that follows son/father/grandfather scheme) - for short term & long term backups/restore
* Advanced monitoring (CloudWatch) with automated alerts
* Zero downtime (blue/green) deployments for the majority of updates. - Outage reporting
-
Automated CloudWatch monitoring with automated alerts setup internally for various warning, such as service downtime, high CPU/RAM usage, TLS or HTTPS alerts.
Outages reported through email to key contacts listed in the SLA.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Multi-Factor Authentication (MFA)
- Access restrictions in management interfaces and support channels
- Username and password. For activation DOB is also required
- Access restriction testing frequency
- At least once a year
- Management access authentication
- Multi-Factor Authentication (MFA)
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
-
DSP Toolkit
ICO registered
Cyber Essentials - Information security policies and processes
-
Full details available here: https://perinatal.org.uk/information/governance
Through recognised frameworks like ISO27001. We use structured policies, risk assessments and documented procedures to govern how data is received, processed, anonymised and stored. Access to systems is role-based, logged, and restricted to authorised staff only. Security controls such as encryption, monitoring, incident management and change control are all implemented as part of our certified ISMS. We review risks regularly through internal audits, management review meetings, and continuous improvement processes. Overall, our approach ensures that all information (identifiable or anonymised) is handled consistently, securely, and in line with NHS and ICO expectations.
Policies include: Acceptable Use Policy; Activity Logging, Retention and Classification Policy; AWS Access Key Management Policy; Change Management Policy; Cryptography Policy; Data Handling Policy; Data Warehouse Policy; DES Checklist; Handling of DES Certificates Information Policy; Health and Safety Management System; HLT Policy; Hybrid WFH Policy ; IG Policy; Information Classification Policy; Information Security Management Policy; Malware Detection and Prevention Policy; Patch Management Policy; Potential Suspected Outage Policy; Privacy Policy; Recruitment of Offenders Policy; Risk Assessment; Security Incident and Event Management Policy; Security Policy; Software Development Policy; Storage Media Policy; Subject Access Request Policy; Vulnerability Management Policy. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
ITIL change management process mantained through ISO27001 certification.
Change management process includes clinical safety impact assessment, CSO review, and hazards in compliance with DCB0129 and 0160.
Change management policy put in place as part of ISO27001, detailing the purpose, scope, change types, role and responsbilities, change management process, impact/risk assessment, approval, testing/validation, implementation, post-implementation review, emergency change management, documentation/records, monitoring/audit, and continous improvment - reviewed at least anually.
Examples of evidence includes: change policy, logged approval/authorisation, risk assessment, testing results, segregation of duties, deployment controls/documentation, and audit logging.
Change management process is managed through Atlassian JIRA software. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
In compliance with Cyber Essentials (certified).
Threats are assessed through an ISO27001 aligned risk based security management approach.
Security updates are applied within 14 days of release, with critical updates implemented without delay.
Trusted external sources monitored include:
•Cloud provider advisories (e.g., AWS bulletins)
•NCSC guidance and alerts
•Vendor advisories for operating systems, frameworks, and dependencies
•CVE/NVD vulnerability feeds
•Penetration test reports and vulnerability scans
•Security monitoring from hosted environments
•Industry best practice, including ISO27001 and NHS guidance
MiRecord undergoes annual third party CREST approved penetration testing.
The Institute also performs regular internal and hybrid penetration tests. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
MiRecord applies protective monitoring aligned with Cloud Security Principle 5, ISO/IEC 27001, Cyber Essentials, and the NHS DSP Toolkit.
Monitoring combines centralised logging, automated alerts, and defined incident response processes proportionate to service risk.
Logged activity includes system, application, authentication, administrative, and configuration events.
Audit logs provide traceability to detect misuse. Cloud infrastructure is monitored for performance, availability, and security events, with alerts for failed logins, privilege changes, or unusual behaviour.
Authorised personnel review logs routinely. Incident management handles triage, investigation, escalation, and resolution.
Monitoring outputs feed into operational oversight, with data retained per policy and protected from unauthorised access. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
MiRecord operates a formal incident management process aligned with ISO27001, the NHS DSP Toolkit, and UK Government Cloud Security Principles.
Incidents are detected, reported, assessed, resolved, and reviewed in a controlled manner.
Pre‑defined procedures cover security incidents, service outages, performance issues, data integrity problems, deployment or configuration errors, and vulnerability or patch‑related events.
Incidents are categorised by severity and escalated as required, with senior or clinical safety review for security‑relevant cases.
Emergency incidents receive immediate containment and restoration.
All incidents are logged in a central system, triaged by authorised staff, and communicated to affected customers with updates and post‑incident reports. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
- Health and Social Care Network (HSCN)
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 1%
- Between £2,500,001 and £5,000,000
- 2%
- Over £5,000,001
- 2%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Management Systems Certification Ltd
- ISO/IEC 27001 accreditation date
- Wednesday 3 December 2025
- What the ISO/IEC 27001 doesn’t cover
- N/a
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Management Systems Certification Ltd
- ISO 9001 accreditation date
- Friday 21 June 2024
- What the ISO 9001 doesn’t cover
- N/a
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Ea3c770a-df8f-4cf0-a770-3ce0458cab10
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 15293816-46b8-46a0-9ac2-5fab25408c08
- Other security certifications
- Yes
- Any other security certifications
- NHS Data Security and Protection Toolkit
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Other measures to offer development opportunities for the target cohort(s) in the contract workforce
-