CareLoop Health for psychosis and schizophrenia
CareLoop is a remote monitoring and symptom management platform for people with Psychosis and Schizophrenia. Recommended by NICE through the EVA pathway, the CareLoop platform identifies early warning signs a patient is becoming unwell as a means to prevent relapse, avoid hospital admissions and support recovery within the community.
Features
- Remote patient symptom monitoring via mobile application
- Clinician-facing web dashboard for real-time symptom review
- Personalised early warning sign algorithms for relapse risk detection
- Automated early warning sign alerts to agreed care team contacts
- Operational tracking and follow-up of early warning sign notifications
- Longitudinal patient-reported symptom data capture and visualisation
- CBTp-informed digital self-management and wellbeing content
- Integration with electronic patient record systems including Access RiO
- Service-level usage and activity reporting for governance and oversight
- MHRA Class I medical device compliant software platform
Benefits
- Identify relapse risk earlier to enable proactive clinical intervention
- Strengthen clinical decision-making using longitudinal symptom data
- Reduce avoidable hospital admissions and crisis service use
- Increase workforce efficiency while safely supporting larger caseloads
- Improve caseload prioritisation using real-time patient symptom insights
- Support safer discharge and stepped-down community care pathways
- Improve therapeutic conversations using shared, patient-reported data
- Support medication management with early feedback on symptom deterioration
- Empower patients to self-manage symptoms and recovery confidently
- Improve engagement and adherence with digital self-management tools
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 8 2 7 3 1 6 7 8 5 8 5 6 9 8
Contact
CARELOOP HEALTH LTD
Nick McBride
Telephone: 447703359038
Email: contact@careloop.health
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Adult Social Care
- Other
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
- The CareLoop Service requires internet connectivity for access to the patient mobile application and clinician dashboard. Planned maintenance and software updates may result in occasional downtime, but are typically scheduled outside of routine business hours, with advance notice provided where reasonably practicable. The clinical dashboard is optimised for use with modern web browsers (e.g. Google Chrome). The patient mobile application requires a supported Android or iOS operating system version. Technical support is provided during standard UK business hours.
- System requirements
-
- Internet connectivity for patient and clinician access
- Modern web browser for clinician dashboard access
- Supported Android or iOS device for patient app
- Valid email address for clinician notifications
- Optional SMS capability for early warning alerts
- Supported operating system for mobile application
- Clinician network access to CareLoop web (e.g. whitelisted IP)
User support
- Email or online ticketing support
- Yes
- Support response times
-
CareLoop Health provides email-based support and operates an online ticketing system. Support requests can be submitted via support@careloop.health and are logged for monitoring and action.
Technical support is provided during standard working hours (09:00–17:30, Monday to Friday, excluding public holidays). CareLoop Health aims to respond to support requests within 48 hours.
Response and resolution times are measured during standard working hours. Support is not provided at weekends. - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes
- Support levels
-
CareLoop Health provides a standard support level that is included within the CareLoop Service licence. Technical support is available to patients and clinicians during standard working hours (09:00–17:30, Monday to Friday, excluding public holidays). Support requests are submitted via email and are logged in CareLoop Health’s ticketing system for monitoring and action. Requests are prioritised based on severity, with response and resolution targets defined in the Service Level Agreement.
There are no additional support tiers or separate charges for enhanced support. All Buyers receive the same standard level of technical support, maintenance, and update services as part of the CareLoop Service.
Each Buyer is assigned a named CareLoop Health account manager to support onboarding, training, adoption, and ongoing service management. The account manager acts as the primary point of contact for operational queries, service reviews, and escalation where required.
CareLoop Health does not provide dedicated cloud support engineers or on-call technical staff. All support services are delivered by the CareLoop Health support team in accordance with the SLA - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Patient onboarding:
Patients receive simple, accessible onboarding materials, including information leaflets, FAQs, and in-app guidance explaining how to download the app, log in, complete questionnaires, and access self-management content. Where required, trained Digital Navigators support patients with app setup, technical troubleshooting, and understanding how to use their own symptom data.
Clinician onboarding:
Clinicians and service administrators receive CPD-accredited training covering service setup, patient enrolment, consent, Early Warning Sign protocols, and use of the clinician dashboard. Training is delivered through a combination of online sessions, workshops, and practical demonstrations, depending on local preference. Step-by-step guides and learning resources are provided.
Implementation and ongoing support:
During implementation, CareLoop Health works with local teams to align the service with clinical pathways, configure local content, and agree alert handling processes. After go-live, users can access refresher training, guidance materials, and ongoing support via the CareLoop Health support team. - Service documentation
- Yes
- Documentation formats
-
- HTML
- ODF
- End-of-contract data extraction
-
At the end of a Call-Off Contract, data extraction is managed by the contractual arrangements between the Buyer and CareLoop Health, in line with the applicable Data Processing Agreement and data protection law.
CareLoop Health acts as a data processor and will provide personal data to the Buyer or relevant data subject where required by law, including in response to subject access requests.
Where requested by the Buyer at contract end and where it is aligned with contractual and data sharing agreements, CareLoop Health will provide service data in a commonly used electronic format (typically .csv files).
The CareLoop Service does not currently provide a self-service data export function for users. - End-of-contract process
-
Contracts for the CareLoop Service run for the term (including any optional extension period) confirmed within each Order Form and Call-Off Contract. Termination rights and notice requirements are governed by the applicable Call-Off Contract and the G-Cloud Framework Agreement. End of contract data exports are negotiated at contract initiation.
Where a Buyer wishes to extend a contract and this is permitted under the Call-Off Contract, this is managed by agreement between the parties.
Where a contract is not extended or is terminated, CareLoop Health will cooperate in good faith with the Buyer to support an orderly exit. Exit arrangements, including service decommissioning, stakeholder coordination, and data handling, are managed in accordance with the Call-Off Contract and the applicable Data Processing Agreement.
CareLoop Health acts as a data processor and will retain, return, or securely dispose of personal data in line with agreed data protection terms and applicable law. - Documentation accessibility standard
- WCAG 2.2 A
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Chrome
- Safari
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
The CareLoop Service is designed to work on mobile devices and desktop environments. CareLoop has two primary interfaces.
Clinicians use a secure web-based dashboard, or an Electronic Patient Record (EPR) view where available, to add patients, review symptom data, and manage Early Warning Sign notifications.
Patients use the CareLoop mobile application to complete questionnaires, record mood and wellbeing information, and access self-management resources and CBTp-informed content.
The clinician service can be accessed on laptops, desktops, or mobile devices. The patient-facing service is delivered through a native mobile application optimised for accessibility and usability on both Android and iOS devices - Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
-
The CareLoop Service provides two primary interfaces: a patient-facing mobile application and a clinician-facing web dashboard.
Patients use the mobile application to complete symptom questionnaires, record mood and wellbeing information, view symptom trends, and access self-management resources and CBTp-informed content.
Clinicians use a secure web dashboard to add patients, review individual and cohort-level symptom data, and manage Early Warning Sign notifications.
The platform analyses patient-reported data in real time and presents personalised prompts for review, supporting timely, clinician-led decision-making. - Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
CareLoop has undertaken structured accessibility testing across both its clinician dashboard and patient mobile application.
For the clinician web dashboard, we have used the WAVE accessibility evaluation tool to identify and remediate critical accessibility and colour contrast issues.
For the mobile application, we have tested using Android’s Accessibility Scanner and manual screen-reader testing (TalkBack and VoiceOver) on Android and iOS devices. This has identified issues relating to contrast, touch target size, control labelling and screen-reader announcements, which are being addressed across both platforms.
CareLoop has also commissioned an independent accessibility review of the patient app by Corporation Pop, based on WCAG 2.x principles, and is implementing the recommendations as part of ongoing development.
CareLoop also engages extensively co-design activities with people with lived experience of psychosis to ensure the platform meets end user needs.
In spring 2026, CareLoop will work with the University of Manchester Digital Accessibility for further accessibility testing. - API
- Yes
- What users can and can't do using the API
-
The CareLoop Integration API supports integration with third party Electronic Patient Record systems. This enables clinicians to seamlessly interact with CareLoop through their native EHR. CareLoop works with the EHR provider to enable user access to CareLoop. The integration API enables clinicians to:
- View patient questionnaire data through their native EHR
- Receive EWS notifications generated by CareLoop patients
- Onboard patients through the EHR
- Refer a patient to the CareLoop system for onboarding
All integration is done through secure channels and in partnership with the EHR provider - API documentation
- Yes
- API documentation formats
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Patient personalisation:
Patients can personalise elements of the CareLoop mobile application to suit their preferences. This includes enabling or disabling optional features such as symptom trend visualisations, journalling functionality, and display of questionnaire completion streaks. Patients can also choose how they engage with self-management content and how they view their own symptom data.
Clinician and service configuration:
Clinicians access the CareLoop Service through a secure web dashboard or, where available, via an Electronic Patient Record (EPR) view. Clinicians can add patients, manage notification recipients, and view individual or cohort-level data. Notification protocols and Early Warning Sign thresholds are configured as part of service implementation in line with agreed clinical pathways.
Who can customise:
Patients can personalise their own in-app experience. Clinicians can manage patient setup and notification routing during set-up.
Service-level configuration is implemented and managed by CareLoop Health during onboarding and ongoing service delivery.
Scaling
- Independence of resources
- CareLoop separates customer data by tenant (group) to ensure isolation. Share processing components are protected using rate limiting to prevent one tenant’s demand from impacting others. The system is continuously monitored for load and performance using automatic alerts and AWS scaling to ensure a reliable service. For future demand growth, we will use parallel processing and additional load balancing to strengthen performance.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
CareLoop Health provides service-level metrics to support governance, implementation and continuous improvement. In line with GDPR and agreed data protection terms, reporting can include enrolment, activation, engagement, questionnaire completion, symptom trends and Early Warning Sign alert volumes.
Where permitted, aggregated and anonymised summaries can be provided for stakeholder and service reporting. These metrics support operational oversight, quality improvement and tracking of service usage against agreed objectives. - Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
-
CareLoop Health acts as a data processor and will provide personal data to the Buyer or relevant data subject where required by law, including in response to subject access requests.
Where requested by the Buyer, CareLoop Health will cooperate in good faith to provide service data in a commonly used electronic format (typically .csv files), subject to scope, technical feasibility, and any applicable contractual terms.
Data export and data handling arrangements are governed by the applicable Data Processing Agreement and the Call-Off Contract. - Data export formats
- CSV
- Data import formats
- Other
- Other data import formats
-
- Patient PROMS via CareLoop Mobile Application
- Mood journaling via CareLoop Mobile Application
- Clinicians/Digital Navigators enter onboarding data via the web dashboard/EPR
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
CareLoop Health targets availability of the CareLoop Service platform and clinician dashboard of 99.9%, calculated monthly and excluding scheduled downtime for planned maintenance and circumstances outside CareLoop Health’s reasonable control. We use AWS for high-availability infrastructure and redundancy to support a reliable service.
Service availability is governed by the Service Level Agreement (SLA), which forms part of the CareLoop Health Supplier Terms. The SLA sets out planned maintenance arrangements, support processes, and service performance monitoring.
CareLoop Health continuously monitors the performance of its servers and platform and may provide service availability or performance reports to the Buyer, including as part of agreed governance or review processes.
Remedies for service availability issues are governed by the applicable Call-Off Contract and the G-Cloud Framework Agreement. - Approach to resilience
-
The CareLoop Service is hosted on Amazon Web Services (AWS) cloud infrastructure. AWS provides a resilient and secure hosting environment designed to support high availability and operational continuity.
CareLoop Health continuously monitors the performance and availability of its servers and platform and uses reasonable endeavours to maintain service availability in line with the Service Level Agreement. Planned maintenance and software updates are scheduled wherever possible to minimise disruption and are normally undertaken during non-peak hours.
CareLoop Health’s operational processes include monitoring for service issues, responding to incidents through established support procedures, and applying updates and defect fixes to maintain platform stability.
Service availability targets and maintenance arrangements are set out in the Service Level Agreement. Remedies for service availability issues are governed by the applicable Call-Off Contract and the G-Cloud Framework Agreement. - Outage reporting
-
CareLoop Health reports service outages and significant service issues to Buyers via email notifications.
There is no public status dashboard or outage reporting API. Where reasonably practicable, CareLoop Health provides advance notice by email of planned maintenance or scheduled downtime. Unplanned outages or service disruptions are communicated to the Buyer through established support and account management contacts.
Service availability and maintenance arrangements are governed by the Service Level Agreement.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
-
Access to the CareLoop clinical dashboard and administrative functions is restricted to authorised users provisioned by CareLoop in accordance with the Buyer’s instructions. Users authenticate using unique named accounts, with multi-factor authentication applied to remotely accessible accounts. Role-based access controls are used to ensure users can access only the functions and data necessary for their role. Support channels are restricted to authorised HCPs and approved contacts via support@careloop.health
. Access changes and removals are managed in line with the Shared Responsibility Model and internal access control procedures. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- You control when users can access audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- You control when users can access audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
-
We are Cyber Essentials and NHS DSP Toolkit compliant.
We use AWS for our cloud hosting environment; AWS is ISO27001 certified.
CareLoop is ISO13485 compliant. - Information security policies and processes
-
CareLoop Health follows documented information security policies and procedures aligned with NHS and UK regulatory requirements.
CareLoop Health is Cyber Essentials and NHS Data Security and Protection Toolkit (DSPT) compliant and meets the NHS Digital Technology Assessment Criteria (DTAC).
CareLoop Health maintains a suite of information security, data protection and governance policies covering areas such as access control, data handling, incident management, risk management and business continuity. These policies are reviewed periodically and updated as required.
A Senior Information Risk Owner (SIRO) is responsible for oversight of information risk and ensuring that information security policies are implemented and followed. Information security responsibilities are embedded within operational and clinical governance arrangements.
New staff receive training on information security, data protection and relevant policies as part of onboarding. Ongoing awareness and refresher training is provided to ensure continued compliance.
Information security incidents are managed in accordance with documented incident response procedures and applicable contractual obligations. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
CareLoop Health follows a documented design and change control process aligned with its ISO 13485 quality management system and regulatory obligations as an MHRA Class I medical device manufacturer.
Service components and change requests are logged and tracked through their lifecycle using CareLoop Health’s change management tooling. Each proposed change is reviewed, verified and approved before implementation.
Change reviews assess impacts on clinical safety, system components, services, risk management and information governance. Security and data protection impacts are considered as part of the review process.
Material user-facing changes are communicated where reasonably practicable, in line with the Service Level Agreement. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
CareLoop Health follows documented Cyber Security Procedures.
Potential threats are assessed through ongoing monitoring, internal testing, post-market surveillance, and review of security advisories from software vendors and cloud service providers. Information about vulnerabilities is obtained from supplier security bulletins, operating system and application vendors, and cloud platform notifications.
Security updates and patches are applied in line with documented security update management procedures. Supported software is kept updated, with critical updates prioritised and deployed as soon as practicable, and other updates applied within defined timescales. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- CareLoop Health follows documented Information Security and Risk Management and Cyber Security Procedures aligned with Cyber Essentials, the NHS DSP Toolkit and DTAC. Potential compromises are identified through monitoring of service availability and security events, user access controls, incident reporting by staff and authorised users, and investigation of suspected or near-miss breaches in accordance with documented procedures. When a potential compromise is detected, CareLoop Health investigates, contains and remediates the issue, escalating to the DPO/IG Lead where required. Incidents are responded to as soon as practicable, with priority given to suspected security breaches affecting service availability or personal data.
- Incident management type
- Supplier-defined controls
- Incident management approach
-
CareLoop Health has Information Security and Risk Management and Cyber Security Procedures. These cover technical incidents, data breaches and service issues. Incidents are investigated, contained and remediated, with escalation to the SIRO and engagement of the DPO/IG Lead where required. Incident updates and post-incident reports are provided to Buyers as appropriate, including details of impact, actions taken and corrective measures.
Clinical safety incidents involving potential patient harm are assessed by our Clinical Safety Officer; and reported to the MHRA if necessary in accordance with UK regulations. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- E6c682c9-e2ef-450d-a028-328e59b5a97d
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- Yes
- Any other security certifications
- NHS Data Security and Protection Toolkit (DSPT)
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-