Skip to main content

Help us improve the Digital Marketplace - send your feedback

CARELOOP HEALTH LTD

CareLoop Health for psychosis and schizophrenia

CareLoop is a remote monitoring and symptom management platform for people with Psychosis and Schizophrenia. Recommended by NICE through the EVA pathway, the CareLoop platform identifies early warning signs a patient is becoming unwell as a means to prevent relapse, avoid hospital admissions and support recovery within the community.

Features

  • Remote patient symptom monitoring via mobile application
  • Clinician-facing web dashboard for real-time symptom review
  • Personalised early warning sign algorithms for relapse risk detection
  • Automated early warning sign alerts to agreed care team contacts
  • Operational tracking and follow-up of early warning sign notifications
  • Longitudinal patient-reported symptom data capture and visualisation
  • CBTp-informed digital self-management and wellbeing content
  • Integration with electronic patient record systems including Access RiO
  • Service-level usage and activity reporting for governance and oversight
  • MHRA Class I medical device compliant software platform

Benefits

  • Identify relapse risk earlier to enable proactive clinical intervention
  • Strengthen clinical decision-making using longitudinal symptom data
  • Reduce avoidable hospital admissions and crisis service use
  • Increase workforce efficiency while safely supporting larger caseloads
  • Improve caseload prioritisation using real-time patient symptom insights
  • Support safer discharge and stepped-down community care pathways
  • Improve therapeutic conversations using shared, patient-reported data
  • Support medication management with early feedback on symptom deterioration
  • Empower patients to self-manage symptoms and recovery confidently
  • Improve engagement and adherence with digital self-management tools

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at contact@careloop.health. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

8 8 2 7 3 1 6 7 8 5 8 5 6 9 8

Contact

CARELOOP HEALTH LTD Nick McBride
Telephone: 447703359038
Email: contact@careloop.health

About your service

Service categories

Applications

Production and operations

Service industry and public sector operations

  • Healthcare
  • Adult Social Care
  • Other
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Private cloud
Service constraints
The CareLoop Service requires internet connectivity for access to the patient mobile application and clinician dashboard. Planned maintenance and software updates may result in occasional downtime, but are typically scheduled outside of routine business hours, with advance notice provided where reasonably practicable. The clinical dashboard is optimised for use with modern web browsers (e.g. Google Chrome). The patient mobile application requires a supported Android or iOS operating system version. Technical support is provided during standard UK business hours.
System requirements
  • Internet connectivity for patient and clinician access
  • Modern web browser for clinician dashboard access
  • Supported Android or iOS device for patient app
  • Valid email address for clinician notifications
  • Optional SMS capability for early warning alerts
  • Supported operating system for mobile application
  • Clinician network access to CareLoop web (e.g. whitelisted IP)

User support

Email or online ticketing support
Yes
Support response times
CareLoop Health provides email-based support and operates an online ticketing system. Support requests can be submitted via support@careloop.health and are logged for monitoring and action.

Technical support is provided during standard working hours (09:00–17:30, Monday to Friday, excluding public holidays). CareLoop Health aims to respond to support requests within 48 hours.

Response and resolution times are measured during standard working hours. Support is not provided at weekends.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes
Support levels
CareLoop Health provides a standard support level that is included within the CareLoop Service licence. Technical support is available to patients and clinicians during standard working hours (09:00–17:30, Monday to Friday, excluding public holidays). Support requests are submitted via email and are logged in CareLoop Health’s ticketing system for monitoring and action. Requests are prioritised based on severity, with response and resolution targets defined in the Service Level Agreement.

There are no additional support tiers or separate charges for enhanced support. All Buyers receive the same standard level of technical support, maintenance, and update services as part of the CareLoop Service.

Each Buyer is assigned a named CareLoop Health account manager to support onboarding, training, adoption, and ongoing service management. The account manager acts as the primary point of contact for operational queries, service reviews, and escalation where required.

CareLoop Health does not provide dedicated cloud support engineers or on-call technical staff. All support services are delivered by the CareLoop Health support team in accordance with the SLA
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Patient onboarding:

Patients receive simple, accessible onboarding materials, including information leaflets, FAQs, and in-app guidance explaining how to download the app, log in, complete questionnaires, and access self-management content. Where required, trained Digital Navigators support patients with app setup, technical troubleshooting, and understanding how to use their own symptom data.

Clinician onboarding:

Clinicians and service administrators receive CPD-accredited training covering service setup, patient enrolment, consent, Early Warning Sign protocols, and use of the clinician dashboard. Training is delivered through a combination of online sessions, workshops, and practical demonstrations, depending on local preference. Step-by-step guides and learning resources are provided.

Implementation and ongoing support:

During implementation, CareLoop Health works with local teams to align the service with clinical pathways, configure local content, and agree alert handling processes. After go-live, users can access refresher training, guidance materials, and ongoing support via the CareLoop Health support team.
Service documentation
Yes
Documentation formats
  • HTML
  • ODF
  • PDF
End-of-contract data extraction
At the end of a Call-Off Contract, data extraction is managed by the contractual arrangements between the Buyer and CareLoop Health, in line with the applicable Data Processing Agreement and data protection law.

CareLoop Health acts as a data processor and will provide personal data to the Buyer or relevant data subject where required by law, including in response to subject access requests.

Where requested by the Buyer at contract end and where it is aligned with contractual and data sharing agreements, CareLoop Health will provide service data in a commonly used electronic format (typically .csv files).

The CareLoop Service does not currently provide a self-service data export function for users.
End-of-contract process
Contracts for the CareLoop Service run for the term (including any optional extension period) confirmed within each Order Form and Call-Off Contract. Termination rights and notice requirements are governed by the applicable Call-Off Contract and the G-Cloud Framework Agreement. End of contract data exports are negotiated at contract initiation.

Where a Buyer wishes to extend a contract and this is permitted under the Call-Off Contract, this is managed by agreement between the parties.

Where a contract is not extended or is terminated, CareLoop Health will cooperate in good faith with the Buyer to support an orderly exit. Exit arrangements, including service decommissioning, stakeholder coordination, and data handling, are managed in accordance with the Call-Off Contract and the applicable Data Processing Agreement.

CareLoop Health acts as a data processor and will retain, return, or securely dispose of personal data in line with agreed data protection terms and applicable law.
Documentation accessibility standard
WCAG 2.2 A

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Chrome
  • Safari
Application to install
Yes
Compatible operating systems
  • Android
  • IOS
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The CareLoop Service is designed to work on mobile devices and desktop environments. CareLoop has two primary interfaces.

Clinicians use a secure web-based dashboard, or an Electronic Patient Record (EPR) view where available, to add patients, review symptom data, and manage Early Warning Sign notifications.

Patients use the CareLoop mobile application to complete questionnaires, record mood and wellbeing information, and access self-management resources and CBTp-informed content.

The clinician service can be accessed on laptops, desktops, or mobile devices. The patient-facing service is delivered through a native mobile application optimised for accessibility and usability on both Android and iOS devices
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
The CareLoop Service provides two primary interfaces: a patient-facing mobile application and a clinician-facing web dashboard.

Patients use the mobile application to complete symptom questionnaires, record mood and wellbeing information, view symptom trends, and access self-management resources and CBTp-informed content.

Clinicians use a secure web dashboard to add patients, review individual and cohort-level symptom data, and manage Early Warning Sign notifications.

The platform analyses patient-reported data in real time and presents personalised prompts for review, supporting timely, clinician-led decision-making.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
CareLoop has undertaken structured accessibility testing across both its clinician dashboard and patient mobile application.

For the clinician web dashboard, we have used the WAVE accessibility evaluation tool to identify and remediate critical accessibility and colour contrast issues.

For the mobile application, we have tested using Android’s Accessibility Scanner and manual screen-reader testing (TalkBack and VoiceOver) on Android and iOS devices. This has identified issues relating to contrast, touch target size, control labelling and screen-reader announcements, which are being addressed across both platforms.

CareLoop has also commissioned an independent accessibility review of the patient app by Corporation Pop, based on WCAG 2.x principles, and is implementing the recommendations as part of ongoing development.

CareLoop also engages extensively co-design activities with people with lived experience of psychosis to ensure the platform meets end user needs.

In spring 2026, CareLoop will work with the University of Manchester Digital Accessibility for further accessibility testing.
API
Yes
What users can and can't do using the API
The CareLoop Integration API supports integration with third party Electronic Patient Record systems. This enables clinicians to seamlessly interact with CareLoop through their native EHR. CareLoop works with the EHR provider to enable user access to CareLoop. The integration API enables clinicians to:

- View patient questionnaire data through their native EHR
- Receive EWS notifications generated by CareLoop patients
- Onboard patients through the EHR
- Refer a patient to the CareLoop system for onboarding

All integration is done through secure channels and in partnership with the EHR provider
API documentation
Yes
API documentation formats
PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Patient personalisation:

Patients can personalise elements of the CareLoop mobile application to suit their preferences. This includes enabling or disabling optional features such as symptom trend visualisations, journalling functionality, and display of questionnaire completion streaks. Patients can also choose how they engage with self-management content and how they view their own symptom data.

Clinician and service configuration:

Clinicians access the CareLoop Service through a secure web dashboard or, where available, via an Electronic Patient Record (EPR) view. Clinicians can add patients, manage notification recipients, and view individual or cohort-level data. Notification protocols and Early Warning Sign thresholds are configured as part of service implementation in line with agreed clinical pathways.

Who can customise:

Patients can personalise their own in-app experience. Clinicians can manage patient setup and notification routing during set-up.
Service-level configuration is implemented and managed by CareLoop Health during onboarding and ongoing service delivery.

Scaling

Independence of resources
CareLoop separates customer data by tenant (group) to ensure isolation. Share processing components are protected using rate limiting to prevent one tenant’s demand from impacting others. The system is continuously monitored for load and performance using automatic alerts and AWS scaling to ensure a reliable service. For future demand growth, we will use parallel processing and additional load balancing to strengthen performance.

Analytics

Service usage metrics
Yes
Metrics types
CareLoop Health provides service-level metrics to support governance, implementation and continuous improvement. In line with GDPR and agreed data protection terms, reporting can include enrolment, activation, engagement, questionnaire completion, symptom trends and Early Warning Sign alert volumes.

Where permitted, aggregated and anonymised summaries can be provided for stakeholder and service reporting. These metrics support operational oversight, quality improvement and tracking of service usage against agreed objectives.
Reporting types
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
In-house destruction process
Data sanitisation type
Deleted data can’t be directly accessed / Cryptographic Erasure

Data importing and exporting

Data export approach
CareLoop Health acts as a data processor and will provide personal data to the Buyer or relevant data subject where required by law, including in response to subject access requests.

Where requested by the Buyer, CareLoop Health will cooperate in good faith to provide service data in a commonly used electronic format (typically .csv files), subject to scope, technical feasibility, and any applicable contractual terms.

Data export and data handling arrangements are governed by the applicable Data Processing Agreement and the Call-Off Contract.
Data export formats
CSV
Data import formats
Other
Other data import formats
  • Patient PROMS via CareLoop Mobile Application
  • Mood journaling via CareLoop Mobile Application
  • Clinicians/Digital Navigators enter onboarding data via the web dashboard/EPR

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
CareLoop Health targets availability of the CareLoop Service platform and clinician dashboard of 99.9%, calculated monthly and excluding scheduled downtime for planned maintenance and circumstances outside CareLoop Health’s reasonable control. We use AWS for high-availability infrastructure and redundancy to support a reliable service.

Service availability is governed by the Service Level Agreement (SLA), which forms part of the CareLoop Health Supplier Terms. The SLA sets out planned maintenance arrangements, support processes, and service performance monitoring.

CareLoop Health continuously monitors the performance of its servers and platform and may provide service availability or performance reports to the Buyer, including as part of agreed governance or review processes.

Remedies for service availability issues are governed by the applicable Call-Off Contract and the G-Cloud Framework Agreement.
Approach to resilience
The CareLoop Service is hosted on Amazon Web Services (AWS) cloud infrastructure. AWS provides a resilient and secure hosting environment designed to support high availability and operational continuity.

CareLoop Health continuously monitors the performance and availability of its servers and platform and uses reasonable endeavours to maintain service availability in line with the Service Level Agreement. Planned maintenance and software updates are scheduled wherever possible to minimise disruption and are normally undertaken during non-peak hours.

CareLoop Health’s operational processes include monitoring for service issues, responding to incidents through established support procedures, and applying updates and defect fixes to maintain platform stability.

Service availability targets and maintenance arrangements are set out in the Service Level Agreement. Remedies for service availability issues are governed by the applicable Call-Off Contract and the G-Cloud Framework Agreement.
Outage reporting
CareLoop Health reports service outages and significant service issues to Buyers via email notifications.

There is no public status dashboard or outage reporting API. Where reasonably practicable, CareLoop Health provides advance notice by email of planned maintenance or scheduled downtime. Unplanned outages or service disruptions are communicated to the Buyer through established support and account management contacts.

Service availability and maintenance arrangements are governed by the Service Level Agreement.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Access to the CareLoop clinical dashboard and administrative functions is restricted to authorised users provisioned by CareLoop in accordance with the Buyer’s instructions. Users authenticate using unique named accounts, with multi-factor authentication applied to remotely accessible accounts. Role-based access controls are used to ensure users can access only the functions and data necessary for their role. Support channels are restricted to authorised HCPs and approved contacts via support@careloop.health
. Access changes and removals are managed in line with the Shared Responsibility Model and internal access control procedures.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password

Audit information for users

Access to user activity audit information
You control when users can access audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
You control when users can access audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
Other
Other security governance standards
We are Cyber Essentials and NHS DSP Toolkit compliant.
We use AWS for our cloud hosting environment; AWS is ISO27001 certified.
CareLoop is ISO13485 compliant.
Information security policies and processes
CareLoop Health follows documented information security policies and procedures aligned with NHS and UK regulatory requirements.

CareLoop Health is Cyber Essentials and NHS Data Security and Protection Toolkit (DSPT) compliant and meets the NHS Digital Technology Assessment Criteria (DTAC).

CareLoop Health maintains a suite of information security, data protection and governance policies covering areas such as access control, data handling, incident management, risk management and business continuity. These policies are reviewed periodically and updated as required.

A Senior Information Risk Owner (SIRO) is responsible for oversight of information risk and ensuring that information security policies are implemented and followed. Information security responsibilities are embedded within operational and clinical governance arrangements.

New staff receive training on information security, data protection and relevant policies as part of onboarding. Ongoing awareness and refresher training is provided to ensure continued compliance.

Information security incidents are managed in accordance with documented incident response procedures and applicable contractual obligations.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
CareLoop Health follows a documented design and change control process aligned with its ISO 13485 quality management system and regulatory obligations as an MHRA Class I medical device manufacturer.

Service components and change requests are logged and tracked through their lifecycle using CareLoop Health’s change management tooling. Each proposed change is reviewed, verified and approved before implementation.

Change reviews assess impacts on clinical safety, system components, services, risk management and information governance. Security and data protection impacts are considered as part of the review process.

Material user-facing changes are communicated where reasonably practicable, in line with the Service Level Agreement.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
CareLoop Health follows documented Cyber Security Procedures.

Potential threats are assessed through ongoing monitoring, internal testing, post-market surveillance, and review of security advisories from software vendors and cloud service providers. Information about vulnerabilities is obtained from supplier security bulletins, operating system and application vendors, and cloud platform notifications.

Security updates and patches are applied in line with documented security update management procedures. Supported software is kept updated, with critical updates prioritised and deployed as soon as practicable, and other updates applied within defined timescales.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
CareLoop Health follows documented Information Security and Risk Management and Cyber Security Procedures aligned with Cyber Essentials, the NHS DSP Toolkit and DTAC. Potential compromises are identified through monitoring of service availability and security events, user access controls, incident reporting by staff and authorised users, and investigation of suspected or near-miss breaches in accordance with documented procedures. When a potential compromise is detected, CareLoop Health investigates, contains and remediates the issue, escalating to the DPO/IG Lead where required. Incidents are responded to as soon as practicable, with priority given to suspected security breaches affecting service availability or personal data.
Incident management type
Supplier-defined controls
Incident management approach
CareLoop Health has Information Security and Risk Management and Cyber Security Procedures. These cover technical incidents, data breaches and service issues. Incidents are investigated, contained and remediated, with escalation to the SIRO and engagement of the DPO/IG Lead where required. Incident updates and post-incident reports are provided to Buyers as appropriate, including details of impact, actions taken and corrective measures.

Clinical safety incidents involving potential patient harm are assessed by our Clinical Safety Officer; and reported to the MHRA if necessary in accordance with UK regulations.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
E6c682c9-e2ef-450d-a028-328e59b5a97d
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
Yes
Any other security certifications
NHS Data Security and Protection Toolkit (DSPT)

Social value

Section B - Commitment for Future: Delivery
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
    • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
    • Actions to invest in the physical and mental health and wellbeing of the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at contact@careloop.health. Tell them what format you need. It will help if you say what assistive technology you use.