How to scope a software project before you ask for quotes
Vague briefs produce quotes that cannot be compared. A few days of structured thinking before you contact suppliers will save weeks of confusion later.
Healthcare & Health Tech
We build patient-facing apps, clinical workflow tools and integrations for health tech companies and care providers, with safety and data protection designed in from the start.

Digital services are now part of how care is delivered: remote consultations, online booking, digital triage, remote monitoring and apps that support patients between appointments. Behind them, providers depend on software to move information between GP systems, hospitals, pharmacies and community services, where interoperability has long been the hardest problem.
Health software carries a different kind of risk. A confusing screen or a missing record can affect a clinical decision, and health data is among the most sensitive personal data there is. Buyers, particularly in the NHS, expect suppliers to show how clinical safety, information governance and security have been handled before a product is adopted, not afterwards.
Clinical information sits in separate systems, so staff re-key data, chase letters and work from incomplete records.
Health tech products stall in procurement because clinical safety documentation, data protection impact assessments or security evidence are incomplete.
Booking, referrals, forms and follow-ups consume clinical time that should go to patients, and paper or email workarounds add risk.
Health apps designed without patients in mind see low engagement, particularly among older users and people with disabilities or low digital confidence.
We build integrations on HL7 FHIR and established APIs wherever possible, so data can move between systems in a structured and maintainable way.
We produce the technical evidence your clinical safety officer and information governance lead need as we build, including hazard inputs, data flows and security controls.
We design around how clinicians and administrators actually work, automating routine steps and surfacing the information needed at each point in the pathway.
We design for accessibility and low digital confidence from the outset and test with real patients, keeping journeys short and language plain.
Booking, questionnaires, secure messaging, results and care plans, with identity verification through NHS login where appropriate.
Referral management, digital triage, task lists and case review tools that fit into existing clinical processes.
Collection of patient-reported outcomes and device readings, with thresholds and alerts that route to the right clinical team.
FHIR APIs, interface engines and data pipelines that connect health tech products with clinical systems and reporting.
Health data needs a lawful basis and an additional condition for processing. We design around data minimisation, role-based access, encryption and audit logging, and support your DPIA with clear data flow documentation.
Manufacturers of health IT must manage clinical risk under DCB0129, and deploying organisations under DCB0160. We work with your clinical safety officer, contributing to hazard logs and safety cases rather than replacing that role.
Organisations handling NHS patient data are expected to complete the Data Security and Protection Toolkit. We design infrastructure, access controls and processes that support your submission and other NHS assurance requirements.
We follow HL7 FHIR and relevant UK profiles for data exchange, and integrate NHS login for patient identity where your service is eligible.
We support it, but the standard requires a named clinical safety officer, a qualified clinician, within your organisation or engaged by you. We work with that person, contributing technical input to the hazard log and safety case and building mitigations into the product.
Some health software is regulated as a medical device, depending on its intended purpose, for example if it informs diagnosis or treatment. That is a regulatory judgement you should take specialist advice on early, and we will design and document the software to fit whichever route applies.
We build integrations using HL7 FHIR and the published APIs available for the relevant systems. Access to many NHS interfaces requires onboarding and assurance processes, so we help plan for those as part of the project timeline.
Typically in UK cloud regions with encryption at rest and in transit, following NHS guidance on cloud hosting. We agree hosting, backups and access arrangements with you and document them for your information governance review.
We design and test against WCAG guidelines, use plain language, support large text and screen readers, and test with patients who reflect your actual user base, not just confident smartphone users.
Vague briefs produce quotes that cannot be compared. A few days of structured thinking before you contact suppliers will save weeks of confusion later.
Rewriting a critical system from scratch is one of the riskiest projects a business can take on. Incremental replacement is slower to describe and far safer to deliver.
Staff use internal tools for hours every day, often far more than customers use your public product. Designing them well is one of the most direct ways to save time and reduce errors.
Tell us what you are trying to achieve. The first conversation is about understanding the problem — not selling you a solution.