A patient portal spends proportionally more time in discovery than a general business system, typically 15–20% of total cost, because the integration route into EMIS Web or SystmOne has to be agreed and accredited before meaningful build work can start, and because the clinical safety case needs a hazard log that is genuinely reviewed against the design, not written retrospectively to match it.
Integration approval cycles with GP system suppliers are a scheduling risk as much as a cost one: they run on the supplier's timetable, not yours, and a build that assumes approval will land inside a fixed sprint boundary is usually wrong. We build calendar slack around these approvals rather than pricing them as fixed- duration tasks, which is one reason the timelines in the worked examples below are given as ranges rather than fixed week counts.
Clinical safety work itself — the hazard log, the safety case document, and the clinical safety officer's sign-off — typically runs in parallel with the later half of the build rather than as a discrete phase afterwards, so that hazards identified during safety review can still be addressed in the design before go-live rather than requiring rework post-launch.