Skip to content
Zorix Systems — software that powers your business

Industries

Healthcare software development

Healthcare organisations rarely lack systems. They have a clinical system of record, a scheduling tool, a document store, a patient communication product and a spreadsheet that reconciles the four. The work we are asked to do is almost never to replace the clinical record — it is to build the operational layer around it that the record was never designed to provide, and to make that layer exchange data safely with everything else.

We build for GP federations and primary care networks, private clinic groups, dental groups, diagnostic providers and digital health companies selling into the NHS. The constraint that shapes every one of those projects is the same: patient data has a regulatory perimeter, clinical functionality carries safety obligations, and integration routes into EMIS Web, TPP SystmOne and hospital PAS estates are governed rather than open.

Where it breaks

The problems described in the sector's own language

The clinical system holds the record but not the workflow

EMIS Web and SystmOne hold consultations, coded observations, medications and documents. They do not run a multi-site recall programme across a federation, a triage queue with service-level thresholds, or a referral pathway with an audit trail across organisational boundaries. Those workflows end up in shared mailboxes, task lists and spreadsheets keyed on NHS number by hand.

Patient contact is spread across products that do not share state

Booking sits in one system, SMS in another, the website form in a third, and the results letter in the document store. A patient who books online, replies to a text and then telephones is three separate records to the staff handling them, and no single view shows what has already been said.

Data is copied between systems by people

A member of staff rekeys demographics from a referral into the clinical system, then rekeys the same details into a billing or claims tool. Every transcription is a chance to attach a record to the wrong patient, which is a clinical safety hazard rather than a data quality annoyance.

Reporting is retrospective and disputed

DNA rates, waiting list positions, chair or room utilisation and recall compliance are assembled monthly from exports. By the time the numbers exist the month is over, and two departments produce different figures because they filtered the export differently.

Growth by acquisition multiplies the estate

A group that acquires practices inherits a mixed estate — EMIS Web in one site, SystmOne in another, Dentally or SOE Exact across the dental arm — and cannot answer basic group-level questions without an integration layer that normalises identifiers and coding.

Accessibility and identity are afterthoughts

Patient-facing services procured without WCAG 2.2 AA requirements or without NHS Login integration fail assessment late, and remediation after build costs several times what designing for it would have cost.

Regulatory context

What the sector has to satisfy

NHS DTAC
The Digital Technology Assessment Criteria consolidate clinical safety, data protection, technical security, interoperability and usability evidence for products used in the NHS. Evidence is gathered during delivery.
DCB0129
Clinical risk management for the manufacturer. Requires a clinical risk management plan, a hazard log maintained through the build, and a clinical safety case report signed by a clinical safety officer.
DCB0160
The deploying organisation's equivalent. The provider deploying the software owns it; we supply the manufacturer artefacts it depends on and support the assessment.
DSPT
The Data Security and Protection Toolkit is the annual self-assessment against the National Data Guardian standards that organisations handling health data are expected to complete.
UK GDPR
Patient data is special category data under Article 9. Lawful basis, retention schedules, data protection impact assessment and processor obligations are documented per project, not assumed.
Caldicott Principles
The eight principles governing use of confidential patient information — including the duty to share where it is in the patient's interest — shape how access controls and data flows are designed.
MHRA classification
Where software interprets clinical data and supports a decision, it may fall within UK MDR 2002 as a medical device. Classification is assessed in discovery, not after build.
HIPAA and SOC 2
For US-facing clients we build to HIPAA safeguards and to the control set expected in a SOC 2 examination.

Integration surface

The systems we connect to, named

Primary care clinical systems

EMIS WebTPP SystmOneVisionGP ConnectIM1 pairing

National services

NHS LoginPDSSpinee-Referral ServiceNHS number tracing

Dental systems

DentallySOE ExactR4Carestream

Hospital and diagnostics

PASRISPACSLIMS

Standards

HL7 v2FHIR UK CoreSNOMED CTdm+dDICOM

Operational systems

SMS gatewayspayment providerse-signatureMicrosoft Entra ID

Solutions

What we build in this sector

Patient portal development

Booking against live practice diaries, repeat prescription requests, rule-based results release, NHS Login identity verification and proxy access for carers, built to WCAG 2.2 AA.

Explore patient portal development

Practice management software

Scheduling and recall, clinician diaries, room and chair utilisation, claims and remittance, waiting list management and DNA tracking across multi-site groups.

Explore practice management software

EHR and EPR integration

IM1 and GP Connect routes, FHIR UK Core resource mapping, write-back permissions, patient matching on NHS number and a defensible audit trail.

Explore ehr and epr integration

Telehealth platform development

Consultation scheduling, WebRTC video, structured clinical note capture, prescribing handoff, consent capture and recording retention policy.

Explore telehealth platform development

Dental software development

Charting and treatment planning, NHS UDA banding with FP17 submission, private plan billing, recall cycles and imaging integration.

Explore dental software development

Healthcare software compliance

A factual reference for DTAC, DCB0129, DCB0160, DSPT, UK GDPR and MHRA classification, and where each sits in a delivery timeline.

Explore healthcare software compliance

Engagement shapes

Typical scope, duration and budget band

Discovery and scoping
Three to five weeks. Integration route assessment, clinical safety hazard identification, data protection impact assessment input, phased estimate. Fixed fee, credited against the build.
Single-service build
A patient portal or a focused integration layer for one organisation. Typically 12 to 20 weeks. Indicative band £250,000 to £400,000.
Operational platform
Practice management or multi-site operations across a group, replacing several tools. Typically 6 to 12 months in phases. Indicative band £400,000 to £900,000.
Integration programme
A federation or group estate with mixed clinical systems and a normalising data layer. Runs alongside other builds. Indicative band £300,000 to £600,000.
Managed run
Post-go-live support with defined response times, release management and a standing change budget. Priced as a monthly retainer against an agreed service level.
How discovery and scoping works

Questions

Frequently asked

Do you work directly with NHS organisations or only with private providers?

Both. The commercial route differs — NHS trusts and integrated care boards buy through framework agreements and formal procurement, private groups and practices buy directly — but the engineering obligations are the same: DCB0129 clinical risk management on our side, DCB0160 on the deploying organisation's side, and DSPT-aligned handling of patient data throughout.

Can you read and write to EMIS Web and TPP SystmOne?

Read access is routinely achievable through GP Connect for the standard capability set, and through IM1 pairing where a deeper or bespoke interface is required. Write-back is narrower: it depends on the specific IM1 interface mechanism agreed with the principal supplier and on what the practice or federation authorises. We map exactly what is readable and writeable in discovery before any build estimate is issued.

Is the software we commission a medical device?

It depends on function, not on technology. Software that stores, displays or transmits clinical data is usually not a device; software that interprets data and drives a clinical decision may be classified under UK MDR 2002 and require MHRA registration and a conformity route. We flag classification risk in discovery and, where it is likely, scope the project so the regulated component is isolated and small.

How is patient data hosted?

UK regions of Azure or AWS by default, with data residency written into the contract, encryption at rest and in transit, role-based access control, and a full audit trail of who viewed which record and when. Sub-processors and international transfer arrangements are listed in the delivery documentation rather than described in general terms.

Do you provide clinical safety documentation?

We produce the manufacturer-side DCB0129 artefacts — hazard log, clinical risk management plan and clinical safety case report — and work alongside your clinical safety officer, who owns the DCB0160 deployment file.

What does an NHS DTAC assessment require from a supplier?

DTAC consolidates evidence across five areas: clinical safety, data protection, technical security, interoperability and usability with accessibility. Most of it is produced during a build rather than retrofitted, which is why we treat the DTAC response as a deliverable of the project rather than a document written after go-live.

Tell us what your systems are doing wrong.

Send the problem, not a brief. We will tell you whether it is a project we should be involved in.

Talk to us