Fixology builds healthcare software for UK clinics, care providers and health tech companies: patient portals for booking, forms and secure messaging, clinical workflow tools, and integrations with Cliniko, Semble and NHS-approved interfaces. A patient portal typically takes 12 to 18 weeks, including accessibility testing and an independent penetration test. Clinical safety evidence under DCB0129, a DPIA and UK hosting are built in from the first sprint, and you own the code from day one.
The systems clinics already depend on
Private clinics in the UK mostly run a practice management system such as Semble, Cliniko, WriteUpp, Pabau or Carebit for appointments and notes, with Healthcode for submitting claims to private medical insurers. GP practices and NHS providers run EMIS Web or SystmOne, with a ring of approved third-party tools around them.
These systems do the clinical record well. Where clinics struggle is the patient journey around it: pre-consultation questionnaires sent as PDFs, referral letters arriving by email, results shared over the phone, and a reception team spending half the day on calls that a good portal would remove. That is where bespoke healthcare software makes the clearest difference.
Patient portals that reduce calls, not add logins
A patient portal works when it removes a phone call each time a patient uses it. The useful features are predictable: booking and rescheduling against real availability, completing medical history and consent forms before the appointment, receiving letters and results, and messaging the care team with a clear expectation of when someone will reply.
Behind that sits a lot of care. Health data is special category data under UK GDPR, so we design access controls, consent records and audit logs first. The portal should meet WCAG 2.2 AA so older and disabled patients can use it, and it should work well on a phone, because that is how most patients will open it. Some clinics also want a mobile app; for most, a well-built web portal is enough and is simpler to maintain.
Clinical safety: DCB0129 and DCB0160
In England, health IT used in patient care falls under two clinical risk management standards. DCB0129 applies to the manufacturer of the software and DCB0160 to the organisation deploying it. Both require a named Clinical Safety Officer, who must be a suitably qualified and experienced clinician, a hazard log, and a clinical safety case report.
When we build software for you, the manufacturer's obligations need an owner. In practice your organisation usually appoints the Clinical Safety Officer, and we run hazard identification workshops with them, record controls in the hazard log as features are built, and produce the evidence each sprint. Doing this as you go is far easier than reconstructing it at the end, and it often changes the design for the better.
DSPT, DTAC and selling into the NHS
Organisations with access to NHS patient data and systems complete the Data Security and Protection Toolkit every year. Digital health products being adopted by NHS organisations are usually assessed against the Digital Technology Assessment Criteria (DTAC), which covers clinical safety, data protection, technical security, interoperability, and usability and accessibility.
None of that is a certificate we can hand you. What we can do is build the product so the answers are straightforward: penetration testing by an independent tester, a DPIA, documented hosting in UK regions, accessibility testing, standards-based interfaces such as FHIR where the buyer needs them, and the clinical safety file described above. NHS login is available for patient-facing services that meet NHS England's criteria and complete its onboarding, and we plan for that process in the timeline rather than treating it as a last-minute integration.
When your software might be a medical device
If software diagnoses, predicts, monitors or recommends treatment for individual patients, it may be a medical device under UK regulations. That brings MHRA registration and conformity assessment, a quality management system and post-market surveillance. Booking, forms, messaging and most administrative tools are not medical devices. A symptom checker that triages patients, or an algorithm that flags abnormal results, may well be.
This changes the timeline, the team and the evidence required, so it needs settling before any build is planned. We will tell you early if we think your idea is heading into medical device territory, and recommend you take specialist regulatory advice before committing.
CQC-registered providers and care services
Providers of regulated activities in England register with the CQC, whose inspections ask whether a service is safe, effective, caring, responsive and well-led. Software does not pass an inspection for you, but it decides how quickly you can show evidence: training records, incident logs, audits, complaints and the actions that followed them.
Home care and care home providers often run a digital care planning system such as Birdie, Nourish or Person Centred Software. The bespoke work around them is usually rostering rules the package cannot express, a family portal, or a single dashboard that combines incidents, staffing and audits across several locations for the registered manager and the board.
A typical project: a five-site physiotherapy group
Here is a hypothetical example. A physiotherapy and sports medicine group with five clinics runs Cliniko, sees self-referred and insured patients, and sends intake forms as PDFs. Reception staff spend hours each week chasing forms and moving appointments by phone.
The first phase is a portal where patients book online, complete their history and consent before arriving, get exercise programmes and letters in one place, and message the clinic. Appointments and notes stay in Cliniko, with the portal reading and writing through its API. The second phase might add outcome measures collected between sessions, giving the group data to show insurers and corporate clients.
Why healthcare providers choose Fixology
We aim to be the UK's leading healthcare software development company, and in this sector that means treating clinical safety and information governance as engineering work, not paperwork. Health projects carry more unknowns than most: integration access, safety controls, IG sign-off and NHS procurement rules. Our discovery phase settles these first and produces a specification, a hazard log started with your Clinical Safety Officer, and a realistic plan for any NHS assurance.
A senior UK team then builds in two-week sprints with a working demo on a test link. Data is hosted in your own cloud account in UK regions, the code is in your repository from day one, and we support the system after launch. If you are comparing suppliers, ask each one how they would handle DCB0129 evidence; our guide on how to choose a software development company lists the other questions worth asking, and our security page sets out how we protect data.