Occentra

Blog

What Is Health Surveillance Software? A Guide for Employers and OH Providers

Buyers often meet three different things under the same search:

  • a health surveillance programme, the ongoing scheme of workplace health checks
  • a health surveillance form, the questionnaire, measurement record or clinical instrument used at one point in that scheme
  • health surveillance software, the system that manages the programme, the people in it, recalls, assessments, forms, records and workflow

Those are related. They are not interchangeable.

A programme is an operational obligation that continues between assessments. A form captures what happened at a particular check. Software is useful when it keeps those checks attached to the people, hazards, recalls and history that give them meaning.

That definition also keeps the category in the right domain. Occupational health surveillance software is for workplace health programmes run by employers and occupational health providers. It is not hospital infection surveillance, patient monitoring, or other clinical surveillance used in secondary care. Those products solve a different problem, even when they share the word surveillance.

Health surveillance is not a sequence of unrelated appointments. Nor is the software merely a place to store questionnaires or test results. Each assessment belongs to a longer operational history, often spanning several years, changes of role and more than one type of surveillance.

A digital form can capture what happened today. Health surveillance software should also explain why the assessment was needed, what must happen next and how today's result relates to what came before.

What is health surveillance?

The Health and Safety Executive (HSE) describes health surveillance as a scheme of repeated health checks used to identify ill health caused by work. It may be needed where workers remain exposed to health risks after controls have been put in place. HSE cites noise, vibration and substances hazardous to health as examples, and says schemes should usually be established with input from a competent occupational health professional. Its health surveillance overview explains the regulatory context in more detail.

Health surveillance does not replace risk assessment or exposure control. The employer's risk assessment establishes whether surveillance is appropriate and which workers need it. Occupational health contributes the clinical expertise. Software supports the resulting programme, but cannot make those judgements on their behalf.

The word programme is important. HSE guidance on setting up a health surveillance scheme refers to an ongoing scheme, the workers exposed to each relevant hazard, operational ownership and practical arrangements. Those are connected management concerns, not properties of an individual form.

The relationship is not a linear sequence. The programme is the ongoing obligation. Forms capture particular assessments within it. Software manages the people, programme membership, recalls, assessments, records and follow-up that keep the programme running between those forms.

HSE's overview of health surveillance and its guidance on record-keeping are the authoritative starting points for what the programme and its records need to contain. Software should support that work, not redefine it.

What does health surveillance software do?

Health surveillance software gives structure to the complete cycle around an employee. In practical terms, it manages the programme, the people who belong to it, recalls, assessments, forms, records and the workflow that connects them.

The cycle often begins outside occupational health. An employer identifies a surveillance requirement from its risk assessment and provides current information about the employee's work, location and relevant exposure. The occupational health service then needs to associate that person with the appropriate programme and determine what activity is due.

From there, the system may support questionnaires, appointments, clinical assessments and test results. It should record an outcome clearly enough to drive the next action. That could be continuing routine surveillance, obtaining more information, arranging a higher-level assessment, issuing fitness advice or scheduling a further review, depending on the programme and the clinical judgement involved.

Completion is not the end of the record. The outcome needs to remain attached to the assessment that produced it. The next recall needs to be visible. When the employee returns, the clinician should be able to see the relevant history without reconstructing it from files, inboxes and a separate tracker.

At an operational level, a useful system should help teams answer questions such as:

  • Who currently requires surveillance, and for which hazard or programme?
  • What is due, booked, completed, overdue or awaiting review?
  • What follow-up was agreed, and who is responsible for it?
  • Which employees have moved role, site or employer since the requirement was set?
  • Can clinical and operational teams see the history appropriate to their role?
  • Can managers understand programme coverage without seeing confidential medical information?

These questions are related. A dashboard of overdue assessments is only dependable if programme membership, due dates and completed outcomes are dependable. An automated reminder is of limited value if it is based on an old role or the wrong recall interval. Reporting does not repair a weak operational record. It exposes it.

The same applies to auditability. A useful history should show meaningful events: a requirement was added, a questionnaire was submitted, an assessment was completed, follow-up was requested and an outcome was recorded. A log showing that somebody edited a row is less informative.

A health surveillance form is not a health surveillance system

Digitising a paper questionnaire can remove rekeying and improve consistency. Configurable health surveillance forms are therefore valuable. They are still only one part of the work.

Consider an employee completing a HAVS screening questionnaire. The submission is an event. The surveillance programme around it has to know that the employee is exposed to hand-arm vibration, which stage of assessment applies, when the previous review took place, whether any answer requires escalation, what the eventual outcome was and when the employee should be recalled.

If the questionnaire is revised next year, the earlier submission should remain intelligible in the context of the version the employee completed. If the employee changes role, the surveillance requirement may need review. If a symptom is reported between planned checks, the process should not depend on waiting for the next form to be sent.

This is the distinction buyers should keep in view:

A form captures an assessment. A health surveillance system manages the programme around it.

A product demonstration can make form building look like the centre of the system because it is visible and easy to show. The less visible questions are usually more consequential. What creates the next action? How are exceptions handled? Can the team see incomplete follow-up? Does history survive a change to the template? Who can see the clinical response, and who should see only the fitness outcome?

The form is the interface to one moment. The system is the account of work over time.

Examples of longitudinal surveillance workflows

Different hazards require different clinical protocols. Software should represent those differences without inventing the protocol itself. HAVS, audiometry and respiratory surveillance show why a generic annual questionnaire is not enough.

HAVS health surveillance

HSE's guidance on health surveillance for hand-arm vibration describes basic surveillance using a regular questionnaire, with positive responses referred to an occupational health provider. It also distinguishes basic screening from higher-level surveillance and expects outcomes such as fitness advice to be acted upon.

Operationally, this creates a staged process. The system needs to retain the screening event, show whether a further assessment was indicated, connect any later clinical activity to the same surveillance cycle and preserve the outcome for future review. A questionnaire marked “complete” is not a satisfactory programme status if the response has triggered work that nobody can see.

Audiometry

Hearing surveillance depends on comparison. HSE says it usually includes regular hearing checks, communication of results, health records and medical examination where hearing damage is identified. It also recommends a baseline where possible and a subsequent series of checks. See the HSE's health surveillance guidance for hearing.

An audiogram has limited operational meaning when detached from the employee's exposure context, earlier results and the action taken after review. The system should make the series visible while preserving the distinction between the clinical result, the employee's health record and the fitness-for-work information provided to the employer.

Respiratory surveillance

Respiratory surveillance may involve questionnaires, lung-function assessment or other checks appropriate to the substance and risk. HSE's COSHH health surveillance guidance makes a particularly useful point: carrying out tests, questionnaires or examinations is not sufficient. Results must be interpreted and followed by action where required.

That is also a useful test of clinical surveillance software. Recording a spirometry result is data capture. Managing interpretation, outcome, follow-up and the relationship to previous assessments is a workflow.

Why spreadsheets become difficult

Spreadsheets can work surprisingly well for a small health surveillance programme. They are familiar, adaptable and quick to change. A capable administrator can build a useful recall register without buying another system.

The difficulty appears as the programme gains relationships.

One employee may require HAVS, hearing and respiratory surveillance, each with different dates and outcomes. People change role, site and manager. Appointments are cancelled. A screening response creates a clinical follow-up. Several users update the tracker. Clinical records sit elsewhere because the spreadsheet is not an appropriate place for them.

At that point, a row is expected to represent a person, an exposure, a programme, the current cycle, the last assessment and the next action at the same time. Adding columns postpones the modelling problem, but does not resolve it.

Spreadsheets are flexible, but they do not inherently understand surveillance. They cannot know that a completed appointment is different from a completed assessment, or that an assessment remains open until its outcome and follow-up are dealt with. Those meanings live in conventions understood by the team.

This is why spreadsheet problems often emerge during staff absence, contract growth or reporting. The file still contains the data, but operating it depends on somebody who knows what each colour, blank cell and locally defined status means.

The right time to consider dedicated software is not determined by an arbitrary employee count. It is when the cost of maintaining those relationships and conventions begins to exceed the convenience of the spreadsheet.

What should you look for in health surveillance software?

Evaluation should begin with a real programme, including its exceptions. A polished questionnaire is easy to demonstrate. Ask the supplier to show what happens before and after it.

A model of the programme

The system should represent employees, surveillance requirements, assessments, outcomes, follow-up and recalls as related concepts. Ask how it handles one employee in several programmes, changes in role or exposure, missed assessments and a requirement that ends.

Configurable workflows and versioned forms

Different hazards and services need different pathways. Teams should be able to configure appropriate forms and workflow steps without commissioning customer-specific development for every change.

Configuration still needs boundaries. If every client can redefine what “complete” means, cross-service reporting becomes unreliable. Look for a system that permits legitimate variation while retaining consistent operational meaning. Ask what happens to past submissions when a form changes.

Longitudinal employee history

A clinician should be able to find the relevant earlier assessments, results and outcomes in context. This does not mean putting every occupational health interaction into one undifferentiated record. It means maintaining continuity between distinct records without losing their purpose.

Recall, scheduling and exception management

Check how due dates are calculated, changed and audited. Ask what happens after a cancellation, non-attendance, positive screening response or overdue clinical review. A reminder feature is not the same as a controlled recall process.

Records, permissions and audit history

Health records and confidential medical records are not interchangeable. HSE's record-keeping guidance distinguishes the employer's health record, which includes matters such as hazard and fitness to continue exposure, from medical records kept in clinical confidence by the occupational health professional.

Buyers should examine role-based access, separation of clinical and employer-facing information, retention controls and a history of meaningful changes. Security claims matter, but the practical question is whether the information model prevents the wrong record being exposed through ordinary use.

Reporting and operational oversight

The system should show programme activity, upcoming work, overdue stages and outcomes without requiring a parallel tracker. Reports should be derived from consistent workflow states and allow appropriate aggregation without disclosing confidential clinical detail.

Integration, portability and change

Surveillance depends on current workforce and employment context, so ask how employee, role, location and exposure-related information enters and leaves the system. Examine data export, record transfer and the consequences of changing provider. Test how the system adapts when an employer adds a site, a provider wins a contract or a clinical form is revised.

The cost of software is not only the subscription or implementation. It is also the effort required to make the next reasonable change.

Health surveillance as part of occupational health

Health surveillance has its own purpose, records and recurring pattern, but it rarely exists in complete isolation.

The same employee may also interact with occupational health through management referrals, appointments, consultations, forms, documents and reports. An occupational health provider needs continuity across that work, with appropriate access controls, without collapsing it into a generic activity log.

Language helps preserve those boundaries. A Referral is a request for occupational health services. Once accepted, the operational work resulting from it is a Case. An appointment is an event within the work, not the Case itself. A form records structured information, while a report communicates an outcome to a defined audience.

This explicit model is one reason to consider surveillance within a wider occupational health platform. Shared employee and employment context can reduce duplication. Distinct workflows can still retain the records, permissions and outcomes appropriate to their purpose.

Choosing health surveillance software

The strongest buying question is not “Can this system create our questionnaire?” It is “Can this system reliably operate the programme around that questionnaire over years?”

Use a representative employee history in the evaluation. Include more than one surveillance requirement, a changed role, a positive response, a missed appointment, a revised form and a follow-up that remains open. Ask the supplier to show what the clinician, administrator, employer and auditor would each see. Then ask how the configuration can change without vendor development or damage to earlier records.

Occentra is being built as a modern occupational health platform around explicit concepts, configurable workflows and long-term operational records. Its current approach connects employees and employment context with Referrals, Cases, versioned Forms, Appointments, Tasks, outcomes and audit history. You can read more about Occentra's approach to health surveillance software.

Good software should make each assessment easier to complete. More importantly, it should preserve the programme's meaning after the people, forms and working arrangements have changed.

← Back to blog