Medicilio RPM
Remote Patient Monitoring software — Clinician Manual
| Symbol | Particular | Value |
|---|---|---|
| Manufacturer | Manufacturer | Cantieri Digitali Medtech S.r.l., Corso di Porta Romana 6, 20122 Milano (IT), VAT/P.IVA IT11328810962 |
| Caution | Consult the Instructions for Use | This document |
| UDI | UDI-DI | [UDI-DI placeholder to be assigned before placing on market] |
| MD | Device category | Medical Device: Class IIa software (MDSW) |
| REF | Trade name | Medicilio RPM |
| Version | Software version | 1.0.0 |
| CE | CE mark | [CE-NUMBER placeholder] · Notified Body: [NB-NUMBER placeholder] |
| Date | Date of issue | 2026-09-07 |
| eIFU | Electronic IFU | Available at https://ifu.medicilio.it per Regulation (EU) 2021/2226 |
EU MDR 2017/745 · Class IIa Medical Device Software (MDSW)
Software version 1.0.0 · Date of issue 2026-09-07
Cantieri Digitali Medtech S.r.l. · Corso di Porta Romana 6, 20122 Milano (IT)
Medicilio RPM is a software medical device intended for the remote monitoring of patients enrolled in a clinician-prescribed care pathway. It collects measurements from compatible connected medical devices and from manual patient input, evaluates each measurement against clinician-set thresholds, raises alerts when thresholds are breached, and supports clinicians in producing AI-assisted telemonitoring reports that they must review and sign before any report is released to the patient.
Medicilio RPM is qualified as Medical Device Software (MDSW) per MDCG 2019-11 and is classified as Class IIa under EU Regulation 2017/745 (MDR).
This document is the Instructions for Use (IFU) for Medicilio RPM. It combines the regulatory IFU content required by Annex I §23 of the MDR with the operational depth required by the intended users to operate the device safely.
Medicilio RPM is delivered as two end-user applications that connect to the manufacturer's cloud back end:
| Component | Required platform | Notes |
|---|---|---|
| Clinician / operator web application | Modern evergreen web browser supporting current Chrome, Firefox, Edge or Safari (latest two major versions) | React 18 single-page application; minimum screen resolution 1280×800. |
| Patient application | Delivered preinstalled on a Medicilio-provided Lenovo Tab M11 tablet (or similar), locked by a Mobile Device Management (MDM) tool to run only the Medicilio application. See §6.2. | |
| Network : clinician web | Stable broadband (≥10 Mbps download / ≥2 Mbps upload), HTTPS to manufacturer cloud and to video provider | Required for video consultations |
| Network and patient mobile | Mobile data or Wi-Fi (≥5 Mbps recommended), HTTPS | Required to upload measurements and to receive notifications |
| Account | Personal account, provisioned by an authorised role | See §7 |
| Time | Device time set automatically via OS network time | Manual time skew may cause incorrect activity scheduling |
The "label" of a software medical device is the in-app device-identification screen, which carries the device identification per §23.2 and §23.4(a). In the clinician web application it is the account dropdown in the top bar, which states that Medicilio RPM is a medical device and shows the software version and the device UDI. The same dropdown carries a User Manual entry that opens the current electronic Instructions for Use.
The Medicilio cloud back end is hosted on Google Cloud in the EU region (Belgium, Frankfurt and Milan). All clinical data remains in the EU. See §14.2 for GDPR compliance and data controller/processor roles.
Cantieri Digitali Medtech S.r.l. Corso di Porta Romana 6 20122 Milano (MI), Italy VAT / P.IVA IT11328810962
| Channel | Contact |
|---|---|
| Support email | info@medicilio.it |
| Support telephone | +39 0238592673 |
| Support hours | Lun–Ven 8:00–20:00, Sab 9:00–13:00 Europe/Rome |
| In-app chat (Medicilio Customer Support) | "Supporto di Medicilio" channel inside the patient app and clinician web app. |
Feedback on these Instructions for Use, or on the device, may be sent to info@medicilio.it. Feedback is not a substitute for the serious-incident reporting procedure described in §18.
These Instructions for Use are delivered electronically as permitted by Regulation (EU) 2021/2226. A printed copy is available, at no charge, within 7 calendar days of a written request sent to the support email above.
The current electronic Instructions for Use can also be opened from inside the applications (see §1.3). Each link resolves to the edition matching the user type, in the language of the application.
The following symbols are used on the cover page and throughout this document, in accordance with ISO 15223-1:2021. Where a harmonised symbol does not apply, a description is provided in this section.
| Symbol | ISO 15223-1 reference | Meaning |
|---|---|---|
| Manufacturer | §5.1.1 | Identifies the manufacturer of the medical device |
| Date | §5.1.3 | 2025 |
| SN | §5.4.1 | Medicilio RPM v1.6 |
| Caution | §5.4.4 | Consult the Instructions for Use |
| eIFU | §5.4.3 | Electronic Instructions for Use indicator |
| MD | §5.7.10 | Identifies a medical device |
| UDI | §5.7.7 | Unique Device Identifier |
| Translated eIFU | §5.7.8 | Electronic Instructions for Use indicator in Italian |
| CE | (EU MDR) | The device complies with applicable EU regulations |
The IFU also uses four in-text callouts to draw attention to information of different criticality:
Information about a hazard that, if ignored, may lead to patient harm, clinically incorrect decisions, or device misuse.
Information whose disregard may degrade device performance or cause an avoidable workflow failure, without immediate patient harm.
Operational context that helps the user act correctly.
Optional guidance to use the device more effectively.
The following warnings apply to all users of the device.
Medicilio RPM is intended for the asynchronous remote monitoring of patients in stable clinical conditions. It is not intended for use in medical emergencies. Alerts and clinical alarms generated by the device are reviewed by clinical staff within the Medicilio RPM web application, not in real time. Medicilio puts at the service of Organisations a Service Center (non-clinical staff, see §5.3.3 and 5.3.4) that support in verifying measurements, training, adherence checks and device technical support. This triage is not real-time, and Service Center operators do not provide or suggest clinical advice to the patient. Confirmed true-positive breaches are escalated to the patient's responsible clinician. In case of a suspected medical emergency, the patient or the user must call the national emergency number (in Italy and EU: 112) and not rely on the device.
Medicilio RPM displays measurements, computes threshold breaches and drafts telemonitoring reports as decision support for qualified healthcare professionals. It does not replace clinical judgement. All clinical decisions, including modifications to therapy or escalation, must be made by a qualified clinician.
Using the device outside its intended use, environment, or user profile described in this section may invalidate the intended performance and may put the patient at risk.
Medicilio RPM : Remote Patient Monitoring software, software version 1.0.0.
Medicilio RPM is a medical device software platform intended for remote monitoring of adult patients by receiving, transmitting, storing, and presenting physiological parameter measurements from compatible connected devices and patient-reported data entered by the patient, to support healthcare professionals in clinical follow-up and chronic disease management.
Medicilio RPM includes an AI-assisted report generation function that produces draft summaries of patient data for review by a healthcare professional.
Medicilio RPM does not itself perform physiological measurements; physiological measurements are provided by the connected devices.
Medicilio RPM addresses two target client populations: (1) healthcare provider organisations (hospitals, clinics, independent practices) that prescribe and operate the pathway, and (2) patients assigned to a pathway.
Per the Intended Use and Use Specification, users fall into three categories: Clinical Users (§5.3.1, §5.3.2), and Lay Users (patients).
Within each client, the device has the following intended users.
"Who can perform this action:" lines later in this document name the roles allowed to perform each specific action, in accordance with the Medicilio permissions list.
| Field | Value |
|---|---|
| Type | Licensed qualified physician practising under Italian SSN / private practice rules |
| Age | Adult (≥18) |
| Training Required | Familiar with electronic clinical records; trained on Medicilio RPM
before first use Independent Practice Doctor: additionally trained on practice-level configuration Head of Department: additionally trained on departmental oversight, template management and threshold-template definition |
| Interface | Clinician / operator web application |
| Field | Value |
|---|---|
| Type | Licensed healthcare professional (nurse, healthcare assistant) supporting one or more clinicians |
| Age | Adult (≥18) |
| Training Required | Trained on Medicilio RPM clinical workflows; works under the supervision of a clinician |
| Interface | Clinician / operator web application |
This is an operational task, not a clinical one. Medicilio Customer Support verifies that a measurement was received and matches the reading the patient sees on their own device, with no clinical framing or interpretation of the data. Where escalation is needed, the operator routes the case to the clinical team; the clinical evaluation and any resulting decision are made solely by the treating clinician
Medicilio RPM is operated in two environments:
The device is not intended to be used in operating theatres, intensive care units, or in any environment where life-supporting decisions must be made in real time.
Adult patients (18 years of age and older) requiring remote monitoring as part of clinical follow-up or chronic disease management. Patients must be able to use the mobile application, or have a designated caregiver acting on their behalf, and must have been prescribed a remote-monitoring pathway by an authorised clinician.
Candidate clinical benefits:
Medicilio RPM is not a measuring device in itself: it records, evaluates and presents measurements taken by compatible connected medical devices listed in §6, each carrying its own CE marking and its own accuracy specification. The performance characteristics of Medicilio RPM are:
Bioimpedance-based body composition scales pass a low-intensity electrical current through the body to estimate body composition. This current may interfere with a cardiac pacemaker or other active implantable cardiac device. Patients with such a device must not be monitored using a bioimpedance scale under Telemonitoring Level 1. These patients require Telemonitoring Level 2, where body weight is measured with a non-bioimpedance scale. Confirm the patient's device history before assigning the pathway's weight-monitoring device.
Medicilio RPM is intended for the asynchronous remote monitoring of patients in stable clinical conditions. It must not be used for medical emergencies, real-time monitoring, ICU or perioperative monitoring, continuous in-person observation, or any clinical situation requiring an immediate response. In a suspected emergency, the patient or user must call the applicable emergency number (in Italy: 112) and must not rely on Medicilio, its alerts, chat, notifications, or messages.
Medicilio RPM is intended for adult patients. Do not use the device for patients outside the intended population, or for patients unable to understand or operate the patient-facing application, unless a designated caregiver is available and use has been assessed and authorized by the responsible healthcare organization.
Who can perform this action (associating devices to a pathway): Department Doctor, Independent Practice Doctor, Department Doctor Head, Medicilio Customer Support, Ops.
Medicilio RPM is used with a configured patient home kit. The devices included depend on the monitoring pathway prescribed to the patient.
Each device has its own Instructions for Use. The user must follow the device manufacturer's IFU for setup, positioning, cleaning, calibration, battery handling, warnings, contraindications, and maintenance.
| Category | Regulatory framework | Treatment in Medicilio RPM |
|---|---|---|
| EU MDR medical devices, predominantly Class IIa, with one Class I device (Omron VIVA) (§6.1.1) | Regulation (EU) 2017/745 (some devices under MDR Article 120 transition from MDD 93/42/EEC) | Measurements are ingested as clinical data and evaluated against per-pathway thresholds. |
| EU IVDD / IVDR in-vitro diagnostic device (§6.1.2) | Directive 98/79/EC (IVDD) / Regulation (EU) 2017/746 (IVDR) | Measurements are ingested by Medicilio RPM as clinical data and evaluated against per-pathway thresholds. |
| Non-medical wellness devices (§6.1.3) | Not regulated as medical devices | Some parameters (body weight, step count, heart rate) may be ingested by Medicilio RPM but are not equivalent to clinical-device measurements. See the warning in §6.1.3. |
For correct positioning, cleaning, calibration, battery handling, warnings and contraindications of each device, consult the IFU supplied by the device manufacturer. The Medicilio RPM Instructions for Use do not replace those documents.
Medicilio RPM connects to CE-marked medical devices, across the following categories:
Each device retains its own CE marking, accuracy specification, and manufacturer's Instructions for Use, which must be followed for setup, positioning, cleaning, calibration, battery handling, warnings, contraindications, and maintenance (see the IMPORTANT note below).
The current list of compatible devices is kept updated and is available to users upon request by contacting Medicilio support (see §2.2).
Each accessory has its own Instructions for Use.
Medicilio RPM may also ingest data from non-medical wellness devices in the following categories: smartwatches (step count, heart rate) and body-composition scales. These devices are not regulated as medical devices; their manufacturers explicitly declare this, and their accuracy claims (where present) are wellness-grade, not clinical-grade. The specific models currently in use are available upon request by contacting Medicilio support (see §2.2).
Medicilio RPM ingests body weight, step count and heart rate from non-medical wellness devices such as smartwatches and body-composition scales. The manufacturers of these devices have explicitly declared that they are not medical devices. Their accuracy claims, when present, are wellness-grade and do not satisfy the performance requirements of EU MDR Class IIa measurement. Clinicians must treat these readings as informative wellness data only. They must not be used as the sole basis for any clinical decision and must not be treated as equivalent to a measurement obtained with one of the Class IIa devices listed in §6.1.1.
The patient receives, as part of the home kit, a tablet on which the Medicilio patient application is preinstalled. The tablet is locked by a Mobile Device Management (MDM) tool so that only the Medicilio application can run on it; navigation outside the app, installation of other applications, and access to the operating system are not permitted.
| Field | Value |
|---|---|
| Brand and model | Lenovo Tab M11. |
| Processor | MediaTek Helio G88 Octa-core (2× Arm Cortex-A75 @ 2.0 GHz + 6× A55 @ 1.8 GHz); Arm Mali-G52 MC2 GPU |
| Memory | 4 GB or 8 GB LPDDR4x (soldered, not upgradable) |
| Storage | 64 GB or 128 GB eMMC 5.1; microSD card slot up to 1 TB (exFAT) |
| Operating system | Android 13 at delivery, with manufacturer-supported OS upgrades to Android 15 and security patches at least until January 2028 (per Lenovo PSREF) |
| Connectivity | Wi-Fi (WLAN model) or Wi-Fi + cellular nano-SIM (WWAN model); Bluetooth; USB-C 2.0 |
| SIM | SIM card with dedicated data plan, supplied in the home kit on WWAN variants. |
| Provided to | The patient, for the duration of the pathway only |
| Permitted use | Solely for the prescribed monitoring activities |
| End of pathway | The tablet must be returned to Medicilio together with the rest of the home kit. See §19.1. |
The tablet's management policy allows the screen to be locked at any time, so that it does not disturb the patient at night. The tablet cannot be switched off: it must stay powered so that scheduled activities, notifications and measurement upload continue to work.
The tablet is locked so that only the Medicilio application can run on it. Attempts to bypass this lock, install third-party applications, change network settings, or use the tablet for any purpose other than the prescribed monitoring may invalidate the intended performance and interrupt monitoring. Report any tablet fault to the Medicilio Customer Support (see §2.2) rather than attempting to repair it.
Medicilio RPM supports the following measurement types:
Ear-mode and forehead-mode readings are ingested and displayed identically. Readings taken in ambient mode measure the environment rather than the patient and are excluded.
Before the home kit is shipped, Medicilio Customer Support and Ops use an internal tool to bind the measurement devices to the pathway, connect the home gateway to the connectivity source configured for the kit, and arrange shipping. Clinicians have read-only access to this information from the pathway's Info tab; they do not configure the kit themselves.
Who can perform this action: Medicilio Customer Support, Ops.
The network card records which of two connectivity configurations the kit uses. In the Router configuration the SIM is in a Wi-Fi router, so measurements reach the platform while the tablet is switched off. In the Hotspot configuration the SIM is in the tablet, which serves the gateway, so connectivity depends on the tablet being on. The configuration type is visible to clinicians on the pathway's Info tab.
One gateway can serve more than one patient, provided every patient sharing it is registered at the same address. Attaching a gateway to a second pathway at a different address is rejected. Each patient sharing a gateway must have their own devices bound to their own pathway: a measurement is attributed by the device that produced it, not by the gateway that relayed it.
Where a gateway serves several patients at one address, a measurement that arrives without an identifiable source device is not assigned to one of them. It is withheld and flagged for operator review. Check the Devices card for each co-resident patient before activation.
Once the pathway is active, changing the gateway identifier, the tablet binding or the device serial-number assignments without following the documented replacement procedure will interrupt measurement ingestion and may trigger spurious alerts. If a device fails after activation, follow the device-replacement procedure below.
When a connected device is unavailable or has failed, the patient may enter a measurement manually in the app. See §9.7 for how manual entries appear to the clinician, and the warning "Verify device suitability" in §4.
Who can perform this action: Healthcare Professional, Department Doctor Head, Department Doctor, Independent Practice Doctor, Medicilio Customer Support, Ops.
Medicilio RPM uses passwordless authentication via one-time password (OTP) sent by email. There is no permanent password to remember.
Each Medicilio account is personal. Users must not share login credentials or one-time passwords. A pathway must not be activated for a patient other than the one identified in the patient record.
On first login, clinicians and medical staff are required to complete a one-time registration process before accessing the application.
If you do not receive the OTP within a few minutes, check the spam folder of your email account. Do not request multiple OTPs in rapid succession; only the latest one is valid.
Open the user menu and select Log out. The session is closed; subsequent navigation requires a new OTP.
Sessions expire automatically after a period of inactivity:
Closing the browser tab or the mobile app does not, by itself, terminate the session, explicit logout is required to terminate the session on demand.
| Step | Performed by |
|---|---|
| Create patient anagraphics, including emergency contacts | Department Doctor, Independent Practice Doctor, Department Doctor Head, Healthcare Professional, Medicilio Customer Support, Ops |
| Create care pathway (custom or from template), set thresholds | Department Doctor, Independent Practice Doctor, Department Doctor Head, Medicilio Customer Support, Ops |
| Configure pathway network (home gateway, tablet, SIM) | Ops |
| Identity verification of the patient by telephone | Medicilio Customer Support, Ops |
| Patient receives kit and activates pathway in the app | Patient (may be assisted by Medicilio Customer Support, Department Doctor, Department Doctor Head, Ops, Organization Admin) |
A pathway is created as a draft, prepared by the Medicilio Customer Support (payment, kit, network), shipped to the patient, then activated by the patient upon receipt. From there it remains active until it is paused (temporarily suspended) or moved to completed at the planned end, or canceled if interrupted early. The system shows the current status as a coloured badge on the pathway header and enforces invalid transitions on the server.
Who can perform this action: Department Doctor, Independent Practice Doctor, Department Doctor Head, Healthcare Professional, Medicilio Customer Support, Ops.
Who can perform this action: Department Doctor, Independent Practice Doctor, Department Doctor Head, Healthcare Professional, Medicilio Customer Support, Ops.
Patients are onboarded by the Medicilio Customer Support over the telephone and activate the device upon receipt of the home kit. The clinician or operator who creates the patient record is responsible for verifying the patient's identity (e.g. tax code, date of birth) before the pathway is activated.
The Email and the phone number must each be unique within the organisation. If you enter a value already registered, the form displays an inline error below the relevant field and blocks submission until it is resolved.
Who can create and edit named équipes: Department Doctor Head, Department Doctor, Independent Practice Doctor, Organization Admin, Medicilio Customer Support, Ops.
Who can add or remove members on a specific pathway: the Responsible Doctor, any member of that patient's équipe, the Department Doctor Head for any pathway in their department, Organization Admin, Medicilio Customer Support, Ops.
An équipe is a named, reusable group of healthcare professionals. A patient's care team is built from one or more équipes, from individually added professionals, or from any combination of the two. The patient is visible to every professional on that team.
Which patients a professional sees depends on their role.
A Healthcare Professional who is on neither a patient's équipe nor an individual assignment for that pathway sees nothing of that patient, alerts included. Confirm that every Healthcare Professional who needs a patient is on that patient's équipe.
An équipe determines which patients a professional sees. What a professional may do is governed by their platform role, as set out in the "Who can perform this action:" lines throughout this document.
For a Department Doctor Head the two rules differ. Every patient in the department is visible, and every pathway in the department opens in full. Clinical action on a pathway is reserved to the professionals who follow that patient.
A Department Doctor Head follows a patient as Responsible Doctor, through one of the patient's équipes, or through an individual assignment on that pathway. On those pathways they work without restriction.
Every other pathway in the department opens read-only. The Info, Details, Trends, History, Alert Threshold Protocol, Documents and Activity diary tabs are readable in full, and the controls that would change the pathway are not offered.
Read-only covers the whole care plan : alert resolution, threshold updates, patient and health information, network information, devices and shipping, pathway status, pause and cancellation, notes, document upload and report settings.
Two things fall outside that rule, in opposite directions.
The Alert tab of the Dashboard shows the alerts of the patients the Department Doctor Head follows as Responsible Doctor, through an équipe, or through an individual assignment. Alerts on the other patients of the department are shown to the professionals who follow those patients. A Department Doctor Head must not treat an empty alerts list as evidence that no patient in the department has an open alert. To take on the alerts of a colleague's patient, join that patient's équipe.
The Patient list shows a Department Doctor Head every patient in the department, and the Alert Threshold Protocol tab of every one of those pathways is readable. Departmental oversight of the thresholds in force is therefore available without joining an équipe.
Two things are reserved to the Responsible Doctor. Only they can sign that patient's telemonitoring report, and they cannot be removed from the pathway. Transferring clinical responsibility requires cancelling and recreating the pathway.
A professional added to an équipe gains access to the patient's complete clinical history, not only to data recorded after they joined.
Organization Admin, Medicilio Customer Support and Ops manage équipe membership without gaining clinical access to the patients concerned.
Once a professional is named on an appointment, they keep it even after being removed from the patient's équipe : the appointment stays assigned and fully manageable, video session included.
For a teleassistenza appointment, the Healthcare Professional offered is the pathway's équipe : its members and any professional added ad hoc to that pathway. Televisit, in-studio and at-home appointments are booked with the pathway's doctor only.
A Department Doctor sees the appointments assigned to them and the appointments of the patients they follow through an équipe. A Department Doctor Head sees, in addition, the appointments of their équipe patients outside the departments they head. A Healthcare Professional sees the appointments of the patients they follow through an équipe or an individual assignment.
An équipe may span departments. The platform derives and displays whether an équipe is single-department or multi-department from its members.
The Admin page lists the members of named équipes only. A professional added directly to a single pathway is not discoverable from this view. To review everyone with access to a patient, open that patient's pathway.
A named équipe can be assigned to many patients. Adding or removing a member from the Admin page propagates immediately to every pathway that équipe is linked to, granting or revoking visibility of all of those patients at once. Where a change is intended for one patient only, add or remove the professional from that patient's pathway instead of editing the équipe.
If a professional reaches the same patient through two équipes, removing them from one of the two does not withdraw the patient from their view: they retain it through the other. When visibility must be withdrawn completely, check every équipe linked to the patient.
Who can perform this action: Department Doctor Head, Department Doctor, Independent Practice Doctor, Medicilio Customer Support, Ops.
Pathways may be created from a pathway template and thresholds template or fully customised. The pathway carries: pathology, duration in months, responsible doctor, list of vital parameters with measurement frequency, a network configuration for the home kit (all mandatory),and a list of associated devices, plus, where applicable, a list of drug intakes, a list of questionnaires, a list of exams (with modality).
The pathway-creation is a four-step process.
Once a pathway is created, the vital parameters being monitored cannot be added to or removed from the pathway, only their measurement frequency can be adjusted afterwards. Review the parameter list carefully at creation time, since correcting an incomplete or incorrect list requires cancelling and recreating the pathway.
For each prescribed vital parameter, set the measurement frequency, the recommended time slot, and whether the timing is fixed or flexible:
| Timing | Behaviour |
|---|---|
| Fixed | The measurement can only be recorded while its prescribed slot is open. Once the slot closes the activity expires, no manual entry is possible, and it is recorded as not performed. Choose this where the time of day is clinically binding, for example a morning blood-pressure reading that must stay comparable across days. |
| Flexible | The measurement counts whenever the patient records it during the day, up to 23:59:59, by device or manually. There is no out-of-window state. The patient sees the recommended time as advice, not as a deadline. Choose this where the time of day carries no clinical meaning. |
Time slots are Morning 05:00–12:00, Afternoon 12:00–18:00 and Evening 18:00–24:00, and are shown with their time range everywhere they appear, on both the clinician web application and the patient application. The fixed or flexible choice can also be changed later, when editing the pathway.
Peak expiratory flow, where prescribed, is measured once or twice daily; for a twice-daily frequency, set the morning and the evening measurement time. It cannot be entered manually by the patient, so a missed reading cannot be recovered after the fact. Monitoring of a parameter can be paused and reactivated later from the pathway's Details tab: while it is paused the activity disappears from the patient app, the patient is notified, and no alert is generated for that parameter. Readings already recorded remain in the history.
Where the comparability of readings depends on the time at which they are taken, keep the measurement fixed. Review this setting for every parameter rather than accepting the template default.
Questionnaires carry no slot assignment: the patient can complete them at any point in the day, up to 23:59:59, and the completion time is recorded.
It is not mandatory to configure thresholds for every vital parameter. You can proceed with the pathway creation leaving some or all parameters without thresholds set. Parameters without a configured threshold will not generate alerts when breached : measurements are still collected and visible, but no yellow- or red-level alert is raised for that parameter until a threshold is set.
Before submitting the pathway, verify the patient's identity (tax code, date of birth, contact details) and the emergency-contact details (configured on the patient record, see §8.3). Errors in these fields propagate to alert routing.
After the pathway is submitted, the Medicilio Customer Support takes over the kit-preparation step (devices, network configuration, shipping) from the Info tab of the pathway (see §6.4). The pathway becomes visible to the patient on the tablet only after the kit is shipped and the patient activates the pathway (see §9.10).
Who can perform this action: Healthcare Professional, Department Doctor Head, Department Doctor, Independent Practice Doctor.
The Info tab is the default view when opening a pathway. The header shows the patient's name, age and gender, the assigned doctor (with organization and specialisation), a phone-call shortcut, the date/time of the last measurement received, and the date/time of the last gateway connection (shown as "Data not available" if the gateway has never connected).
The tab is organised into the following cards:
Department Doctor Head, Department Doctor, and Independent Practice Doctor can pause or cancel the pathway directly from the Pathway Status card. A confirmation modal always appears before pausing or cancelling, to prevent accidental actions.
The doctor and the patient receive an email when the pathway is paused (including when this happens automatically after repeated payment failures).
Reactivation is an operational action performed only by Medicilio Customer Support or Ops. If a paused patient needs to resume monitoring, contact the Medicilio Customer Support (see §2.2). If the pathway was paused manually, the subscription start date realigns to the reactivation date; if it was paused automatically due to repeated payment failures, the original renewal dates remain unchanged.
Medicilio Customer Support and Ops can cancel a pathway from any status : To be paid, Kit to be shipped, Kit shipped or Active. The pathway moves straight to Cancelled, and none of the intermediate status emails is sent to the patient.
The doctor and the patient receive an email when the pathway is cancelled. The wording depends on where the pathway was cancelled from: a pathway cancelled from Active gets the end-of-monitoring email, written for a patient who has actually used the service; a pathway cancelled from any earlier status gets a shorter, generic cancellation notice instead.
Side-effects summary:
Cancelling a pathway is irreversible. Use pause if the interruption is temporary.
The doctor and the patient receive an email when the pathway reaches its planned end.
Who can view this tab: Healthcare Professional, Department Doctor Head, Department Doctor, Independent Practice Doctor.
The Details tab shows the configuration of the care pathway, organised into cards:
Pathway Info: pathway name, duration, start/end date, pathology, goal (free text), assigned doctor and organization.
Parameters to Monitor (mandatory): the vital parameters prescribed in the pathway, each with its monitoring frequency. The list of parameters itself is fixed at pathway creation and cannot be edited afterwards, only the frequency of each already-listed parameter can be changed.
Medications (optional): prescribed drug intakes, each with name, dosage, frequency, and instructions.
Questionnaires (optional): prescribed questionnaires, each with frequency and indicative start date where relevant.
Recommended Exams (optional): recommended exams, each with frequency/modality.
Who can view this tab: Healthcare Professional, Department Doctor Head, Department Doctor, Independent Practice Doctor.
Medicilio RPM calculates a compliance score for each pathway, measuring how consistently the patient completes prescribed activities (measurements, drug intakes, questionnaires).
In the Pathways list:
A column labelled "Compliance" shows the overall compliance percentage for each pathway, as a coloured pill:
An arrow next to the pill shows the 7-day trend (improving / stable / declining). Click the column header to sort by compliance, highest or lowest first.
At the bottom of the Trends tab, a compliance chart shows how consistently the patient is following the prescribed care plan, with four independently toggleable lines:
The Y-axis is fixed between 0% and 100%. Hover over any date to see a tooltip with the values of the currently visible lines. If the patient has not yet completed any activities, a placeholder message is shown instead of an empty chart.
Compliance = completed activities ÷ prescribed activities, calculated from the patient's first confirmed activity. Days when the pathway was paused, or days with no prescribed activities, are excluded from the calculation. Scores are recalculated daily (and immediately after certain events, such as a pathway status change); they are not real-time. Compliance charts are also included in the AI-generated telemonitoring report, under the "Terapia e Aderenza" section (see §12). Compliance scores are visible to all clinical and operational roles.
Who can perform this action: Healthcare Professional, Department Doctor Head, Department Doctor, Independent Practice Doctor.
The Appuntamenti tab, inside a patient's pathway, shows that patient's appointments only (televisit, teleassistenza, in-studio, and at-home visits). From here you can also schedule a new appointment for this patient directly, without going through the global Appointments page, the patient is pre-selected, so the booking flow starts from selecting the service.
For the full appointment scheduling, joining, updating, and cancellation procedures, see §11. The same procedures apply whether you start from this tab or from the global Appuntamenti page.
Who can perform this action: Healthcare Professional, Department Doctor Head, Department Doctor, Independent Practice Doctor.
Unlike Appuntamenti, there is no separate global Documents page, the Documents tab inside a patient's pathway is the only place to access this patient's documents. It contains four sub-tabs: Reports, signed teleassistenza reports, Questionnaire Responses, and Shared Documents.
For telemonitoring reports see §12. For signed teleassistenza reports see §11.5, "Write and sign a teleassistenza report".
The Questionnaire Responses sub-tab lists completed questionnaires, with columns: Name, Description, Type, Questions, Date, and Action. Only answered questionnaires appear, past unanswered and future scheduled questionnaires are not shown. Use the search (by name) or filters (type, date) to narrow the list. Click View to open a questionnaire's responses as a PDF. If no questionnaires have been answered yet, an empty-state message is shown.
The Shared Documents sub-tab lists contain all the files shared for this pathway: uploaded by clinical staff, by the patient or shared via chat. Each row shows: Name, Owner, Origin (Shared by Patient / Shared by Physician / Chat), Upload Date, and Patient Access status. Documents can be searched by name or owner, and filtered by origin, date, and patient-access status.
| Constraint | Value |
|---|---|
| Maximum file size | 20 MB |
| Maximum batch size | 5 files |
| Allowed MIME types | PDF, JPEG, PNG |
| Download URL validity | 1 hour |
| QR-upload session validity | 30 minutes |
Who can perform this action: Healthcare Professional, Department Doctor Head, Department Doctor, Independent Practice Doctor, Medicilio Customer Support, Ops.
Who can perform this action: Healthcare Professional, Department Doctor Head, Department Doctor, Independent Practice Doctor, Medicilio Customer Support, Ops.
When a connected device is unavailable or has failed, the patient may enter a measurement manually in the app. Manual entries are stored with an explicit "manual" data-source tag and are distinguishable from device-sourced measurements in this view. See the warning "Verify device suitability" in §4 : manual entries are not equivalent to a verified measurement from a compatible medical device.
A device reading is shown plainly regardless of whether it falls inside or outside the prescribed window; a manual entry carries a hand icon. The out-of-window indicator marks a device reading stored in a slot other than the one prescribed, and the prescribed activity itself stays not performed. The not-prescribed indicator marks a device reading taken on a day with no activity scheduled for that parameter. Hovering either indicator shows the expected timing against the actual recording time. Both indicators describe the timing of a reading, never its clinical value.
The plausibility limits below are the outer boundary of what is physiologically possible, not a statement of clinical normality. They are applied platform-wide, independently of the per-pathway alert thresholds in §9.8.
| Parameter | Accepted range |
|---|---|
| Blood pressure : systolic | 40–250 mmHg |
| Blood pressure : diastolic | 20–180 mmHg |
| Oxygen saturation (SpO₂) | ≥ 70% |
| Heart rate | 20–280 bpm |
| Body temperature | 34–43 °C |
| Body weight | 20–180 kg |
| Peak expiratory flow | 30–900 L/min |
A reading is stored but flagged as erroneous, and hidden from both the clinician and the patient, when the measuring device signals an internal error or an unusable signal, when the value falls outside physiologically plausible limits, or when it carries a timestamp earlier than the activation of the pathway. A flagged reading does not appear in this table, in trends, or in reports, and raises no alert; the patient is notified and prompted to repeat the measurement. A parameter can therefore show a gap on a day when the patient did attempt a measurement. Where a gap matters clinically, confirm with the patient.
When a patient answers that a measurement was taken by another person, the reading is excluded from this history table, from trends, and from telemonitoring reports, for readings taken with a device and for values entered manually alike. This is separate from the "Not the patient" alert-resolution reason described in §10.4, which is a clinician action on an alert.
Where drug intakes are prescribed, the Measurements table also carries a medication-adherence column. Each prescribed intake resolves to one of four states, shown identically in the dashboard, in the patient history and in the care-plan history:
| State | Meaning |
|---|---|
| Taken on time | The patient declared the dose taken while its prescribed slot was open. |
| Taken outside the window | The patient declared the dose taken after its slot had closed, and attributed it to the window in which it was actually taken. Both the prescribed and the actual window are shown. |
| Not taken | The patient declared the dose not taken, and gave one or more reasons. |
| Not recorded | No declaration was made before the day closed at 23:59:59. |
An out-of-window intake is recorded from the patient's own statement of when the dose was taken, and it cannot be amended once confirmed. Where the exact time of an intake is clinically material, confirm it with the patient.
Who can update per-pathway thresholds: Department Doctor Head, Department Doctor, Independent Practice Doctor.
Thresholds are stored per pathway in the alert service, not per template. Each parameter can carry up to two threshold levels, yellow and red, each with one of four threshold types: high, low, weight variation percentage (computed over 1-day, 3-day and 7-day windows), and boolean (presence/absence, e.g. AFib flag on ECG).
Each parameter is presented as a card carrying the parameter name, an information icon giving the recommended clinical range and an explanation of how that parameter's thresholds work, a colour-coded scale bar, and the editable threshold fields. Each field shows its comparator (≤ or ≥) on the left and its unit on the right, and the standard adult normal range appears between the fields as non-editable reference text.
The scale bar follows the direction in which the parameter can breach: blood pressure and heart rate are bidirectional, oxygen saturation and peak expiratory flow breach on the low side, body temperature and weight variation on the high side. The bar is informational: it does not affect how alerts are evaluated.
The ECG card is titled Atrial fibrillation. It carries a single red-level toggle, labelled "Present" when enabled, with no threshold fields and no yellow level.
Entering a value outside the recommended clinical range for a parameter highlights the field and shows a warning naming the range that was exceeded. The warning does not block saving.
| Parameter | Recommended range | Warning shown when |
|---|---|---|
| Blood pressure : systolic | 90–160 mmHg | The value falls outside this range |
| Blood pressure : diastolic | 60–100 mmHg | The value falls outside this range |
| Heart rate | 50–140 bpm | The value falls outside this range |
| Oxygen saturation (SpO₂) | ≥ 88% | The value is set below 88% |
| Body temperature | 35.8–40 °C | The value falls outside this range |
| Weight variation | 2–3% | The value falls outside this range |
The ranges above are advisory: Medicilio RPM warns but saves the configuration you enter. A threshold set far outside the recommended range can prevent a genuine deterioration from ever raising an alert. Confirm that any deviation is clinically intended before saving, and record the reason in the patient's clinical record.
Saving is blocked in one case only: when the yellow and red levels of a parameter are ordered inconsistently, for example a red maximum lower than the yellow maximum, because the resulting alert logic would be incoherent. An inline validation message is shown on the field until the ordering is corrected.
Peak expiratory flow is not evaluated against a fixed value but against the patient's own recent readings. An alert is raised on a progressive drop across two or more consecutive measurements within the last seven days, or on a reading markedly below the seven-day rolling median. A manoeuvre with a forced expiratory time below three seconds is technically invalid: no value is produced and the patient is asked to repeat the measurement.
A change to a per-pathway threshold takes effect on the next incoming measurement. The previous threshold is not preserved as a historical clinical decision in the user interface. If retention of the previous threshold is clinically required, document the change in the patient's clinical record outside the device.
Who can manage pathway notes: Healthcare Professional, Department Doctor Head, Department Doctor, Independent Practice Doctor, Medicilio Customer Support, Ops.
The Activity Diary tab shows both manually added notes and the history of resolved alerts (with resolution reason and status) in a single chronological view, see §10.5 for the alert-resolution history detail.
The note is timestamped with the author and is visible to all clinical-workflow roles assigned to the pathway.
From the Activity diary tab, click the three dots next to the note. Choose Edit note to amend the content, or Delete to remove the note.
After a pathway is submitted, the Medicilio Customer Support and Ops team handle kit preparation on the pathway's Info tab: binding the measurement devices, configuring the home gateway and tablet, and arranging shipping. Clinicians have read-only visibility into this information (see §6.4) but do not perform these steps themselves.
The pathway status progresses automatically through this process: once payment is confirmed, it moves to Kit to be shipped; once the kit is physically shipped and configured, Medicilio Customer Support/Ops advance it to Kit shipped.
The pathway can be activated in two ways:
In both cases, once the status is Active the care plan monitoring begins and the patient's data starts being collected.
Who can perform this action: Patient (the patient activates upon kit receipt). The action may also be performed on behalf of the patient by Department Doctor, Department Doctor Head, Independent Practice Doctor, Medicilio Customer Support, Ops, Organization Admin.
The Medicilio Customer Support calls the patient at kit delivery to walk through the first measurement. The responsible doctor receives an email when the patient completes their first measurement, indicating when the next telemonitoring report is expected. If a patient reports difficulties beyond the in-app tutorial, escalate to the prescribing clinician.
Who can manage pathway templates and threshold templates: Department Doctor Head, Independent Practice Doctor (for own practice), Medicilio Customer Support, Ops.
Edits to a template do not retro-apply to pathways that were already created from that template. To update an active pathway, edit the pathway directly (see §9.1 and §9.8).
This section explains alert meaning, alert lifecycle, and the user responses required by role.
Two alert levels are defined.
| Level | Meaning | Automatic escalation |
|---|---|---|
| yellow | Threshold breached; under clinical review threshold not in critical band | No automatic escalation. Recorded and shown to clinicians for review at the next interaction. |
| red | Threshold breached in a critical band as defined per pathway | Automatic notification to patient, Medicilio Customer Support and emergency contacts, with timed escalation. |
Only red-level breaches trigger automatic notification to the patient, the Medicilio Customer Support and caregivers in a pre-defined escalation path in order to verify the measurement. Yellow-level breaches are recorded and shown in the clinician interface for review but do not trigger automatic measurement confirmation flows or any alert notification to the patient or the Medicilio Customer Support. Clinicians and Healthcare Professionals must actively review the alerts list to inspect yellow-level breaches. If clinical review of yellow-level breaches is critical to the patient, the prescribing clinician must define the appropriate red thresholds at pathway level.
In the clinician interface every red-level alert is shown as either pending (open, awaiting clinical action) or resolved (closed). Internal escalation states (re-measurement requested, escalation to emergency contacts) happen automatically in the background per §10.7 and are not surfaced as separate user states.
Measurements are uploaded over the patient's mobile data or Wi-Fi connection. If the network is unavailable, the measurement remains on the local device until connectivity is restored, and threshold evaluation and any consequent alerts are delayed accordingly. Users must not assume the absence of an alert means the patient is well, particularly if the patient reports feeling unwell or other clinical concerns are present.
| Action | Roles allowed |
|---|---|
| View the alerts list (pending, resolved) | Healthcare Professional, Department Doctor Head, Department Doctor, Independent Practice Doctor, Medicilio Customer Support, Ops |
| Resolve an alert | Healthcare Professional, Department Doctor Head, Department Doctor, Independent Practice Doctor, Medicilio Customer Support |
The roles above act on the alerts of the patients they see under §8.4. For a Department Doctor Head those are the patients followed as Responsible Doctor, through an équipe, or through an individual assignment, and not the whole department.
Do not rely on automatic notifications alone. Once a red-level alert becomes visible in your Alerts view, review it and act promptly : the platform does not track or enforce a response deadline on your side.
Select multiple alerts using the checkboxes in the alerts list, then use the Resolve selected action to resolve them together (e.g. several pending alerts for the same patient after one clinical action). The resolution reason and the optional chat message are applied to all selected alerts.
When an alert is resolved manually, document the clinical reasoning in the patient's pathway notes, using the Alert note category in the Activity diary (see §9.9). The alert audit trail records the status change but not the rationale.
Resolving an alert with the reason "Device error", "Patient error" or "Not the patient" marks the underlying measurement as not attributable to the patient. From that point the measurement is excluded from the measurements dashboard, from trends, from the history table, from telemonitoring reports, and from the baseline used to evaluate subsequent alerts for that parameter. A weight baseline, for example, is recomputed from the remaining valid readings. The alert itself remains visible in the Activity diary with its resolution reason. Every other resolution reason leaves the measurement in place. Choose the reason deliberately: it changes the clinical record, not only the alert status.
Doctors receive a daily email summarising unresolved alerts, reports pending signature, and the day's scheduled appointments. This digest is a convenience aid : it does not replace actively checking the Alerts view (see the warning above).
The emergency contacts used by the alert service are those recorded in the patient record (see §8.3). The alert recipient binding is created automatically when a pathway transitions to active, and removed when the pathway is cancelled or completed. To inspect or update the binding:
When a red-level alert is triggered, the Medicilio Customer Support and the emergency contact are notified automatically. Notification delays are platform-wide constants and apply uniformly to every red-level alert across all organisations and pathways.
Who can create, update or cancel appointments: Healthcare Professional, Department Doctor Head, Department Doctor, Independent Practice Doctor, Medicilio Customer Support, Ops, Tech (per permissions list). Who can perform at-home appointment dispatch: Medicilio Customer Support, Ops.
| Status | Meaning |
|---|---|
| Not scheduled | Activity exists in the pathway but no concrete slot yet |
| To be scheduled | A slot must be assigned |
| Scheduled | Slot assigned and confirmed |
| Completed | Appointment has taken place |
| Cancelled | Appointment cancelled by an authorised user |
Durations: 30, 45 or 60 minutes.
Two appointment types require a video session:
A patient's appointments (televisit, teleassistance, at-home, and in-studio) are also listed, in the Appointments tab of their pathway : useful when reviewing a specific patient's schedule without going through the global Appuntamenti page.
Video sessions are conducted through the integrated telemedicine module. No clinical data is transmitted to the video provider. Televisit and teleassistance sessions follow the same underlying video technology, but differ in who can join: only the assigned Department Doctor can join a televisit, while either the assigned Department Doctor or Healthcare Professional can join a teleassistance.
A live camera preview is shown. Click Connect to enter the session.
If you close the session after the patient has joined, the appointment is marked completed. If the patient never joined, it is marked not conducted, and the appointment must be rescheduled. If either participant loses connection, they can rejoin within the same waiting-room flow as long as the appointment is still within its scheduled window; if the professional does not return within 10 minutes, or both participants remain disconnected for more than 10 minutes, the session ends automatically.
After a teleassistenza session is completed (with both participants having joined), the assigned professional can optionally write a clinical report from the appointment or from Appointments→ Past. Televisits do not have a report-writing flow.
If the video or audio quality is insufficient to perform the clinical consultation, reschedule the appointment. Do not make a clinical decision based on degraded audiovisual material.
The global Appointments page (sidebar) lists and manages all appointments across patients, with three tabs: Scheduled, To be scheduled, and Past. The Appointments tab inside a patient's pathway shows that patient's appointments only.
Appointments added while creating or editing a care pathway do not have a confirmed date/time yet : they appear in the To be scheduled tab with an indicative date. Use the Manage action there to assign a real date, time, and (if requested) professional. If left unscheduled for more than 7 days past the indicative date, the status changes to Not Scheduled, but the appointment is not deleted.
Who can perform this action: Healthcare Professional, Department Doctor Head, Department Doctor, Independent Practice Doctor, Medicilio Customer Support, Ops.
Only teleassistance requests submitted by the patient can be deleted, and only while they have not yet been accepted by the Medicilio Customer Support. Once the request has been taken in charge, it can no longer be deleted or modified. Appointments scheduled by a clinician cannot be cancelled from the patient app.
Who can perform this action: the Department Doctor or Healthcare Professional assigned to the completed teleassistenza (report writing is available only for teleassistenza, not for televisit : see §11.4)
The system does not automatically verify geographic coverage for at-home appointments, and no specific clinician is assigned in-app.
Telemonitoring reports can be configured at frequencies: weekly, biweekly, monthly, quarterly, final, or custom.
Each report goes through three stages:
| Status | Meaning |
|---|---|
| Generating | The AI component is drafting the report. Not visible to the patient. |
| To review | The AI draft is ready. A clinician must review, edit if necessary, and electronically sign the report. Not visible to the patient. |
| Sent | The clinician has signed the report. The patient can now view it. |
Once signed, the report records the signature timestamp and tracks whether the patient has opened it. The report is created through a three-step process: configure settings → review and edit the AI draft → review the final PDF and sign.
The report creation screen shows the report as a list of editable sections (one card per section). Only sections relevant to the patient's pathway are included : for example, if the patient has no prescribed medications, the Medication section does not appear. Categories that are not part of the care plan are omitted rather than described as missing data. Where drug intakes or questionnaires are prescribed, the "Terapia e Aderenza" section carries the patient's compliance chart for the report period (see §9.4). Where peak expiratory flow is prescribed, a dedicated section carries its trend chart.
If you proceed from step 2 without having modified any section, Medicilio RPM asks you to confirm that you have reviewed the report and verified its content against the patient's clinical data. The confirmation checkbox is not pre-selected and the flow does not advance until it is ticked. Ticking the box is a clinical declaration: do not confirm a report you have not read in full against the source data.
All reports for a patient, signed and unsigned, are listed together in the pathway's Reports tab (see §12.4, "Download a report"). The list shows each report's name, creation date, period, status, and owner (the clinician who created/signed it). Reports in Sent status can be downloaded; reports in To review status can be opened for review and signature with the Review action, which opens the section editor directly at step 2 rather than restarting the generation flow.
Telemonitoring reports include AI-drafted content and may contain errors or inaccuracies. The report is generated automatically and is not visible to the patient until a qualified clinician has reviewed the content, edited it as necessary, verified all clinical information, and applied an electronic signature. The signature certifies the report as a clinical document under the clinician's responsibility, content in Generating or To review status must never be shown, communicated, or sent to the patient in any form.
Who can generate a telemonitoring report: Department Doctor Head, Department Doctor, Independent Practice Doctor, Medicilio Customer Support, Ops.
Who can review and edit the AI draft of the Pathway Report: Department Doctor Head, Department Doctor, Independent Practice Doctor.
Who can sign a telemonitoring report: Department Doctor Head, Department Doctor, Independent Practice Doctor.
Who can submit feedback on a generated report: Department Doctor Head, Department Doctor, Independent Practice Doctor.
For a Department Doctor Head every report action applies to the patients they follow, per §8.4. The Reports section of any other pathway in the department is empty.
A report is a clinical document only after the clinician has signed it. Content in Generating or To review status must never be shown, communicated, or sent to the patient in any form.
While reviewing a report (see §12.2), the clinician can mark individual sections of the AI draft as good or in need of improvement.
The feedback is stored against the report version and is used by Medicilio to monitor and improve AI quality.
Who can perform this action: Healthcare Professional, Department Doctor Head, Department Doctor, Independent Practice Doctor, Medicilio Customer Support, Ops.
A report can only be deleted while it is in To review status, before it has been signed and sent. Once a report has been signed and sent, it can no longer be deleted and remains permanently available to the patient in their app.
Your organization may have default report settings (frequency, sections, preferences) configured centrally. Settings changed here apply only to this patient's pathway and override the organization default; they do not affect other patients.
Who can update the telemonitoring report settings: Department Doctor Head, Department Doctor, Independent Practice Doctor, Medicilio Customer Support, Medicilio Sales Team, Ops.
Reports produced after a televisit or teleassistance appointment are stored separately as Appointment Report, signed electronically, and are visible to the patient only after signature.
Who can perform this action: Organization Admin.
An Analytics entry appears in the main navigation for Organization Admins, and is the page shown on login. It reports the organisation's activity in aggregate across every department and doctor. No other role can reach the page, and it contains no individual patient data.
The page opens on the last 30 days. Other presets and a custom date range are available, and the selected period drives every widget on the page at once. It reports:
Each figure is shown against the equivalent immediately preceding period. Where the organisation has no history covering that baseline, the comparison is suppressed rather than presented as growth.
The page is recalculated once a day and covers data through the end of the previous day, so it lags the patient and pathway lists and the two will not always agree. Never use Analytics to assess an individual patient's clinical situation, and never treat an aggregate figure as evidence about a specific patient. Use the Alerts, Pathways and patient views for every clinical decision.
Two chat channels exist in the patient app.
| Channel | Purpose | Allowed participants |
|---|---|---|
| Supporto di Medicilio | Non-clinical operational support (Medicilio Customer Support) | Patient, Medicilio Customer Support, Ops |
| Supporto Medico Dottore | Clinical communication channel with the assigned clinical team | Patient, Department Doctor, Independent Practice Doctor, Department Doctor Head, Healthcare Professional |
Patients and healthcare professionals must distinguish clinical communications from administrative messages, automated notifications, and non-clinical support communications. Administrative, automated, or support-channel communications must not be interpreted as individualized clinical advice unless clearly identified as such by the responsible healthcare professional. Clinically relevant exchanges in chat must be summarized in the patient's clinical record according to the healthcare organization's procedure.
Where clinical information is exchanged in the Supporto Medico Dottore channel, the clinician must summarise any clinically relevant exchange in the patient's pathway notes; chat messages are a communication channel, not a clinical record.
Medicilio RPM is hosted on Google Cloud Platform in the EU region (Belgium, Frankfurt and Milan). All clinical data and personal data are stored in the EU. Databases and their backups are held in the regions named above. Object storage, which holds archived application logs, uses Google Cloud EU multi-region storage and may therefore hold data in any European Union member state.
Personal data is processed in accordance with Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree 196/2003 as amended. The Data Controller is the healthcare provider organisation that prescribes the pathway; Cantieri Digitali Medtech S.r.l. acts as Data Processor.
Medicilio's information-security controls follow the principles of confidentiality, integrity and availability appropriate to a Class IIa MDSW under MDR §23.4(ab) and MDCG 2019-16. This Instructions for Use does not cite specific information-security management standards; the underlying organisational controls are documented in Medicilio's internal Quality Management System.
If you suspect that an unauthorised person has access to your Medicilio account or to the email inbox associated with it:
Medicilio RPM is delivered as cloud software (back end) and as two client applications (web and mobile). The release cadence is approximately one release every three months; security and hotfix releases may be issued more often. User-notification mechanism for updates is TBD
Patient and pathway data are backed up by the manufacturer as part of the cloud back-end operation. Users do not need to perform local backups.
See §15.2.
The table below covers the most common user-facing failure modes.
| Symptom | Likely cause | Action |
|---|---|---|
| OTP email never arrives | Email filtered as spam, or wrong email | Check spam folder; ensure the address matches the one on file; contact support |
| Measurement does not appear in the app | Connectivity loss; gateway off; device battery low | Restore network; charge the device |
| Video session does not start | Browser permissions for camera/microphone denied; firewall blocks Whereby | Grant browser permissions; check the network; restart the browser |
| Patient cannot delete a document | Healthcare professional has already reviewed it | This is intended behaviour. Patient must contact the clinical team. |
| A parameter shows a gap on a day the patient says they measured | The reading was flagged as erroneous by the device or by the plausibility check and is therefore hidden (see §9.7) | Ask the patient to repeat the measurement; if gaps recur on the same device, report it to support |
| Patient reports the app is showing a technical-issue card | Gateway disconnected, router without signal, or tablet battery below 10% | The patient can follow the guided steps in the app; if verification fails, the service centre is alerted and contacts the patient |
Any serious incident that occurs in relation to Medicilio RPM must be reported to:
A "serious incident" is defined in Article 2(65) of MDR 2017/745 as an incident that, directly or indirectly, led, might have led or might lead to: the death of a patient, user or other person; the serious deterioration of a person's state of health; or a serious public-health threat.
Reporting a serious incident is mandatory under the MDR. The reporter (clinician, Medicilio Customer Support operator, or patient) should preserve any screenshots, message threads, or device logs that may help reconstruct the incident.
When a pathway reaches its planned end, it is marked as Completed. If it needs to be ended early, it is marked as Cancelled. In both cases, any future scheduled activities are removed and the associated devices are released from the patient's record.
At the end of the pathway, the patient must return the entire home kit, including the MDM-locked tablet (see §6.2), the home gateway, the SIM card, and all measurement devices, to Medicilio using the return instructions provided by the Medicilio Customer Support. The tablet remains locked to the Medicilio application and must not be retained for personal use.
Who can delete a patient record: Department Doctor Head, Independent Practice Doctor, Medicilio Customer Support, Ops.
When a patient record is deleted, the following sequence is applied:
Once a patient is deleted, the personal data are not visible or recoverable through the Medicilio RPM user interface. Restoration from the sealed audit store is performed only by Medicilio data-protection staff and only in response to a documented data-subject or regulatory request. Confirm the patient's identity and the deletion intent before proceeding.
Clinical data linked to a pathway are retained for 10 years from the end of the pathway, in accordance with the applicable Italian SSN rules on healthcare records and with the GDPR principle of storage limitation. At the expiry of the retention period, retained clinical data are deleted or further anonymised so that they can no longer be attributed to an identified or identifiable patient.
The 10-year retention period applies to clinical data associated with the pathway. Operational records, billing records, and vigilance-related records may be subject to different statutory retention obligations under Italian law.
| Term | Definition |
|---|---|
| Pathway | A clinician-prescribed care plan combining vital-parameter measurements, drug intakes, questionnaires and appointments over a defined duration. |
| Activity | A discrete scheduled action within a pathway (measurement, drug intake, questionnaire). |
| Medicilio Customer Support | The internal Medicilio support team, operationally distinct from any external Medicilio Customer Support project. Includes the roles Medicilio Customer Support and Ops. |
| Threshold | The numeric or boolean limit configured per pathway against which incoming measurements are evaluated. |
| Alert | A record created when a threshold is breached; carries a level (yellow or red) and a status. |
| AlertNotification | The record that drives Medicilio Customer Support and emergency-contact notifications for red-level breaches. |
| Telemonitoring report | A clinical document drafted by the AI component and reviewed, edited and signed by the clinician before release to the patient. |
| AppointmentReport | The signed report produced after a televisit or teleassistance. |
| Home kit | The set of devices delivered to the patient (gateway, tablet, one or more measurement devices, SIM). |
| MDR | Regulation (EU) 2017/745 on medical devices. |
| MDSW | Medical Device Software (MDCG 2019-11 qualification). |
| SSN | Servizio Sanitario Nazionale : the Italian national health service. |
| UDI-DI | Unique Device Identifier : Device Identifier. |
| eIFU | Electronic Instructions for Use (Regulation (EU) 2021/2226). |
| Medicilio Customer Support (chat channel) | The non-clinical "Supporto di Medicilio" channel. |
| Whereby | The third-party video provider used for televisits and teleassistance. |
| Équipe | A named, reusable group of healthcare professionals. The équipes and individual professionals assigned to a patient determine which professionals can see that patient. See §8.4. |
| Responsible Doctor | The clinician who owns a pathway. The only user who can sign that patient's telemonitoring report, and the only member of the care team who cannot be removed from it. |
| Compliance score | The percentage of prescribed activities the patient has completed, computed from the first confirmed activity and excluding paused days and days with no prescribed activity. See §9.4. |
| Fixed / flexible measurement | A per-measurement property set by the clinician. A fixed measurement can only be recorded inside its prescribed time slot; a flexible one counts at any point in the day. See §9.1. |
| Time slot | Morning 05:00–12:00, Afternoon 12:00–18:00, or Evening 18:00–24:00. Activity logging for a day closes at 23:59:59. |
| PEF | Peak expiratory flow, in litres per minute. See §6.3. |
| Version | Date | Author | Summary of changes |
|---|---|---|---|
| 1.0.0 | 2026-09-07 | Cantieri Digitali Medtech S.r.l. | Initial issue. |