CLAI
CLAI is a comprehensive ambient scribe platform built for NHS workflows. Our clinical user base can generate letters, summaries and clinical notes directly from audio recordings, automatically extract a range of clinical codes and create follow up orders – all bi-directionally
integrated into EPR via a truly frictionless workflow automation.
Features
- Near real time text transcripts of consultation audio recordings
- AI powered automated letter and note creation
- AI powered clinical code discovery
- AI powered follow up diagnostic order discovery
- Comprehensive bi-directional EPR integration
- Oracle Millennium (Cerner) MPage development and support
- Full RBAC support with EPR driven audit logging
- Endlessly customisable letter templates
- Session continuity across devices and encounters
- Comprehensive reporting and analytics
Benefits
- Generate clinic letters in seconds
- Automatically determine follow up diagnostic orders
- Discover SNOMED CT, ICD10, OPCS and RTT codes automatically
- Publish platform output in real time to EPR
- Save up to 6 minutes per acute outpatient consultation
- Manage your service delivery via real time reporting
- Launch directly from EPR without separate credentials
- Full user management and EPR drive audit logging
- Start on mobile and switch to desktop
- Manage multiple patient encounters in parallel
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 1 4 6 3 8 2 7 9 0 5 1 1 8 5
Contact
MAYDEN HOUSE LIMITED
Tom Scott
Telephone: 01249 701100
Email: tenders@mayden.co.uk
About your service
- Service categories
-
Application Development and Deployment
AI platforms
AI software services
- Conversational AI Software Services
- Generative AI Software Services
- Document AI Software Services
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
-
For a complete service, CLAI requires a supported EPR platform, please contact us for a complete list of supported EPRs as we are adding support for new clinical systems on an ongoing basis.
CLAI offers a functional and well featured stand alone service, albeit some functionality is limited. - System requirements
-
- Supported web browser (all modern browser platforms supported)
- Internet connection
- On device microphone (desktop, laptop, tablet, smartphone)
- Direct connection to TIE or EPR
User support
- Email or online ticketing support
- Yes
- Support response times
-
All queries registered via support log will be responded to within 2 days (excluding bank holidays and weekends).
Requests relating to system unavailability will be assessed with an appropriate “Priority Type” assigned. The “Priority Type” matrix, with target day time response, is between 1 hour for high priority and 8 hours for low priority.
Support hours are between 9:00 - 17:00 Monday to Friday, with phone lines operated between 08:00 - 18:00 Monday to Friday.
Critical incidents (P1) are responded to on a 24/7/365 basis. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- No
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Customers have access to a comprehensive single tier support team as well as being assigned a dedicated account manager.
Users log their issue via our provided ticketing system and can track, update and sign-off and rate the service received. Updates to support log items are automatically sent to the user and your designated CLAI account manager via email. This provides full and efficient transparency of all support requests logged.
Support hours are between 9:00 - 17:00 Monday to Friday, with phone lines operated between 08:00 - 18:00 Monday to Friday. The first point of contact is the reception or account management teams.
Critical (P1) outages are managed on a 24/7 basis with out of hours support available.
Response times to requests vary depending on the nature of the request. However, all queries will receive an initial response within 2 working days. Requests relating to system unavailability will be responded to within 1 and 8 hours depending on the level of urgency. More information may be found in our service level agreement (SLA). - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
We have developed effective and efficient processes to ensure integration, configuration and service mobilisation runs smoothly.
CLAI co-creates a Project Initiation Document (PID) with the service, outlining the configuration, phases, actions, owners and intended weeks of completion. A dedicated project manager will
support each customer with their transition to CLAI. During the configuration phase, we work through a rehearsed process to ensure the system is set up to meet the customer’s requirements.
Customers are provided with a “demo/training” environment where configuration of the system starts in a safe environment – usually the customers mock or test EPR environment. Only once both the data and site have been accepted by the sign-off authority in writing will the product be
deployed.
Full system training is provided, including dedicated reports and super user training. CLAI operates on a ‘train the trainer’ model. Each service is assigned a dedicated account manager to offer additional help and guidance. This support is available from the start, and throughout, the duration of the contract. - Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
-
- .doc
- .docx
- End-of-contract data extraction
-
The CLAI platform does not persist patient data. PII is held securely only until an encounter is concluded and submitted to EPR.
The majority of user access and audit log data is held within EPR.
Anonymised platform use data and reports will be transferred to the customer during the offboarding process. CLAI will securely store this data for up to one year post contract termination, to allow ample time for data transfer to be actioned. - End-of-contract process
-
The customer is the Data Controller, and we will always act on their instructions. At the end of the contract we will discuss with you what you would like us to do with the data we store. We will arrange for a system closure date and data transfer date.
Logs and anonymised use data is made available as CSV files.
The CLAI platform does not persist patient data. PII is held securely only until an encounter is concluded and submitted to EPR. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Our onboarding and offboarding documentation is accessible in a number of different formats and we will work with all service users to provide the format required. We are actively working towards WCAG 2.1 AA and ensure that where possible current documents are aligned with this standard.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- There are no differences in platform functionality between device types.
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- CLAI is a cloud based ambient scribe platform. Its user interface is web based and all features are accessed through a supported internet browser.
- Accessibility standards
- None or don’t know
- Description of accessibility
- We are committed to making our ambient scribe platform accessible to as many users as we can, including people with disabilities. Our software aims for clear, simple workflows. We follow recognized accessibility standards focused on WCAG 2.1 AA and continuously test and improve usability across devices and environments. Accessibility is built into our product development process, from design through to deployment. If you encounter barriers or have suggestions, we welcome your feedback and will work to provide timely, reasonable accommodations, and commit to transparency and ongoing improvement.
- Accessibility testing
- We do not currently test with users who use assistive technology, but plan to support requests for assistive technology platforms in the future, should our clinical user base require this.
- API
- Yes
- What users can and can't do using the API
-
The CLAI platform includes a comprehensive integration engine that utilises a range of technologies (including industry standard API’s) to enable seamless and bi-directional communication with host EPR platforms. Alongside more legacy standards like HL7 2.x, we also
support a full range of HL7 FHIR R4 API commands.
Our API layer is managed by the CLAI development team and is not publicly available or directly available to customers. We work in collaboration with our customer’s IT teams to ensure seamless and stable EPR connectivity. - API documentation
- Yes
- API documentation formats
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
CLAI supports multiple customisation options. Users have a high degree of control across the three main content output areas:
- Documents: CLAI supports an endless degree of letter and note types, users can either choose from our library of existing templates, or use a custom interface to create their own, bespoke, template. Multiple templates can be created per user. Additionally,
for those organisations who wish to enforce standardisation, templates can be created and enforced at sub-specialty, specialty, department or organisation level.
- Coding: CLAI offers full support to customise clinical code extraction. Confidence sliders can be set to vary the quantity and associated confidence rating of suggest codes. Code types can be included or excluded with ease.
- Orders: CLAI matches its platform to your orders catalogue, ensuring only supported and relevant orders are suggested. Within this envelope, a high degree of customisation is possible, allowing orders to be filtered based on multiple criteria and by sub-specialty,
specialty, or department.
Scaling
- Independence of resources
-
CLAI delivers validated, real-time performance tailored for acute clinical environments, ensuring Zero-Lag interaction. CLAI provides its service at scale with high responsiveness.
Architecture, Initiation and Latency: We utilise a decoupled, cloud-native architecture. Crucially, we do not use fragile WebSockets; audio is buffered locally and submitted via resilient API calls, ensuring stability even on potentially intermittent hospital Wi-Fi.
Load Testing: The system maintained 100% persistence and zero dropped connections, with CPU usage managed via Azure App Service Auto scale.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
CLAI contains built-in dashboards and a reporting suite that can be used to monitor service usage metrics. The reporting suite produces standard reports and enables users to apply filters and split the data by a range of parameters to generate custom reports. Our reporting capability is constantly evolving in line with customer demand – key platform performance items include correction rate, word error rate and reported issues / hallucination rate. Additionally, service
managers can monitor clinical usage, outstanding but not completed encounters, encounter completion rate and many other metrics. - Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Data Erasure
Data importing and exporting
- Data export approach
-
CLAI provides a real time, on demand set of dashboards that support data extraction as CSV or PDF files.
Raw usage data not held in EPR (for example platform usage data) is available on request and can normally be provided within 24 hours. - Data export formats
-
- CSV
- Other
- Other data export formats
- Data import formats
-
- CSV
- Other
- Other data import formats
- Other SQL database formats
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
Our service level agreement (SLA) is available on request. CLAI has a target uptime of 99.7%, any incident is recorded along with the impact and duration.
All calls escalated by customers are assessed and prioritised from High to Low, with response times ranging between 1 to 8 hours. Fix time targets are between 4 hours to 4 days, depending on the nature of the problem. Complete system unavailability is automatically treated as a high priority with a target maximum fix time of 4 hours. Most issues are resolved in minutes.
We take a proactive approach to customer satisfaction. Quarterly contract review meetings are held with customers, providing an opportunity to review system performance and response(s) to support logs. Example KPI’s covered in the quarterly review include:
● Overall system availability
● System availability by feature
● System response times
● Time to first response for support logs
● Customer satisfaction on each log
● Logs raised by subject area to help identify area for support and training - Approach to resilience
-
CLAI delivers validated, real-time performance tailored for acute clinical environments, ensuring Zero-Lag interaction. CLAI provides its service at scale with high responsiveness.
We provide an "Always-On" service architecture designed for mission-critical healthcare use.
* Availability: We have a proven ≥99.7% uptime (SLA) over the last 12 months. Critical services (Database, API) utilise Zone-Redundant Storage (ZRS), synchronously replicating data across physically separated availability zones to ensure zero data loss (RPO = 0).
* Disaster Recovery (DR): In a catastrophic regional outage, automated health probes trigger traffic re-routing to our secondary region. Validated failover tests confirm a Recovery Time Objective (RTO) of just 43 seconds (App Service warm-up time), significantly outperforming the ≤5-minute requirement.
* Non-Disruptive Updates: We utilise Blue/Green deployment slots. New versions are deployed and health-checked in parallel before traffic is instantly swapped, resulting in zero downtime for users during updates.
CLAI's architecture is designed to deliver a continuous uninterrupted service to users.
Detailed system architecture specifications are available on request. - Outage reporting
-
We have a live status page for our applications that users can access at any time.
Communication is also shared directly to a key contact nominated by each customer. This is sent via email from either the CLAI product owners and/or each customer's dedicated account manager. Users may also contact us for status updates via our phone line.
Following any outages, CLAI will produce a Root Cause Analysis report. This report contains further details, including the mitigations put in place to prevent further outages.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Limited access network (for example PSN)
- Other
- Other user authentication
- Users are authenticated via the host EPR platform (typically NHS SmartCard) – a secure and time limited session key is then created to allow access to the CLAI application.
- Access restrictions in management interfaces and support channels
- We restrict access to production systems by job role and on a “need to know basis” within the company. For example, developer teams do not have access to the same number of systems, or to the same level, as the systems team.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
-
○ Cyber Essentials
○ Cyber Essentials Plus
○ Data Security and Protection Toolkit - Standards Exceeded - Information security policies and processes
-
We are accredited to ISO27001 and have policies and controls in place in order to manage risks and threats across all projects.
To ensure compliance with ISO27001 and the NHS Data Security and Protection Toolkit, we have a full Information Security Management System in place. This consists of 36 policies that all staff have to comply with.
These policies include: Information Security Policy, Risk Management, Internal Audit Plan, Business Continuity, Clear Desk and Screen, Email Security, Laptop and Portable Device Security, Physical Access to Information Systems, Confidentiality Code of Practice, Personal
Information Handling, Network and Router Security, Document and Record Control, Record Retention and Disposal, IT & Software, Development Change Management & Control, Principles for Secure System Engineering, Software Update and Patch Policy and Server Network and Malware Management.
Staff complete monthly and annual security training via knowb4. Policies are reviewed annually and staff have to review and confirm they have read them. This, along with the policies, are audited for compliance by our information security officer who is a qualified lead auditor. The information security officer reports to the information governance lead who is also the managing director. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Services components are tracked via GitHub and Azure pipelines, managing the lifecycle from development to 'OneDeploy' production. We utilise a multi-instance architecture, allowing traffic rerouting to secondary instances during upgrades to ensure zero-downtime releases. Changes undergo automated load testing and cross-platform compatibility checks on target NHS devices. Security impacts are assessed against ISO27001 standards, while clinical risks are evaluated through 'clinic session simulations' to guarantee performance and data integrity before deployment.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
We conduct internal vulnerability assessments to assess the risk we expose our environment to. This is backed by Common Vulnerabilities and Exposures (CVE) and The National Vulnerability Database (NVD) security bulletins. These bulletins are delivered to us daily. We have tooling for
real time monitoring of our infrastructure.
Internal processes facilitate the triage and patching process within 48 hours of a vulnerability being identified. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
We utilise Azure Monitor and Traffic Manager for continuous, real-time protective monitoring. Automated health probes validate integrity every 60 seconds.
If a compromise or anomaly is detected (e.g. an instance fails a health check), our architecture automatically isolates the affected instance, takes it offline, and provisions a clean instance immediately.
We supplement this with NCSC Early Warning alerts. In the event of a verified breach, our 'Submit & Wipe' policy ensures no patient data is retained on the infrastructure, limiting exposure while our security team manages containment. - Incident management type
- Supplier-defined controls
- Incident management approach
-
All incidents are added to our internal CRM System and communicated to the customer as appropriate. The customer is regularly updated with the proposed corrective and preventive actions.
In accordance with CLAI’s Service Level agreement (SLA), incidents involving system unavailability are reported to the customer, within 1 and 8 hours depending on the severity. Incidents are reviewed at quarterly IG group meetings to ensure that corrective and preventive
action is implemented. This includes identifying possible trends and ensuring root cause analysis has been undertaken effectively. Incidents are monitored by the information security and assurance leads. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- CLAI offers a FOC enterprise-wide trial of our platform to NHS acute trusts. This trial is limited to 1500 consultants over a two month period, post an implementation phase.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 2.5%
- Over £5,000,001
- 5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- The British Standards Institute
- ISO/IEC 27001 accreditation date
- Wednesday 24 July 2024
- What the ISO/IEC 27001 doesn’t cover
- All departments within Mayden are included in the scope of certification. Individual product lines designed by Mayden are not included within the scope of certification.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 23378551-78ab-441d-bd3b-22999a89b8e1
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- F9be227d-f73f-4495-a1a5-b24fcbfb3b30
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
-