Integration & Interoperability - Calian Corolar
Calian Corolar is a next generation Cloud based integration platform that allows seamless communication and interoperability between diverse healthcare systems. Base don Corolar Cloud and with a range of additional modules and extensive API library. We provide customisation and API development services.
Features
- Integrate disparate systems
- Integrate ERP, EPR, Smart building and wider systems
- Suite of established APIs
- Fully hosted or on premise solutions
- Client specific development
- Internationally proven solution and functionality
- Supports industry standards
Benefits
- Increased efficiency
- Reduced Cost
- Reduced Risk
- Increased interoperability
- Accelerated deployment
- Compliant design, implementation & delivery
- Experienced specialist support
- Improved outcomes
- Sustained benefits realisation
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 1 8 1 2 6 1 6 1 9 3 0 7 4 6
Contact
ST VINCENT’S CONSULTING LTD
Kyle Dollan
Telephone: 07989415358
Email: frameworks@stvconsulting.uk
About the service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Education
- Public Order and Safety
- Police
- Defence
- Social Security Administration
- Adult Social Care
- Children's Social Care
- Other
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes
- What software services is the service an extension to
- An integration platform between client systems
- Cloud deployment model
- Public cloud
- Service constraints
- There are no constraints on the platform as an interoperailty platform,.
- System requirements
- Client must be able to present and receive valid data
User support
- Email or online ticketing support
- Yes
- Support response times
- 30 minutes to review and action teh ticket. Resolution timesales are dictated by teh nature of teh issue.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- We provide client support to meet the customers requirements and service levels they wish to consume. We provide a technical account manager to ensure clear communications and a first course of escalation if needed. Our standard service support is included in the annual fee. Additional costs will be determined by what level and availability they require
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- We follow the St Vincent Implementation methodology for implementations. This includes a Training Needs Analysis and development of use tailored roles based training for users. This can include both virtual and online training. We provide access to digital user documentation and FAQ
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- As an integration platform there is no customer data to extract. Clients receive a full schematic of the integration architecture and an access and activity audit report
- End-of-contract process
- The client has governance over all aspects of the platform and manage it's closure . Once closed we will erase the customer instance so as to be irrecoverable once the client has agreed that we are able to do so
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Chrome
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Inteface Management portal
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- Not applicable
- API
- Yes
- What users can and can't do using the API
-
There are multiple API available and user specific can be developed at additional cost.
There can be payload size limitations that may require a bespoke solution - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Clients can transform and amend integration messages and flows within there deployed platform. Clients can request tailored API for and we develop API to integrate with wider clinical and Smart Hospital solutions, transferring data, coding and key information between system.
Scaling
- Independence of resources
- Each customer has there own instance which is unique to them. The Microsoft Azure platform automatically scales up capacity and proccessing as needed to meet demand
Analytics
- Service usage metrics
- Yes
- Metrics types
-
This is a custom service available to our customers dependant upon the client requirements.
This is available at infrastructure and in built application reporting - Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Supplier type
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- Calian Corolar
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- In-house
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
-
As an integration platform we provide live transfer and translation of data between systems. We do do not typically retain data that nay need to be exported.
We export live data using APIs - Data export formats
- Other
- Other data export formats
- API
- Data import formats
- Other
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- These are client specific. A service failure is refunded through service credits
- Approach to resilience
- We can provide a wide range of resilience depending on client requirements. Available upon request
- Outage reporting
- Customers are advised by email alerts,. There is also a Public dashboard for our Azure environment
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Other
- Other user authentication
- If the client hosts this policy will be dependant on their approach
- Access restrictions in management interfaces and support channels
- Roless baszed access
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Other
- Description of management access authentication
- In client hosted environment we adopt the client policy
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- CSA CSM version 4.0
- ISO/IEC 27001
- Information security policies and processes
- We have established policies and processes that meet, and in many cases exceed, required regulatory and industry standards.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- All components and configurations are detailed and tracked through there lifetime. Any changes are subject to rigorous, review and testing, prior to deployment. Any proposed changes are tested to ensure there are no IG or security implications. This includes robust security testing where required and development of appropriate mitigations to address any potential risks.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
We use Calian's cyber security division and there specialist services and systems to asses potential threats. They provide certified services of this nature to national governments, public and health sector organisations and major international companies including NCSC in the UK.
Any patches are deployed quickly using our Agile development and deployment processes.
We source information and intelligence from commercial, internal and national cyber security partners - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
We adopt the Azure proactive monitoring approach where we are hosting the solution. We respond to potential compromise in accordance with our established policies and processes which are driven by the risk score that has been assessed. We respond as quickly as practicable, implementing interim solutions if a full solution requires development.
Where the solution is hosted by the client in they are responsible for protective monitoring and we support them in identification and response to potential compromises - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- We have pre-defined processes for common and uncommon events. Users can report incidents by email, within the platform or by phone. We provide incident reports to our customers and update these as any changes or patches are implemented
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
-
- Public Services Network (PSN)
- Other
- Other public sector networks
- No limitations
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber Essentials Certificate Number
- 6c91fbc8-b65b-4c9b-a965-e45be7c7aad6
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
- Other security certifications
- Yes
- Any other security certifications
- NHS - Data Security & Protection Toolkit (DSPT)
Social value
- Mission: Kick start economic growth
-
To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract