CliniBooks Endoscopy Management System
CliniBooks EMS is an end to end reporting and management solution, developed with clinicians and compatible with NEDi2, The system schedules procedures, provides worklists for key users, tracks histology and surveillance cases, provides an electronic record in real time, saving valuable clinical time. Supports national reporting requirements.
Features
- Patient demographics - can integrate with other patient admininistration systems
- Electronic triage of referrals
- Integrated image capture
- Scheduling of appointments in line with Joint Advisory Group
- Nurse noting - completion of patient pathway
- Generation of JAG audits and NEDi2 compatible
- Surveillance - automatically bringing patients back for review
- Automated reporting configured to meet national requirements
- Dashboards - to track KPI's at a glance
- Suitable for large and small deployments
Benefits
- Tracking of histology - ensuring results are chased and actioned
- Electronic triage - allowing clinicians to assess on the move
- Surveillance patients - automated triage 6/52 before review date
- Automated letter and label production - saving admin time
- Cloud based system - supporting remote working where possible
- JAG requirement of NED met
- System fully auditable to individual, date and time improving safety
- Scheduling to point system - improves productivity and utilisation
- System can be configurable to individual client need
- Reports configured to meet commissioner and national requirements
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 6 3 3 8 5 2 0 5 3 9 6 3 2 6
Contact
RESPONSIVE HEALTHCARE SOLUTIONS LIMITED
Rose Bolton
Telephone: 07979771262
Email: rose@responsivehealth.co.uk
About your service
- Service categories
-
Application Development and Deployment
Application platforms
- Model driven application platforms
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
- Planned maintenance would normally be undertaken outside of normal working hours within the contract - agreed with the client.
- System requirements
-
- Supported web browsers include Chrome, Edge, Firefox and Safari
- Supported on Android (5.0+) mobile and tablet devices
- Supported on iOS (8.0+) mobile and tablet devices
- A PDF reader is required to open generated documents
User support
- Email or online ticketing support
- Yes
- Support response times
-
Technical and End user support - Monday to Friday 08:00 - 18:00 hours excluding public holidays in the UK. Weekend support can be offered at an enhanced cost.
Responsive Healthcare will use all reasonable endeavours to provide technical support services in accordance with the following service leves:
(a) Critical issue resolution time - 4 business hours
(b) Serious issue resolution time - 6 business hours
(c) Moderate issue resolution time - 1 business day
(d) Minor issue resolution time - 3 business days - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AAA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
The Service Provider will use all reasonable endeavours to provide technical support services in accordance with the following services levels:
(a) Critical issue resolution time – 4 business hours
(b) Serious issue resolution time – 6 business hours
(c) Moderate issue resolution time – 1 business day
(d) Minor issue resolution time – 3 business days
Dedicated account manager to each project - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Initially we will agree the scope of the system and will be keen to have a joint project team to guide deployement. We provide onsite training, online training and user documentation for all our systems. At deployment we offer floor walking on site for the first 1 or 2 days of deployment where appropriate. All our systems have a training module so staff have the opportunity to put any training into practice. With any major version update, we will populate the training module so that staff again have an opportunity to familiarise themselves with the new changes.
- Service documentation
- Yes
- Documentation formats
-
- Other
- Other documentation formats
- Word
- End-of-contract data extraction
- As part of our contract we commit to working with our clients to ensure appropriate data transfer can take place at the end of the contract.
- End-of-contract process
-
On termination or expiration of a contract RHS promptly purge and destroy all Customer Confidential Information, and Customer Data contained in the ASP Infrastructure and applications within 3 weeks and give a written undertaking through an officer of the Service Provider stating that this has occurred.
Should there be a requirement for data transfer the methodology would be discussed with the client. Depending on requirements there could be additional costs at £1000.00 per day - Documentation accessibility standard
- WCAG 2.2 AAA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Windows
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The mobile application offers the same level of functionality as the desktop service
- Service interface
- No
- User support accessibility
- WCAG 2.2 AAA
- API
- No
- Customisation available
- Yes
- Description of customisation
-
Workflows and forms are fully configurable to meet any specific requirements. If any changes to the standard configuration are needed, Responsive Healthcare consultants will work closely with you during the implementation of the system to define and input these changes.
Letters templates, dropdown lists and KPIs can be configured by the Systems Administrator. System administrator also has can provide access to users in their organisation
Scaling
- Independence of resources
-
With our cloud partner, Microsoft Azure, we are able to scale up to large volumes with ease so that user are unaffected when demand is high.
Responsive Healthcare Solutions technicians regularly monitor performance to identify any bottlenecks or issues that may affect performance.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Responsive Healthcare Solutions work closely with the client to obtain key performance metrics and ensure that the system can produce the routine reports that they require.
The system is designed to meet NEDi2 requirements.
Where there are national returns we produce reports in the format that the client requires so that client effort is more about checking accuracy rather than report configuration to meet national/local needs. The system produces DM01,DID, NED returns. - Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- Data can be exported into CSV/excel spreadsheet.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- HL7 messaging
- JSON
- XML
- FHIR
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- Excel
- HL7 messaging
- JSON
- XML
- FHIR
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
Responsive Healthcare Solutions will use reasonable endeavours to make the Services available 24 hours a day, seven days a week except for: planned maintenance and unscheduled maintenance performed outside Normal Business Hours, advance notice of which will only be given where reasonably practicable.
Through our cloud partner, Microsoft Azure, we are able to offer 99.95% up-time on our application services and 99.99% on our databases. All of our servers are geo-replicated across 2 data centres in the UK ensuring high availability.
If an incident occurs which cannot be handled using normal procedures, a major incident will be declared and the Business Continuity Policy will be used to provide a framework for a response to the incident. An incident report will also be filed once the immediate situation is brought under control. There are currently no refund arrangements in place. Loss of service availability will be assessed on a case by case basis depending on the cause, extent and impact of the loss of availability. A root cause analysis will be performed, and practical steps to prevent further future service disruption will be put in place as part of policy. - Approach to resilience
-
Databases will be hosted as an Azure SQL Server database.
Patient documents (such as referral letters, histology reports) will be stored on Azure Storage Blob.
Database backup files will be installed on a separate Azure Storage Blob.
Only the applications services listed above, and the Service Provider will have direct access to the database.
Endoscopy databases and patient documents will be stored as separate resources.
All data will be geo-replicated across the 2 UK datacentres.
All data will be AES256 encrypted at rest.
Each database will have maximum of 250GB of storage.
Each storage blob will have maximum of 250GB of storage.
Microsoft Azure SQL Server SLA Monthly Availability 99.9%
Microsoft Azure Blob Storage SLA Monthly Availability 99.9% - Outage reporting
- Responsive Healthcare Solutions utilises industry standard monitoring solutions which immediately alert our teams to a service outage. Contact with customers is made via telephone or email to agree contacts.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- All users are approved by the organisation/clients. Users must use organisation specific email. Role based system, agreed with client. Client responsible for removing/informing RHS re individuals as users.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
-
Annually complete Data Security Protection Toolkit for NHS Digital
Cyber Essentials - Information security policies and processes
-
Responsive Healthcare Solutions is a small organisation and any variance from our information security policies is very evident. The Technical Director approves access to systems within the company and individual access rights to the systems themselves.
Our overarching Information Policy includes policies on password management, individual system policies, introducing new systems, information governance and data protection, information risk management, monitoring access, information breaches, transmitting patient data, clear desk policy, mobile computing, disposal of equipment. This list is not exhaustive.
New staff which would include contractors would be taken through the overarching policy and its contents and asked to sign their understanding. Policies are updated every year as part of the DSP Toolkit and staff are made aware of any changes. Where there is a change outside of the annual review, policy changes are made. RHS has Cyber Essentials. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- All requests are logged via our support desk and issued with a unique reference number. This tracks the issue through to completion within the assigned team. Should the issue require software development effort, it is managed through our DevOps software. Servers and infrastructure are hardened in line with industry standard best practice. The environment and applications are tested for vulnerabilities, with any issues treated as faults and resolved appropriately.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Through our cloud partner, Microsoft Azure, our database are scanned and technicians are alerted to any issues on a weekly basis. RHS is immediately notified if data is accessed from an unknown location.
We annually perform penetration and security testing though an independent third-party. Results of the tests are resolved by making a development change or making configuration changes to the hosted platform. In either case, the fixes are made based on priority according to the nature of the software and hosting methods. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Potential compromises are identified immediately by our cloud partner, Microsoft Azure.
In the event of a breach or security incident which relates to the customer or the infrastructure, the customer would be informed typically via phone call or via email. Remediation/action takes place immediately and all security incidents are logged. - Incident management type
- Supplier-defined controls
- Incident management approach
- RHS does have systems and processes in place. Processes follow those set out by the Information Commissioner's Office. Depending on the severity of the incident, an individual would report to one of the directors. Incident would investigated. If the incident included data relating to a client (organisation using system) then the client would be informed. If the incident was serious then it could be reported to the ICO or through NHS reporting.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- We can provide access to a trial area on request. The trial area will have full functionality. Access to the trial area will be limited to 30 days and entering actual patient data into the trial area is strictly prohibited.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 10%
- Between £250,000 and £500,000
- 10%
- Between £500,001 and £1,000,000
- 10%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 5fde8c97-a01b-40b2-bee5-13b4f314dd5b
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
- Other security certifications
- Yes
- Any other security certifications
- Data Security Protection Toolkit NHS
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-