Skip to main content

Help us improve the Digital Marketplace - send your feedback

QUALITY COMPLIANCE SYSTEMS LTD

QCS Care Management Software (formerly Carebeans)

QCS Care Management Software is an NHS assured supplier,in line with the DSCR Capability Assessment and Standards Assurance Process. Streamlines careplans,compliance and communication,ensuring efficient operations and improved client outcomes. With real-time updates, secure data handling, and user-friendly tools,QCS Care Management empowers teams to deliver personalized,high-quality care while reducing administrative burden.

Features

  • Real-time digital care plans accessible on any connected device.
  • Automated scheduling for staff shifts and client appointments with alerts.
  • Secure cloud-based storage for compliance and data protection standards.
  • Integrated medication management with reminders and dosage tracking tools.
  • Customizable templates for assessments, reports, and care documentation.
  • Mobile-friendly interface for carers to update records on-the-go
  • Role-based access control for enhanced security and accountability.
  • Instant messaging and notifications for team communication and updates.
  • Comprehensive audit trails for regulatory compliance and transparency.
  • Analytics dashboard for performance monitoring and operational insights.

Benefits

  • Improves care quality through accurate, up-to-date client information access.
  • Reduces administrative workload, freeing staff for more client interaction.
  • Enhances compliance with automated documentation and audit-ready records.
  • Minimizes medication errors via integrated tracking and timely reminders.
  • Boosts efficiency by streamlining scheduling and reducing missed appointments.
  • Strengthens data security with encrypted cloud storage and controlled access.
  • Facilitates better communication among teams for coordinated care delivery.
  • Provides actionable insights for informed decision-making and resource allocation.
  • Supports scalability for growing care organizations without added complexity.
  • Increases client satisfaction through personalized, consistent, and reliable care.

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at laura@carebeans.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

6 2 2 6 3 0 1 5 6 6 5 6 7 1 8

Contact

QUALITY COMPLIANCE SYSTEMS LTD Laura Young
Telephone: 0333 405 3333
Email: laura@carebeans.co.uk

About your service

Service categories

Application Development and Deployment

Data management

Database administration and development

  • Database Administration
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
No
System requirements
  • Modern web browser – Chrome or Edge,
  • Reliable internet connection with minimum 5 Mbps download speed recommended.
  • Device running Windows 10 or macOS 11 or newer versions.
  • Minimum 4 GB RAM for smooth application performance and responsiveness.
  • Processor equivalent to Intel i3 or higher for optimal speed.
  • Screen resolution of 1280x720 or greater for proper interface display.
  • Secure network environment with HTTPS enabled for data protection compliance.
  • Latest version of Chrome, Edge, or Safari for compatibility assurance.
  • Enabled cookies and JavaScript for session management and interactive features.
  • Access to email for notifications, password resets, and system alerts.

User support

Email or online ticketing support
Yes
Support response times
Response within 24 hours from initial support query
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
Yes
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
WCAG 2.2 AA
Web chat accessibility testing
QCS has conducted accessibility testing on the integrated web chat feature to ensure it meets the needs of users relying on assistive technologies. Testing focused on compatibility with screen readers such as JAWS, NVDA, and VoiceOver, verifying that all chat content, buttons, and notifications are properly announced using ARIA roles and semantic HTML. Keyboard-only navigation was rigorously checked to confirm that users can access all chat functions without a mouse, maintaining logical tab order and visible focus indicators. Color contrast ratios were validated against WCAG 2.1 standards to support low-vision users, while zoom and magnification tests ensured the interface scales without distortion. Speech-to-text and text-to-speech functionality was tested for voice control users, alongside alternative input devices like adaptive keyboards and switch controls. Error messages and status updates were reviewed for clarity and accessibility, ensuring they are screen-reader friendly. Real-world usability sessions with assistive technology users provided critical feedback, helping refine the chat experience for inclusivity and compliance. These measures guarantee that our web chat is fully accessible, enabling seamless communication for all users regardless of ability.
Onsite support
Yes, at extra cost
Support levels
We provide 24/7 assistance, guaranteed response SLAs, and proactive system monitoring. Includes dedicated Technical Support.
Support available to third parties
No
AI chatbot
Yes

Onboarding and offboarding

Getting started
QCS CMS is designed to make onboarding simple and effective for care providers. We offer multiple support options to ensure users can start using the platform confidently. Our onboarding process begins with comprehensive user documentation, including step-by-step guides, FAQs, and video tutorials accessible online. These resources cover everything from setting up user accounts to creating care plans and managing schedules.
For organizations requiring hands-on assistance, QCS Care Management provides online training sessions via live webinars or recorded modules, allowing staff to learn at their own pace. These sessions include practical demonstrations and Q&A opportunities to address specific needs.
Additionally, on-site training can be arranged for larger teams or organizations with complex workflows. Our trainers work directly with staff to configure the system, customize templates, and ensure compliance requirements are met.
Examples of support include guided setup for care plans, role-based permissions, and integration with payroll or rostering systems. For ongoing help, our support team offers email and live chat assistance, ensuring users have expert guidance whenever needed.
This multi-channel approach guarantees that every customer can start using QCS Care Management quickly and effectively, tailored to their preferred learning style.
Service documentation
Yes
Documentation formats
  • PDF
  • Other
Other documentation formats
  • Knowledge Base Centre
  • Videos
  • Interactive tutorials
  • API documentation
  • Compliance and security manuals
End-of-contract data extraction
QCS CMS ensures customers retain full control of their data at the end of a contract. Users can extract all service data through multiple secure methods. The platform provides export functionality within the administration dashboard, allowing authorized users to download care plans, client records, schedules, and compliance reports in standard formats such as CSV, Excel, or PDF. For organizations requiring bulk or automated transfers, the QCS Care Management API supports structured data export using RESTful endpoints, ensuring smooth migration to other systems.
Before termination, QCS Care Management offers guidance and optional support to assist with data extraction, including step-by-step documentation and dedicated help from our technical team. All exports comply with GDPR and data protection standards, ensuring security during transfer.
Limitations: Certain system-level configurations and proprietary analytics dashboards cannot be exported, but all core operational and compliance data remains accessible. Data extraction must be completed before account deactivation, as access is removed after termination.
This approach guarantees transparency and continuity, enabling organizations to retain essential records and maintain compliance even after leaving the QCS Care Management platform.
End-of-contract process
QCS CMS follows the DSCR Data Migration Standard. We deliver a Data Migration Service to safely transfer all required records to the target solution, including service‑user data, documents, images, tasks, appointments, and complete audit trails, in human‑readable form and against agreed SLAs. Providers receive a Documented Data Extract (DDE) and migration approach aligned to DSCR onboarding/assurance expectations.
Data content and structure meet the DSCR Minimum Operational Data Standard (MODS) so the exported dataset is consistent and interoperable across adult social care systems. We also follow CQC guidance on digital records to maintain safety, integrity, and secure sharing during transitions.
In parallel, we honour UK GDPR data portability: on request, personal data is provided in structured, commonly used, machine‑readable formats (e.g., CSV/JSON/XML) and transmitted via secure methods within statutory timescales.
Included in price: DSCR‑compliant export of core operational records and audit trails; secure portal access during the migration window; standard support communications.
Additional cost (optional): bespoke transformation/mapping to non‑DSCR schemas, complex third‑party integrations, extended on‑site support, and TAM/CSE-led project management beyond baseline SLAs.
After the window closes, user access is removed and backups are retained/purged per records‑management and retention codes applicable to adult social care.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Chrome
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
QCS CMS offers a consistent experience across mobile and desktop, but each platform is optimized for its environment. Desktop services provide full functionality with advanced reporting, analytics dashboards, and bulk data management, ideal for office-based staff. Mobile services focus on convenience for carers on-the-go, enabling quick access to care plans, real-time updates, and secure messaging. The mobile interface is streamlined for speed and simplicity, supporting offline access for areas with poor connectivity. While both platforms maintain compliance and security standards, desktop excels in administrative tasks, and mobile ensures flexibility and responsiveness in the field.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
The QCS CMS service interface is a secure, cloud-based platform designed for simplicity and efficiency. It features a clean, intuitive dashboard that provides real-time access to care plans, schedules, and compliance alerts. Role-based navigation ensures users see only relevant tools, while responsive design adapts seamlessly to desktop and mobile devices. Integrated communication tools, quick-action menus, and customizable templates streamline daily tasks. Accessibility is a priority, with compatibility for screen readers, voice control, and keyboard-only navigation. Built with encrypted connections and multi-factor authentication, the interface combines usability with robust security, empowering care teams to deliver high-quality, compliant care effortlessly.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
QCS CMS has undergone extensive accessibility testing to ensure its interface is fully inclusive for users relying on assistive technologies. Our quality compliance team validated compatibility with leading screen readers such as JAWS, NVDA, and VoiceOver, ensuring all menus, alerts, and interactive elements are announced correctly using ARIA roles and semantic HTML. Keyboard-only navigation was rigorously tested to confirm logical tab order, visible focus indicators, and complete functionality without a mouse. Voice control tools were assessed for hands-free operation, supporting users with motor impairments.
The interface was reviewed against WCAG 2.2 standards for color contrast, scalable text, and alternative text for icons and images. Zoom and magnification features were tested to maintain layout integrity for low-vision users. Additionally, speech-to-text and text-to-speech capabilities were evaluated for seamless integration with assistive software.
Real-world usability sessions with individuals using adaptive keyboards, switch controls, and other assistive devices provided critical feedback, helping refine workflows and improve accessibility. These measures ensure QCS Care Management delivers a secure, intuitive, and compliant experience for all users, regardless of ability, reinforcing our commitment to inclusivity and regulatory compliance.
API
Yes
What users can and can't do using the API
The QCS CMS API enables secure integration with external systems for streamlined data exchange. Through the API, users can retrieve and update care plans, schedules, and client records, as well as manage staff profiles and compliance data. Users can be set up via API by creating accounts with assigned roles and permissions, ensuring access aligns with organizational policies. Authentication uses secure tokens, and all requests follow RESTful standards over HTTPS.
Users can make changes such as updating client details, modifying schedules, and submitting care notes programmatically. However, certain actions—like deleting core compliance records or altering audit trails—are restricted to maintain regulatory integrity. Bulk data imports and exports are supported, but require predefined formats for validation.
Limitations include role-based restrictions, meaning administrative functions (e.g., creating new organizations or changing system-wide settings) cannot be performed via API. Additionally, API rate limits apply to prevent system overload, and some advanced analytics features remain accessible only through the main interface.
These measures ensure flexibility while safeguarding security and compliance, allowing organizations to integrate QCS Care Management into their workflows without compromising data integrity.
API documentation
Yes
API documentation formats
Open API (also known as Swagger)
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
QCS CMS can be customized to meet the unique needs of care providers, offering flexibility without compromising compliance or security. Customization options include configuring care plan templates, scheduling rules, reporting formats, and user roles to align with organizational workflows. Customers can also tailor notifications, permissions, and dashboard views for different staff levels, ensuring relevant information is easily accessible.
Customization is performed through the platform’s administration settings or via the QCS Care Management API for advanced integrations. Authorized administrators or technical teams can implement changes, while Care Beans support specialists are available for guidance and complex configurations.
What can be customized? Care documentation templates, shift patterns, compliance alerts, and data export formats. Additionally, branding elements such as logos and color schemes can be applied for a personalized experience.
Limitations: Core compliance features, audit trails, and regulatory data structures cannot be altered to maintain legal standards. System-wide architecture changes and removal of mandatory fields are restricted.
This approach ensures organizations can adapt QCS Care Management to their processes while preserving security, reliability, and regulatory integrity.

Scaling

Independence of resources
QCS CMS ensures users aren’t impacted by others’ demand through multi-tenant isolation and resource fairness. Each tenant’s data and operations are logically separated, preventing interference. The platform uses auto-scaling to add capacity during spikes, and rate limiting to stop any single user from monopolizing resources. Resource quotas and throttling policies maintain balanced performance across all accounts. Continuous monitoring detects anomalies early, while QoS policies and SLAs guarantee uptime and responsiveness. By combining isolation, elasticity, and proactive controls, Care Management delivers consistent service quality even under variable workloads. This approach prevents the “noisy neighbour” problem common in shared SaaS environments.

Analytics

Service usage metrics
Yes
Metrics types
QCS CMS provides detailed service user metrics to help care providers monitor quality and compliance. Metrics include care plan completion rates, visit punctuality, and task performance, ensuring care delivery aligns with agreed standards. The platform tracks medication administration accuracy, incident reports, and alert responses for safety oversight. Wellbeing indicators, such as mood observations and health notes, support holistic care monitoring. Metrics are accessible via real-time dashboards, exportable reports (CSV, PDF), and API endpoints for integration with external systems. These insights enable providers to improve outcomes, allocate resources effectively, and maintain regulatory compliance.
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Staff screening not performed
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least every 6 months
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with another standard
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
QCS CMS provides secure, self-service data export options for customers. Administrators can download all core records—such as care plans, client details, schedules, and compliance logs—directly from the platform via the Export Tool in the admin dashboard. Data is available in standard formats like CSV, Excel, or PDF for easy migration. For bulk or automated transfers, the QCS Care Management API supports structured exports using RESTful endpoints. All exports comply with GDPR and DSCR standards, ensuring security and interoperability. Users must complete data extraction before account deactivation, after which backups are securely purged according to retention policies.
Data export formats
  • CSV
  • Other
Other data export formats
  • PDF
  • Excel
Data import formats
  • CSV
  • Other
Other data import formats
  • XML
  • Text
  • Json
  • ODS

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
We guarantee 99.9% availability between 0800 and 1800 Monday to Friday.
Approach to resilience
Information available upon request.
Outage reporting
Email alerts.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
RBAC, MFA and IP Restrictions.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
Other
Other security governance standards
Cyber Essentials Plus
Information security policies and processes
We maintain and periodically update information security and policies. Said policies are reviewed by senior leadership and are clearly communicated, attested to and understood by our staff.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Application manifest (virtualised infrastructure and application codebase). We impact assess all changes (configuration and code based) to identify potential security impact.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
We monitor threat intelligence feeds from industry sources (CISA, CERT, security vendors).
Conduct vulnerability scanning and penetration testing
Review security logs for anomalies.
Track CVE databases and vendor security advisories
Patch Deployment Speed:
Critical security patches: Often within 24-48 hours for urgent vulnerabilities
High-priority patches: Typically 7-30 days depending on testing requirements
Routine patches: Monthly or quarterly cycles
Speed depends on patch testing, change management processes, and system criticality

Information Sources:
National vulnerability databases (NVD, CVE)
Vendor security bulletins
Security research communities
Internal security teams and monitoring
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Regular security audits and forensic analysis. Network traffic analysis for anomalies or suspicious patterns. File integrity monitoring.

Incident Response Process:

Identification: Confirm and classify the incident severity
Containment: Isolate affected systems to prevent spread
Eradication: Remove the threat and close vulnerabilities
Recovery: Restore systems and verify they're clean
Lessons Learned: Post-incident review and process improvement

Response Timeframes:

Critical incidents (active breach, ransomware): Immediate response, 24/7 on-call teams
High-severity alerts: Response within minutes to hours
Medium-severity: Response within hours to 24 hours
Low-severity: Response within days, during business hours
Incident management type
Supplier-defined controls
Incident management approach
We have incident response playbooks as well as a defined incident response policy. Users can report incidents by email or telephone 24/7. We provide written incident reports once an incident has been resolved detailing the root cause of the incident, mitigating steps taken and how we intend to prevent future recurrence.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
Yes
Connected networks
Health and Social Care Network (HSCN)

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
10%
Between £250,000 and £500,000
10%
Between £500,001 and £1,000,000
10%
Between £1,000,001 and £2,500,000
10%
Between £2,500,001 and £5,000,000
10%
Over £5,000,001
10%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
No
Cyber Essentials Alternative
None of the criteria
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
34d8f76f-14bb-49eb-bf76-de63292b660c
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
    • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
    • Actions to invest in the physical and mental health and wellbeing of the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at laura@carebeans.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.