Medical Audits Software
Mobile auditing software platform for healthcare.
Monitor and manage risks, manage non-compliances, monitor trends.
Choose from 80+ ‘off the shelf’ audits such as cleaning, Infection Prevention, Facilities and Nursing or add your own bespoke audits.
Real time data, configurable templates and seamless expansion are standard in Medical Audit’s dependable platform.
Features
- Remote access
- Real time digital dashboards
- Web based platform
- Data analysis, patterns, trend analysis
- Mobile auditing - on line and off line
- Works with Edge, Chrome, Firefox, Safari and more
- Compatible with Android, Windows and Apple phones, tablets and computers
- Infection Prevention Audit software
- Cleaning audit software
- Clinical and Risk management software
Benefits
- Save time - triple your audit capacity
- Save money - proven reduction in infection rates
- Reduce stress- easy to use and easy to implement
- Cease time wasting double data-entry
- Monitor and evidence compliance
- Identify and monitor risks and trends
- Measure KPIs and Patient Outcomes
- Increase audit output -less resource intensive
- Immediate access to results - real time dashboards
- Standardise processes
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 0 0 9 1 5 0 8 9 3 9 2 3 7 1
Contact
Medical Audits
Ann Higgins
Telephone: 0121 2708865
Email: ann@medicalaudits.co.uk
About your service
- Service categories
-
Application Development and Deployment
Application development
- Software construction components
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Community cloud
- Service constraints
-
Planned Maintenance;
Medical Audits will carry out planned maintenance without affecting service.
Generally this will the carried out outside of office hours to ensure maintenance is during periods of anticipated low traffic and by carrying out planned maintenance on part, not all, of the network at any one time - System requirements
-
- No minimum system requirements other than access to intermittent Wi-Fi
- Works on any device connected to internet
- Works with or without wi-fi
- No need to download any apps
User support
- Email or online ticketing support
- Yes
- Support response times
-
Email Support
We respond to customer emails with 6 hours - office hours and within 12 hours evenings and weekends.
Helpdesk support
Phone support is also provided for support issues during office hours
Email support is provided but during and out of office hours - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AAA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), 7 days a week
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
-
Keyboard navigation: Ensuring users can navigate through and operate all chat features using only a keyboard.
Understandability: Assessing if the chat interface and messages are easy to understand and free of complex layouts or jargon.
Perceivability: Checking if information is perceivable by users with different needs, such as users with low vision who might use screen magnifiers.
Operability: Ensuring that users can operate all chat controls and functions, including sending and receiving messages, in an efficient and accessible manner.
Real-world scenarios: Designing tasks that reflect typical usage, such as asking a question, navigating to a new page, or completing a form, to observe how users interact with the chat under realistic conditions.
Iterative testing: Use the feedback from users to make improvements to the chat interface, then conduct another round of testing to ensure the fixes are effective - Onsite support
- Yes, at extra cost
- Support levels
-
Hours of Support: Monday to Friday 9am to 6pm as part of a service level agreement.
Support facilities can include and is not limited to the following:
Helpdesk Support:
Helpdesk support will be provided by telephone and email.
When appropriate, we will endeavour to give an estimate of how long
a problem may take to resolve.
Medical Audits will keep the Customer informed of the progress of problem resolution.
Our support staff will attempt to solve a problem immediately or as soon thereafter as possible.
Remote logged in support:
Medical Audits, where necessary, can remotely login to provide support. - Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
Once a Medical Audit’s customer decides to implement Medical Audits, we will immediately prepare their cloud environment, commence configuration and system set up and agree a training schedule to suit the customer.
The new customer will supply basic information to include in the system and agree set up and configuration requirements.
The standard system set up and training approach is provided as per the pricing document.
Our staff are highly experienced and have a wealth of expertise in change management and auditing processes. We therefore support a range of services which may be considered useful for end user engagement and process readjustment.
These services are available based on specific customer requirements and are subject to the SFIA rate card. - Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
- Video clips
- End-of-contract data extraction
-
All our data is directly extractable into excel. Users can do this at any time during the contract or when the contract ends.
Our standard approach in line with our SLA is:
To provide and offline the customer’s data.
After 90 days (or earlier upon customer confirmation) the data in the data centre will be deleted.
User accounts will also be deleted.
Where applicable, decommissioned devices are formatted and physically destroyed to prevent any possibility of data being retrieved - End-of-contract process
-
All our data is directly exportable into excel and users can do this at any time.
Our standard approach in line with our SLA is:
To provide and offline the customer’s data.
After 90 days (or earlier upon customer confirmation) the data in the data centre will be deleted.
User accounts will also be deleted.
Where applicable, decommissioned devices are formatted and physically destroyed to prevent any possibility of data being retrieved. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
There is no difference in the service users access via mobile or desktop.
All the same features and functionality are available,
The user interface has been specifically designed and developed for mobile access on both phones and different sized tablet computers and the mobile version has been adapted with a slightly different layout to utilise the smaller phone screen for usability. - Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
-
There is a graphical user interface which has been bespoke developed for easy user access to system features.
The interface uses colour, icons, text and search features for a smooth and intiutive user experience.
Talk to text features are enabled for improved accessibility and speed of data entry. - Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
We have tested our software interface with individuals who user screen readers, magnifiers and voice recognition software and alternative input devices to and alternative input devices to ensure the interface is accessible and functional for them.
We have users with vision and auditory impairment using our software effectively. - API
- No
- Customisation available
- Yes
- Description of customisation
-
Our system is customisable by users (based on role access)
We have designed over 80 audit and risk management systems based on best practice standards. These are peer reviewed and designed to meet CQC and NHS standards.
Users can customise audits if they wish.
User can add their own audits to our system.
We can add customers own audits for them if they prefer.
Configuration
We set the system up with customer’s own hospitals, wards and departments as part of implementation.
The customer can then change and update these as the need arises.
If we have added rooms, customers can easily edit and change these.
The customer can also easily change email recipients, set up users and alter report features and outputs.
Scaling
- Independence of resources
- We utilise load balancing to manage traffic and distribute workloads across resources to ensure users aren't affected by the demand of other users. We have complete control over the maximum demand on our resources and can scale up as necessary base on the number of customers and their peak demands. For our customer this means a dynamically scalable solution because users only consume the amount of online computing resources they actually want. We continue to monitor traffic on our servers and can increase the capacity as required thus guaranteeing users are unaffected by demands of other users.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
We can provide data on storage usage. However we don't charge customers based on the usage.
We can provide data on users accessing the system dates, times and length of time accessing.
We can also provide specific user data such as audit results by user and number of observations entered etc - Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- In-house
- Protecting data at rest
- Physical access control, complying with SSAE-18 / ISAE 3402
- Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
-
- Explicit overwriting of storage before reallocation / Secure Erase
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
-
All our data is directly exportable into excel by users at any time.
The process is very simple.
Service Migration:
Medical Audits commits to returning all customer data as requested. We are happy to support migration requests. Pricing for service is according to our SFIA rate card. ON request, data in our data centre can be deleted. - Data export formats
-
- CSV
- Other
- Other data export formats
-
- EXCEL
- WORD
- Data import formats
- Other
- Other data import formats
-
- Talk to text
- Touch screen select from options
- Type in data using keyboard
Data-in-transit protection
- Data protection between buyer and supplier networks
- Private network or public sector network
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
Service level agreements guarantee 99.99% availability.
Any refunds are dependent on the service level agreement and downtime. - Approach to resilience
- Data centre set up is available on request.
- Outage reporting
-
Any outages such as unplanned downtime are emailed directly to customers.
Urgent issues are phoned directly to the customer superuser.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Dedicated link (for example VPN)
- Username or password
- Access restrictions in management interfaces and support channels
-
Strict control over access levels.
User defined access controlled by Director of Technology
Access on a needs basis only - principle of least privilege
Supported by:
MFA via email
locking access after 3 failed attempts
A minimum password length of at least 10 characters
automatic blocking using deny list
Audited policy to remove or disable user accounts when no longer required - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Access to information is restricted to authorised users who have a bona-fide business need to access information and a formal policy controls access to management privileges which are on a need to know basis only. User accounts with special access privileges (e.g. administrative accounts) are not used for day to day basis and are used for the minimum time required to carry out the specified tasks.
Administrative access is reviewed on a regular basis.
Passwords on admin accounts are changed every 60 days.
A list of the people who have admin accounts is maintained and stored securely.
The complete process is audited as part of our internal audit programme and falls under our ISO9001 2015 compliance monitoring. This ensures compliance with the processes and policies are also checked by external auditors. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
We manage our own dedicated servers which are hosted in an ISO27001 certified data centre.
All changes to information systems, applications, and networks are reviewed and approved, and users are not allowed to make changes without approval from Director of Technology.
A Data Protection Impact Assessment (DPIA) is carried out prior to the implementation of new systems and projects.
We have an up-to-date asset register, for both physical and information assets. All assets have named owners and all are tracked through their life cycle from purchase to disposal. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
We monitor for potential threats through a multi-layered approach that includes:
Penetration testing performed bi- annually and after any major system upgrades.
Vulnerability scans of our systems and networks carried out bi-annually using OpenVAS.
Periodic audits to ensure applications and infrastructure align with security standards and identify areas for improvement.
Encouraging and promoting a security aware culture within the organisation.
We have a policy of updating software by default to ensure we quickly deploy patches and software updates.
Most are set to auto-update for complete assurance.
Information about potential threats comes monitoiring internet chatter as well as Malwarebytes notifications. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
We maintain an audit trail of system access and/or data use and review this weekly.
All devices are configured to enable automatic internet time to ensure logs and audits are in sync.
Event warnings and error messages are automated to appear in one secure moitored email account.
Furthermore our security and antimalware scans also notify us of potential breaches which we can then quarantine and investigate further.
Potential compromises are actioned immediately.
Whilst we have had no breaches of security policy, if one did occur, data would be isolated with a coordinated shutdown of any/all possible compromised data storage/hardware. - Incident management type
- Supplier-defined controls
- Incident management approach
-
Users have access to a structured online incident reporting form. Process updates are fed back within publicised timescales.
Internally any events identified are recorded in an incident electronic log and reviewed daily by the IT director to investigate any patterns or updates required or immediately for urgent events.
Predefined processes are in place for common events e.g. slowing of the web application ensuring incidents and near misses are reported to the director of IT and investigated. Records are kept of the outcome of all security incident investigations in accordance with our ISO 9001 2015 accreditation process. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- We are happy to provide a free trial of the software. The potential customer will be provided with the majority of the functionality of the system for an agreed period of time. We provide onsite support for trials.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 3%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Amtivo
- ISO 9001 accreditation date
- Wednesday 11 February 2015
- What the ISO 9001 doesn’t cover
-
There is nothing not covered.
The certification covers the provision of our bespoke auditing and reporting software systems to the Healthcare sector including research and specification, software design and development, implementation and deployment, maintenance and technical and customer support of our software systems. Training, education and consultancy. - Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 890b38d7-b782-4d4f-9f0e-642280c6f4da
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
- Other security certifications
- Yes
- Any other security certifications
- IASME cyber assurance
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
-