Skip to main content

Help us improve the Digital Marketplace - send your feedback

Medical Audits

Medical Audits Software

Mobile auditing software platform for healthcare.
Monitor and manage risks, manage non-compliances, monitor trends.
Choose from 80+ ‘off the shelf’ audits such as cleaning, Infection Prevention, Facilities and Nursing or add your own bespoke audits.

Real time data, configurable templates and seamless expansion are standard in Medical Audit’s dependable platform.

Features

  • Remote access
  • Real time digital dashboards
  • Web based platform
  • Data analysis, patterns, trend analysis
  • Mobile auditing - on line and off line
  • Works with Edge, Chrome, Firefox, Safari and more
  • Compatible with Android, Windows and Apple phones, tablets and computers
  • Infection Prevention Audit software
  • Cleaning audit software
  • Clinical and Risk management software

Benefits

  • Save time - triple your audit capacity
  • Save money - proven reduction in infection rates
  • Reduce stress- easy to use and easy to implement
  • Cease time wasting double data-entry
  • Monitor and evidence compliance
  • Identify and monitor risks and trends
  • Measure KPIs and Patient Outcomes
  • Increase audit output -less resource intensive
  • Immediate access to results - real time dashboards
  • Standardise processes

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at ann@medicalaudits.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

9 0 0 9 1 5 0 8 9 3 9 2 3 7 1

Contact

Medical Audits Ann Higgins
Telephone: 0121 2708865
Email: ann@medicalaudits.co.uk

About your service

Service categories

Application Development and Deployment

Application development

  • Software construction components
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Community cloud
Service constraints
Planned Maintenance;
Medical Audits will carry out planned maintenance without affecting service.
Generally this will the carried out outside of office hours to ensure maintenance is during periods of anticipated low traffic and by carrying out planned maintenance on part, not all, of the network at any one time
System requirements
  • No minimum system requirements other than access to intermittent Wi-Fi
  • Works on any device connected to internet
  • Works with or without wi-fi
  • No need to download any apps

User support

Email or online ticketing support
Yes
Support response times
Email Support
We respond to customer emails with 6 hours - office hours and within 12 hours evenings and weekends.
Helpdesk support
Phone support is also provided for support issues during office hours
Email support is provided but during and out of office hours
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AAA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
Yes
Web chat support availability
9 to 5 (UK time), 7 days a week
Web chat support accessibility standard
WCAG 2.2 AA
Web chat accessibility testing
Keyboard navigation: Ensuring users can navigate through and operate all chat features using only a keyboard.
Understandability: Assessing if the chat interface and messages are easy to understand and free of complex layouts or jargon.
Perceivability: Checking if information is perceivable by users with different needs, such as users with low vision who might use screen magnifiers.
Operability: Ensuring that users can operate all chat controls and functions, including sending and receiving messages, in an efficient and accessible manner.
Real-world scenarios: Designing tasks that reflect typical usage, such as asking a question, navigating to a new page, or completing a form, to observe how users interact with the chat under realistic conditions.
Iterative testing: Use the feedback from users to make improvements to the chat interface, then conduct another round of testing to ensure the fixes are effective
Onsite support
Yes, at extra cost
Support levels
Hours of Support: Monday to Friday 9am to 6pm as part of a service level agreement.
Support facilities can include and is not limited to the following:

Helpdesk Support:

Helpdesk support will be provided by telephone and email.
When appropriate, we will endeavour to give an estimate of how long
a problem may take to resolve.
Medical Audits will keep the Customer informed of the progress of problem resolution.
Our support staff will attempt to solve a problem immediately or as soon thereafter as possible.

Remote logged in support:
Medical Audits, where necessary, can remotely login to provide support.
Support available to third parties
Yes
AI chatbot
Yes

Onboarding and offboarding

Getting started
Once a Medical Audit’s customer decides to implement Medical Audits, we will immediately prepare their cloud environment, commence configuration and system set up and agree a training schedule to suit the customer.
The new customer will supply basic information to include in the system and agree set up and configuration requirements.
The standard system set up and training approach is provided as per the pricing document.
Our staff are highly experienced and have a wealth of expertise in change management and auditing processes. We therefore support a range of services which may be considered useful for end user engagement and process readjustment.
These services are available based on specific customer requirements and are subject to the SFIA rate card.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
  • Other
Other documentation formats
Video clips
End-of-contract data extraction
All our data is directly extractable into excel. Users can do this at any time during the contract or when the contract ends.
Our standard approach in line with our SLA is:
To provide and offline the customer’s data.
After 90 days (or earlier upon customer confirmation) the data in the data centre will be deleted.
User accounts will also be deleted.
Where applicable, decommissioned devices are formatted and physically destroyed to prevent any possibility of data being retrieved
End-of-contract process
All our data is directly exportable into excel and users can do this at any time.
Our standard approach in line with our SLA is:
To provide and offline the customer’s data.
After 90 days (or earlier upon customer confirmation) the data in the data centre will be deleted.
User accounts will also be deleted.
Where applicable, decommissioned devices are formatted and physically destroyed to prevent any possibility of data being retrieved.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
There is no difference in the service users access via mobile or desktop.
All the same features and functionality are available,

The user interface has been specifically designed and developed for mobile access on both phones and different sized tablet computers and the mobile version has been adapted with a slightly different layout to utilise the smaller phone screen for usability.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
There is a graphical user interface which has been bespoke developed for easy user access to system features.

The interface uses colour, icons, text and search features for a smooth and intiutive user experience.

Talk to text features are enabled for improved accessibility and speed of data entry.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
We have tested our software interface with individuals who user screen readers, magnifiers and voice recognition software and alternative input devices to and alternative input devices to ensure the interface is accessible and functional for them.
We have users with vision and auditory impairment using our software effectively.
API
No
Customisation available
Yes
Description of customisation
Our system is customisable by users (based on role access)

We have designed over 80 audit and risk management systems based on best practice standards. These are peer reviewed and designed to meet CQC and NHS standards.
Users can customise audits if they wish.
User can add their own audits to our system.
We can add customers own audits for them if they prefer.
Configuration
We set the system up with customer’s own hospitals, wards and departments as part of implementation.
The customer can then change and update these as the need arises.
If we have added rooms, customers can easily edit and change these.
The customer can also easily change email recipients, set up users and alter report features and outputs.

Scaling

Independence of resources
We utilise load balancing to manage traffic and distribute workloads across resources to ensure users aren't affected by the demand of other users. We have complete control over the maximum demand on our resources and can scale up as necessary base on the number of customers and their peak demands. For our customer this means a dynamically scalable solution because users only consume the amount of online computing resources they actually want. We continue to monitor traffic on our servers and can increase the capacity as required thus guaranteeing users are unaffected by demands of other users.

Analytics

Service usage metrics
Yes
Metrics types
We can provide data on storage usage. However we don't charge customers based on the usage.
We can provide data on users accessing the system dates, times and length of time accessing.
We can also provide specific user data such as audit results by user and number of observations entered etc
Reporting types
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least every 6 months
Penetration testing approach
In-house
Protecting data at rest
Physical access control, complying with SSAE-18 / ISAE 3402
Data sanitisation process
Yes
Equipment disposal approach
In-house destruction process
Data sanitisation type
  • Explicit overwriting of storage before reallocation / Secure Erase
  • Physical Destruction / Hardware containing data is completely destroyed

Data importing and exporting

Data export approach
All our data is directly exportable into excel by users at any time.
The process is very simple.
Service Migration:
Medical Audits commits to returning all customer data as requested. We are happy to support migration requests. Pricing for service is according to our SFIA rate card. ON request, data in our data centre can be deleted.
Data export formats
  • CSV
  • Other
Other data export formats
  • PDF
  • EXCEL
  • WORD
Data import formats
Other
Other data import formats
  • Talk to text
  • Touch screen select from options
  • Type in data using keyboard

Data-in-transit protection

Data protection between buyer and supplier networks
Private network or public sector network
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Service level agreements guarantee 99.99% availability.

Any refunds are dependent on the service level agreement and downtime.
Approach to resilience
Data centre set up is available on request.
Outage reporting
Any outages such as unplanned downtime are emailed directly to customers.
Urgent issues are phoned directly to the customer superuser.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Dedicated link (for example VPN)
  • Username or password
Access restrictions in management interfaces and support channels
Strict control over access levels.
User defined access controlled by Director of Technology
Access on a needs basis only - principle of least privilege
Supported by:
MFA via email
locking access after 3 failed attempts
A minimum password length of at least 10 characters
automatic blocking using deny list
Audited policy to remove or disable user accounts when no longer required
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Dedicated link (for example VPN)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Access to information is restricted to authorised users who have a bona-fide business need to access information and a formal policy controls access to management privileges which are on a need to know basis only. User accounts with special access privileges (e.g. administrative accounts) are not used for day to day basis and are used for the minimum time required to carry out the specified tasks.
Administrative access is reviewed on a regular basis.
Passwords on admin accounts are changed every 60 days.
A list of the people who have admin accounts is maintained and stored securely.
The complete process is audited as part of our internal audit programme and falls under our ISO9001 2015 compliance monitoring. This ensures compliance with the processes and policies are also checked by external auditors.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
We manage our own dedicated servers which are hosted in an ISO27001 certified data centre.
All changes to information systems, applications, and networks are reviewed and approved, and users are not allowed to make changes without approval from Director of Technology.
A Data Protection Impact Assessment (DPIA) is carried out prior to the implementation of new systems and projects.

We have an up-to-date asset register, for both physical and information assets. All assets have named owners and all are tracked through their life cycle from purchase to disposal.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
We monitor for potential threats through a multi-layered approach that includes:
Penetration testing performed bi- annually and after any major system upgrades.
Vulnerability scans of our systems and networks carried out bi-annually using OpenVAS.
Periodic audits to ensure applications and infrastructure align with security standards and identify areas for improvement.
Encouraging and promoting a security aware culture within the organisation.
We have a policy of updating software by default to ensure we quickly deploy patches and software updates.
Most are set to auto-update for complete assurance.
Information about potential threats comes monitoiring internet chatter as well as Malwarebytes notifications.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
We maintain an audit trail of system access and/or data use and review this weekly.
All devices are configured to enable automatic internet time to ensure logs and audits are in sync.
Event warnings and error messages are automated to appear in one secure moitored email account.
Furthermore our security and antimalware scans also notify us of potential breaches which we can then quarantine and investigate further.
Potential compromises are actioned immediately.
Whilst we have had no breaches of security policy, if one did occur, data would be isolated with a coordinated shutdown of any/all possible compromised data storage/hardware.
Incident management type
Supplier-defined controls
Incident management approach
Users have access to a structured online incident reporting form. Process updates are fed back within publicised timescales.
Internally any events identified are recorded in an incident electronic log and reviewed daily by the IT director to investigate any patterns or updates required or immediately for urgent events.
Predefined processes are in place for common events e.g. slowing of the web application ensuring incidents and near misses are reported to the director of IT and investigated. Records are kept of the outcome of all security incident investigations in accordance with our ISO 9001 2015 accreditation process.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
We are happy to provide a free trial of the software. The potential customer will be provided with the majority of the functionality of the system for an agreed period of time. We provide onsite support for trials.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
3%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
5%
Between £1,000,001 and £2,500,000
10%
Between £2,500,001 and £5,000,000
10%
Over £5,000,001
10%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
Amtivo
ISO 9001 accreditation date
Wednesday 11 February 2015
What the ISO 9001 doesn’t cover
There is nothing not covered.
The certification covers the provision of our bespoke auditing and reporting software systems to the Healthcare sector including research and specification, software design and development, implementation and deployment, maintenance and technical and customer support of our software systems. Training, education and consultancy.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
890b38d7-b782-4d4f-9f0e-642280c6f4da
Cyber essentials plus
No
Cyber Essentials Alternative
You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
Other security certifications
Yes
Any other security certifications
IASME cyber assurance

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
    • Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at ann@medicalaudits.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.