Skip to main content

Help us improve the Digital Marketplace - send your feedback

Red Star

Red Star FLS

A secure cloud-based Fracture Liaison Service (FLS) management system supporting NHS teams to identify, track and follow up patients at risk of fragility fracture. The service replaces manual spreadsheets, improves pathway visibility, supports audit reporting, and helps services deliver consistent secondary fracture prevention.

Features

  • Secure cloud-based Fracture Liaison Service patient management system
  • Role-based access control with user authentication and audit logging
  • Centralised patient tracking across the full FLS pathway
  • Configurable workflows aligned to local NHS service models
  • Dashboard reporting for service activity, performance and outcomes
  • DXA referral and results tracking functionality
  • Structured data capture replacing spreadsheets and local databases
  • Secure data hosting within UK-based Microsoft Azure environment
  • Exportable reports supporting national and local audit requirements
  • Web-based access without local software installation

Benefits

  • Reduce administrative time managing patients and follow-up activity
  • Improve visibility of patients across the fracture prevention pathway
  • Support consistent delivery of secondary fracture prevention services
  • Replace manual spreadsheets with a secure, auditable system
  • Improve data quality for reporting and audit submissions
  • Enable faster identification of patients requiring follow-up
  • Support service planning through clear activity and performance dashboards
  • Improve continuity when staff change or services expand
  • Support safer management through improved oversight and traceability
  • Help services demonstrate impact and value of FLS provision

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at andrew.conkie@redstar.ai. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

1 0 1 9 5 2 8 1 4 1 2 9 0 8 8

Contact

Red Star Andrew Conkie
Telephone: 07853 599317
Email: andrew.conkie@redstar.ai

About your service

Service categories

Applications

Production and operations

Service industry and public sector operations

  • Healthcare
Multi cloud support
No

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
The service can integrate with existing NHS clinical and administrative systems, including electronic patient record systems, radiology systems and DXA reporting systems, where available. It is not dependent on any third-party software and can operate fully as a standalone Fracture Liaison Service management system.
Cloud deployment model
Public cloud
Service constraints
The service requires internet access and a modern web browser. The platform is designed for high availability, with routine maintenance planned to minimise disruption and typically carried out outside normal working hours. Integration with local NHS systems is subject to local information governance approval and availability of technical interfaces.
System requirements
  • Internet connection with access to secure NHS or organisational networks
  • Modern web browser such as Chrome, Edge, Firefox or Safari
  • JavaScript and cookies enabled in the web browser
  • Screen resolution suitable for web-based clinical systems
  • User account with role-based access permissions
  • Email access for account setup and notifications
  • Access to organisation-approved authentication method where required
  • Standard workstation or laptop device
  • No local software installation required

User support

Email or online ticketing support
Yes
Support response times
Support requests are acknowledged within two hours during standard UK business hours (Monday to Friday, 9am–5pm).

Initial response times may vary depending on issue complexity. High-priority issues are prioritised for resolution and typically addressed within 24 hours where possible. Other requests are triaged on receipt and scheduled accordingly.

Reduced response coverage applies at weekends and public holidays, with urgent issues reviewed as required.

Out-of-hours support can be arranged by prior agreement where required.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Standard support is included within the service licence and is provided via email during UK business hours (Monday to Friday, 9am–5pm). Support requests are acknowledged within two hours, with issues prioritised based on severity and impact.

Standard support covers user queries, configuration assistance, incident investigation and fault resolution.

A named account contact is provided for service coordination and ongoing communication.

Enhanced support options, including extended hours support, accelerated response times, and onsite support for training or service activities, can be provided at additional cost by prior agreement.

The service does not require a dedicated technical account manager or cloud support engineer, as the platform is fully managed by Red Star. Technical support is provided by the core delivery team with knowledge of the service architecture and NHS deployment requirements.

Support arrangements, including service levels and any additional support requirements, can be agreed as part of the individual customer contract.
Support available to third parties
No

Onboarding and offboarding

Getting started
Red Star supports onboarding through a structured implementation process tailored to local Fracture Liaison Service requirements. This includes initial service setup, configuration aligned to local pathways, and user account creation.

Training is provided remotely via online sessions for clinical and administrative users, covering system navigation, day-to-day use and reporting. User guidance, SOPs and supporting documentation are provided to help users get started and to support ongoing use.

Onsite training or workshops can be provided where required and are agreed separately.

Red Star works with nominated service leads during onboarding to ensure the service is configured appropriately and users are supported through go-live. Ongoing support is available following implementation.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
At the end of the contract, data can be extracted in commonly used formats such as CSV or Excel. Data extracts are provided securely following confirmation from the NHS organisation acting as data controller.

Red Star supports data extraction on request to enable service transition or local archiving. Following confirmation that data has been successfully transferred, data will be securely deleted in accordance with agreed retention schedules and information governance requirements.

Data extraction support is provided as part of the contract close-down process.
End-of-contract process
T the end of the contract, continued access to the service ceases in line with the agreed contract end date unless an extension or renewal is agreed.

As part of the standard contract close-down process, Red Star will support secure data extraction in commonly used formats following confirmation from the NHS organisation acting as data controller.

Following confirmation that data has been successfully transferred, Red Star will securely delete customer data in accordance with agreed retention schedules and information governance requirements.

Standard end-of-contract activities, including data extraction and secure data deletion, are included within the contract price.

Additional support beyond standard close-down activities, such as extended access periods, bespoke data transformations, or additional reporting, can be provided at extra cost by prior agreement.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
The service is accessed through a secure, web-based user interface designed for use on standard NHS desktop and laptop devices. Users access the system via a modern web browser to view dashboards, manage patient records, enter data and generate reports or letters. The interface uses clear layouts, consistent navigation and role-based views to support clinical and administrative workflows.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
Formal testing with users of assistive technology has not yet been undertaken. Accessibility is considered during design and development, and the service follows recognised accessibility good practice. Feedback from users is reviewed on an ongoing basis, and accessibility improvements can be prioritised where required.
API
Yes
What users can and can't do using the API
The service includes secure APIs used to support system integrations and data exchange with authorised third-party systems, subject to agreement and information governance approval.

APIs can be used to support controlled data import and export, such as patient demographics, radiology reports, labs, letters. These typically use HL7 or HL7/FHIR compatible standards.

Service configuration, workflow setup and user management are not performed directly through the API and are managed by Red Star as part of service onboarding and change control.

API access is restricted, authenticated and enabled on a per-customer basis. The APIs are not publicly exposed and are not intended for unrestricted self-service integration.
API documentation
Yes
API documentation formats
PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
The service can be configured to reflect local Fracture Liaison Service pathways and operational requirements. Configurable elements include workflows, data fields, letter templates lists of values, user roles and terminology.

Customisation is agreed during onboarding or through managed change requests and is implemented by Red Star to ensure consistency, safety and information governance compliance.

End users do not directly modify system configuration. Customisation requests are submitted by authorised service leads or administrators and reviewed prior to implementation.

This approach enables local flexibility while maintaining a standardised, secure and supported platform.

Scaling

Independence of resources
The service is hosted within a secure cloud environment designed to support multiple organisations concurrently. Resources are managed to ensure appropriate capacity and performance across tenants. Usage is monitored to identify and manage unusual demand, and the underlying cloud platform provides scalable infrastructure to maintain service availability and performance for all users.

Analytics

Service usage metrics
Yes
Metrics types
The service provides usage and activity metrics to support service monitoring and reporting. Metrics may include numbers of active users, patient records created and updated, pathway activity, follow-up status, and reporting volumes. Aggregated service activity information can be used to support operational oversight, audit and service evaluation.
Reporting types
  • Real-time dashboards
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure

Data importing and exporting

Data export approach
Users can export data through standard reporting and export functions within the service, subject to role-based access permissions. Data can be exported in commonly used structured formats such as CSV or Excel for reporting, local analysis and upload into local systems where appropriate.

Report outputs may also be generated in PDF format.

Where required, Red Star can support additional data exports on request, subject to information governance approval from the NHS organisation acting as data controller.
Data export formats
  • CSV
  • Other
Other data export formats
PDF
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
The service is designed to be highly available and is hosted within a resilient cloud environment. Red Star targets 99.9% service availability, measured on a monthly basis, excluding planned maintenance.

Availability is monitored continuously, and planned maintenance is scheduled to minimise user impact and is typically carried out outside normal working hours where possible.

Formal service level agreements, including any service credits or remedies, can be agreed as part of individual customer contracts where required.
Approach to resilience
The service is hosted within Microsoft Azure UK and is designed to be resilient to infrastructure failure. Resilience is achieved through the use of built-in redundancy and failover mechanisms within the cloud platform.

The service is deployed across multiple availability zones within the UK region to support continued operation in the event of an availability zone outage. Traffic management and health monitoring are used to detect service degradation and automatically route traffic away from unavailable components until recovery is complete.

The underlying cloud environment provides redundant power, networking and cooling, reducing the risk of service disruption due to single points of failure.

Data is stored on resilient storage with automated backup and recovery processes in place. Service health is continuously monitored, with alerts supporting timely investigation and resolution of incidents.

Further technical detail regarding resilience architecture can be provided to customers on request where appropriate.
Outage reporting
Service availability is monitored continuously. In the event of a service outage or significant degradation, affected customers are notified via email with details of the issue, impact, and progress updates where appropriate.

Planned maintenance and service updates are communicated in advance wherever possible.

There is currently no public status dashboard or API for outage reporting, however status updates and post-incident summaries can be provided to customers on request.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is restricted to authorised personnel only. Role-based access controls are used to ensure users can access only the functions required for their role.

Administrative access is limited to approved staff and protected through federated authentication and multi-factor authentication.

Support requests are managed through controlled channels, with access restricted to nominated contacts.

Access rights are reviewed periodically and removed promptly when no longer required.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
Security governance is aligned with recognised good practice, including the Software Security Code of Practice.

CE+ certification is in place. ISO/IEC 27001 certification is planned, with implementation underway and target certification in Q2 2026.

Further information is available on request.
Information security policies and processes
Red Star maintains a set of documented information security policies and procedures covering access control, data protection, incident management, change management, supplier management and secure development.

Security governance is overseen by senior management, with clear roles and responsibilities defined for information security and data protection. Policies are reviewed regularly and updated in response to changes in risk, regulation or operational practice.

Compliance with policies is supported through role-based access controls, technical safeguards, audit logging and regular monitoring. Security incidents are managed through a defined incident response process, including assessment, containment, investigation and reporting where required.

Staff receive security awareness training and are required to follow documented procedures as part of their role.

Additional detail on policies, controls and reporting structures is available to customers on request.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Red Star operates supplier-defined configuration and change management controls to ensure system changes are implemented in a controlled/auditable manner.

Changes to the service are assessed for risk and impact prior to implementation. Where appropriate, changes are reviewed and approved before deployment.

Configuration is managed using version control and standard deployment processes to reduce the risk of unauthorised or untested changes.

Changes are tested prior to release, and production deployments follow defined release procedures.

Access to make configuration changes is restricted to authorised personnel only, with role-based access controls in place.

Records of changes are maintained to support traceability and investigation.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Red Star assesses potential threats through vendor security advisories, cloud platform security notifications, software dependency updates and periodic penetration testing.

Identified vulnerabilities are reviewed and assessed based on severity, exploitability and potential impact. Remediation actions are prioritised according to risk, with critical vulnerabilities patched within 14 days or sooner.

Security patches and updates are deployed in a timely manner following appropriate testing to minimise operational risk.

Information on emerging threats is obtained from trusted sources including cloud service providers and software vendors.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Red Star uses proactive monitoring to identify potential security issues through system logging, audit trails and automated cloud platform monitoring for abnormal or malicious activity.

Logs are reviewed to detect unusual activity, access anomalies or indicators of potential compromise. Alerts are generated where thresholds or abnormal patterns are identified.

When a potential security issue is detected, it is assessed and investigated in line with incident management procedures. Appropriate containment and remediation actions are taken as required.

Incidents are responded to promptly based on severity, with escalation and communication managed in accordance with defined incident response processes.
Incident management type
Supplier-defined controls
Incident management approach
Red Star operates defined incident management processes for common operational and security events with an established Incident Response Plan.

Users report incidents via agreed support channels. Incidents are logged, assessed and prioritised based on severity and potential impact.

Response actions follow documented procedures, including investigation, containment and resolution.

Customers are kept informed of significant incidents through status updates, with incident reports provided where appropriate following resolution.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
Yes
Connected networks
Scottish Wide Area Network (SWAN)

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0.0%
Between £250,000 and £500,000
5.0%
Between £500,001 and £1,000,000
10.0%
Between £1,000,001 and £2,500,000
15.0%
Between £2,500,001 and £5,000,000
20.0%
Over £5,000,001
25.0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
1bb70d50-a7ea-4100-9c5c-031e7d696ba9
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
627124d6-d868-44c9-9faf-abc53f2ec8b6
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
    • Actions to invest in the physical and mental health and wellbeing of the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at andrew.conkie@redstar.ai. Tell them what format you need. It will help if you say what assistive technology you use.