Amadeus Digital Care Record
Amadeus Digital Care Record seamlessly integrates rich data sets from disparate health and care systems to provide a comprehensive single view of all patient information. Amadeus empowers healthcare professionals to deliver more efficient, effective, coordinated care by improving access to data and providing tools that enhance patient care and workflows.
Features
- Shared Care Record covering 24 million+ patients in the UK
- Aggregates, normalises, displays health and social care data in real-time
- Standards-based interoperability (FHIR, IPS, HL7 v2, NRL, standard APIs, PRSB)
- Browser-based, intuitive and WCAG compliant Clinical Portal viewer
- Advanced granular privacy, consent, role-based access controls protecting patient information
- Seamless and secure access through SSO and MFA
- Integrated clinical workflow and care coordination tools
- Simple creation of forms and care plans (ReSPECT, EOL, TEP)
- Flexible platform to add capability and functionality over time
- Ongoing product development and innovation, including AI powered enhancements
Benefits
- Improved care delivery, patient safety and outcomes
- Access to the right information at the point of care
- Reduced clinical risk through more informed decision-making
- Improved patient experience in meeting individual needs and care planning
- Empowers patients to engage and take control of their wellbeing
- Improved operational efficiencies by enhancing patient flow across care settings
- Reduced costs through less repeated tests and unnecessary appointments
- Ease clinician burnout by connecting and simplifying access to data
- Improved communication and collaboration between multiple health and care providers
- Provides the foundation for future digital health and care delivery
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 3 2 1 3 6 5 6 3 6 4 2 9 9 7
Contact
ORION HEALTH LIMITED
Ian Binks
Telephone: 07827833794
Email: ian.binks@orionhealth.com
About your service
- Service categories
-
Application Development and Deployment
Integration and orchestration
Integration software
- Integration Platforms
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
-
The service is based on an open, modular software stack and constraints may vary depending on the modules taken.
The service is browser-based, dependencies listed below. - System requirements
-
- Desktop Operating Systems: Windows 7 or above, macOS
- Database Servers: Oracle, SQL Server
- Secure browser-based via HTTPS
- Browsers: Latest versions of Chrome, Microsoft Edge, Mozilla Firefox, Safari
- Mobile/Tablet add-on supported mobile browsers: Mozilla Firefox, Safari, Google Chrome
User support
- Email or online ticketing support
- Yes
- Support response times
-
Support services are typically submitted via a client portal directly into our IT Service Management tools, where they are triaged by Support Analysts as part of our regional Service Delivery team. Our Support Tracker tool has several levels of prioritising requests.
Queries are assigned a Level depending on how critical the problem is. Standard Initial Response Times per Ticket (incident) are:
Level 1 (Critical business impact) - 30 minutes
Level 2 (Business impact - Urgent) - 1 hour
Level 3 (Minor operational impact) - Next Working Day
Level 4 (No production impact - Planned) - Next Working Day - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Orion Health offers the following support and maintenance services tailored to client requirements:
Service Delivery Management:
- Central point of coordination for incident tracking, feedback, escalation and reporting
- Planning, execution, management of SLA reports, Service Improvement Plans, Major Incident Management process and Root Cause Analysis reports
Tier 2 Support Helpdesk:
- 24x7 phone, email, portal and remote connected support services for Priority 1 incidents
- Business hours phone, email, portal and remote connected support services for Priority 2+ incidents
- Diagnosis and implementation of incident solutions (workarounds, emergency fixes, data fixes, recoveries, re compiles, bug fixes)
Application Monitoring & Maintenance
- Proactive monitoring and maintenance of the application stack
- Deployment of product upgrades, changes, fixes and enhancements
- Change management - change and version release documentation
- Database optimisation and data archiving services
- Monthly application performance reporting and software advisory
Infrastructure Monitoring & Maintenance
- Proactive monitoring and maintenance of infrastructure stack
- Network management and maintenance
- Patching and upgrades of operating systems and infrastructure
- Monthly infrastructure performance reporting and advisory
- Backup and disaster recovery planning and execution
SOC & SIEM
- 24/7 monitoring to detect and address cybersecurity events in real time - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Orion Health offers a wide range of training courses and materials to facilitate rapid adoption of the solution. Training is offered through:
- Online Academy; online self-paced modules with quizzes and file submissions graded by an experienced Orion Health trainer
- Instructor-led; face to face training with an experienced Orion Health trainer often at the customer site
- Webinar; instructor-led training with the convenience of a virtual learning environment.
A 'Train the Trainer' approach is often recommended, whereby Orion Health provide the local team with the knowledge and skills necessary to establish an ongoing end user program independent of Orion Health resources. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- At the end of a contract, users can export their configuration and data before the server is cleared by Orion Health. Orion Health retains all intellectual property in the software, and grants a perpetual license to the customer, subject to payment of the license fee. The customer owns the configuration of the Orion Health solution at the customer site. The customer does not receive the source code of the software, but Orion Health offers an escrow service at an additional cost.
- End-of-contract process
- An agreed exit plan will be included in any contract with a customer. The exit plan will contain all the detail necessary to affect a smooth and orderly termination of the services and hand-over to the customer or a new service provider. As such the deliverables and activities that would typically form part of an exit and handover include the obligations of each party, applicable schedule and timescales and the approach to data migration.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Usability and accessibility are important aspects of our products and key guidelines, including W3C recommended Web Content Accessibility Guidelines (WCAG), are carefully considered. Some of the ways we have incorporated accessibility standards into the design includes employing a San's font, making use of iconography, avoiding use of italic content and large blocks of text - which is preferable for dyslexic users. Our designs don't rely on colour to portray information, where possible other visual elements are used, e.g. Bold plus colour used.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The user experience is designed to remain consistent across devices. Our mobile capability utilises progressive web app technology, enabling native app-like experiences for iOS and Android. The solution is fully mobile responsive irrespective of device or browser, rendering the display to the device in use. The layout reflects the device in use, e.g., on tablets, navigation around the screen and selection of screen elements is done with finger swipes and taps vs mouse navigation on a desktop.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Clinical Portal is a secure web-based solution that provides users with tools to support patient care through a single point of entry to the consolidated patient record. Data is arranged into a unified and consistent view, making it relevant to the role of the user. The interface is easy to use; it has an efficient, modern and intuitive graphical interface that will be familiar to anyone who has browsed the internet and used common clinical systems.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
Our products are tested with assistive technologies such as JAWS for Windows and VoiceOver for Mac. We manually evaluate the output of screen readers to determine how easily visually impaired users can identify and navigate our products using only audio speech feedback. We also test keyboard accessibility to evaluate how easily our products can be navigated using only a limited subset of keys, and also use screen readers in conjunction to determine accessibility for users who depend on both screen readers and keyboard usage.
We perform overall accessibility validation using validator tools such as WAVE and Total Validator. These tools automatically check how accessible our products are based on standards and guidelines such WCAG 2.2 and present the results in a readable report. - API
- Yes
- What users can and can't do using the API
- Third party developers can access the rich data and services held in the platform through our Open APIs, which are built using industry standards such as REST and HL7 FHIR. Our APIs provide access to structured data resources held within the service, such as demographics, encounters, medications, etc. They currently provide read only capability.
- API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
The Clinical Portal is highly customisable by both system administrators and end users to meet the needs of individual users and departments and/or specialities.
Administrators can, for example, create and modify forms, design simple pathways, schedule tasks, and configure users and user groups for access.
Users can customise the way data is presented to present information that is most relevant to the individual users' workflow.
Scaling
- Independence of resources
- Each customer has their own instance of the service with dedicated application and database servers. The service uses elastic scaling load balances to handle peaks in demand and service monitoring allows proactive scaling of hosting infrastructure.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Orion Health provides a range of system metrics and reports. Examples include:
- Total monthly logins
- Account status
- Total licences used
- Monthly users created
- Total support tickets logged/open/closed for a month
- Any high priority issues
- Any problem tickets
- Any outages
- Server space report / Disk space used
- Total messages processed
- Portal account summary
- Patient access review
- Number of patient records viewed
- Number of patient records available
- Monthly usage figures (total logins)
- Number of pathology reports viewed
- Number of radiology reports viewed
- Open incidents - Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- At the end of a contract, users can export their configuration and data before the server is cleared by Orion Health. Orion Health retains all intellectual property in the software, and grants a perpetual license to the customer, subject to payment of the license fee. The customer owns the configuration of the Orion Health solution at the customer site. The customer does not receive the source code of the software, but Orion Health offers an escrow service at an additional cost.
- Data export formats
-
- CSV
- Other
- Other data export formats
- XML
- Data import formats
-
- CSV
- Other
- Other data import formats
- Data can be uploaded in any documented format
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Legacy SSL and TLS (under version 1.2)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- Orion Health offers high availability solutions that are operational 24/7, 365 days per year. Typically, the only downtime is for scheduled maintenance (i.e. upgrades) which are usually scheduled for off-peak hours when there are minimal users online. Most Orion Health customers experience availability of at least 99.9%, with some operating at 99.99%.
- Approach to resilience
-
The Amadeus platform is engineered for high resilience and uptime, with core system availability consistently exceeding 99.9%. Our infrastructure is monitored 24/7, supported by automated alerting, redundancy across key components, and robust disaster recovery provisions.
High availability is achieved using using elastic scaling infrastructure, connection load balancers with service health monitoring, multiple redundant nodes geographically distributed over two or more availability zones, and block level data replication.
The datacentre setup is designed with multiple layers of resilience to ensure high availability, reliability, and continuity of service. - Outage reporting
- Outages are handled as part of our Incident Management Process and reported through real-time customer communications and follow-up monthly reports.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- The service supports Role Based Access Controls (RBAC) whereby access is controlled based on the user's role and their membership in one or more user groups (e.g. administrator level access). Management access (e.g. for engineers) can be requested explicitly by individuals requiring access. Requests are reviewed and approved in accordance with our documented security policy and, if appropriate, granted with time bound, least privileged, constraints.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
-
Cyber Essentials Plus
Data Security and Protection Toolkit (DSPT)
Information Commissioners Office
General Data Protection Regulation (GDPR) and the
Data Protection Act 2018
Caldicott Principles - Information security policies and processes
-
Orion Health’s dedicated Security, Risk and Assurance team provide independent information governance and cyber security oversight of product development, service delivery and support activities. Our Information Security Policy is supported by a collection of administrative, technical, and physical policies and processes aligned with best practice advised by ISO 27002:2013 and expected by Article 32 GDPR. These policies and procedures ensure the integrity and confidentiality of personal data (including health data) and protect against anticipated threats or hazards to the security or integrity of such information.
The Information Security policy is approved by senior management and subject to continuous, systematic review and improvement. Orion Health has established a “secure by design” program that considers security as integral to the service lifecycle and regularly engages employees in Information Security, Privacy, and Code of Conduct training. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Our configuration and change management follows a Change and Release Management process within our ITIL aligned customer support service. All configuration items are authorised, documented and tracked throughout their lifecycle to minimise system impact. Changes undergo structured requirements gathering, approval and release management under the Software Quality Assurance Plan (SQAP). Security impact is assessed through integrated security management aligned to our ISO 27701 certified Information Security Management System, alongside risk, testing, and clinical safety management processes to ensure changes are secure, controlled and compliant.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Orion Health subscribes to various agencies for information and alerts related to emerging threats and vulnerabilities. Additionally, we conduct internal and external security scans of all Orion Health managed production environments, on at least a monthly basis. All findings are managed using Orion Health's Patch and Vulnerability Process. The risk associated with each finding is assessed, and remediation is prioritised and managed in accordance with the Orion Health Risk Management Process.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- The Orion Health solution is monitored 24x7x365 by the Security Operations Center provded by the Managed Security Services Provider. This includes real time log monitoring, via a SIEM, from various log sources including Firewalls, Intrusion Prevention/Detection Systems, File Integrity Management, Anti-Malware, as well as infrastructure and administrator log events. Access to the environment is controlled via business requirements, strict minimum necessary permissions, and MFA. Access audits are conducted twice a year.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
The Incident Management process is managed as part of our industry standard ITIL aligned customer support service through the provision of the Orion Health Customer Support Service Desk. The Support Desk is responsible for receiving and processing service requests, for assisting users, and for coordinating incident resolution. Customer incidents are logged via a toll-free support telephone number and through an online support system, Support Tracker.
The incident management function is extended to deliver a problem management function to ensure analysis of root causes and to prevent incidents from recurring in the future. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
-
- Scottish Wide Area Network (SWAN)
- Health and Social Care Network (HSCN)
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 1%
- Between £500,001 and £1,000,000
- 2%
- Between £1,000,001 and £2,500,000
- 3%
- Between £2,500,001 and £5,000,000
- 5%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- LRQA
- ISO/IEC 27001 accreditation date
- Friday 5 December 2025
- What the ISO/IEC 27001 doesn’t cover
- The ISO/IEC 27001:2013 certification is applicable to the provision of Interoperable Health Software from the Orion Health UK and Ireland business, including our London, Glasgow and Belfast offices, and third party hosting services. This includes sales, implementation and support functions being delivered to the public and private sector.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 37f97030-f6ee-426b-b2cf-eba059780015
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 43497fe9-ec7f-4d4c-8922-245b3fe224bd
- Other security certifications
- Yes
- Any other security certifications
-
- Compliance with GDPR and Data Protection Act 2018
- Completion of the current year's DSPT assessment with Standards Exceeded
- Registration with the Information Commissioners Office (ICO)
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-