Skip to main content

Help us improve the Digital Marketplace - send your feedback

EYEV LIMITED

EYEV: Referrals and Single Point of Access Platform

EYEV Referrals allows clinicians to send, triage, book and process referrals with ease, in an easy to use web platform. It integrates with existing electronic patient records, patient administrations and reporting systems using open APIs which follow international standard such as FHIR and HL7.

Features

  • Online referral platform
  • Customisable referral forms
  • Triage module with auto-triaging capabilities
  • Integration with NHS Spine, PDS
  • Integration with e-RS
  • Real-time reporting
  • Automated feed for BI platforms, such as Power BI
  • APIs for all aspects of the platform

Benefits

  • Cut triage time by up to 2 minutes
  • Make referrals quicker
  • Get structured information from referrals
  • 7 day a week support
  • Patient communication
  • Patient choice of provider

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at cellan@eyev.health. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

1 3 3 6 8 8 1 7 3 5 5 8 0 4 0

Contact

EYEV LIMITED Cellan Griffiths
Telephone: 0115 650 0102
Email: cellan@eyev.health

About your service

Service categories

Applications

Production and operations

  • Other operations

Service industry and public sector operations

  • Healthcare
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
N/A - Service available as warranted.
System requirements
Internet access via modern web browser

User support

Email or online ticketing support
Yes
Support response times
Within 2 working days. A working day is Monday-Sunday, excluding bank holidays.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AAA
Phone support
Yes
Phone support availability
9 to 5 (UK time), 7 days a week
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Standard - No cost

Email and phone support Monday-Friday 8am-8pm, Saturday and Sunday 9am-4pm.

Enhanced - Cost per rate card.

Face to face support at customer site, with floor walkers if required.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
We provide users with a number of comprehensive virtual training sessions with our senior staff, and product experts. We set up as many sessions as required for each type of staff group (for example, clinical staff, followed by referral and booking staff) to ensure that all aspects of the system have been trained.

We also have a permanent online user guide and training videos for each user, which is downloadable. This means that users can refer back to the online guide at any time, and download as offline documentation in order to adopt it into standard operating procedures within the organisation.

Our clinical and operational lead also works in tandem with the customer to ensure that process mapping is completed comprehensively and accurately, which ensures a smooth onboarding service.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
Users are able to download an extract of all of their data on the system in CSV, SQL and JSON format.

They can also download all of their data via our REST API, or by liaising with our support team to provide a bulk extract in CSV, SQL or JSON format to be sent via agreed means.
End-of-contract process
At the end of the contract, our support team will ensure that all data is provided to the customer in an agreed format, and will support the customer to ensure that all information has been extracted. This is included in the price.

We will also assist the customer in manually migrating data to a new supplier, and performing the migration ourselves. This will incur an additional day rate cost at the "Software Developer" day rate.
Documentation accessibility standard
WCAG 2.2 AAA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
There is no difference between the core mobile and desktop service, except the online screens have been adapted for mobile size screens on mobile devices.

Large-scale BI reporting is only available on desktop devices.
Service interface
No
User support accessibility
WCAG 2.2 AAA
API
Yes
What users can and can't do using the API
Our service is "API First", this means that you can access all functions available in the browser via our API.

There is no difference between the service offered in the main system, versus via the API.
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
  • PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Buyers can customise the referral forms, and what referral pathways are available in the system. Users with this level of access are called "Tenant Admins".

The service is fully configurable via the browser.

It is also possible to perform system-level configuration by contacting your Account Manager, who ca arrange customisations to the service.

Scaling

Independence of resources
To ensure that users aren't affected by the demand others place on our service, we employ a robust load balancing system that distributes traffic across multiple servers, maintaining high availability and performance. Our scalable cloud infrastructure automatically adjusts resources based on demand, and rate limiting prevents excessive use. Our support team uses advanced monitoring tools to manage issues and can augment resources to accommodate new services. These strategies guarantee stable and reliable access for all users.

Furthermore, many aspects of our infrastructure use serverless functions, which are highly scalable without affecting our underlying service.

Analytics

Service usage metrics
Yes
Metrics types
We provide service uptime, user usage, organisational usage, referral volume, triage outcomes and time to triage.

All information contained within the system can be extracted via the API, or produced in a customisable reporting dashboard.

We also support automated DSCRO submissions via MESH to the Data Landing Portal to support commissioner datasets.
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CHECK service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Physical access control, complying with another standard
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
Yes
Equipment disposal approach
In-house destruction process
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Users are able to log into the platform and export their data to CSV, JSON or SQL.

They can also call our REST APIs to export their data.

Additionally, users can make support requests to our service desk to request a specific export of data.
Data export formats
  • CSV
  • Other
Other data export formats
  • SQL
  • JSON
  • XML
Data import formats
  • CSV
  • Other
Other data import formats
  • SQL
  • JSON
  • XML
  • FHIR R4 API Requests

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Other
Other protection within supplier network
Virtual Private Cloud (VPCs)

Availability and resilience

Guaranteed availability
We guarantee a service availability of 99.9%. Our Service Level Agreement (SLA) specifies that if availability falls below this threshold, users are entitled to service credits. These credits are calculated on an hourly basis and are proportional to the annual fee, providing compensation for downtime beyond 48 hours in any given month. This ensures our commitment to maintaining high levels of service and offers users a form of recompense if the agreed standards are not met. The process for claiming these credits is streamlined and clearly detailed in our user agreements to ensure transparency and ease of understanding for all parties involved.
Approach to resilience
Available on request.
Outage reporting
Service outages are reported via the following means:

- Email notifications to users
- SMS notifications to users
- An online Statuspage website

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Username or password
Access restrictions in management interfaces and support channels
We enforce strict access restrictions in management interfaces and support channels to safeguard our services and data. Access is limited to authorised personnel only, based on roles and responsibilities. We use multi-factor authentication (MFA) to ensure that only verified users can gain access, and all access attempts are logged and monitored.

Role-based access control (RBAC) provides users with the minimum necessary permissions needed for their duties, preventing unauthorised actions. Regular audits review access privileges and ensure compliance with security policies, maintaining secure and controlled access.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
You control when users can access audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
Between 6 months and 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Our organisation is committed to maintaining rigorous information security policies and processes, certified to ISO 27001. This certifies that our Information Security Management System (ISMS) is compliant and deployed within our organisation.

Security Policies: Our security policies cover data protection, access control, incident response, and risk management. These guidelines are frequently updated to meet ISO 27001 standards and address new security challenges.

Compliance and Auditing: We enforce our security policies through regular internal audits and at least annual external audits conducted by third-party CHECK pentest.

Reporting Structure: Our Technology Director oversees the support and software engineering teams, handling our security policies. This direct reporting structure ensures that security concerns are integrated into broader company policy.

Training and Awareness: All employees undergo regular training to stay informed about security threats and preventive measures. We subscribe to feeds from the National Cyber Security Centre and NHS England Cyber Feeds.

Penetration Testing: We conduct internal penetration tests monthly and external penetration tests at least annually to proactively discover and mitigate potential security vulnerabilities.

Enforcement: Monitoring tools are utilised to ensure compliance with our security policies. Any deviations are promptly addressed, with actions taken depending on the severity of the issue.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Our configuration and change management processes are designed to ensure stability and security across all service components. Each component's lifecycle is meticulously tracked from deployment to decommissioning using automated systems that log updates, modifications, and status changes. Before any change is implemented, it undergoes a rigorous assessment to evaluate potential security impacts. This involves a preliminary security review by our Technology Director, followed by tests in a controlled staging environment. Only after thorough testing and approval are changes applied to the live environment, ensuring that our services remain secure and functional without disrupting user experience.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Our vulnerability management process proactively identifies and mitigates threats to ensure robust service security. We assess potential threats by continuously monitoring various security channels, including industry advisories, security forums, and partnerships with cybersecurity organisations. We also subscribe to the NCSC Threat Intelligence Feeds.

Upon identifying a vulnerability, we prioritise its severity and impact on our services. Critical patches are deployed within 24 hours, while less urgent updates follow a structured schedule to minimise disruption, though within 30 days.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
Incident management type
Supplier-defined controls
Incident management approach
Our incident management process is robust, with pre-defined procedures for common security events to ensure swift and effective resolution. Users can report incidents via email, phone, or through our dedicated online portal, which is accessible 24/7. Each report is immediately logged and assessed by our Technology Director, who oversees the response. We provide detailed incident reports to the affected users, outlining the nature of the incident, actions taken, and steps for prevention in the future. These reports are typically delivered within a few hours of incident resolution, ensuring transparency and maintaining trust with our users.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
Yes
Connected networks
Health and Social Care Network (HSCN)

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
10%
Between £500,001 and £1,000,000
15%
Between £1,000,001 and £2,500,000
30%
Between £2,500,001 and £5,000,000
30%
Over £5,000,001
35%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Amtivo Group Limited T/A British Assessment Bureau
ISO/IEC 27001 accreditation date
Monday 11 August 2025
What the ISO/IEC 27001 doesn’t cover
N/A - Whole organisation
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
3e3b9a58-16c5-493e-bb28-8ad71bddb865
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
Yes
Any other security certifications
NHS Data Security and Protection Toolkit (Standards Exceeded)

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Ensuring new workers are informed of their right to join a trade union
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Activities to cascade good practice on fair working conditions throughout the supply chain
    • Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
    • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Volunteering opportunities for staff

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at cellan@eyev.health. Tell them what format you need. It will help if you say what assistive technology you use.