Skip to main content

Help us improve the Digital Marketplace - send your feedback

PRESCRIBING SERVICES LTD

NHS Secure Data Environment (SCHOLAR)

Eclipse SCHOLAR (Secure Clinical Hub for Online Learning Audit & Research) empowers NHS ICBs to effortlessly implement a secure pseudonymised data environment for regional activities with full data specialist support. The system allows ICBs to work collaboratively on research programmes with 28 million live patient portals already integrated.

Features

  • Live Secure Centralised integrated NHS Platform optimising Insights and Impact.
  • Secure Virtual Desktop Infrastructure
  • Python, R and Stata included within Secure Virtual Desktop
  • Scalable & flexible compute power to suit your need.
  • Import reference data securely
  • Output results securely
  • Data specialist support

Benefits

  • Integration within a fully secure and compliant infrastructure
  • Flexible and Intuitive web-based access.
  • Securely integrate all key regional and NHS centralised databases.
  • Population level analysis, prioritisation, implementation, validation
  • Complete Data Security through AWS TRE infrastructure.
  • Fully Auditable access tracking.
  • Predictive Modelling for Research Optimisation.
  • Largest accredited NHS Research Database.

Pricing

  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at support@prescribingservices.org. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

1 5 6 5 3 8 9 1 6 2 6 5 0 6 2

Contact

PRESCRIBING SERVICES LTD Jake Finney
Telephone: 01553 615555
Email: support@prescribingservices.org

About your service

Service categories

Application Development and Deployment

Analytics and business intelligence

  • Business Intelligence
  • Advanced and predictive analytics
  • Location and geospatial data management and analytics
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
  • Public cloud
  • Private cloud
Service constraints
The service is available only over the web. Access is restricted to authorised users. Routine maintenance and upgrades are minimised and aligned to central NHS assurance accreditation. Sensitive codes set by NHS England are excluded. The local requirements maybe constrained by local IG and security policies
System requirements
  • Current Web Browser
  • Active Data Processing Contract in place
  • HSCN connectivity

User support

Email or online ticketing support
Yes
Support response times
Training is given on commencement of live service. Email/ticket queries will be responded to during usual business hours, we aim to respond within the hour of receiving a query. We have out of office support for any emergencies, as detailed in our user guide.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), 7 days a week
Web chat support
No
Onsite support
Yes
Support levels
The Eclipse Service Management Function and support structures have completed central NHSE Assurance. Upon service commencement full user training is offered in the form of in person or remote and user guides are provided. Each region has a dedicated account manager who can be contacted for any general queries during usual business hours, they have access to our technical team and IT support. In addition our phone line operates during usual business hours alongside our email inboxes. Onsite training can be offered depending on customer need. All costs are included within our service price
Support available to third parties
Yes

Onboarding and offboarding

Getting started
All training, implementation and on-going support activity within Eclipse has completed central NHSE Assurance. Training is implemented in line with client and end user preferences and learning need analysis. Training is delivered in person, or remotely, one to one or in groups. User manuals and support materials are available within the service platform and utilised within training events. Service demo's are provided and training impact is validated with end users.
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
The Eclipse Platform utilises dynamic data flow derived from the Clinical Systems and as such data extraction when the contract ends is not required.
End-of-contract process
Upon contract closure and at the customer’s request, all data associated with the customer organisation is deleted. This is included in the price of the contract.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
N/A
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
Web based Clinical Support Platform
Accessibility standards
WCAG 2.2 AA
Accessibility testing
Testing ensures digital accessibility for people with disabilities. We are continually improving the user experience for everyone, and applying the relevant accessibility standards
API
No
Customisation available
Yes
Description of customisation
Our service platform is designed to be modular and is continuously updated to meet user requirements. Approved end users can configure data presentation and preferences.

Scaling

Independence of resources
Eclipse is delivered using a multi-tenant SaaS architecture with logical separation between customers. Platform capacity, availability, and performance are monitored 24/7 and hosted on virtualised infrastructure to support scalability and high availability.

An N+1 resilience approach, frequent backups, database mirroring, and use of multiple servers across separate geographic locations ensure that demand from one customer does not impact others. All Eclipse services have completed NHS England service functionality assurance. Capacity is proactively managed using monitoring, alerting, and scaling controls, with workload management in place to prevent excessive demand from a single tenant affecting overall service performance.

Analytics

Service usage metrics
Yes
Metrics types
Our service tracks service usage metrics including key performance indicators as defined locally and priority project indicators for equality, safety and admissions avoidance. In addition to qualitative insights, all activity is tracked for audit and quality purposes.
Reporting types
  • Real-time dashboards
  • Regular reports
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with another standard
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Reports can be exported into Excel / CSV / PDF Formats.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Other
Other protection between networks
The environment is protected behind firewall security, and data is accessible by authorised personnel only
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Other
Other protection within supplier network
The environment is protected behind firewall security, and data is accessible by authorised personnel only.

Availability and resilience

Guaranteed availability
In compliance with our NHS central assurance and terms we use reasonable endeavours to maintain a service minimum availability percentage of 99.99% through service provision (excluding scheduled downtime) in any calendar month.
Approach to resilience
Systems are hosted on virtualised infrastructure to ensure scalability, high availability and reduce single point of failures. All infrastructure implements an N+1 policy to ensure rapid resolution of infrastructure downtime. Frequent backups, database mirroring and multiple servers in separate geo-locations ensure robust resiliency. Data processed by our accredited data centre is hosted within industry standard data platform that conforms to industry best practices (ISO27001 & G-Cloud IL3) and standards for security as defined in the relevant contract terms and conditions.
Outage reporting
As per our accreditation as a NHS centrally assured clinical support provider our service platform is continually monitored for any interruptions or outages. This is implemented within our Data and Service Management team function. In the event of any issues all end users and stake holders are updated via email alerts.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Limited access network (for example PSN)
  • Username or password
Access restrictions in management interfaces and support channels
Services apply Role Based Access Control (RBAC), to manage which functions a user has access to and which views they are able to see. This leverages local administration rights and approvers.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Limited access network (for example PSN)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Aligned to our British Assessment Bureau certification ISO 27001:2022 we have established Information Security Management systems (ISMS) that ensure our overall approach to information security and the processes we follow, encompassing the information security policy. Regular ISMS review meetings review and refine the functioning of the ISMS, and progress against actions arising from internal audit and external ISO assurance visits. There is a formal annual review of the ISMS to further ensure its continuing suitability and correct implementation. Annual internal audit is used to ensure policies are being followed and identify any remedial actions required. To support the effective delivery of information security, we train all staff on induction, and as part of annual Information Governance refresher training. This approach delivers against our Information Security policy.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
In line with our central NHS assurance we implement a standard ITIL deployment methodology for all Design, Development and Change Management practices for software and platform releases. We use a standard methodology to log, track and manage change requests. All Releases and changes are version controlled through our Change Management process. All system changes complete UAT and Release requirements.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Our vulnerability management approach consists of a combination of internal vulnerability scanners, system monitoring and industry sources. We apply patches within 14 days of their release, unless regarded as urgent which are implemented upon release . We also utilise the NHS CARE-cert and nationally recognised industry vulnerability publications. We also undertake regular penetration testing against OWASP top 10.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Utilising real time firewall based Intrusion Detection / Prevention Systems (IDS / IPS) to actively monitor and prevent intrusions. Alerts are issued on any suspicious activity and investigated immediately by the technical security team.
Incident management type
Supplier-defined controls
Incident management approach
In line with both our central NHS assurance obligations and established industry standards all reported incidents are received and managed by our Data Security and Governance Team. The team implements a standard approach raising an event report, completing a clinical risk assessment, root cause analysis, and resolution report. All events are managed through our established escalation process and defined with NHS England. All documentation is shared with key stake holders and subject to senior team review.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
Yes
Connected networks
  • Public Services Network (PSN)
  • Health and Social Care Network (HSCN)

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
NHS Integrated Care Systems are able to trial the Eclipse SCHOLAR Platform modules to validate their impact. The free trial will be available provided data usage costs are covered for cloud based activity. Clear achievement targets need to be agreed to allow formal evaluation to be implemented and impact demonstrated.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
British Assessment Bureau
ISO/IEC 27001 accreditation date
Monday 19 February 2024
What the ISO/IEC 27001 doesn’t cover
The ISO/IEC 27001 certification covers the information security management system supporting the Eclipse platform and associated prescribing analytics services. It does not extend to customer-owned infrastructure, third-party systems operated independently of Prescribing Services Ltd, or local customer environments beyond PSL’s control.
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
Citation ISO Certification Limited
ISO 9001 accreditation date
Wednesday 12 July 2023
What the ISO 9001 doesn’t cover
The ISO 9001 certification covers Prescribing Services Ltd’s quality management system for the design, delivery and support of its prescribing analytics and Medicines Optimisation services. It does not cover customer-owned processes, third-party systems operated independently of Prescribing Services Ltd, or activities carried out entirely outside the defined scope of the certified quality management system.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
C4646f46-6a7f-4b1f-b46d-4649bb79afa4
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
75fa54ea-e5b5-45c7-b0f0-1d6a35b0712c
Other security certifications
Yes
Any other security certifications
  • NHS DSP Toolkit (DSPT) - Standards exceeded
  • NHS Digital Assured
  • DTAC
  • ICO. Data Protection Register
  • NHSE Section 251 Status

Social value

Section B - Commitment for Future: Delivery
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at support@prescribingservices.org. Tell them what format you need. It will help if you say what assistive technology you use.