Access CM - Care Management
The CM platform is the award-winning software at the heart of our services to Local Authorities & Community Health customers. It’s used by over 95 Councils for 1) a single workforce/care management solution to run "in-house/internal" care services; 2) to manage quality, risk and payment calculations for community based Providers.
Features
- Scheduling/rostering of community base care workers
- Mobile app for care workers providing diary & care records
- Full digital care records with eMAR medication & digital forms
- Real-time visit monitoring of care workers using landline or mobile
- Calculation of mileage, expenses, payroll, invoices
- Quality, risk & capacity management of care providers
- Billing arbitration between commissioned, planned & actual delivery
- Reporting, dashboards and business intelligence
- Outcomes based monitoring/management of care delivery
- Fully hosted, SaaS, 24/7/365 technical support
Benefits
- Workforce management automation / efficiencies
- Automation of schedule/roster creation
- Reduction in travel costs, office administrators
- Real-time visibility of care delivery , missed visits, visit length
- Administration automation/savings of payroll, expenses & billing calculations
- Increased care service capacity from same care workers
- Secure full digital care records available on mobile/web browser
- Significant savings based on actual care delivery not commissioned/planned
- Automation of billing calculations through flexible rule based arbitration
- Analytics to improve performance, decision making & lower risk
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 7 5 4 7 5 5 1 3 0 8 2 3 1 4
Contact
ACCESS UK LTD
Stacey Graham
Telephone: 01206322575
Email: buyer.enablement@theaccessgroup.com
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Adult Social Care
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
-
- Solution supported on manufacturer supported web browsers and mobile operating systems (Android & iOS)
- Planned software maintenance window is 12 midnight - 5am
- Support level/SLA determined by Customer Success Plan selected - System requirements
-
- Mobile app runs on manufacturer supported Android/iOS smart phones
- Parts of solution use Citrix with free browser/OS plug-in
User support
- Email or online ticketing support
- Yes
- Support response times
- Call response times depend on the priority of the issue and the Customer Success Plan selected - please see the CM Service Definition. For urgent matters we'll respond within 1 hour.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- N/A
- Onsite support
- Yes, at extra cost
- Support levels
- As a Standard Plan customer you benefit from faster response times and can access our support teams via telephone and live chat, as well as through our Customer Success portal. To help your team be more productive, you are provided with continued access to our e-learning content as well as a programme of Success webinars, designed to keep you up to date with new features and share best-practice advice and guidance. Our Premier Plan enables your team to achieve more and improve productivity through an ongoing relationship with your own designated Customer Success Manager. Your Customer Success Manager will get to understand how you’re using the technology and will advise you on how to get more from it. Our Premier+ Plan provides the highest level of dedicated support to maximise your technology investment. Building on the Premier Plan benefits, you receive more frequent consultations with your designated Customer Success Manager and also benefit from a Lead Technical Support Engineer who prioritises your complex and business-critical issues, ensuring rapid resolution when it matters most. Costs for each plan are contained within the pricing document.
- Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
Access provides a comprehensive on-boarding process which has been designed for public sector needs/processes. Each solution has an implementation Flightpath that defines a process to onboard the solution from initial scoping through to go-live support. Flexible options are available so we can provide a tailored approach/project to meet your exact needs.
The implementation process has been designed so the solution is designed and configured in-line with the training around the system to build in a step by step process to align to your needs. Training sessions are fairly short and staggered as the system is configured rather than a "big bang" approach or self-teach.
The default implementation these days is for an online remote implementation, which is fully proven and has been adjusted to work best to the new ways of working, however onsite sessions can be run if needed. Online videos and documentation are available through our online portal so new users can get up to speed through self-teach if need be. - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
-
Customers have a number of options available to them:
1) Data Extraction Wizard - a step by step wizard process that allows you to extract data on bulk from the system.
2) Reports & Dashboards - over 140 standard reports and the ability to write your own reports/dashboards (with CMBI) means data can be easily extracted.
3) Write a Bespoke Extract yourself - using CMBI you can create your own data extract and run this as many times as you like. A repeating pattern can be defined.
4) Access produces Bespoke Extract - as a chargeable service we can extract the data you need - a specification will be agreed and we'll provide the data in the format needed. - End-of-contract process
-
At the end of the contract we will agree an Exit Plan between us. This will cleanly shutdown the system, comply with GDPR in terms of data destruction etc and extract any data that you need.
As outlined above on the previous question there are 3 options a customer can execute to extract their data themselves. If these are not suitable then Access can extract the data to a bespoke scope and format - this is an additional chargeable service.
Once any necessary data has been extracted we will decommission the system and destroy the data in-line with GDPR requirements. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Access Group's onboarding and offboarding documentation is accessible through the Customer Success Portal (https://access-support.force.com/Support/s/), which provides 24/7 online access to comprehensive resources including a knowledge base with FAQs, product guides, e-learning content, on-demand webinar recordings, feature release updates, and training materials that can answer most day-to-day user questions. All users can register for portal access regardless of their Success Plan level (Essential, Standard, or Premier), with additional support available through online case submission for all customers, telephone support for Standard and Premier customers, and dedicated resources like Customer Success Managers and Lead Technical Support Engineers for Premier customers, ensuring documentation and guidance is readily available throughout the entire customer lifecycle from initial onboarding through ongoing system use and any eventual offboarding scenarios.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Windows
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The CM solution includes a mobile app (called CM Mobile) for the Care Workers that includes their work schedule and a digital care record of the Service Users they are visiting. Visit verification is possible plus the recording of the care delivered, tasks, eMAR, digital forms, outcomes, care notes etc. App also includes a messaging solution to work colleagues, lone worker safety and expenses.
- Service interface
- No
- User support accessibility
- None or don’t know
- API
- No
- Customisation available
- Yes
- Description of customisation
-
Extensive in-product configuration allows customisation of solution to suite individual customer needs. Some examples are provided below:
- all drop down lists in CallConfirmLive can be changed by customer admin users.
- Different interface styles are available to suit individual's needs e.g. for colour blindness.
- Standard reports are highly configurable plus customer can build their own reports, dashboards and extracts using CMBI
- Multiple fields allow customers to structure their teams as needed by geography, service, contract etc so very flexible.
- Any type of repeating shift pattern can be created by the users
- Pay & invoicing rates can be set/changed by customers
- Content of Client Portal can be configured by the customer to control what stakeholders see.
All configuration is controlled by administrative rights that are managed by the customer.
Scaling
- Independence of resources
- All systems are scaled to operate at peak demand. Allocation of resource through a combination of monitoring, auto-scaling and resource isolation are designed to minimise any impact of other customers, or the so-called 'noisy-neighbour' effect. In the unlikely event of any system reaching pre-defined thresholds or KPIs, systems where performance is impacted for a specific platform, resources are re-allocated to ensure that this is rectified.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Our monthly invoice provides a breakdown of volumes used so provides the usage of the variable system volumes (e.g. carers, service users, SMS messages etc).
We can also provide support desk statistics and availability uptime.
Reporting of SLA performance and KPIs can also be provided. - Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
-
There are a number of ways users of the system can extract their data:
1) Data Extraction Wizard - step by step wizard that allows you to extract data to a flat file.
2) Reports & Dashboards - the system comes with over 140 standard reports + you can build your own reports and dashboards using CMBI.
3) CMBI - build your data extract that will execute automatically on a recurring basis set by you with distribution options. - Data export formats
-
- CSV
- Other
- Other data export formats
-
- Excel
- Data import formats
-
- CSV
- Other
- Other data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- The threshold for application availability in any month is 99.8%, measured on a 24 hours per day, 365 days per year basis, excluding planned or previously agreed downtime for Maintenance.
- Approach to resilience
-
There are several levels of resilience and failover built into the live production solution, including:
- Virtualised environment, providing protection should a physical server fail
- Leading anti-virus software within the virtualised environment to capture known viruses and malware to proactively prevent loss of signal and system interruption
- Enterprise grade NetApp, that tolerates multi-disk failures without data loss
- Multiple redundant servers available to handle calls/failover
- Multiple resilient internet lines into the production environment
- Multiple resilient routes for the landline monitoring solution
- Alternate data centre hosting for our mobile monitoring solution to allow fast failover should a significant data centre issue occur. - Outage reporting
- We provide a customer accessible Status Page that shows the key solution elements with their current status. Planned maintenance is notified through the portal and any degradation of service and outages are also recorded. Updates are provided hourly as to progress of an issue. An email alert mechanism is available so any customer can receive automated email notifications off the Status Page so are pushed communication of issues and their resolution.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
-
We operate a role based access control, based on the last least privileged access, this applies to all our services.
At an application level the only staff that have access to customer's data is the support team and any project/service delivery staff that have been given permission. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- All controls included within Annex A of the ISO27001:2013 standard. Statement Of Applicability (SOA) available on request.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Changes to the production environment are controlled by the Change Management process so all development changes are subject to this procedure. Development teams are responsible for raising a formal Request for Change into our configuration management system. The change cannot go ahead until it has been approved by a team of approvers from across the organisation including security. Changes are tested by the Quality Assurance (QA) team and deployed by the Production Team. Continuous Integration tools provide an audit of what has been released, where and when. Octopus Deploy enables constraints to ensure a Feature/Development branch cannot accidently be released.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
Access uses multiple defense layers including Layer7 Firewalls, IDS/IPS, behavioral analytics, and phishing protection. Palo Alto Firewalls inspect traffic using App-ID technology with WildFire threat detection. Weekly automated vulnerability scans via Tenable IO and Nessus supplement 24/7/365 monitoring through a Hybrid CSOC with managed detection providers.
Critical security patches deploy within 72 hours based on CVE scores and mitigations. Non-critical OS patches apply within one month, first to non-production then production environments. Anti-virus signatures update hourly.
Threat intelligence sources include vendor repositories, internet-based feeds, WildFire cloud sandboxing, Cortex XDR behavioral monitoring, Palo Alto threat feeds, and managed security service providers. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- We have traffic monitoring and content based alerting which alerts on changes to the site and/or traffic flows implemented at infrastructure and application level. We proactively monitor third party suppliers (hardware, OS, application/web and database server software) vulnerability reporting and security fix availability. Any vulnerabilities found and fixes provided by third parties are patched by our infrastructure team in a timescale appropriate for their level of severity. Any penetration test findings are fixed by Development in a timescale appropriate for their level of severity. Our infrastructure response for the highest priority incidents is within 1 hour on a 24/7/365 basis.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- We operate a robust incident management process in line with ISO27001:2013. Staff are encouraged to report all incidents using a pre-defined process using the EQMS system that formally tracks and controls all incidents. The first aim is to recover from an incident in an effective and timely manner, whilst the second aim is to thoroughly investigate the incident cause and implement corrective actions and process change to reduce the risk of any re-occurrence. The Incident Management Team take immediate action to secure and contain the incident and reduce the risk of further breach or incident impact.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 5%
- Between £250,000 and £500,000
- 6%
- Between £500,001 and £1,000,000
- 12%
- Between £1,000,001 and £2,500,000
- 15%
- Between £2,500,001 and £5,000,000
- 18%
- Over £5,000,001
- 25%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Alcumus ISOQAR
- ISO/IEC 27001 accreditation date
- Saturday 4 January 2014
- What the ISO/IEC 27001 doesn’t cover
- Nothing is excluded from the standard certification.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- BSI
- ISO 9001 accreditation date
- Friday 1 September 2023
- What the ISO 9001 doesn’t cover
- The scope covers the design, integration, maintenance and hosting of managed information systems and software applications, consultancy, user training and support for the Health, Education, Social Care and Local authorities. Excluding all other products that fall outside of this scope.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 88f162a5-ea3c-4f9a-83d5-42769c7d8459
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
- Other security certifications
- Yes
- Any other security certifications
-
- ISO 42001
- ISO 27701
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
-