ADAMS Platform
Our platform provides self‑service healthcare data exploration, giving clinical, operational and research teams the ability to ask questions, analyse multi‑source patient data and measure impact. It uses privacy‑preserving synthetic data for safe collaboration and includes advanced analytics with an AI copilot to generate insights on demand.
Features
- Web based service analytics
- Multi source healthcare data integration
- Event based longitudinal data model
- Synthetic data generation
- Natural language processing for unstructured data
- AI assisted data exploration
- Role based access control and permissions
- Secure authentication and enterprise integration
- Reusable queries and repeatable workflows
- Export and collaboration controls
Benefits
- Enable users to answer clinical, operational and research questions independently
- Enabling repeatable self-service analysis by reducing manual reporting
- Enabling safe insight sharing, using synthetic data with reduced risks.
- Guide service redesign through a support pathway and outcome analysis
- Extract meaningful insights from unstructured clinical text.
- Enable consistent benchmarking with reusable queries and cohorts
- Accelerate research and audit through accessible authorised data.
- Extend secure data access with strict roles and governance.
- Support informed decisions by providing data at need.
- Increase insight generation while reducing cost and effort.
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 8 1 0 3 4 3 2 2 5 3 4 9 6 2
Contact
MDClone ltd
Matthew Whitty
Telephone: 07590571966
Email: matthew.whitty@mdclone.com
About your service
- Service categories
-
Application Development and Deployment
Integration and orchestration
Integration software
- Integration Platforms
Event stream processing
- Stream Processing Software
- Functions Software
- Process Mining and Insights Software
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Hybrid cloud
- Service constraints
- We provide comprehensive remote support, offering quick issue resolution and regular system monitoring. Minor releases require no downtime, while major releases may involve limited downtime. Minimising disruption, maintenance is scheduled outside business hours where possible, with advance notification.
- System requirements
-
- A web browser
- Modern operating system – Windows, macOS or Linux
- Evergreen web browser, such as Google Chrome or Microsoft Edge
- Stable internet connection
User support
- Email or online ticketing support
- Yes
- Support response times
- We are committed to delivering exceptional customer service with every interaction. We ensure every response is clear, helpful and genuinely supportive. To honour that commitment, we reply to all questions within 24 hours on weekdays and within 48 hours at weekends. Our priority is to provide timely, reliable assistance that gives our customers complete confidence in the care they receive from us.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- EN 301 549
- Phone support
- No
- Web chat support
- No
- Onsite support
- No
- Support levels
-
MDClone currently offers one unified support level: Our standard support package is automatically available to all customers and covers general assistance, issue investigation and access to the support team for day to day operational queries. Standard Support is designed to help customers maintain smooth usage of the platform and resolve challenges as they arise.
Cost of support levels
As our standard support is fully included in the license cost, customers do not incur any additional or separate support fees. All users with an active license automatically receive the same level of support without requiring upgrades, add ons or additional contracts.
Technical Account Manager and Cloud Support Engineer
Our Technical Account Manager (TAM) or Cloud Support Engineer (CSE) experts are available on a case by case basis. Their involvement depends on the nature and complexity of the issue. To ensure customers receive the expertise needed for resolution, strategic guidance or deeper technical support when required, MDClone will engage the appropriate specialist. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Helping customers to start using our service, MDClone provides a comprehensive, multi-model training programmes designed to support different learning styles, roles, and stages of adoption across the organisation.
Our training offerings include:
-Online, self-paced training via the MDClone Online Academy (LMS), covering onboarding, advanced workflows, and role-based learning tracks.
-Structured courses that introduce users to the ADAMS platform, for different types of users - TTT, Admins, End-users, Synthetic.
-+100 Short “how-to” video tutorials embedded within the platform and available through the Academy, enabling just-in-time learning based on the user’s current step or task (available in the LMS and on ADMAS platform)
-Live and recorded webinars focused on new features, best practices, and real-world clinical and operational use cases
-Podcasts that explore thought leadership, customer success stories, and data-driven innovation in healthcare
-Support for trainers and power users, enabling internal knowledge sharing and scalable learning across teams - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
At the end of the contract data extraction:
-Customers receive a complete extraction in their chosen format
-We include agree records, audit trails and configuration artefacts
-Under the customer’s governance, we perform the handover inside their environment
-We confirm access revocation and provide an exit summary for audit - End-of-contract process
-
End-of-contract process
At the end of the contract, we provide a secure and comprehensive data extraction service. All contract-related data is exported using standard network protocols to a location agreed with the customer. This includes structured data from databases, file-based sources and reports generated during the contract period. The extraction process ensures data integrity, confidentiality and completeness.
The process also includes a final review and validation with the customer to confirm that all required data has been delivered.
Included in the price
Standard end-of-contract data extraction, including databases, file-based sources, reports and dashboards, is included in the contract price. Secure transfer to the customers designated storage environment is covered.
Additional costs
Custom transformations, additional data formatting, integration with third-party systems or extraction beyond agreed data sets may incur extra charges. Any complex or high-volume migrations requiring extended technical support are also treated as optional, additional services.
This approach ensures a smooth transition, maintains data security and gives customers complete control over their information at the end of the contract. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Chrome
- Other
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
-
The service operates as a secure, web-based platform accessed through a browser using enterprise authentication.
Customer data from agreed source systems is ingested and organised into an event based data mode in a dedicated datalake that is built specifically for this purpose, in the client’s environment behind the firewall and under the client’s control. Authorised users explore and analyse this data through a self-service interface to define cohorts, apply filters, and run analyses. - Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- MDClone has conducted several rounds of interface testing with users who rely on assistive technology. We observed how screen reader users navigate key workflows. We listened closely as they described which labels were unclear and which controls disrupted their flow. We also tested keyboard-only navigation with participants who preferred not to use a mouse. They identified where focus indicators were missing or confusing. We worked with users who enlarged text or used high contrast settings. They highlighted visual elements that failed to scale or maintain clarity. To quickly address barriers, throughout each session, we captured feedback in real time and adjusted prototypes. These tests helped us to refine layouts, improve semantic structure and ensure interactive elements behaved predictably.
- API
- Yes
- What users can and can't do using the API
-
The API
Users can set up the service through the API by configuring Single Sign-On using SAML with their external Identity Provider. This enables secure and seamless user authentication aligned with organisational access controls. The API supports connection to existing relational databases and file-based data sources via a dedicated ingestion server. Users can register data sources and automate extraction processes through secure API-driven configuration. Ensuring sensitive data processing remains within the organisation’s protected network boundary, secure connectivity to private cloud-based generative AI resources is established using a Site-to-Site VPN.
Making changes
Users can make changes by updating SSO configurations, including identity provider settings and access parameters. The API allows modification of data ingestion schedules and source configurations as operational needs evolve. To trigger external third-party processes, users can manage and update webhook endpoints. The API supports demand-driven export of results to external storage or third-party environments. To ensure compatibility and secure data transfer, exports use standard network protocols.
Limitations and the API
Users cannot bypass authentication, encryption or network security controls through the API. Core system logic, security architecture and VPN configurations cannot be altered via the API. Certain administrative or high-risk changes may require manual approval outside the API. - API documentation
- Yes
- API documentation formats
-
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
What can be customised
Users can customise user roles, permissions and workflow rules to match governance and operational processes. To reflect internal escalation paths, we can adjust notification settings and approval routes. To focus on the metrics most relevant to teams, we can tailor dashboards and reports. These options allow organisations to adapt the platform without writing custom code.
How users can customise
Most configuration changes can be made directly through an intuitive interface designed for administrators. Users can adjust workflows, notifications, dashboards and reports quickly and safely. For advanced customisation or complex scenarios, our technical team provides expert support to implement changes. This approach keeps control in the organisation’s hands while maintaining security and governance standards.
Who can customise
Platform Administrators are primarily responsible for making configuration changes. They can manage roles, permissions, workflows, notifications, dashboards and reports. To ensure proper implementation, advanced or complex changes may involve collaboration with the technical team. This setup allows organisations to scale data use, accelerate adoption and maintain consistent governance without relying on bespoke development.
Scaling
- Independence of resources
- We design the service so one customer’s demand never affects another. We isolate workloads through dedicated resource pools that prevent capacity contention. Our platform automatically scales to handle spikes in data protection, information security and virtualisation tasks. We monitor performance in real time and adjust compute and storage resources before slowdowns occur. We enforce strict tenant isolation to keep processing separate and stable. We use traffic shaping to maintain consistent throughput peak activities. Our architecture protects critical operations, including encryption, classification and federation from external load. These controls ensure every user experiences predictable and reliable performance at all times.
Analytics
- Service usage metrics
- Yes
- Metrics types
- To maintain visibility and confidence in service performance, we provide continuous monitoring. A central monitoring cluster tracks system health, logs and audit activity in real-time. Customers receive clear usage and performance metrics through dashboards and scheduled reports, including adoption measures aligned to our volume and value framework. We track Priority 1 incidents against our service level agreement, with a target resolution or workaround within 48 hours. We conduct reviews and root-cause analysis to prevent recurrence, Shared success metrics are discussed in quarterly service reviews. Reporting follows FinOps FOCUS standards, with cadence and thresholds agreed during onboarding.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Staff screening not performed
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- Other locations
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- Users can export their data through the application’s built‑in export features. The data will be exported from within the application to a designated space, with access restrictions defined and controlled by the customer. This process allows users to decide who can view, download or manage exported information. They can select the specific data sets they want to extract and choose the appropriate format. Once the export completes, users can retrieve the files from the designated space and move them into their own systems. This approach ensures secure handling and gives customers full authority over their data throughout the extraction process.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- Other
- Other protection between networks
- Reassuring customers regarding the safety of their data, MDClone does not store data. All data storage and all data processing occur entirely within the platform inside the organisation’s private infrastructure.
- Data protection within supplier network
- Other
- Other protection within supplier network
-
To protect data within our own network, we enforce encryption at rest using industry-standard controls. Key management follows customer policies and approved procedures. We isolate traffic using firewalls and network security groups. Private endpoints and network segmentation prevent exposure to the public internet.
We protect data between networks using private connectivity and VPN gateways and restrict access to named support accounts with full logging. We protect data within using a demilitarised zone (DMZ). Compute and storage remain inside our customer's private infrastructure. We monitor events using a central monitoring cluster. Logs and audit trails are captured for all administrative actions.
Availability and resilience
- Guaranteed availability
-
We design our services for high availability and resilience. We continuously measure availability using automated monitoring across critical service components. We offer the following service level agreement (SLA):
1. No system access (blocking) – production use is completely stopped. MDClone will begin work within 4 working hours and we will aim to resolve within 48 working hours.
2. Critical – production use is severely impacted and cannot reasonably continue. MDClone will begin work within 96 working hours.
3. High – important features are unavailable with no workaround materially impacting productivity. MDClone’s initial response will be with 24 working hours.
4. Medium – important standard features are unavailable (workaround exists) or less significant features are unavailable (no reasonable workaround). MDClone’s initial response will be within 48 working hours.
5. Low – request for information enhancement or documentation clarification with no impact on platform operation. MDClone will provide a clarification within 10 working days.
We do not offer refunds however, in the unlikely event, we do not meet the SLAs credits we would review all availability incidents, communicate root causes, and implement corrective actions to prevent recurrence. - Approach to resilience
-
MDClone designs our systems to protect critical healthcare assets and remain resilient under operational, technical and security stress. The platform deploys entirely within the customer’s own private infrastructure, on-premises or private cloud, so it inherits and aligns with existing resilience, availability, and recovery controls already approved for healthcare data.
We build resilience through layered architecture, fault isolation and support for high-availability configurations. Customers can deploy redundant components, replicate storage and use native snapshot and backup tooling to meet their RPO and RTO objectives. To ensure safe roll backs, we require full system backups before major upgrades.
To meet data residency and asset protection requirements, the datacentre setup follows customer-defined standards and includes resilient power, networking and physical security, with compute and storage kept in the same region. To reduce blast radius and support controlled recovery, the platform operates within a dedicated DMZ.
To improve resilience, we continuously monitor platform health, manage changes carefully and review incidents. Detailed datacentre architecture and resilience documentation are available on request. - Outage reporting
-
MDClone reports outages through clear, direct communication aligned with customer environments and governance.The platform runs inside the customer’s private infrastructure, so infrastructure-level outages surface through the customer’s existing monitoring and alerting tools.
For platform-related issues, MDClone uses proactive monitoring and logs health across core services and dependencies. When we detect a service-impacting issue, we raise an incident internally and notify the customer through agreed channels.
We provide outage notifications and updates via email and the customer support portal. Customers can view incident status, progress updates and resolution notes directly within the portal.
We do not operate a public status dashboard because the service is customer-hosted and environment-specific. We do not expose a public outage API, as monitoring integrates with customer tooling. For major incidents, we provide regular updates, clear timelines and post-incident reports.
For critical or prolonged outages the assigned Account Manager coordinates communication.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Other
- Other user authentication
- Users are authenticated through secure, enterprise-aligned mechanisms, primarily via Single Sign-On (SSO) and SAML integration with the organisation’s identity provider. Access is role-based, with configurable permissions controlling visibility and functionality according to governance policies. All authentication occurs within the customer’s private infrastructure and no credentials or sensitive data leave the environment. Ensuring only authorised personnel access the platform, Administrator-managed accounts are audited and monitored. Optional AI copilot features operate under the same access controls. Together, these measures ensure secure, compliant user authentication while enabling clinicians, researchers and operational teams to explore healthcare data safely and efficiently.
- Access restrictions in management interfaces and support channels
-
Aligned to organisational governance policies, we restrict access in management interfaces and support channels using role-based permissions. Ensuring identity verification, users authenticate via enterprise SSO or SAML. Administrators assign roles that control visibility and allowed actions across datasets and features.
Providing full auditability, all support access occurs through a secure jump box with individual-named accounts. Synthetic data limits exposure during collaboration and AI copilot interactions respect these permissions. Monitoring and logging track every activity for compliance and traceability. Data never leaves the customer environment unless explicitly authorised. These measures maintain privacy, security and governance while enabling self-service exploration and collaboration. - Access restriction testing frequency
- At least once a year
- Management access authentication
- Multi-Factor Authentication (MFA)
Audit information for users
- Access to user activity audit information
- You control when users can access audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- You control when users can access audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- MDClone also holds ISO27799:2016 for information security in the health sector.
- Information security policies and processes
-
MDClone follows ISO 27001, Cyber Essentials and privacy-by-design principles. Policies cover role-based access, data encryption and synthetic data generation. Staff report via a secure jump box to the Account Manager, who escalates incidents through a structured tiered process.
MDClone monitors compliance through audit logs, centralised platform monitoring and annual penetration tests. Access controls and permissions are enforced continuously, and users are trained via e-learning and live sessions. All procedures ensure only authorised personnel can access sensitive data, while governance and reporting structures guarantee adherence to internal policies and regulatory requirements. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
Tracking components
MDClone tracks service components through their lifecycle using a centralised configuration management system, recording versions, dependencies and ownership. We formally assess changes before deployment, including evaluation of potential security, privacy and operational impacts. Ensuring synthetic or live datasets remain protected, risk analysis considers regulatory compliance, access controls and data sensitivity.
Assessing changes
MDClone logs approved changes in isolated environments and monitors post-release for stability. Minor updates follow streamlined procedures, while major changes require advance notice and stakeholder sign-off. Ensuring the platform evolves securely and reliably, continuous audit and monitoring enable traceability, accountability and adherence to ISO 27001-aligned practices. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
Assessing threats
MDClone continuously monitors healthcare data ecosystems, identifying potential vulnerabilities using automated scanning and manual reviews. Threat intelligence comes from ISO 27001 alerts, vendor advisories, and industry sources.
Deploying patches
Critical patches are deployed within 24–48 hours, with minor updates scheduled during maintenance windows. Our processes ensure minimal disruption while maintaining platform integrity and security compliance.
Threat intelligence sources
MDClone gathers insights from trusted security feeds, vendor bulletins, government advisories, industry forums and internal penetration tests. AI-assisted monitoring enhances early detection and prioritisation of risks. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
How we identify potential compromises
To detect unusual patterns or potential compromises, we continuously monitor platform activity and system logs. Automated alerts and audit logs support rapid detection.
How we respond when we find a potential compromise
Alerts trigger immediate investigation by our security team using predefined procedures. Confirmed threats are isolated, contained and we notify the customer. Investigations include root-cause analysis, audit trail review and post-incident reporting.
How quickly we respond to incidents
Our response follows a priority-based model. Ensuring minimal impact while maintaining strict privacy and regulatory compliance, we address critical incidents within four working hours - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
Whether you have pre-defined processes for common events
MDClone uses pre-defined procedures for common incidents. To investigate, contain and resolve issues quickly, the security and support teams follow structured workflows.
How users report incidents
Users submit incidents through the central Customer Support Portal. Tickets capture priority, context and impact. Account Managers coordinate resolution and provide transparent updates.
MDClone incident reports
For all incidents, MDClone delivers post-incident summaries. Critical events include root cause analysis, mitigation actions and recommendations. Reports are shared promptly with customers for review and follow-up. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 2.5%
- Between £2,500,001 and £5,000,000
- 5%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- The Standards Institution of Israel
- ISO/IEC 27001 accreditation date
- Thursday 12 July 2018
- What the ISO/IEC 27001 doesn’t cover
- There is nothing specified for what is not covered, but the certificate specifies that the following is covered: 'IT Operations Department related to big data technology for healthcare IT management.'
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 5341cc2e-df40-4f2f-b500-c25cb3457564
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- Yes
- Any other security certifications
- ISO27799:2016
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Introducing transparency to pay and reward processes
-