Skip to main content

Help us improve the Digital Marketplace - send your feedback

MDClone ltd

ADAMS Platform

Our platform provides self‑service healthcare data exploration, giving clinical, operational and research teams the ability to ask questions, analyse multi‑source patient data and measure impact. It uses privacy‑preserving synthetic data for safe collaboration and includes advanced analytics with an AI copilot to generate insights on demand.

Features

  • Web based service analytics
  • Multi source healthcare data integration
  • Event based longitudinal data model
  • Synthetic data generation
  • Natural language processing for unstructured data
  • AI assisted data exploration
  • Role based access control and permissions
  • Secure authentication and enterprise integration
  • Reusable queries and repeatable workflows
  • Export and collaboration controls

Benefits

  • Enable users to answer clinical, operational and research questions independently
  • Enabling repeatable self-service analysis by reducing manual reporting
  • Enabling safe insight sharing, using synthetic data with reduced risks.
  • Guide service redesign through a support pathway and outcome analysis
  • Extract meaningful insights from unstructured clinical text.
  • Enable consistent benchmarking with reusable queries and cohorts
  • Accelerate research and audit through accessible authorised data.
  • Extend secure data access with strict roles and governance.
  • Support informed decisions by providing data at need.
  • Increase insight generation while reducing cost and effort.

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at matthew.whitty@mdclone.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

1 8 1 0 3 4 3 2 2 5 3 4 9 6 2

Contact

MDClone ltd Matthew Whitty
Telephone: 07590571966
Email: matthew.whitty@mdclone.com

About your service

Service categories

Application Development and Deployment

Integration and orchestration

Integration software

  • Integration Platforms

Event stream processing

  • Stream Processing Software
  • Functions Software
  • Process Mining and Insights Software
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
Hybrid cloud
Service constraints
We provide comprehensive remote support, offering quick issue resolution and regular system monitoring. Minor releases require no downtime, while major releases may involve limited downtime. Minimising disruption, maintenance is scheduled outside business hours where possible, with advance notification.
System requirements
  • A web browser
  • Modern operating system – Windows, macOS or Linux
  • Evergreen web browser, such as Google Chrome or Microsoft Edge
  • Stable internet connection

User support

Email or online ticketing support
Yes
Support response times
We are committed to delivering exceptional customer service with every interaction. We ensure every response is clear, helpful and genuinely supportive. To honour that commitment, we reply to all questions within 24 hours on weekdays and within 48 hours at weekends. Our priority is to provide timely, reliable assistance that gives our customers complete confidence in the care they receive from us.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
EN 301 549
Phone support
No
Web chat support
No
Onsite support
No
Support levels
MDClone currently offers one unified support level: Our standard support package is automatically available to all customers and covers general assistance, issue investigation and access to the support team for day to day operational queries. Standard Support is designed to help customers maintain smooth usage of the platform and resolve challenges as they arise.

Cost of support levels

As our standard support is fully included in the license cost, customers do not incur any additional or separate support fees. All users with an active license automatically receive the same level of support without requiring upgrades, add ons or additional contracts.

Technical Account Manager and Cloud Support Engineer

Our Technical Account Manager (TAM) or Cloud Support Engineer (CSE) experts are available on a case by case basis. Their involvement depends on the nature and complexity of the issue. To ensure customers receive the expertise needed for resolution, strategic guidance or deeper technical support when required, MDClone will engage the appropriate specialist.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Helping customers to start using our service, MDClone provides a comprehensive, multi-model training programmes designed to support different learning styles, roles, and stages of adoption across the organisation.

Our training offerings include:

-Online, self-paced training via the MDClone Online Academy (LMS), covering onboarding, advanced workflows, and role-based learning tracks.
-Structured courses that introduce users to the ADAMS platform, for different types of users - TTT, Admins, End-users, Synthetic.
-+100 Short “how-to” video tutorials embedded within the platform and available through the Academy, enabling just-in-time learning based on the user’s current step or task (available in the LMS and on ADMAS platform)
-Live and recorded webinars focused on new features, best practices, and real-world clinical and operational use cases
-Podcasts that explore thought leadership, customer success stories, and data-driven innovation in healthcare
-Support for trainers and power users, enabling internal knowledge sharing and scalable learning across teams
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
At the end of the contract data extraction:

-Customers receive a complete extraction in their chosen format
-We include agree records, audit trails and configuration artefacts
-Under the customer’s governance, we perform the handover inside their environment
-We confirm access revocation and provide an exit summary for audit
End-of-contract process
End-of-contract process
At the end of the contract, we provide a secure and comprehensive data extraction service. All contract-related data is exported using standard network protocols to a location agreed with the customer. This includes structured data from databases, file-based sources and reports generated during the contract period. The extraction process ensures data integrity, confidentiality and completeness.
The process also includes a final review and validation with the customer to confirm that all required data has been delivered.
Included in the price
Standard end-of-contract data extraction, including databases, file-based sources, reports and dashboards, is included in the contract price. Secure transfer to the customers designated storage environment is covered.
Additional costs
Custom transformations, additional data formatting, integration with third-party systems or extraction beyond agreed data sets may incur extra charges. Any complex or high-volume migrations requiring extended technical support are also treated as optional, additional services.
This approach ensures a smooth transition, maintains data security and gives customers complete control over their information at the end of the contract.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Chrome
  • Other
Application to install
No
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
The service operates as a secure, web-based platform accessed through a browser using enterprise authentication.
Customer data from agreed source systems is ingested and organised into an event based data mode in a dedicated datalake that is built specifically for this purpose, in the client’s environment behind the firewall and under the client’s control. Authorised users explore and analyse this data through a self-service interface to define cohorts, apply filters, and run analyses.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
MDClone has conducted several rounds of interface testing with users who rely on assistive technology. We observed how screen reader users navigate key workflows. We listened closely as they described which labels were unclear and which controls disrupted their flow. We also tested keyboard-only navigation with participants who preferred not to use a mouse. They identified where focus indicators were missing or confusing. We worked with users who enlarged text or used high contrast settings. They highlighted visual elements that failed to scale or maintain clarity. To quickly address barriers, throughout each session, we captured feedback in real time and adjusted prototypes. These tests helped us to refine layouts, improve semantic structure and ensure interactive elements behaved predictably.
API
Yes
What users can and can't do using the API
The API

Users can set up the service through the API by configuring Single Sign-On using SAML with their external Identity Provider. This enables secure and seamless user authentication aligned with organisational access controls. The API supports connection to existing relational databases and file-based data sources via a dedicated ingestion server. Users can register data sources and automate extraction processes through secure API-driven configuration. Ensuring sensitive data processing remains within the organisation’s protected network boundary, secure connectivity to private cloud-based generative AI resources is established using a Site-to-Site VPN.

Making changes

Users can make changes by updating SSO configurations, including identity provider settings and access parameters. The API allows modification of data ingestion schedules and source configurations as operational needs evolve. To trigger external third-party processes, users can manage and update webhook endpoints. The API supports demand-driven export of results to external storage or third-party environments. To ensure compatibility and secure data transfer, exports use standard network protocols.

Limitations and the API

Users cannot bypass authentication, encryption or network security controls through the API. Core system logic, security architecture and VPN configurations cannot be altered via the API. Certain administrative or high-risk changes may require manual approval outside the API.
API documentation
Yes
API documentation formats
  • HTML
  • PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
What can be customised

Users can customise user roles, permissions and workflow rules to match governance and operational processes. To reflect internal escalation paths, we can adjust notification settings and approval routes. To focus on the metrics most relevant to teams, we can tailor dashboards and reports. These options allow organisations to adapt the platform without writing custom code.

How users can customise

Most configuration changes can be made directly through an intuitive interface designed for administrators. Users can adjust workflows, notifications, dashboards and reports quickly and safely. For advanced customisation or complex scenarios, our technical team provides expert support to implement changes. This approach keeps control in the organisation’s hands while maintaining security and governance standards.

Who can customise

Platform Administrators are primarily responsible for making configuration changes. They can manage roles, permissions, workflows, notifications, dashboards and reports. To ensure proper implementation, advanced or complex changes may involve collaboration with the technical team. This setup allows organisations to scale data use, accelerate adoption and maintain consistent governance without relying on bespoke development.

Scaling

Independence of resources
We design the service so one customer’s demand never affects another. We isolate workloads through dedicated resource pools that prevent capacity contention. Our platform automatically scales to handle spikes in data protection, information security and virtualisation tasks. We monitor performance in real time and adjust compute and storage resources before slowdowns occur. We enforce strict tenant isolation to keep processing separate and stable. We use traffic shaping to maintain consistent throughput peak activities. Our architecture protects critical operations, including encryption, classification and federation from external load. These controls ensure every user experiences predictable and reliable performance at all times.

Analytics

Service usage metrics
Yes
Metrics types
To maintain visibility and confidence in service performance, we provide continuous monitoring. A central monitoring cluster tracks system health, logs and audit activity in real-time. Customers receive clear usage and performance metrics through dashboards and scheduled reports, including adoption measures aligned to our volume and value framework. We track Priority 1 incidents against our service level agreement, with a target resolution or workaround within 48 hours. We conduct reviews and root-cause analysis to prevent recurrence, Shared success metrics are discussed in quarterly service reviews. Reporting follows FinOps FOCUS standards, with cadence and thresholds agreed during onboarding.
Reporting types
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Staff screening not performed
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • Other locations
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
Deleted data can’t be directly accessed / Cryptographic Erasure

Data importing and exporting

Data export approach
Users can export their data through the application’s built‑in export features. The data will be exported from within the application to a designated space, with access restrictions defined and controlled by the customer. This process allows users to decide who can view, download or manage exported information. They can select the specific data sets they want to extract and choose the appropriate format. Once the export completes, users can retrieve the files from the designated space and move them into their own systems. This approach ensures secure handling and gives customers full authority over their data throughout the extraction process.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
Other
Other protection between networks
Reassuring customers regarding the safety of their data, MDClone does not store data. All data storage and all data processing occur entirely within the platform inside the organisation’s private infrastructure.
Data protection within supplier network
Other
Other protection within supplier network
To protect data within our own network, we enforce encryption at rest using industry-standard controls. Key management follows customer policies and approved procedures. We isolate traffic using firewalls and network security groups. Private endpoints and network segmentation prevent exposure to the public internet.

We protect data between networks using private connectivity and VPN gateways and restrict access to named support accounts with full logging. We protect data within using a demilitarised zone (DMZ). Compute and storage remain inside our customer's private infrastructure. We monitor events using a central monitoring cluster. Logs and audit trails are captured for all administrative actions.

Availability and resilience

Guaranteed availability
We design our services for high availability and resilience. We continuously measure availability using automated monitoring across critical service components. We offer the following service level agreement (SLA):

1. No system access (blocking) – production use is completely stopped. MDClone will begin work within 4 working hours and we will aim to resolve within 48 working hours.
2. Critical – production use is severely impacted and cannot reasonably continue. MDClone will begin work within 96 working hours.
3. High – important features are unavailable with no workaround materially impacting productivity. MDClone’s initial response will be with 24 working hours.
4. Medium – important standard features are unavailable (workaround exists) or less significant features are unavailable (no reasonable workaround). MDClone’s initial response will be within 48 working hours.
5. Low – request for information enhancement or documentation clarification with no impact on platform operation. MDClone will provide a clarification within 10 working days.

We do not offer refunds however, in the unlikely event, we do not meet the SLAs credits we would review all availability incidents, communicate root causes, and implement corrective actions to prevent recurrence.
Approach to resilience
MDClone designs our systems to protect critical healthcare assets and remain resilient under operational, technical and security stress. The platform deploys entirely within the customer’s own private infrastructure, on-premises or private cloud, so it inherits and aligns with existing resilience, availability, and recovery controls already approved for healthcare data.
We build resilience through layered architecture, fault isolation and support for high-availability configurations. Customers can deploy redundant components, replicate storage and use native snapshot and backup tooling to meet their RPO and RTO objectives. To ensure safe roll backs, we require full system backups before major upgrades.

To meet data residency and asset protection requirements, the datacentre setup follows customer-defined standards and includes resilient power, networking and physical security, with compute and storage kept in the same region. To reduce blast radius and support controlled recovery, the platform operates within a dedicated DMZ.

To improve resilience, we continuously monitor platform health, manage changes carefully and review incidents. Detailed datacentre architecture and resilience documentation are available on request.
Outage reporting
MDClone reports outages through clear, direct communication aligned with customer environments and governance.The platform runs inside the customer’s private infrastructure, so infrastructure-level outages surface through the customer’s existing monitoring and alerting tools.

For platform-related issues, MDClone uses proactive monitoring and logs health across core services and dependencies. When we detect a service-impacting issue, we raise an incident internally and notify the customer through agreed channels.

We provide outage notifications and updates via email and the customer support portal. Customers can view incident status, progress updates and resolution notes directly within the portal.

We do not operate a public status dashboard because the service is customer-hosted and environment-specific. We do not expose a public outage API, as monitoring integrates with customer tooling. For major incidents, we provide regular updates, clear timelines and post-incident reports.

For critical or prolonged outages the assigned Account Manager coordinates communication.

Identity and authentication

User authentication needed
Yes
User authentication
Other
Other user authentication
Users are authenticated through secure, enterprise-aligned mechanisms, primarily via Single Sign-On (SSO) and SAML integration with the organisation’s identity provider. Access is role-based, with configurable permissions controlling visibility and functionality according to governance policies. All authentication occurs within the customer’s private infrastructure and no credentials or sensitive data leave the environment. Ensuring only authorised personnel access the platform, Administrator-managed accounts are audited and monitored. Optional AI copilot features operate under the same access controls. Together, these measures ensure secure, compliant user authentication while enabling clinicians, researchers and operational teams to explore healthcare data safely and efficiently.
Access restrictions in management interfaces and support channels
Aligned to organisational governance policies, we restrict access in management interfaces and support channels using role-based permissions. Ensuring identity verification, users authenticate via enterprise SSO or SAML. Administrators assign roles that control visibility and allowed actions across datasets and features.

Providing full auditability, all support access occurs through a secure jump box with individual-named accounts. Synthetic data limits exposure during collaboration and AI copilot interactions respect these permissions. Monitoring and logging track every activity for compliance and traceability. Data never leaves the customer environment unless explicitly authorised. These measures maintain privacy, security and governance while enabling self-service exploration and collaboration.
Access restriction testing frequency
At least once a year
Management access authentication
Multi-Factor Authentication (MFA)

Audit information for users

Access to user activity audit information
You control when users can access audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
You control when users can access audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
MDClone also holds ISO27799:2016 for information security in the health sector.
Information security policies and processes
MDClone follows ISO 27001, Cyber Essentials and privacy-by-design principles. Policies cover role-based access, data encryption and synthetic data generation. Staff report via a secure jump box to the Account Manager, who escalates incidents through a structured tiered process.

MDClone monitors compliance through audit logs, centralised platform monitoring and annual penetration tests. Access controls and permissions are enforced continuously, and users are trained via e-learning and live sessions. All procedures ensure only authorised personnel can access sensitive data, while governance and reporting structures guarantee adherence to internal policies and regulatory requirements.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Tracking components

MDClone tracks service components through their lifecycle using a centralised configuration management system, recording versions, dependencies and ownership. We formally assess changes before deployment, including evaluation of potential security, privacy and operational impacts. Ensuring synthetic or live datasets remain protected, risk analysis considers regulatory compliance, access controls and data sensitivity.

Assessing changes

MDClone logs approved changes in isolated environments and monitors post-release for stability. Minor updates follow streamlined procedures, while major changes require advance notice and stakeholder sign-off. Ensuring the platform evolves securely and reliably, continuous audit and monitoring enable traceability, accountability and adherence to ISO 27001-aligned practices.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Assessing threats

MDClone continuously monitors healthcare data ecosystems, identifying potential vulnerabilities using automated scanning and manual reviews. Threat intelligence comes from ISO 27001 alerts, vendor advisories, and industry sources.

Deploying patches

Critical patches are deployed within 24–48 hours, with minor updates scheduled during maintenance windows. Our processes ensure minimal disruption while maintaining platform integrity and security compliance.

Threat intelligence sources

MDClone gathers insights from trusted security feeds, vendor bulletins, government advisories, industry forums and internal penetration tests. AI-assisted monitoring enhances early detection and prioritisation of risks.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
How we identify potential compromises

To detect unusual patterns or potential compromises, we continuously monitor platform activity and system logs. Automated alerts and audit logs support rapid detection.

How we respond when we find a potential compromise

Alerts trigger immediate investigation by our security team using predefined procedures. Confirmed threats are isolated, contained and we notify the customer. Investigations include root-cause analysis, audit trail review and post-incident reporting.

How quickly we respond to incidents

Our response follows a priority-based model. Ensuring minimal impact while maintaining strict privacy and regulatory compliance, we address critical incidents within four working hours
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Whether you have pre-defined processes for common events

MDClone uses pre-defined procedures for common incidents. To investigate, contain and resolve issues quickly, the security and support teams follow structured workflows.

How users report incidents

Users submit incidents through the central Customer Support Portal. Tickets capture priority, context and impact. Account Managers coordinate resolution and provide transparent updates.

MDClone incident reports

For all incidents, MDClone delivers post-incident summaries. Critical events include root cause analysis, mitigation actions and recommendations. Reports are shared promptly with customers for review and follow-up.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
2.5%
Between £2,500,001 and £5,000,000
5%
Over £5,000,001
10%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
The Standards Institution of Israel
ISO/IEC 27001 accreditation date
Thursday 12 July 2018
What the ISO/IEC 27001 doesn’t cover
There is nothing specified for what is not covered, but the certificate specifies that the following is covered: 'IT Operations Department related to big data technology for healthcare IT management.'
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
5341cc2e-df40-4f2f-b500-c25cb3457564
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
Yes
Any other security certifications
ISO27799:2016

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Introducing transparency to pay and reward processes

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at matthew.whitty@mdclone.com. Tell them what format you need. It will help if you say what assistive technology you use.