Context MDT
Context MDT is a secure, cloud-based multidisciplinary team platform for healthcare providers. It enables clinicians to review imaging, pathology and clinical data, collaborate in real time, record decisions, and streamline cancer pathways. The service improves efficiency, reduces delays and supports safe, compliant, auditable MDT decision-making.
Features
- Secure cloud-based MDT platform for clinical collaboration and decisions.
- Real-time viewing of imaging, pathology and clinical documents.
- Integrated video conferencing for virtual MDT meetings.
- Structured case templates for consistent decision recording.
- Role-based access control with full audit logging.
- Automatic recommendation creation and case workflow management.
- Fast upload and display of DICOM imaging.
- Centralised case repository accessible across organisations.
- Azure-hosted service with high availability and resilience.
- Comprehensive governance reporting and export capability.
Benefits
- Speeds up MDT preparation and reduces administrative workload.
- Improves clinical accuracy by centralising all case information.
- Reduces delays from diagnosis to treatment for patients.
- Reduces admin workload through automated agendas and workflows.
- Ensures consistent, structured MDT decision-making.
- Enhances cross-team collaboration across hospitals and specialties.
- Provides full auditability for governance, QA and inspections.
- Supports safer clinical decisions through complete information access.
- Minimises duplicated tasks across clinical and administrative teams.
- Supports compliance with clinical standards and best-practice pathways.
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 9 0 9 9 1 8 6 2 7 3 0 4 8 2
Contact
CONTEXT HEALTH LIMITED
Kevin Davis
Telephone: 07751757173
Email: support@contexthealth.com
About your service
- Service categories
-
Applications
Collaborative
- Team collaboration
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
-
Service constraints
• Planned maintenance windows are normally carried out outside UK business hours and may cause brief periods of reduced performance or temporary unavailability.
• Emergency maintenance may be required from time to time to address security or performance issues.
• The service requires a modern web browser (Chrome, Edge, Firefox or Safari) and a stable internet connection for video-based MDT meetings.
• Browser security settings or local IT policies that block WebRTC or microphone/camera access may limit functionality.
• Integration with third-party systems (for example, PACS/DICOM viewers or SSO) is dependent on the buyer’s local configuration and connectivity. - System requirements
-
- Modern browser: Chrome, Edge, Firefox or Safari, latest versions.
- Stable internet connection suitable for HD video conferencing.
- Microphone and camera enabled for MDT meetings.
- JavaScript and cookies must be enabled in the browser.
- WebRTC support required for secure video communication.
- Organisation firewall must allow outbound HTTPS traffic.
- Minimum screen resolution 1280x720 for optimal display.
- PDF viewer required for downloading MDT reports.
- Email account needed to receive login and MFA codes.
- Optional SSO requires buyer’s identity provider configuration.
User support
- Email or online ticketing support
- Yes
- Support response times
-
Email and ticketing support is provided during UK business hours.
Typical first-response time is within 4 working hours.
Evening and weekend queries are monitored, with responses issued next working day unless urgent. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Support levels
We provide a single standard support level for all customers, with optional enhanced support available by agreement.
Standard support (included)
• Email and ticketing support during UK business hours
• Phone support 9 to 5, Monday to Friday
• First-response target within 4 working hours
• System monitoring and alerts
• Security updates and maintenance included
Cost: included in the subscription price
Enhanced support (optional, charged)
• Priority response
• Out-of-hours assistance by prior agreement
• Optional onsite visits
Cost: priced per engagement based on time and travel
Technical account management
We provide a named technical contact for onboarding, integrations and ongoing service coordination.
We do not provide a dedicated full-time Technical Account Manager unless agreed as part of an enhanced support package. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- We provide a structured onboarding process that includes online training sessions for administrators and coordinators, along with user documentation, quick-start guides and video tutorials. We offer both virtual and in-person group training on request. Each organisation is assigned a named technical contact to support setup, user management and configuration during onboarding.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
- Video Tutorials
- End-of-contract data extraction
- Users can request a full data export at the end of the contract. We provide all records in standard open formats, including CSV for structured data and PDF for MDT reports and documents. Exports are delivered securely via encrypted download or secure file transfer. If required, we can also supply a complete file archive of uploaded documents and meeting materials. Data extraction is arranged through the administrator and handled by our support team to ensure completeness and secure transfer.
- End-of-contract process
-
At the end of the contract, access to the service is closed once all data has been successfully extracted and transferred to the organisation. A full export of structured data (CSV) and MDT reports (PDF) is included in the contract price. We retain data only long enough to complete the agreed extraction, after which it is securely deleted in line with our data-retention policy.
Additional costs apply only where a buyer requests non-standard extraction work, such as bespoke data formats, complex restructuring, or physical media delivery. No other termination fees are charged. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Context MDT works on all modern mobile browsers for viewing agendas, documents and messages, and many clinicians join live video MDTs on iPhone and Android devices. The full hosting experience is optimised for desktop, but mobile access is fully supported for participants.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Context MDT provides a secure, browser-based interface for clinicians and MDT coordinators. Users can view agendas, upload and review documents, join video meetings, update patient information, and manage tasks directly within the platform. The interface is designed to be simple, fast and intuitive, with clear navigation and role-based access to features. It works on all modern desktop and mobile browsers without additional software.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- We have tested core user journeys using screen readers, keyboard-only navigation, zoom and high-contrast modes. Testing covered login, agenda viewing, document access, video-meeting entry and basic form interactions. We validated focus order, labels, headings and error messages to ensure compatibility with common assistive technologies. Further accessibility improvements are reviewed as part of ongoing development.
- API
- No
- Customisation available
- Yes
- Description of customisation
-
MDT administrators and coordinators can customise user roles, permissions and notification settings, and administrators can manage MFA, activate or deactivate users and configure system preferences. Organisation branding, such as adding a logo, can be applied on request. Clinical data form changes can also be requested where organisations require adjusted fields or layouts. Workflow pathways can be configured where needed, allowing organisations to define multi-step processes for specific case types. Customisation requires the appropriate permission level:
• Administrator – full access to configuration, user management, permissions, MFA and notifications
• Coordinator – can manage cases, meeting workflows and pathway steps
• Clinician – can review cases, upload documents and complete pathway steps
• Viewer – read-only access where required
All configuration is completed through the built-in admin interface, with changes limited to users with appropriate or designated permissions.
Scaling
- Independence of resources
- The service runs on dedicated, auto-scaling Azure resources that isolate tenant workloads. Performance is maintained through containerised services, load balancing and resource monitoring, ensuring one customer’s activity cannot impact another. Capacity scales automatically, and Azure guarantees consistent compute, storage and network performance for all users.
Analytics
- Service usage metrics
- Yes
- Metrics types
- We provide usage metrics including number of MDT meetings held, attendance counts, time spent in meetings, case volumes, and user activity levels such as logins and role activity. Administrators can view meeting throughput, clinician participation, and session durations to support capacity planning and audit requirements.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- Users can export data by requesting a full extraction through the administrator. Our support team prepares the export and provides the data in standard formats such as CSV and PDF via secure download or secure file transfer.
- Data export formats
-
- CSV
- Other
- Other data export formats
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- Png
- Jpg
- Mov
- Mpeg
- DICOM
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- We guarantee 99.9 percent service availability. The platform is hosted on Microsoft Azure with redundancy across availability zones. Availability is monitored continuously. If availability drops below the guaranteed level, users receive service credits in line with our SLA, applied as a percentage reduction to the following month’s subscription charge.
- Approach to resilience
- The service is hosted on Microsoft Azure and designed with redundancy at every layer. Data and services are replicated across availability zones, with automated failover, load balancing and continuous monitoring. Backups are encrypted and stored separately. Further architectural detail is available on request.
- Outage reporting
- Outages are communicated through email alerts and direct notifications to named customer contacts. We provide ongoing incident updates by email until the issue is resolved. A public status dashboard can be provided on request.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces is restricted to authorised staff using role-based access controls, MFA, and least-privilege permissions. Administrative functions are available only through secured Azure portals and internal tools. Support channels are limited to approved personnel, with access controlled through authenticated accounts and activity logging. Customer data can only be accessed when needed for support, and all access is auditable.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- We operate an ISO 27001 certified Information Security Management System covering all policies, processes and controls. Policies include access control, data protection, incident management, change management and supplier security. Compliance is overseen by the Information Security Lead and reviewed regularly through internal audits, management reviews and mandatory staff training.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- We maintain a formal change management process aligned with ISO 27001. All service components are tracked through their lifecycle using Azure DevOps and documented in our configuration management records. Changes follow a controlled workflow including review, approval, testing, and staged deployment. Security impact is assessed as part of every change, with higher-risk changes requiring additional review and sign-off. Production changes are logged, auditable, and deployed using automated pipelines to ensure consistency and traceability.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- We operate a structured vulnerability management process aligned with ISO 27001. We use Azure Security Centre, Microsoft Defender, and regular external scans to identify vulnerabilities and emerging threats. Threat intelligence is sourced from Microsoft, NCSC advisories, CVE feeds, and our CREST penetration testers. Critical patches are deployed as soon as possible, typically within 24–72 hours, with other updates applied through scheduled maintenance windows. All vulnerabilities are assessed, prioritised, and tracked to closure, with remediation verified before completion.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- We use Azure Security Centre, Microsoft Defender, and centralised logging to monitor for suspicious activity, access anomalies, and potential compromise indicators. Alerts are triaged and investigated promptly, with critical events escalated immediately. If a potential compromise is identified, we isolate affected components, analyse the root cause, and apply remediation. Incident response follows our ISO 27001-aligned process, with response times typically within minutes for high-severity alerts. All incidents are documented, reviewed, and used to improve future monitoring and controls.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- We have predefined incident management processes aligned with ISO 27001, covering common events such as service outages, security alerts, access issues, and data concerns. Users report incidents through our support portal or by email to our support mailbox. All incidents are logged, triaged, and managed through a structured workflow including investigation, resolution, and communication. We provide incident reports on request, including cause, impact, actions taken, and preventative measures.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- The free version provides full access to a demo environment of Context MDT, including case creation, agenda building and meeting workflows. It excludes live clinical data, integrations and custom configuration. Access is time-limited to 30 days and for evaluation purposes only.
- Link to free trial
- Support@contexthealth.com
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 5%
- Between £2,500,001 and £5,000,000
- 7.5%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- British Assessment Bureau
- ISO/IEC 27001 accreditation date
- Tuesday 12 September 2023
- What the ISO/IEC 27001 doesn’t cover
- The certification covers Context Health’s cloud-based SaaS operations, development, support, and hosting arrangements within Microsoft Azure. Activities not included within the scope are non-IT administrative functions and any services or products not part of the Context MDT platform.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- British Assessment Bureau
- ISO 9001 accreditation date
- Monday 4 September 2023
- What the ISO 9001 doesn’t cover
- The certification covers the quality management system for the development, delivery, and support of the Context MDT platform. Activities not included within the scope are non-software-related administrative functions and any services or products outside the Context MDT solution.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 72de0e81-0eed-44bd-818a-a4dccb099484
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-