Ardens Clinical
Ardens Clinical is the leading Clinical Decision Support tool for Primary Care. It provides easy access to evidence-based resources based upon current guidance. This includes clinical templates, alerts, reports, formularies, protocols and referral forms. Ardens Clinical delivers standardised best practice, whilst protecting patient safety and maximising savings.
Features
- Clinical decision support
- Safety alerts
- Referral capacity and demand
- Reports for commissioning, clinical reporting
- Safeguarding and risk stratification
- Practice management tools
- High-risk drug monitoring
- Regularly updated clinical templates
- Links to drug formularies for efficient prescribing
- Support for remote consultations
Benefits
- Easily access clinically rigorous templates from within clinical systems
- Standardise care across teams and practices
- Promote patient safety
- Improve best practice and reduce significant events
- Simplify referral processes and safety netting
- Reduce administrative costs
- Upskill your workforce and increase productivity
- Promote self-care
- Increase GP QOF and enhanced services income
- Save money through consistent prescribing
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 6 8 5 7 3 2 6 0 2 5 9 8 8 7
Contact
ARDENS HEALTH INFORMATICS LIMITED
Ardens Accounts Team
Telephone: 01725 762062
Email: accounts@ardens.org.uk
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes
- What software services is the service an extension to
-
SystmOne Electronic Health Record (The Phoenix Partnership Ltd)
and EMIS Web Electronic Health Record (Optum Health Solutions UK Ltd) - Cloud deployment model
- Private cloud
- Service constraints
- Ardens can only be used in conjunction with SystmOne and EMIS Web. Planned maintenance or downtime to these platforms will temporarily restrict our ability to install, update and implement Ardens. During periods of planned maintenance or downtime, we will communicate with our clients informing them of the maintenance period and how we can support them in the meantime.
- System requirements
-
- Must Have access to SystmOne or EMIS-Web
- Must have a HSCN connection
User support
- Email or online ticketing support
- Yes
- Support response times
- A summary of response times can be found at https://www.ardens.org.uk/key-performance-indicators/. We aim to respond to all support requests within 3 working days of receipt although we strive to respond much quicker. Serious incidents will be acknowledged within 4 hours of occurrence and resolved within 2 working days (excluding issues outside of Ardens control). Urgent Change Requests including updates & issues will be completed within 5 working days and non-urgent change requests within 20 working days. The Ardens Support Desk is operational Monday to Friday. It is closed at the weekend.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
All of our customers have access to the same support levels. Our expert post-implementation Support Team is available from 08:30-17:00 Monday – Friday. They are responsible for answering customer queries and ensuring that Ardens Clinical has been fully installed and optimised successfully on our customer’s systems. Further support can be provided depending on customer need, such as customising dashboards to meet specific, local contract reporting requirements.
All customers have access to:
Screensharing facilities with Ardens’ staff to rectify problems
Webinars
Users guides
Online forums and Facebook group chats discussing Ardens
Email support
Telephone Support
Our post-implementation Support Team
Online learning platform - Ardens Academy - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
As part of the Ardens initial setup package, we provide free training to support deployment and adoption. These will be tailored to the customer’s specific systems, most used templates and customer type (e.g. individual GP practice or GP Federation or ICS) to ensure the customer’s full understanding, confidence and ease of use. Training can also be delivered for more specific topics such as Medicines Management. Additionally, all users are provided with an online set-up guide and email instructions. Documentation will be tailored to customer type and customer location to meet each customer’s specific needs.
Users can visit the support page on our website to access resources for further assistance such as:
• Frequently asked questions
• A contact form and our Support Desk for specific queries
• News and updates
• Webinars
• Guides
• Training videos
• Help via screensharing
• Online forums and Facebook group chats - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- We are committed to our clients having access to their data even if they decide to end their contract with us. All health data is stored within the Electronic Patient Record System provided by either EMIS Web or SystmOne. Therefore, no data extraction is required post-contract.
- End-of-contract process
-
At the end of the contract, customers are invited to renew their Ardens Clinical subscription. If the contract is ended without renewal, the customer and all 3rd party users – such as GP practices if the customer is an ICB or other Group - will lose access to all Ardens Clinical Templates and associated functionality. As part of our offboarding process, customers are supported to provide a smooth transition. Users can buy another licence for Ardens Clinical at any time.
All patient data is stored within the Electronic Patient Record (EMIS Web or SystmOne) and is not deleted as part of the end-of-contract process – all data entered via our Clinical Templates is retained
None of our end-of-contract processes attract an additional cost. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
Our onboarding training documentation is designed to be clear, comprehensive and easily accessible to customers.
When new customers are onboarded, they are provided with information on the training resources to get them started. This is included within the onboarding email to clients. This includes:
Contact email (training@ardens.org.uk) to book practice, PCN or ICB level training.
Access to Ardens Academy to enrol on the ‘Getting Started with Ardens Manager’ course to help the customers navigate the system efficiently.
Links to support articles covering instructions on how to use the resources, common frequently asked questions and best practices to ensure customers are making the most of the platform.
See our attached Terms and Conditions document for more details.
Using the service
- Web browser interface
- No
- Application to install
- Yes
- Compatible operating systems
- Windows
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
The product is built within the constraints of Clinical Systems (EMIS Web and SystmOne). Where these systems allow mobile integration, we have created resources that are compatible. In general, these are limited resources (focusing on client use needs rather than resource creation for the sake of) for use on mobile devices SystmOne Online and Brigid
Our questionnaires for online consultations are available on the TPP Airmid App. We have worked with SystmOne to provide these online consultations for free for all SystmOne users. - Service interface
- No
- User support accessibility
- None or don’t know
- API
- No
- Customisation available
- Yes
- Description of customisation
- Customers can request customisation. Ardens can customise various components including localised enhanced services, referral forms and formularies. For further information, please see www.ardens.org.uk/packages.
Scaling
- Independence of resources
-
From an operational standpoint, our service is locally hosted by our clients within their instance of EMIS Web or SystmOne. Therefore, each individual instance doesn’t draw on resources used by other clients.
See our attached Terms and Conditions document for more details.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Ardens is able to provide detailed usage metrics for Ardens Clinical including which template resources have been utilised. Due to technical constraints this is only possible for organisations that use both Ardens Clinical and Ardens Manager.
- Reporting types
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- NCSC approved service provider
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Other
- Other data at rest protection approach
- Data held within EMIS Web and SystmOne Electronic Health Records is subject to the suppliers technical and organisational controls.
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- The Ardens Clinical templates are created and stored on the central EMIS Web and SystmOne servers. These are then shared with practices via the EMIS Web Resource Publisher functionality and the equivalent SystmOne Organisation Group functionality. Ardens Clinical does not have access to and cannot export any of the data from the completed templates, as this resides within the Electronic Patient Record.
- Data export formats
- Other
- Other data export formats
- Not applicable
- Data import formats
- Other
- Other data import formats
- Not applicable
Data-in-transit protection
- Data protection between buyer and supplier networks
- Private network or public sector network
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- Ardens Clinical is locally hosted on the clients’ instance of SystmOne or EMIS Web. Therefore, uptime is 100% of the Electronic Health Record systems’ uptime.
- Approach to resilience
-
Our cloud services are securely hosted on a UK based server, and we have an SLA in place to guarantee resilience within our server environment.
Ardens resilience protocol and safeguards are available on request. - Outage reporting
- We report any outages to our clients as soon possible according to our Terms of Supply and Use. We can alert clients via webpage notifications, email and our Ardens Support Facebook group.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Dedicated link (for example VPN)
- Username or password
- Access restrictions in management interfaces and support channels
- Ardens manages access control for management interfaces and support channels in alignment with ISO 27001 and NHS Data Security and Protection Toolkit Standards. Role-based access control ensures users receive only the minimum privileges required, with access formally approved, regularly reviewed, and removed when no longer needed. Administrative and support systems are restricted to authorised staff using unique accounts and multi-factor authentication. All activity is authenticated, logged, and auditable. Sensitive actions are performed only by authorised personnel under defined ISMS-controlled processes.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
We meet the requirements of the NHS Data Security and Protection Toolkit and are fully accredited with ISO27001 and Cyber Essentials Plus. A range of policies and procedures support the security of our system. These are available to clients on request and though our website.
All staff are trained on security as part of their induction, and receive regular training updates to ensure continued compliance. For those with access to sensitive parts of software – for example, our development environment – additional security training is carried out, as well as appropriate pre-employment checks. These include DBS.
Our reporting structure is in line with our security policy. Our SIRO is a member of the Board, and has responsibility for identifying and mitigating risks. Overall, our Chief Executive has overall responsibility for security, supported by individual product leads. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Prior to the delivery of new resources, a Clinical Safety Case Report (CSCR) is established. Once changes are deployed, the validity of any assumptions and the effectiveness of any controls made in the CSCR are monitored to ensure the perceived level of clinical risk remains representative and acceptable.
Should modifications be identified (e.g. defect fixes or new functionality) we review the CSCR to establish if modifications or updates impact on existing hazards or introduce new hazards. Ardens hold a log of all modifications delivered.
Our approach is strictly detailed in our Clinical Safety documentation (available on request). - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Ardens vulnerability management approach combines continuous monitoring and independent assurance. Threat intelligence is drawn from our 24x7 third-party Security Operations Centre (SOC), Microsoft security feeds, and vendor advisories. Our physical and network infrastructure is protected and monitored by the SOC alongside our in-house team.
Microsoft Defender provides near real-time visibility of vulnerabilities including severity and exploitability, supported by Qualys scanning for critical infrastructure. Quarterly vulnerability scans are also performed by a third-party. Critical and high-severity vulnerabilities are remediated within 14 days, with autonomous patching often enabling faster resolution. Externally facing critical and high vulnerabilities are prioritised within 7 days. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Devices are protected and monitored using Microsoft Defender and Microsoft 365 security tooling to detect compromise, including suspicious behaviour such as mass file modification or deletion.
Monitoring is supported by a third-party Security Operations Centre (SOC), which receives telemetry from deployed sensors across the business and provides 24x7 oversight.
Potential compromises are triaged by the SOC and escalated to our in-house team for investigation and response. Suspected or confirmed incidents are acted upon promptly, with high-severity incidents investigated immediately. Confirmed incidents are managed through defined incident response procedures, including rapid containment measures such as isolating affected devices from the network - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Ardens maintains a comprehensive incident management framework aligned with ISO 27001 and compliant with the NHS Data Security and Protection Toolkit. Incidents can be reported through dedicated internal channels or via our Service Desk, and all staff follow our documented Incident Management Plan. Severity-based response times ensure prompt action: Minor incidents (minor issues for a small number of recipients) are acknowledged within 4 hours and resolved within 2 working days, whilst critical incidents will be reported to the NHS Service Bridge. Incident reports are provided to clients in accordance with our Terms of Supply and Use or upon request.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
- Health and Social Care Network (HSCN)
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- Ardens Clinical offers a three-month trial providing full access to national resources, including core templates, alerts and reports. Training is included where needed. Localisation may be considered for large-scale trials. The trial is quick to set up, has no commitment and allows practices to assess suitability in a live environment.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 2.5%
- Between £1,000,001 and £2,500,000
- 2.5%
- Between £2,500,001 and £5,000,000
- 2.5%
- Over £5,000,001
- 2.5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- British Assessment Bureau
- ISO/IEC 27001 accreditation date
- Thursday 30 January 2025
- What the ISO/IEC 27001 doesn’t cover
- All annex A controls are covered within the Statement of Applicability
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 97e52154-3c3f-4b3c-ba66-ae51741dc21d
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- Fd7e775f-36d0-4672-97bd-2291d7f3e021
- Other security certifications
- Yes
- Any other security certifications
- NHS Data Security and Protection Toolkit
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
-