CareLineLive
CareLineLive homecare management suite Cloud software service assists homecare providers, including Local Authority In-house Reablement services, to manage and deliver efficient, quality, compliant services. Including: referrals, care planning, visit scheduling, tasks, medication, outcome planning, allocating care workers, issuing/updating rosters automatically, electronically via integrated apps, monitoring, and family portals.
Features
- NHS England Digital Social Care Record (DSCR) assured supplier
- NHS Data Security Protection (DSP) Toolkit certified
- PRSB, PCSP, About Me and GP Connect certified
- Care Planning and Outcomes address individual service user care requirements
- Matching service user visits to carers, including qualifications, preferences, mileage
- Integrated app, providing electronic rota delivery to carers
- App electronic care/visit monitoring with customisable eForms, notes feedback/observations capture
- Automated confirmation of internal/in-house care at home visits, all electronic
- Alarms for delayed visits, alerts for pending reviews
- Electronic gross payroll and invoicing financial outcomes via exports/integration, benchmarking
Benefits
- Person-centred care planning, service delivery and reporting toolset
- Tailored care plans, outcomes aid service users improve their health
- Use of qualifications, preferences helps prevent conflict, allergic reactions etc.
- Only if regular care worker unavailable visit needs reallocating
- Real-time integration scheduling <-> mobile apps, enable rapid changes
- Electronic call monitoring eliminates paper timesheets/automates processing/aids efficiency
- Real-time electronic visit monitoring -> safeguarding, via delayed visit alarms
- Electronic customisable Assessments, Reviews, Benchmarking aids CQC compliance
- Electronic visit notes/observations/concerns/task completions -> on/offline data capture via mobile
- Integration maximises benefits -> no double keying, timely, accurate information
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 0 5 6 7 6 9 9 8 7 3 9 1 0 5
Contact
MAS NETWORKS LTD T/A CARELINELIVE
Peter Briggs
Telephone: 0330 088 5767
Email: sales@carelinelive.com
About the service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Adult Social Care
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- CareLineLive homecare management suite cloud software is web-based, so it can be accessed from any suitable, Chromium-based browser enabled device, e.g. Chrome, Edge, Chrome preferred, with an internet connection. The Carer Companion mobile app operates on current supported versions of Android and iOS mobile devices (smartphones), recommended minimum mobile data allowance 1GB per mobile device/line p.m.
- System requirements
-
- Management Platform/Care Circle: via secure internet Chromium-based browser.
- Management Platform/Care Circle: two latest versions of Chrome/Edge.
- Management Platform/Care Circle: desktop/laptops required for UI access.
- Carer Companion app: requires current Android & iOS versions.
- Android app requires Android 5 (Lollipop)/above, GPS, rear-facing camera.
- IOS app requires iOS 13.0/above and use Google maps.
- Carer Companion app: distributed via Play Store and AppStore.
- Evidenced visit times/locations with Carer app use QR codes.
- Carer Companion app: location co-ordinates captured via GPS.
- Carer Companion app: Google maps must be installed on phone.
User support
- Email or online ticketing support
- Yes
- Support response times
-
Issues raised by email: MAS Networks Ltd use best endeavours to determine (during Working Hours, i.e. Mon-Fri 9am - 5:30pm excluding public holidays in England, unless stated otherwise below) whether an issue affects protected functionality and into which priority category an issue raised falls. Priority categories:
Critical (reported 24x7)
High
Medium/Normal
Low
Target acknowledgement (email): 30 minutes.
Target response and fix times:
Critical: 2 hours response, 4 hours fix (24x7x365 clock)
High: 4 hours response, 2 working days fix
Normal: 8 hours response, 7 working days fix
Low: 3 working days response, future release fix - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- None or don’t know
- How the web chat support is accessible
- The CareLineLive support desk is available via online chat facility, e-mail and phone.
- Web chat accessibility testing
- None to date.
- Onsite support
- Yes, at extra cost
- Support levels
-
CareLineLive Support Service operates 24x7x365 days p.a. for Critical (Cloud software service down, not due to customer specific localised issues affecting a customer such as failure of customer devices, mobile coverage, or local internet access etc.) issues, and during office hours (9:00 a.m. – 5:30 p.m., Monday to Friday excluding English public holidays) for all issues.
The Support Service is the first point of contact for all Customer enquiries and service-related issues, receives support requests via email to our support portal 24x7x365, or by phone or web chat during office hours. Support calls/emails/messages are logged, processed and followed up by our Support Service Staff for the cloud software SaaS prices quoted.
CareLineLive Support Service also provides general advice and guidance on Service use, incident knowledge, workarounds and next release information.
Client management:
During implementation, MAS Networks’ Project Manager is responsible with escalation to the designated MAS Networks' Account Manager for the customer, and then MAS Networks' Operations Director or Managing Director if/when applicable.
Post implementation, MAS Networks' designated Account Manager and Contract Manager for the customer are responsible for BAU liaison and Contract and Performance reviews respectively, with escalation to MAS Networks' Operations Director or Managing Director if/when applicable. - Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
-
We provide business process guidance to aid customers define the most appropriate changes to their business process to obtain maximum benefit from our cloud software. Upon implementation CareLineLive homecare management suite and mobile cloud software will then reflect the new business process requirements and workflow as configured. We then provide contextual onsite training, online training, and user documentation (collectively onboarding), plus support via a designated project management, and our Support Service.
Training and documentation
Comprehensive training is part of our onboarding process. There are three sessions covering:
Session One
• How to access and use our eLearning platform
• Setting up your first user account on CareLineLive, and share details of how to get in touch with support
Session Two
• Carer and client schedules
• Rostering
• Tasks and eMAR
• The carer companion app
Session Three
• Invoicing and payroll
• HR tools - requirements, training, reviews
• Reporting - Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
-
MAS Networks Ltd will assist with the migration of data at the end of the contract, in a CSV Export format for CareLineLive, with the following quite straightforward process which is our standard approach in this regard:
1. The Buyer provides written contract termination notice to: accounts@mas-group.co.uk
2. The Buyer will receive a written notification reply letting you know we have received the request. Our reply will include the end date.
3. MAS Networks will confirm at the same time what data we will be able to extract and deliver to you, please see the Service Definition for details.
4. The Buyer will be provided instruction on how to receive your data. The data comes in the form of CSV exports for CareLineLive.
5. MAS Networks will delete the Buyer data in our hosting including any back-ups, within 3 months of the termination date, typically as stipulated in the Call-off Contract. - End-of-contract process
-
Our quoted cloud software SaaS charge normally includes sufficient time in each contract for our designated project manager (exit) to prepare and agree the exit plan with the customer, then manage the exit (supplier side) and for our technical services team to offboard the customer's data, preparing the CSV file exports, prior to deleting the customer's data in accordance with the following quite straightforward process which is our standard approach in this regard:
1. The Buyer provides written contract termination notice to: accounts@mas-group.co.uk
2. The Buyer will receive a written notification reply letting you know we have received the request. Our reply will include the end date.
3. MAS Networks will confirm at the same time what data we will be able to extract and deliver to you, please see the Service Definition for details.
4. The Buyer will be provided instruction on how to receive your data. The data comes in the form of CSV exports for CareLineLive.
5. MAS Networks will delete the Buyer data in our hosting including any back-ups, within 3 months of the termination date, typically as stipulated in the Call-off Contract. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Onboarding and offboarding documentation would be shared via email on project commencement, and cessation respectively.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Chrome
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
CareLineLive Management Platform and Carer app services are fully integrated, real time, complementary.
Scheduling: performed in CareLineLive Management Platform, individual care plans, assessments and reviews created per service user, rosters, tasks, medication plans configured, assigned to visits, and published.
Rotas: sent automatically via the Carer Companion app: carers view their own rota, visit, task details (including medication) etc., log visit times, record feedback/visit notes, observations, concerns, and service user comments.
Visit times, task completions, and data including medication dispensed: once logged/recorded, automatically updates the planned roster with actual times/data for processing/reviews.
CareLineLive Management Platform includes an optional Benchmarking module. - Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
-
CareLineLive Management Platform/Care Circle Family Portal:
Browser based: instant access to the main functional areas of the CareLineLive service via a vertical tool bar, multiple browser tabs can be kept open. Data entry/review is via configurable, auto verifying fields for data type at the point of saving if not before. Extensive use made of colours, graphic charts, fly by/hover over tips.
Carer Companion app:
Native app-based: Care workers view their rota, visit, task details (including medication tasks) etc., log their visit times (via QR code), record feedback/visit notes/observations/carer concerns, including service user comments (all as applicable).
Supports online/offline working. - Accessibility standards
- WCAG 2.2 A
- Accessibility testing
-
The CareLineLive homecare management suite system is cloud based, accessed via standard Chromium-based browsers, such as Chrome, Edge, Chrome preferred, and is designed to support standard browser-compatible accessibility tools. The CareLineLive Carer Companion app is supported on current supported versions of Android and iOS, and hence support the standard accessibility tools on each of these platforms respectively.
CareLineLive is compliant against WCAG 2.2 A, and we design our CareLineLive solution against the WCAG 2.2 AA standard, but the latter has not as yet been externally audited. With respect to WCAG 2.2 A, for example:
• Our design system enforces colours that use appropriate contrast levels to remain legible to vision-impaired users.
• We employ automated linting for HTML pages that ensures appropriate aria- attributes are in place to enable use of screen readers.
• Forms controls are built to enable keyboard navigation. - API
- Yes
- What users can and can't do using the API
-
We have several API endpoints in place or currently in development for fetching information, so we request that Buyers please contact us for the latest information in this respect. That said, our CareLineLive API is in line with Gov standards: REST, OpenAPI documentation, HTTPS, UTF-8, JSON, authorisation will be via OAuth2; JSON response format.
Only push processing supported.
We would expect to work with the customer's analysts to develop a complete configuration blueprint that describes how the solution needs to be configured to deliver the full functionality.
Our consultants would work with the customer's and/or 3rd party system analysts using configuration tools supplied as part of the Solution to build the desired configuration into the base Solution, and to test completeness and accuracy. Typically, this work is scoped and priced within the contract value. - API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
CareLineLive has been built to service the Domiciliary Care sector, for use by care providers delivering social care services in the community. The use of CareLineLive is not restricted to only domiciliary care, and is highly configurable, off-the-shelf as it were. E.g. the teams and teams names, service user types, staff types and grades, booking types, tasks, and qualifications required, reviews and assessments can all be configured by the customer. Service users and staff can be assigned to their respective teams (staff can be assigned to multiple teams, service users usually to one team relevant to their service type and geographical location). CareLineLive includes the ability to colour customise areas of the system such as the rota so that colour indications can be set for various visit types and statuses allowing users to easily identify certain events/triggers or occurrences as per their own logic and schema. And CareLineLive includes the ‘Permissions Matrix’, which enables customer System Administrators to assign each of their user types to the appropriate roles and thus invoke the relevant permissions.
Furthermore, CareLineLive includes User Defined Fields so any additional fields required by the Council can be added too.
Scaling
- Independence of resources
- CareLineLive is built using a SQL database architecture, utilising PostgreSQL, and therefore is inherently fully scalable. In addition, CareLineLive is hosted for UK customers by Amazon Web Services (AWS) in London (UK), a Tier 4 professional datacentre, using AWS High Availability, Multi-AZ and spot instances allowing the platform to grow automatically as required, on demand to suit any load. Hence, with this in-built spare capacity for large surges in activity, and by hosting on high availability servers, our AWS hosting scales and shrinks using spot instances.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Generally we would include the provision of the following service metrics and a review online with the customer on a quarterly basis:
1. Service availability levels.
2. Number of Customer-reported incidents at each priority level and fix times.
3. Number of supplier self-notified incidents at each priority level and fix times.
4. Any issues/support/breaches of the SLA.
5. Downtime periods.
6. Service availability figures and other relevant information to be provided to the Customer 5 days in advance of each meeting.
7. Product - issues, feature requests.
8. Product - new functionality exposure, anything in roadmap to look forward to. - Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Supplier type
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Other
- Other data at rest protection approach
-
CareLineLive:
• Architecture adheres to NHS public cloud guidelines.
• Public cloud supplier, currently hosted+processed on AWS Tier-4 professional datacentre in the UK (London).
• Single-tenancy environment.
• Utilises PHP 8.2+PostgreSQL 14+Kubernetes 1.26
• BC/DR Plan available
• Auto-scaling architecture
• Backup: PITR+31-day snapshot retention, off-site replication, replication+failover enabled.
• No fixed-IP addresses.
• Strict firewall rules.
• Zero-trust methodology.
• Anti-malware protections.
• Web Application Firewall protects against DDOS attacks+potentially harmful connections.
• Automated testing of new software/dependency versions pre-deployment.
• Data stored at-rest encrypted using AES_256_GCM, data in-transit encrypted using AES_128_GCM, supported by TLS 1.3 minimum SSL connections. - Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
-
CareLineLive:
• Includes 30+ Management Information System reports including visit financial information, carer utilisation, aiding pinpointing areas for improvement, helping evidence performance against standards (CQC). Reports can be exported in a range of formats, Excel, CSV or PDF depending on type.
• Complies with the Data Migration DSC standard. Data is made available using the CareLineLive Data Extract feature via CSV and/or JSON files (manually initiated), depending on preference.
• Offers a Custom Report Dashboard.
• Subject to requirements/costs, read-only replication databases optional for real time reporting via customers internal data warehousing/reporting tools.
• Custom reporting via integrated Looker. - Data export formats
-
- CSV
- Other
- Other data export formats
- PDF (subject to the report type)
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- Other
- Other protection between networks
-
CareLineLive complies with current National Cyber Security Centre (NCSC) guidance. CareLineLive:
• Supports multi-factor authentication (MFA)
• All data stored at-rest is encrypted using AES_256_GCM, and data in-transit is encrypted using AES_128_GCM, supported by TLS 1.3 minimum for SSL connections, and;
• The platform has minimum password requirements in place.
• Is accessible via public internet; SSL enforced; authentication via OAuth2.
• Disables SSL 2.0, SSL 3.0, TLS 1.0 and TLS 1.1 protocols.
• Web services conform to local authority encryption standards.
• Utilises Service accounts with complex 32 character passwords.
• Microsoft Entra ID integration is available and offered. - Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
-
CareLineLive:
• Architecture adheres to NHS public cloud guidelines.
• Public cloud supplier, currently hosted+processed on AWS Tier-4 professional datacentre in the UK (London).
• Single-tenancy environment.
• Utilises PHP 8.2+PostgreSQL 14+Kubernetes 1.26
• BC/DR Plan available
• Auto-scaling architecture
• Backup: PITR+31-day snapshot retention, off-site replication, replication+failover enabled.
• No fixed-IP addresses.
• Strict firewall rules.
• Zero-trust methodology.
• Anti-malware protections.
• Web Application Firewall protects against DDOS attacks+potentially harmful connections.
• Automated testing of new software/dependency versions pre-deployment.
• Data stored at-rest encrypted using AES_256_GCM, data in-transit encrypted using AES_128_GCM, supported by TLS 1.3 minimum SSL connections.
Availability and resilience
- Guaranteed availability
- We propose a Service Level Agreement, which includes the Target Service Availability of 99.85% for our hosted services in any given 12-calendar month period, 24 hours per day, 7 days a week, 365 days per annum, planned maintenance periods excepted.
- Approach to resilience
-
CareLineLive is an integrated solution, updating in real time, with all components developed by MAS Networks, hosted in the UK on AWS a Tier 4 professional datacentre, and we have 'automated' 24x7 monitoring.
As a consequence we have very high up-time records (to date showing 100% availability throughout 2024 & 2025, upto and including 28th Jan 2026!). To evidence this, please refer to the following website:
CareLineLive Status: https://carelinelive.statuspage.io/
Indeed, we are classified as a Silver service by the NHS guidelines, reference this link: https://digital.nhs.uk/services/cloud-centre-of-excellence/cloud-security-good-practice-guide/9.-appendix-b-service-classifications
MAS Group also operate our own Business Continuity Plan, to maintain support to customers in the event of a threat to normal operations.
Consequently, we are pleased to confirm that we will provide our CareLineLive solution with target availability of 99.85% (i.e. in the absence of P1 Critical system down, target availability is 99.85%, planned maintenance periods excepted). - Outage reporting
- Via the CareLineLive Status: https://carelinelive.statuspage.io/
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Other
- Other user authentication
-
In accordance with current National Cyber Security Centre (NCSC) guidance CareLineLive:
a) Supports multi-factor authentication (MFA)
b) All data is encrypted in-transit and at-rest, protecting against interception as well as unauthorised access to the underlying servers and supported by TLS 1.3 minimum for SSL connections, and;
c)the CareLineLive platform has minimum password requirements in place. These are:
- Minimum of 8 Characters
- Must not be a compromised password (known to be exposed in a data leak according to pwned.com)
Federated authentication via Microsoft Entra ID is also available and offered. - Access restrictions in management interfaces and support channels
-
MAS Networks Ltd has access to all data, because we will be hosting the database and file storage. However, appropriate and strict access controls in place ensure that only the MD/Director of Development can authorise access to the data. Data is encrypted in-transit and at-rest at all stages.
For customer support, if trouble-shooting requires access to data within a particular customer's environment, explicit permission is requested for access from the customer, then access is approved for a MAS Networks staff member by either the MD, Director of Development/Director of Operations. All access requests are logged for future audit purposes. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Username or password
- Other
- Description of management access authentication
-
CareLineLive secure user management:
o Authentication of (admin) users to management interfaces and support channels
▪ 2FA is enforced for all admin users, complex password requirements.
▪ Management/support requests accepted via telephone, email, support portal, and chat.
▪ ISO 27001:2013 and Cyber Essentials Plus (+Cyber Essentials) certified
o Separation with access control within management interfaces
▪ Each organisation is hosted in a logically separate environment.
▪ Authentication credentials are separately managed for each environment.
▪ ISO 27001:2013 and Cyber Essentials Plus (+Cyber Essentials) certified
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
-
MAS Networks Ltd, part of MAS Group, has the following Certifications:
• ISO 9001/2700
• Cyber Essentials Plus (+Cyber Essentials)
• NHS Digital Security Protection (DSP) Toolkit registered
• DCB0129 compliant
• Registered with the Information Commissioners Office (ICO)
CareLineLive: an NHS England Digital Social Care Record (DSCR) assured solution. - Information security policies and processes
-
MAS Group (/MAS Technicae Group (International) Ltd encompassing MAS Networks Ltd and C4 Ulysses Ltd) operates an IMS that has gained ISO 9001:2015 and ISO 27001:2013 certifications, including aspects specific to its Scope of Certification. MAS Group aims to provide defect-free products and services to its customers on time and within budget, and is committed to operating its business responsibly in fulfilment of its compliance obligations. It is the Organisation’s declared policy to operate with and to maintain good relations with relevant regulatory bodies. MAS Group has prepared and published an Information Security Policy and a suite of information security aspect-specific IS policies, held as part of the IMS, that should be used in conjunction with this overall IMS Policy. Top management is committed to:
• Develop and improve the IMS
• Continually improve the effectiveness and performance of the Integrated Management System
• The enhancement of customer satisfaction.
All personnel understand the requirements of this IMS Policy and comply with the contents of the IMS. The Organisation constantly monitors its performance and implements improvements when appropriate. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
Managing changes covers requirement gathering, specification, coding, testing and release management with respect to the live CareLineLive environment.
We adhere to a strict change control process, documented in the MAS Group ISO Secure Systems & Development Aspects Policy. Any change requests will be carefully considered, documented in a requirements specification documentation that has to be agreed and signed off by all stakeholders prior to resources being assigned.
Major changes: applied during planned maintenance window in consultation and with agreement of the customer typically during low traffic periods. Minor changes: applied during normal hours of business at MAS Group discretion. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
Appropriate patching controls ensure technical vulnerabilities are managed effectively: adherence to the Malware and Vulnerability Aspects Policy and Directive.
Controls (Anti-Virus software, hardware/software firewalls, Internet web traffic): scanned for malware, potential phishing threats are used to detect threats. Threats risk assessed, appropriate action determined by the ISMS committee, recorded in the risk register, risks mitigated depending on severity/impact.
Issues deemed critical: target resolution within two business days or as soon as possible.
Anti-Virus software, hardware/software firewalls, Internet web traffic scanned for malware, and potential phishing threats: Logs are checked regularly, any significant reports escalated to the ISMS Committee and investigated. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
MAS Group perform protective monitoring in accordance with our ISO policies and procedures, (clause A.12.4 refers) overview:
A12.4.1 Event logging: Event logs that record user activities, exceptions and information security events to be generated and retained for an agreed period to assist in monitoring access control and as evidence in potential information security investigations.
A.12.4.2 Protection of log information: Event logs and the systems and services used to generate them to be protected against unauthorised access or modification.
A.12.4.3 Administrator and operator logs: System administrator and operator activities to be recorded, with the logs protected and subject to review. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
Incident reporting uses our ISO9001 logging process, identifies the problem, possible source, etc. Threat assessment is done determining what impact is likely and escalated as required. All incidents are reported on ISO27001 logs which will be shared with the Customer. We report routinely monthly but if there is a serious incident e.g. a GDPR breach then this is reported and acted upon immediately to minimise or mitigate any damage. Where needed we will also report to the ICO and other bodies as required.
Incident management processes are in place and tested yearly as part of disaster recovery testing. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
-
- Health and Social Care Network (HSCN)
- Other
- Other public sector networks
- CareLineLive is integrated with: NHS HSCN
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- ISO/IEC 27001 accredited by
- Citation ISO Certification Limited
- ISO/IEC 27001 accreditation date
- Tuesday 27 May 2025
- What the ISO/IEC 27001 doesn’t cover
- None to report.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- ISO 9001 certification accredited by
- Citation ISO Certification Limited
- ISO 9001 accreditation date
- Tuesday 27 May 2025
- What the ISO 9001 doesn’t cover
- None to report.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber Essentials Certificate Number
- 258881ab-07bf-46aa-ad96-9a7271326dc7
- Cyber essentials plus
- Yes
- Cyber Essentials Plus Certificate Number
- A3ea88c7-38c1-490f-8f0c-e701e546147c
- Other security certifications
- Yes
- Any other security certifications
-
- NHS DSP Toolkit, 2025-26 (version 8)
- Clinical Safety (DCB0129)
- Data Protection Act 2018
Social value
- Mission: Kick start economic growth
-
To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Plans for positive actions with community groups.
- Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
- Collaborating with anchor institutions and community groups to make facilities available for education, training or community events