Skip to main content

Help us improve the Digital Marketplace - send your feedback

ENGAGE HEALTH SYSTEMS LIMITED

Engage Suite for General Practice

The Engage Suite comprises a complete set of unified, patient engagement tools covering the entire patient journey from initial online or telephone contact through triage, secure messaging and video to appointment booking, reminders and touch screen arrivals and call. Fully NHS App, Notify and Login integrated.

Features

  • Customisable online front door - patient portal, online consultations
  • Secure 2-way messaging: individual, batch, SMS, email, or NHS App
  • Pre-defined and customisable coded medical and admin questionnaires
  • Point to point and point to multi-point video
  • Clinician initiated appointment allocation or self booking invitation
  • Appointment reminders
  • Automated arrivals via touchscreens or mobile
  • Patient call and video display / information boards
  • Cross organisation workflow with care navigation, automatic routing and prioritisation
  • Comprehensive self-serve reporting. Automated OC stats to NHS

Benefits

  • Reduce admin burden and make better use of clinician time
  • NHS branded, accessible patient experience integrated with NHS App,Login
  • Slash SMS costs using NHS Notify through the NHS App
  • Wide range of integrations (Pharmacy1st, Telephony etc)
  • Assured Clinical System API integration
  • Hardware agnostic - reuse your existing assets
  • Modular, only pay for the components you need
  • Reduce DNAs, cancellations and unnecessary appointments
  • Share workload with group and inter-organisational messaging. Hub working.
  • High level of service customisation at organisation level

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at contracts@engagehealth.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

3 1 8 1 2 6 9 6 9 8 8 5 7 8 7

Contact

ENGAGE HEALTH SYSTEMS LIMITED <removed>
Telephone: <removed>
Email: contracts@engagehealth.uk

About your service

Service categories

Applications

Collaborative

  • Team collaboration

Conferencing and virtual event

  • Web Conferencing Applications
Multi cloud support
No

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Components can be used standalone or integrated with a host clinical system (TPP, EMIS, Medicus, Vision etc). Online consultations can also be accessed through the NHS App. We also have integrations with an array of telephony and clinical service providers
Cloud deployment model
Public cloud
Service constraints
An Internet First service the Engage Suite runs on a wide selection of hardware and operating systems.
Our UK based infrastructure is fully elastic and scales automatically to meet demand with uptime exceeding 99.99% as monitored by an external service (https://status.engagehealth.uk/).
Our deployment pipeline allows us to release quickly and safely without any interruption to service, with automated release notes in advance through the UI to ensure there's no unexpected changes.
System requirements
  • Any supported NHS workstation is capable of running the service
  • Wider range of compatibility for patient devices and browsers
  • Arrive: OS independent, Touch screen device with browser
  • Call: Android 12 or higher
  • Unfiltered Internet connectivity to *.engage.gp via HTTPS
  • Camera and Microphone for Video consultations

User support

Email or online ticketing support
Yes
Support response times
Core UK based service desk open for email and voice 0800-1700 Monday to Friday

OOH contact by ticketing system/email with response according to priority.

24/7 monitoring and on-call for high severity response

Streams from 1st line to specialist training or technical teams as required.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Our UK based service desk agents are multi-skilled and have the tools and permissions to fix the vast majority of issues first time.

Where remote access is required, we use TeamViewer to establish a secure connection to a customer workstation to view issues first hand and provide the fastest possible resolution.

We run an ISO20001-1 aligned service management system that conforms to the NHS model regarding incident and problem management and have established channels with the clinical system providers and the NHS service bridges.

We are well used to interfacing with the service teams of ICBs/HBs/LHBs and can establish bespoke ways of working as required.

All electronic and voice support included in the base line costs. Site visits will incur an additional, per case charge
Support available to third parties
Yes

Onboarding and offboarding

Getting started
We put a lot of effort into making our services as intuitive as possible, but this doesn't mean that we don't offer a full onboarding as part of the service.

Our range of services is large and every customer has different needs. We initially identify which areas will deliver the most immediate benefit and focus there with a mix of self-service support articles, video and 1:1 / 1:many virtual training sessions to get a site live in the most efficient manner.

Once an organisation has bedded down with the service, we then work with them to establish the next area to focus on and, with this iterative approach, deliver the most value in the shortest timeframe without overloading people.

Where appropriate, we provide on-site assistance - particularly at locality events and training days.
Service documentation
Yes
Documentation formats
  • HTML
  • ODF
  • PDF
End-of-contract data extraction
We are firm believers that all relevant data should be on the patients medical record and use assured APIs and automation to make sure this happens. We have data management tools that allow customers to manage their live-service retention policies, and it is these that we employ once the customer is happy for deletion to take place.
These arrangements are usually captured in the Data Processing Agreement we have with a Controller to allow us to Process their data.
End-of-contract process
Our customer success team will identify the intent to terminate as the contract term comes to a close and establish a tailored off-boarding plan that covers service migration and data deletion.
We are very flexible with our customers and understand that delays might occur late in the day and can provide fractional billing for any over-run period to provide service continuity.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
Yes
Compatible operating systems
  • Android
  • IOS
  • Linux or Unix
  • MacOS
  • Windows
  • ChromeOS
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Limited clinical system integration for HCPs on mobile, but for patients they receive the full service optimised for the device they are using.
Native app experience available though the Engage and/or the NHS App
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
The Admin/Clinical interface is a modern and intuitive design that can be used through either the Engage Client for a fully integrated experience or any modern web browser.

Patients and carers have a similar experience, tailored to their chosen device or method of contact and, where appropriate, is made available in a wide range of languages.

Connections to 3rd party systems (such as EMIS, TPP and Vision) are transparent to users.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
We have regular service audits by an external 3rd party that specifically looks at accessibility issues. Identified issues are promptly prioritised and resolved to maintain a minimum level of WCAG2.2 AA.
API
Yes
What users can and can't do using the API
We have an open pairing policy with 3rd parties to allow our services to interconnect. Established on a case by case basis, the API predominantly allows the creation of messages in our system from such as from Telephony providers or 3rd party website providers.

We welcome new use cases and generally do not charge for creation of additional API capabilities or transactional usage.
API documentation
Yes
API documentation formats
Open API (also known as Swagger)
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
The service is highly configurable by authorised end users via their management console. Our deployment and training team can provide both initial "Get you going" support and advice on how to tailor the service as a customer becomes more comfortable with it. Aspects of configurability include:
- Customisation of patient portal, including services, administrative requests, signposting, self-help, and information gathering for long-term condition reviews
- Information obtained in response to medical or administrative requests from patients or staff
- Care navigation tools allow automatic routing and/or prioritising for the patient concerned, their age, request type, or content.
-Establishing groups of users and sharing with other organisations
- Service hours and granular capacity management to harmonise with staff availability
- Creation and sharing of coded questionnaires
- Message templates
- Location awareness of sites, rooms, and waiting areas
- Information gathering on appointment arrival, e.g., demographic checks, clinical measurements etc.
- Upload own content (Video and static) for the Call / Information boards
- Appointment availability for offering self-book
- Friends & Family Test following appointment or consultation
- SMS sender ID
- Appointment reminder schedule
- Outcomes for reporting purposes
- Confirmation messages/emails

Scaling

Independence of resources
Our infrastructure is containerised and scales automatically on demand.
Batch, maintenance and housekeeping tasks are scheduled for the quiet hours.
Monitoring scripts identify any use trends by customers that might lead to performance issues and are proactively addressed.

Some resource expensive operations are run locally at customer sites

Analytics

Service usage metrics
Yes
Metrics types
All transactions are recorded and surfaced through an array of pre-configured reports in the Management Console on both a single and multiple organisational basis.

Our use of Elastic/Kibana allows a high degree of customised reporting if required (may be chargeable)

Where required, automated reporting to national teams is included in the cost (Example: MESH reporting to NHS in England)
Reporting types
  • Real-time dashboards
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CHECK service provider
Protecting data at rest
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Patients have the ability to export their details from a self-serve area of the service.
Customer data can be exported self-serve via the reporting tools in the management console.
Customised exports are available on request and, dependant on scope, may be subject to an additional charge
Data export formats
Other
Other data export formats
JSON
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
As witnessed by https://status.engagehealth.uk/, our availability is usually at 100% but we guarantee in excess of 99.99% in accordance with the standards set down by the NHS for these classes of service. We run a CI pipeline that allows updates with zero downtime. In exceptional circumstances when downtime is required, it will be announced in advance and conducted well out of normal operating hours.

Protection against malicious action is achieved by regular and on-going penetration and vulnerability testing with 3rd party services layered in front to mitigate brute attacks such as a DDoS.

For hardware we supply, we generally get a replacement shipped within 48 hours
Approach to resilience
We leverage the considerable investment made by Amazon in their AWS platform to provide a high-availability service split across zones to protect against service outages in the facility. We are hosted primarily in London (eu-west-2) for both IG reasons and to keep the service as close to users as possible.
Outage reporting
Our status page at https://status.engagehealth.uk/ allows users to subscribe to any updates. Minor issues are shown through the service via notifications. Internally, issues are reported to our DevOps via a separate comms channel.
Where contractually arranged, we mirror these alerts to Service Desk Bridges and dedicated customer teams.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Access to the production environment can only be achieved from our own offices using secure tunnels. Staff have limited access to aspects of production based on their roles. Access from overseas locations is denied.
Robust onboarding/offboarding ensures considered access is granted and that it is removed once no longer required.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Dedicated link (for example VPN)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
We have a very wide range of policies and procedures based around ISO27001 and DCB0129 to ensure we deliver services that are IG and clinically safe. We are externally audited annually on our processes and our staff are all DBS checked and subject to continuation security training.

Annual penetration testing by a CHECK rated organisation of our services

Other standards and tools we follow/use include UK NCSC, NHS DSP Toolkit, CE and CE+

The Company Executive is ultimately responsible for the delivery of these policies and there is a direct route for any employee to raise issues (in confidence, if required)
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Our development pipeline goes through multiple lower environments before a release candidate is deployed to Pre-Prod, a staging environment that replicates production with representative synthetic data. A mix of automated and manual tests are performed on this during regression testing before it is cleared for release to production. These tests include architectural, technical, security and clinical consideration of the changes proposed.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
We subscribe to and monitor the security feeds of all packages and components we use to deliver our services. Where there is an issue, we have the ability through our CI pipeline to deploy a fix within a few hours.
As a matter of routine, we build time into our development schedule to make sure we always keep on top of component and technology updates.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Though use of visualisation tools and malware scanning agents, abnormal activities that might indicate a potential compromise are quickly identified and categorised. We have a detailed incident response plan to address any incident that covers both our production and domestic / ops environments.
Incident management type
Supplier-defined controls
Incident management approach
All service issues are categorised and recorded in our ticketing system (FreshDesk) which allows the linking of incidents and identification of problems as well as providing a library of curated KB articles that we can provide in response.
Issues can be raised by email or telephone, with a third channel for product feedback integrated into the service itself.

Tickets (and linked tickets) receive updates on the status of the incident and are notified by email.

Internally, we have a monthly reporting process to identify trends and drive service improvement.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
All components are available for a free trial, generally targeted at a pilot / First of Type organisation in a locality evaluating our services. This will include the full onboarding package but we may have to charge for 3rd party licencing fees (e.g. Clinical integration)
Link to free trial
https://engagehealth.uk/

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
3%
Between £500,001 and £1,000,000
5%
Between £1,000,001 and £2,500,000
10%
Between £2,500,001 and £5,000,000
10%
Over £5,000,001
15%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
British Assessment Bureau
ISO/IEC 27001 accreditation date
Tuesday 30 September 2025
What the ISO/IEC 27001 doesn’t cover
Our SoA covers all aspects of our operations and is reviewed annually or on significant change to company operations.
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
British Assessment Bureau
ISO 9001 accreditation date
Tuesday 30 September 2025
What the ISO 9001 doesn’t cover
Closely aligned with our 27001 SoA due to the nature of our business, it covers all areas of our operations and is reviewed at least annually or on significant change to the business or it's operations.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
F9a42869-0013-4571-891c-8f25f92a7a65
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
292b7649-1658-456b-a63e-6d7e92f4ed0f
Other security certifications
Yes
Any other security certifications
  • NHS DTAC
  • NHS DSPTK

Social value

Section B - Commitment for Future: Delivery
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
    • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
    • Actions to invest in the physical and mental health and wellbeing of the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at contracts@engagehealth.uk. Tell them what format you need. It will help if you say what assistive technology you use.