Engage Suite for General Practice
The Engage Suite comprises a complete set of unified, patient engagement tools covering the entire patient journey from initial online or telephone contact through triage, secure messaging and video to appointment booking, reminders and touch screen arrivals and call. Fully NHS App, Notify and Login integrated.
Features
- Customisable online front door - patient portal, online consultations
- Secure 2-way messaging: individual, batch, SMS, email, or NHS App
- Pre-defined and customisable coded medical and admin questionnaires
- Point to point and point to multi-point video
- Clinician initiated appointment allocation or self booking invitation
- Appointment reminders
- Automated arrivals via touchscreens or mobile
- Patient call and video display / information boards
- Cross organisation workflow with care navigation, automatic routing and prioritisation
- Comprehensive self-serve reporting. Automated OC stats to NHS
Benefits
- Reduce admin burden and make better use of clinician time
- NHS branded, accessible patient experience integrated with NHS App,Login
- Slash SMS costs using NHS Notify through the NHS App
- Wide range of integrations (Pharmacy1st, Telephony etc)
- Assured Clinical System API integration
- Hardware agnostic - reuse your existing assets
- Modular, only pay for the components you need
- Reduce DNAs, cancellations and unnecessary appointments
- Share workload with group and inter-organisational messaging. Hub working.
- High level of service customisation at organisation level
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 1 8 1 2 6 9 6 9 8 8 5 7 8 7
Contact
ENGAGE HEALTH SYSTEMS LIMITED
<removed>
Telephone: <removed>
Email: contracts@engagehealth.uk
About your service
- Service categories
-
Applications
Collaborative
- Team collaboration
Conferencing and virtual event
- Web Conferencing Applications
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Components can be used standalone or integrated with a host clinical system (TPP, EMIS, Medicus, Vision etc). Online consultations can also be accessed through the NHS App. We also have integrations with an array of telephony and clinical service providers
- Cloud deployment model
- Public cloud
- Service constraints
-
An Internet First service the Engage Suite runs on a wide selection of hardware and operating systems.
Our UK based infrastructure is fully elastic and scales automatically to meet demand with uptime exceeding 99.99% as monitored by an external service (https://status.engagehealth.uk/).
Our deployment pipeline allows us to release quickly and safely without any interruption to service, with automated release notes in advance through the UI to ensure there's no unexpected changes. - System requirements
-
- Any supported NHS workstation is capable of running the service
- Wider range of compatibility for patient devices and browsers
- Arrive: OS independent, Touch screen device with browser
- Call: Android 12 or higher
- Unfiltered Internet connectivity to *.engage.gp via HTTPS
- Camera and Microphone for Video consultations
User support
- Email or online ticketing support
- Yes
- Support response times
-
Core UK based service desk open for email and voice 0800-1700 Monday to Friday
OOH contact by ticketing system/email with response according to priority.
24/7 monitoring and on-call for high severity response
Streams from 1st line to specialist training or technical teams as required. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Our UK based service desk agents are multi-skilled and have the tools and permissions to fix the vast majority of issues first time.
Where remote access is required, we use TeamViewer to establish a secure connection to a customer workstation to view issues first hand and provide the fastest possible resolution.
We run an ISO20001-1 aligned service management system that conforms to the NHS model regarding incident and problem management and have established channels with the clinical system providers and the NHS service bridges.
We are well used to interfacing with the service teams of ICBs/HBs/LHBs and can establish bespoke ways of working as required.
All electronic and voice support included in the base line costs. Site visits will incur an additional, per case charge - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
We put a lot of effort into making our services as intuitive as possible, but this doesn't mean that we don't offer a full onboarding as part of the service.
Our range of services is large and every customer has different needs. We initially identify which areas will deliver the most immediate benefit and focus there with a mix of self-service support articles, video and 1:1 / 1:many virtual training sessions to get a site live in the most efficient manner.
Once an organisation has bedded down with the service, we then work with them to establish the next area to focus on and, with this iterative approach, deliver the most value in the shortest timeframe without overloading people.
Where appropriate, we provide on-site assistance - particularly at locality events and training days. - Service documentation
- Yes
- Documentation formats
-
- HTML
- ODF
- End-of-contract data extraction
-
We are firm believers that all relevant data should be on the patients medical record and use assured APIs and automation to make sure this happens. We have data management tools that allow customers to manage their live-service retention policies, and it is these that we employ once the customer is happy for deletion to take place.
These arrangements are usually captured in the Data Processing Agreement we have with a Controller to allow us to Process their data. - End-of-contract process
-
Our customer success team will identify the intent to terminate as the contract term comes to a close and establish a tailored off-boarding plan that covers service migration and data deletion.
We are very flexible with our customers and understand that delays might occur late in the day and can provide fractional billing for any over-run period to provide service continuity. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Linux or Unix
- MacOS
- Windows
- ChromeOS
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
Limited clinical system integration for HCPs on mobile, but for patients they receive the full service optimised for the device they are using.
Native app experience available though the Engage and/or the NHS App - Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
-
The Admin/Clinical interface is a modern and intuitive design that can be used through either the Engage Client for a fully integrated experience or any modern web browser.
Patients and carers have a similar experience, tailored to their chosen device or method of contact and, where appropriate, is made available in a wide range of languages.
Connections to 3rd party systems (such as EMIS, TPP and Vision) are transparent to users. - Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- We have regular service audits by an external 3rd party that specifically looks at accessibility issues. Identified issues are promptly prioritised and resolved to maintain a minimum level of WCAG2.2 AA.
- API
- Yes
- What users can and can't do using the API
-
We have an open pairing policy with 3rd parties to allow our services to interconnect. Established on a case by case basis, the API predominantly allows the creation of messages in our system from such as from Telephony providers or 3rd party website providers.
We welcome new use cases and generally do not charge for creation of additional API capabilities or transactional usage. - API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
The service is highly configurable by authorised end users via their management console. Our deployment and training team can provide both initial "Get you going" support and advice on how to tailor the service as a customer becomes more comfortable with it. Aspects of configurability include:
- Customisation of patient portal, including services, administrative requests, signposting, self-help, and information gathering for long-term condition reviews
- Information obtained in response to medical or administrative requests from patients or staff
- Care navigation tools allow automatic routing and/or prioritising for the patient concerned, their age, request type, or content.
-Establishing groups of users and sharing with other organisations
- Service hours and granular capacity management to harmonise with staff availability
- Creation and sharing of coded questionnaires
- Message templates
- Location awareness of sites, rooms, and waiting areas
- Information gathering on appointment arrival, e.g., demographic checks, clinical measurements etc.
- Upload own content (Video and static) for the Call / Information boards
- Appointment availability for offering self-book
- Friends & Family Test following appointment or consultation
- SMS sender ID
- Appointment reminder schedule
- Outcomes for reporting purposes
- Confirmation messages/emails
Scaling
- Independence of resources
-
Our infrastructure is containerised and scales automatically on demand.
Batch, maintenance and housekeeping tasks are scheduled for the quiet hours.
Monitoring scripts identify any use trends by customers that might lead to performance issues and are proactively addressed.
Some resource expensive operations are run locally at customer sites
Analytics
- Service usage metrics
- Yes
- Metrics types
-
All transactions are recorded and surfaced through an array of pre-configured reports in the Management Console on both a single and multiple organisational basis.
Our use of Elastic/Kibana allows a high degree of customised reporting if required (may be chargeable)
Where required, automated reporting to national teams is included in the cost (Example: MESH reporting to NHS in England) - Reporting types
-
- Real-time dashboards
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
-
Patients have the ability to export their details from a self-serve area of the service.
Customer data can be exported self-serve via the reporting tools in the management console.
Customised exports are available on request and, dependant on scope, may be subject to an additional charge - Data export formats
- Other
- Other data export formats
- JSON
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
As witnessed by https://status.engagehealth.uk/, our availability is usually at 100% but we guarantee in excess of 99.99% in accordance with the standards set down by the NHS for these classes of service. We run a CI pipeline that allows updates with zero downtime. In exceptional circumstances when downtime is required, it will be announced in advance and conducted well out of normal operating hours.
Protection against malicious action is achieved by regular and on-going penetration and vulnerability testing with 3rd party services layered in front to mitigate brute attacks such as a DDoS.
For hardware we supply, we generally get a replacement shipped within 48 hours - Approach to resilience
- We leverage the considerable investment made by Amazon in their AWS platform to provide a high-availability service split across zones to protect against service outages in the facility. We are hosted primarily in London (eu-west-2) for both IG reasons and to keep the service as close to users as possible.
- Outage reporting
-
Our status page at https://status.engagehealth.uk/ allows users to subscribe to any updates. Minor issues are shown through the service via notifications. Internally, issues are reported to our DevOps via a separate comms channel.
Where contractually arranged, we mirror these alerts to Service Desk Bridges and dedicated customer teams.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
-
Access to the production environment can only be achieved from our own offices using secure tunnels. Staff have limited access to aspects of production based on their roles. Access from overseas locations is denied.
Robust onboarding/offboarding ensures considered access is granted and that it is removed once no longer required. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
We have a very wide range of policies and procedures based around ISO27001 and DCB0129 to ensure we deliver services that are IG and clinically safe. We are externally audited annually on our processes and our staff are all DBS checked and subject to continuation security training.
Annual penetration testing by a CHECK rated organisation of our services
Other standards and tools we follow/use include UK NCSC, NHS DSP Toolkit, CE and CE+
The Company Executive is ultimately responsible for the delivery of these policies and there is a direct route for any employee to raise issues (in confidence, if required) - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Our development pipeline goes through multiple lower environments before a release candidate is deployed to Pre-Prod, a staging environment that replicates production with representative synthetic data. A mix of automated and manual tests are performed on this during regression testing before it is cleared for release to production. These tests include architectural, technical, security and clinical consideration of the changes proposed.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
We subscribe to and monitor the security feeds of all packages and components we use to deliver our services. Where there is an issue, we have the ability through our CI pipeline to deploy a fix within a few hours.
As a matter of routine, we build time into our development schedule to make sure we always keep on top of component and technology updates. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Though use of visualisation tools and malware scanning agents, abnormal activities that might indicate a potential compromise are quickly identified and categorised. We have a detailed incident response plan to address any incident that covers both our production and domestic / ops environments.
- Incident management type
- Supplier-defined controls
- Incident management approach
-
All service issues are categorised and recorded in our ticketing system (FreshDesk) which allows the linking of incidents and identification of problems as well as providing a library of curated KB articles that we can provide in response.
Issues can be raised by email or telephone, with a third channel for product feedback integrated into the service itself.
Tickets (and linked tickets) receive updates on the status of the incident and are notified by email.
Internally, we have a monthly reporting process to identify trends and drive service improvement. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- All components are available for a free trial, generally targeted at a pilot / First of Type organisation in a locality evaluating our services. This will include the full onboarding package but we may have to charge for 3rd party licencing fees (e.g. Clinical integration)
- Link to free trial
- https://engagehealth.uk/
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 3%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 15%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- British Assessment Bureau
- ISO/IEC 27001 accreditation date
- Tuesday 30 September 2025
- What the ISO/IEC 27001 doesn’t cover
- Our SoA covers all aspects of our operations and is reviewed annually or on significant change to company operations.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- British Assessment Bureau
- ISO 9001 accreditation date
- Tuesday 30 September 2025
- What the ISO 9001 doesn’t cover
- Closely aligned with our 27001 SoA due to the nature of our business, it covers all areas of our operations and is reviewed at least annually or on significant change to the business or it's operations.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- F9a42869-0013-4571-891c-8f25f92a7a65
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 292b7649-1658-456b-a63e-6d7e92f4ed0f
- Other security certifications
- Yes
- Any other security certifications
-
- NHS DTAC
- NHS DSPTK
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-