Skip to main content

Help us improve the Digital Marketplace - send your feedback

INTEGRATED MEDICAL SOLUTIONS LIMITED

MAXIMS cura (Sexual Health)

MAXIMS cura (Sexual Health) SaaS. A secure, cloud-based platform providing real-time access to patient records for organisations providing Sexual Health, HIV and Family Planning. It improves care quality, streamlines workflows, and ensures compliance with GDPR and NHS standards. A multi-disciplinary, cross community solution for services providing primary and secondary care.

Features

  • Thin client , latest platforms. Central deployment and administration.
  • Modular application
  • Ability to define templates for workflow management
  • Realtime Order and result management
  • Patient self registration, booking and arrival through kiosk and online
  • Appointment reminders, Recalls and Results sent as SMS to patients
  • Supports Statutory reporting for Sexual Health Services
  • Ad Hoc reporting feature enables user defined reporting

Benefits

  • Flexible Clinic management
  • Patient tracking and reporting for analysis and effective clinic management
  • Flexible patient self-registration and booking through portal and kiosk support
  • Support for patient self-arrival through kiosks or their own device
  • Partner notification - cross referencing, reporting and worklist
  • Proforma templates - Customisable flow of modules
  • Create alerts for patients and HCP's

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at bids@imsmaxims.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

3 2 6 2 8 4 9 8 5 5 1 3 0 0 8

Contact

INTEGRATED MEDICAL SOLUTIONS LIMITED IMS MAXIMS Bid Team
Telephone: 0203 66 86 999
Email: bids@imsmaxims.com

About your service

Service categories

Applications

Production and operations

Service industry and public sector operations

  • Healthcare
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
  • Public cloud
  • Hybrid cloud
Service constraints
The service requires deployment on Windows Server environments.
Chromium based web browsers supported.
Requires Microsoft SQL Server for hosting the database.

[Desktop PCs]
Intel Core i15 (8th Gen or newer) or AMD Ryzen 5 3000 series or newer.
8 GB minimum (16 GB recommended).
128 GB HDD/SDD.
1280 x 1024 or higher.
Gigabit Ethernet + Wi-Fi 5 (802.11ac) or better.
Supported version of Microsoft Windows Desktop Operation system
Supported versions of Google Chrome or Microsoft Edge (Chromium).
System requirements
  • Windows Server 2022 or later , Intel X86 64 Bit
  • Microsoft SQL 2022 Server
  • Desktop i5Core, RAM 8GB,128GB HD,1280x1024
  • Gigabit Ethernet + Wi-Fi 5 (802.11ac) or better
  • Virtualised infrastructure 4vCPU,16GB RAM
  • Integration HL7
  • Browsers supported Edge,Chrome
  • SAN Storage

User support

Email or online ticketing support
Yes
Support response times
Response During Core Hours (Mon–Fri, 08:00–18:00)

We offer tailored SLAs. Response and resolution targets depend on incident/request severity.

Standard targets:

Severity 1 – Response: 10 mins | Resolution: 4 hrs (24x7x365)
Severity 2 – Response: 10 mins | Resolution: 8 hrs (24x7x365)
Severity 3 – Response: 1 working day | Resolution: 20 working days (core hours)
Severity 4 – Response: 5 working days | Resolution: 90 working days or next maintenance release (core hours)
Severity 5 – Response: 5 working days | Resolution: next/future maintenance release (core hours)
Severity 6 (Service Request) – Response/Resolution: N/A
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
IMS MAXIMS offers tiered Support and Service Management for NHS, (and HSE, and private customers)
Our tiers range from Diamond, which includes:

[ Allocated Service Delivery Manager]
SLA performance targets with contractual penalties
24×7×365 support for high-severity incidents
Service reporting and review meetings
Annual upgrades and call-off days for ad-hoc needs

Through to Bronze, providing application support during core hours (Mon–Fri, 8am–6pm).

Full details of Diamond, Platinum, Gold, Silver, and Bronze tiers are available on request.
Solutions can be fully managed in Azure or supported on-premises, with tiered offerings defining included services. For hosted Diamond, IMS MAXIMS implements proactive system monitoring to minimise downtime, covering:

Application availability and performance
Server health (disk, memory, CPU)

All tiers follow ITIL-aligned processes via the MAXIMS Service Desk Portal, supporting:

Incident, Request, Problem,and Change Management
Customer database and online Customer Portal

Where included, the Service Delivery Manager ensures SLA compliance, acts as escalation point, provides reports, hosts review meetings, and drives service improvements. Customer satisfaction is measured at incident closure, in reviews, and via an annual NPS survey.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
[Training and Support Services]
Train-the-Trainer Programme

IMS MAXIMS supports a train-the-trainer model, delivering remote online sessions to equip customer trainers with the skills to cascade knowledge effectively.

[Knowledge Base – MAX Help]
Our MAX Help portal provides comprehensive resources, including:

Articles on system configuration and usage for analysts and trainers
Embedded e-learning materials such as instructional videos

[Quick Reference Guides]
Concise guides are produced and distributed as needed to support specific functions and workflows.

[Interactive Learning]

Product Workshops – “Show and Tell” sessions for user groups
User Forums – A platform for raising issues and sharing feedback, with all items logged for review and resolution

[Training Environments]
Customers receive multiple environments for configuration and training, including rollback functionality to streamline practice and data setup.

[Go-Live Assistance]
On-site support is available where required, including floor-walker assistance to ensure a smooth transition.

[Post-Training Services]
Professional services packages are offered for onboarding, refresher training, and ongoing support.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
  • Other
Other documentation formats
  • MAX HELP Online help center
  • SCRIBE embedded into MAX HELP
End-of-contract data extraction
IMS will provide a full DB backup in SQL server format back up and/or CSV table extracts
End-of-contract process
When the contract ends, the customer’s access to the SaaS platform is terminated unless an extension or renewal is agreed. The customer retains full ownership of their data, and the supplier provides secure data extraction in standard formats (such as CSV) to support migration or archiving. Any additional services—like extended data hosting, bespoke migration support, or conversion to non-standard formats—are usually offered at extra cost. After data handover, the supplier ensures compliance with data protection regulations and confirms deletion of any residual data from their systems.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
MAXHELP Access and Management

All resources are available through our online MAXHELP application which is an accessibility friendly platform.

This is a role and web based content article management application where relevance of 'modules' is aligned to customers needs. Images , files , and video can be incorporated.

The platform’s themes and markup are designed to support screen readers, keyboard navigation, and semantic structure, which are core WCAG requirements.

SCRIBE allows for audio conversion of text and text tool tips of audio embedded into MAXHELP.

Users are encouraged to request access initially, which is managed and controlled by IMS MAXIMS.

Content Updates::
Whenever articles are updated or new documentation is published, notification emails are automatically sent to subscribed users.

Access Review Process:
To maintain security and relevance:

We will audit subscriber activity, reviewing the last accessed record.
If access appears unnecessary, it will be removed after consultation.
Users will be contacted to confirm their ongoing requirements before any changes are made.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Chrome
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Desktop Service is designed for healthcare providers such as clinicians, nurses, and administrative staff, the desktop application streamlines patient management, appointment scheduling and consultation. It supports efficient workflows and accurate documentation to enhance care delivery.

Online or mobile service is made available for patients. It offers self-service features, including registration, appointment booking, and triage submission. This empowers patients to manage their healthcare conveniently while providing clinicians with essential information in advance, improving efficiency and patient experience.
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
User Access Methods
Users can access the service via a web browser

Authentication & Security:
Log in via username/password

Interface Characteristics
Graphical user interface (GUI)

Supported Devices & Platforms:
Windows, iOS , Android

Integration
HL7 2.3

Web technologies
HTML, Javascript, XML, JSON
Accessibility standards
None or don’t know
Description of accessibility
MAXIMS cura UI has improved contrast ratios that comply with WCAG, this makes the application easy to read with content easily distinguishable and in a meaningful sequence. Input assistance is provided by way of meaningful feedback should the user encounter any errors.

MAXIMS cura is partially conformant with WCAG 2.1 level. Web Accessibility conformance is part of the cura Roadmap
Accessibility testing
Screen readers have not been tested
ARIA tags not present in system making it difficult for screen readers to actively represent the screen layout and content
On road map for resolution
API
No
Customisation available
Yes
Description of customisation
MAXIMS cura – Customisation Overview

[Flexible Configuration]
The MAXIMS cura can be tailored extensively to align with organisational workflows at both system and role levels.

[Role-Based Access Control] (RBAC)
Granular permissions ensure secure access and configuration of customised dashboards, menus, and features.

[Editable Components]

Locations, users, resources, roles, and permissions
Navigation structures
Lookup tables and taxonomy mappings
Proforma templates for noting and assessments
Custom reports, templates, and analytics options
Result alert settings.
Dashboard views,
Clinics
[Key Capabilities]

Highly Customisable Platform – Adapt workflows, screens, and processes to local requirements without coding.

Clinical Coding Flexibility – Supports SNOMED, ICD-10, and ICD-11 taxonomies with configurable start/end dates.

Customisable Interfaces – Design intuitive screens and navigation for different specialties and care settings.

Integration Options via HL7

Scaling

Independence of resources
MAXIMS uses redundant load balancers with session stickiness and health checks to ensure high availability. It supports horizontal scaling, adding servers as demand grows, and modular deployment for flexibility. IMS separate workloads e.g operational from reporting and business intelligence.

Cloud environments leverage zone-redundant services and VM clustering for resilience. Performance is maintained through proactive monitoring, QoS policies, and disaster recovery with dual data centres and SQL clustering, guaranteeing continuity and SLA compliance.

Analytics

Service usage metrics
Yes
Metrics types
A performance report is produced for each service period, detailing compliance with agreed Service Levels. It can include system availability (excluding planned downtime), response times, resource consumption , user metrics, and any Service Credits incurred.
The report also summarises severity levels, incidents, breaches, outstanding issues, corrective actions, and repeat incident resolutions.

It lists Service Credits applied, rolling totals for six months, and any failures against contractual requirements. Additional details may be provided as requested. Reports are typically monthly but frequency can be adjusted. The aim is to ensure transparency, track performance, and outline actions to prevent recurrence of issues.
Reporting types
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Physical access control, complying with another standard
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
[Supported Formats]
Structured formats: HL7 or CSV for tabular data.
Reports: PDF and Excel (.csv/.xlsx) for clinical and administrative outputs.

[Access Method]
Users with appropriate permissions can initiate exports via the application’s secure interface.
Bulk data extracts via SQL server tooling or third party tooling

[Vendor Support]
We provide documentation and support for configuring exports.
Optional consultancy for complex migrations or integrations.

SQL server tooling standards tooling or third party tooling
Business intelligence tools that support SQL server
Data export formats
  • CSV
  • Other
Other data export formats
  • PDF for clinical summaries and discharge reports.
  • XML for structured data exchange.
  • JSON for API-based integrations.
  • HL7
Data import formats
  • CSV
  • Other
Other data import formats
  • HL7 for messaging based data exchange
  • CSV for tabular data
  • XML for structured datasets
  • JSON for API-based integrations.

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
IMS MAXIMS offer our customers tailored SLA’s which can include targets for system availability. Failure to achieve availability targets can incur service credits in the form of service credit points and associated financial penalties.

A percentage of the monthly ASM charge can be paid back to, or retained by, the customer for failing to meet availability targets.

Availability targets are often banded with increasing penalties depending on the availability achieved. As an example:

Availability Service Credit

≥99.9% ≤100% 0 – above minimal level

≥99.5% ≤99.89% 1% of the Monthly Charge

≥99% ≤99.49% 5% of the Monthly Charge

≥98.5% ≤98.99% 10% of the Monthly Charge

≥98% ≤98.49% 15% of the Monthly Charge

≥97% but ≤97.99% 20% of the Monthly Charge

≥96% but ≤96.99% 30% of the Monthly Charge

≥95.01% but ≤95.99% 40% of the Monthly Charge

Equal to or Less than 95% 50% of the Monthly Charge
Approach to resilience
Our approach to resilience is flexible and can be tailored to meet buyer requirements. We offer options ranging from single-site deployments to multi-site, high-availability configurations with automated failover and disaster recovery.
Standard resilience includes hosting in Tier 3+ data centres with redundant power, cooling, and network connectivity. Enhanced resilience options, such as active-active replication across multiple availability zones, are available at additional cost.
Full details of resilience and disaster recovery options are available on request.
Outage reporting
Hosted customers are provocatively monitored via PRTG and other monitoring tools (network and IT infrastructure monitoring tool )
Email alerts are generated as per configuration

The majority of customers are hosted on the clients NHS owned infrastructure which does not provide a public outage dashboard or API.
Outage reporting follows NHS operational protocols and notifications communicated through NHS operational channels

Identity and authentication

User authentication needed
Yes
User authentication
  • Public key authentication (including by TLS client certificate)
  • Dedicated link (for example VPN)
  • Username or password
Access restrictions in management interfaces and support channels
Access Restrictions in Management Interfaces

Role-Based Access Control (RBAC)
Access to management interfaces is restricted based on job role and principle of least privilege.
Multi-Factor Authentication (MFA)
All administrative accounts require MFA.
Network Segmentation & VPN
Management interfaces are only accessible via secure VPN or dedicated management network.
IP Whitelisting
Access is limited to approved IP ranges for internal and authorized support personnel.
Logging & Monitoring

Identity Verification
Support requests require identity verification
Secure Communication
Support channels use encrypted protocols (TLS 1.2+)
Privileged Session Management
Remote support sessions are time-bound, monitored, and recorded for compliance.
No Shared Accounts
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Dedicated link (for example VPN)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
We operate an Information Security Management System (ISMS) aligned with ISO 27001:2022

Access Control – Role-based access, MFA, and least privilege principles.

Data Protection – Encryption in transit (TLS 1.2+) and at rest (AES-256).

Incident Management – Defined process for detection, escalation, and resolution within SLA.

Supplier Security – All third-party contracts include security clauses (aligned with ISO 27001 A.5.20).

Risk Management – Regular risk assessments and vulnerability scans.

Compliance – Adherence to GDPR, UK Data Protection Act

Board-Level Oversight: The Chief Information Security Officer (CISO) is a member of the Senior Management Teams.

Escalation Path: Incidents are escalated from Service Desk → IT → CISO → Board as required by the severity of the incident.

Roles and responsibilities are documented in our ISMS and reviewed annually.

Mandatory Training: All staff complete annual security awareness and GDPR training.

Audits & Monitoring: Internal audits every 6 months; external ISO 27001 audits annually.

Automated Controls: SIEM for continuous monitoring, alerting on anomalies.

Compliance Reviews: Regular compliance checks and audits against CCS and ISO standards.

Reporting & KPIs: Security metrics reported to senior management team
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
IMS follow structured configuration and change management process aligned with ITIL . IMS is certified to ISO 27001 & ISO9001 ensure service integrity and security.
Service components (software versions, infrastructure dependencies, configuration items) are recorded.
Version control for code and infrastructure is managed via GIT.
Each component is tracked throughout its lifecycle, with version control and audit.
Changes are logged and managed in our Jira ticketing
Every change request undergoes formal review.
Changes are assessed for potential security impact, including data protection, access control, and compliance with NHS and government standards.
Risk assessments and rollback plans are documented before implementation.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
IMS follows an ISO27001-aligned framework. Threats are assessed using CVSS scoring and continuous scanning via ManageEngine, which detects zero-day vulnerabilities, misconfigurations, and non-approved applications. External intelligence is sourced from CISA.GOV, NHS, Crowdstrike and other similar alerts.
Patching adheres to strict SLAs: Low severity within 12 weeks, Medium within 4 weeks, High/Critical within 14 days. Development servers patch automatically; production servers follow after one week for stability.
Mitigation includes patching, disabling services, adjusting access controls, and increasing monitoring. Vulnerabilities are escalated within 48 hours to ensure rapid response and compliance. This process safeguards services and minimises disruption.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
IMS MAXIMS uses PRTG-based probes and other similar monitoring systems in an ISO27001:2022-aligned solution to continuously monitor application performance, network connectivity, and security events. Potential compromises are detected through simulated user actions and anomaly alerts. When identified, incidents follow the ISMS Incident Management Procedure for immediate containment, investigation, and remediation, ensuring GDPR compliance. Actions include disabling affected services, applying emergency patches, and adjusting access controls. Critical incidents are addressed immediately, supported by contractual SLAs to restore service integrity and minimise disruption.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
We operate a documented incident management framework aligned with ITIL and GDPR. Users report incidents via the MAXIMS Service Desk portal, with options for phone or agreed support channels under contractual SLAs. All incidents are logged, tracked, and prioritised based on impact and urgency. Incident reports include status updates, resolution details, and root cause analysis where applicable. Customers receive resolution confirmation and, for major incidents, formal reports outlining actions taken and lessons learned. This process ensures transparency, compliance, and minimal service disruption.

Pre-defined procedures exist for common events, including service disruptions and security incidents, to ensure rapid containment and resolution.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
Yes
Connected networks
Health and Social Care Network (HSCN)

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
10%
Between £250,000 and £500,000
10%
Between £500,001 and £1,000,000
10%
Between £1,000,001 and £2,500,000
10%
Between £2,500,001 and £5,000,000
10%
Over £5,000,001
10%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Nqa
ISO/IEC 27001 accreditation date
Friday 20 August 2021
What the ISO/IEC 27001 doesn’t cover
N/A everything is in scope
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
Nqa
ISO 9001 accreditation date
Tuesday 20 March 2001
What the ISO 9001 doesn’t cover
N/A everything is in scope
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
Aa483b5c-231f-4811-9baf-5dde93f857d2
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
Yes
Any other security certifications
  • NHS Data Security Protection Toolkit
  • DTAC

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at bids@imsmaxims.com. Tell them what format you need. It will help if you say what assistive technology you use.