MAXIMS cura (Sexual Health)
MAXIMS cura (Sexual Health) SaaS. A secure, cloud-based platform providing real-time access to patient records for organisations providing Sexual Health, HIV and Family Planning. It improves care quality, streamlines workflows, and ensures compliance with GDPR and NHS standards. A multi-disciplinary, cross community solution for services providing primary and secondary care.
Features
- Thin client , latest platforms. Central deployment and administration.
- Modular application
- Ability to define templates for workflow management
- Realtime Order and result management
- Patient self registration, booking and arrival through kiosk and online
- Appointment reminders, Recalls and Results sent as SMS to patients
- Supports Statutory reporting for Sexual Health Services
- Ad Hoc reporting feature enables user defined reporting
Benefits
- Flexible Clinic management
- Patient tracking and reporting for analysis and effective clinic management
- Flexible patient self-registration and booking through portal and kiosk support
- Support for patient self-arrival through kiosks or their own device
- Partner notification - cross referencing, reporting and worklist
- Proforma templates - Customisable flow of modules
- Create alerts for patients and HCP's
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 2 6 2 8 4 9 8 5 5 1 3 0 0 8
Contact
INTEGRATED MEDICAL SOLUTIONS LIMITED
IMS MAXIMS Bid Team
Telephone: 0203 66 86 999
Email: bids@imsmaxims.com
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Hybrid cloud
- Service constraints
-
The service requires deployment on Windows Server environments.
Chromium based web browsers supported.
Requires Microsoft SQL Server for hosting the database.
[Desktop PCs]
Intel Core i15 (8th Gen or newer) or AMD Ryzen 5 3000 series or newer.
8 GB minimum (16 GB recommended).
128 GB HDD/SDD.
1280 x 1024 or higher.
Gigabit Ethernet + Wi-Fi 5 (802.11ac) or better.
Supported version of Microsoft Windows Desktop Operation system
Supported versions of Google Chrome or Microsoft Edge (Chromium). - System requirements
-
- Windows Server 2022 or later , Intel X86 64 Bit
- Microsoft SQL 2022 Server
- Desktop i5Core, RAM 8GB,128GB HD,1280x1024
- Gigabit Ethernet + Wi-Fi 5 (802.11ac) or better
- Virtualised infrastructure 4vCPU,16GB RAM
- Integration HL7
- Browsers supported Edge,Chrome
- SAN Storage
User support
- Email or online ticketing support
- Yes
- Support response times
-
Response During Core Hours (Mon–Fri, 08:00–18:00)
We offer tailored SLAs. Response and resolution targets depend on incident/request severity.
Standard targets:
Severity 1 – Response: 10 mins | Resolution: 4 hrs (24x7x365)
Severity 2 – Response: 10 mins | Resolution: 8 hrs (24x7x365)
Severity 3 – Response: 1 working day | Resolution: 20 working days (core hours)
Severity 4 – Response: 5 working days | Resolution: 90 working days or next maintenance release (core hours)
Severity 5 – Response: 5 working days | Resolution: next/future maintenance release (core hours)
Severity 6 (Service Request) – Response/Resolution: N/A - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
IMS MAXIMS offers tiered Support and Service Management for NHS, (and HSE, and private customers)
Our tiers range from Diamond, which includes:
[ Allocated Service Delivery Manager]
SLA performance targets with contractual penalties
24×7×365 support for high-severity incidents
Service reporting and review meetings
Annual upgrades and call-off days for ad-hoc needs
Through to Bronze, providing application support during core hours (Mon–Fri, 8am–6pm).
Full details of Diamond, Platinum, Gold, Silver, and Bronze tiers are available on request.
Solutions can be fully managed in Azure or supported on-premises, with tiered offerings defining included services. For hosted Diamond, IMS MAXIMS implements proactive system monitoring to minimise downtime, covering:
Application availability and performance
Server health (disk, memory, CPU)
All tiers follow ITIL-aligned processes via the MAXIMS Service Desk Portal, supporting:
Incident, Request, Problem,and Change Management
Customer database and online Customer Portal
Where included, the Service Delivery Manager ensures SLA compliance, acts as escalation point, provides reports, hosts review meetings, and drives service improvements. Customer satisfaction is measured at incident closure, in reviews, and via an annual NPS survey. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
[Training and Support Services]
Train-the-Trainer Programme
IMS MAXIMS supports a train-the-trainer model, delivering remote online sessions to equip customer trainers with the skills to cascade knowledge effectively.
[Knowledge Base – MAX Help]
Our MAX Help portal provides comprehensive resources, including:
Articles on system configuration and usage for analysts and trainers
Embedded e-learning materials such as instructional videos
[Quick Reference Guides]
Concise guides are produced and distributed as needed to support specific functions and workflows.
[Interactive Learning]
Product Workshops – “Show and Tell” sessions for user groups
User Forums – A platform for raising issues and sharing feedback, with all items logged for review and resolution
[Training Environments]
Customers receive multiple environments for configuration and training, including rollback functionality to streamline practice and data setup.
[Go-Live Assistance]
On-site support is available where required, including floor-walker assistance to ensure a smooth transition.
[Post-Training Services]
Professional services packages are offered for onboarding, refresher training, and ongoing support. - Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
-
- MAX HELP Online help center
- SCRIBE embedded into MAX HELP
- End-of-contract data extraction
- IMS will provide a full DB backup in SQL server format back up and/or CSV table extracts
- End-of-contract process
- When the contract ends, the customer’s access to the SaaS platform is terminated unless an extension or renewal is agreed. The customer retains full ownership of their data, and the supplier provides secure data extraction in standard formats (such as CSV) to support migration or archiving. Any additional services—like extended data hosting, bespoke migration support, or conversion to non-standard formats—are usually offered at extra cost. After data handover, the supplier ensures compliance with data protection regulations and confirms deletion of any residual data from their systems.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
MAXHELP Access and Management
All resources are available through our online MAXHELP application which is an accessibility friendly platform.
This is a role and web based content article management application where relevance of 'modules' is aligned to customers needs. Images , files , and video can be incorporated.
The platform’s themes and markup are designed to support screen readers, keyboard navigation, and semantic structure, which are core WCAG requirements.
SCRIBE allows for audio conversion of text and text tool tips of audio embedded into MAXHELP.
Users are encouraged to request access initially, which is managed and controlled by IMS MAXIMS.
Content Updates::
Whenever articles are updated or new documentation is published, notification emails are automatically sent to subscribed users.
Access Review Process:
To maintain security and relevance:
We will audit subscriber activity, reviewing the last accessed record.
If access appears unnecessary, it will be removed after consultation.
Users will be contacted to confirm their ongoing requirements before any changes are made.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Chrome
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
Desktop Service is designed for healthcare providers such as clinicians, nurses, and administrative staff, the desktop application streamlines patient management, appointment scheduling and consultation. It supports efficient workflows and accurate documentation to enhance care delivery.
Online or mobile service is made available for patients. It offers self-service features, including registration, appointment booking, and triage submission. This empowers patients to manage their healthcare conveniently while providing clinicians with essential information in advance, improving efficiency and patient experience. - Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
-
User Access Methods
Users can access the service via a web browser
Authentication & Security:
Log in via username/password
Interface Characteristics
Graphical user interface (GUI)
Supported Devices & Platforms:
Windows, iOS , Android
Integration
HL7 2.3
Web technologies
HTML, Javascript, XML, JSON - Accessibility standards
- None or don’t know
- Description of accessibility
-
MAXIMS cura UI has improved contrast ratios that comply with WCAG, this makes the application easy to read with content easily distinguishable and in a meaningful sequence. Input assistance is provided by way of meaningful feedback should the user encounter any errors.
MAXIMS cura is partially conformant with WCAG 2.1 level. Web Accessibility conformance is part of the cura Roadmap - Accessibility testing
-
Screen readers have not been tested
ARIA tags not present in system making it difficult for screen readers to actively represent the screen layout and content
On road map for resolution - API
- No
- Customisation available
- Yes
- Description of customisation
-
MAXIMS cura – Customisation Overview
[Flexible Configuration]
The MAXIMS cura can be tailored extensively to align with organisational workflows at both system and role levels.
[Role-Based Access Control] (RBAC)
Granular permissions ensure secure access and configuration of customised dashboards, menus, and features.
[Editable Components]
Locations, users, resources, roles, and permissions
Navigation structures
Lookup tables and taxonomy mappings
Proforma templates for noting and assessments
Custom reports, templates, and analytics options
Result alert settings.
Dashboard views,
Clinics
[Key Capabilities]
Highly Customisable Platform – Adapt workflows, screens, and processes to local requirements without coding.
Clinical Coding Flexibility – Supports SNOMED, ICD-10, and ICD-11 taxonomies with configurable start/end dates.
Customisable Interfaces – Design intuitive screens and navigation for different specialties and care settings.
Integration Options via HL7
Scaling
- Independence of resources
-
MAXIMS uses redundant load balancers with session stickiness and health checks to ensure high availability. It supports horizontal scaling, adding servers as demand grows, and modular deployment for flexibility. IMS separate workloads e.g operational from reporting and business intelligence.
Cloud environments leverage zone-redundant services and VM clustering for resilience. Performance is maintained through proactive monitoring, QoS policies, and disaster recovery with dual data centres and SQL clustering, guaranteeing continuity and SLA compliance.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
A performance report is produced for each service period, detailing compliance with agreed Service Levels. It can include system availability (excluding planned downtime), response times, resource consumption , user metrics, and any Service Credits incurred.
The report also summarises severity levels, incidents, breaches, outstanding issues, corrective actions, and repeat incident resolutions.
It lists Service Credits applied, rolling totals for six months, and any failures against contractual requirements. Additional details may be provided as requested. Reports are typically monthly but frequency can be adjusted. The aim is to ensure transparency, track performance, and outline actions to prevent recurrence of issues. - Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
-
[Supported Formats]
Structured formats: HL7 or CSV for tabular data.
Reports: PDF and Excel (.csv/.xlsx) for clinical and administrative outputs.
[Access Method]
Users with appropriate permissions can initiate exports via the application’s secure interface.
Bulk data extracts via SQL server tooling or third party tooling
[Vendor Support]
We provide documentation and support for configuring exports.
Optional consultancy for complex migrations or integrations.
SQL server tooling standards tooling or third party tooling
Business intelligence tools that support SQL server - Data export formats
-
- CSV
- Other
- Other data export formats
-
- PDF for clinical summaries and discharge reports.
- XML for structured data exchange.
- JSON for API-based integrations.
- HL7
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- HL7 for messaging based data exchange
- CSV for tabular data
- XML for structured datasets
- JSON for API-based integrations.
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
IMS MAXIMS offer our customers tailored SLA’s which can include targets for system availability. Failure to achieve availability targets can incur service credits in the form of service credit points and associated financial penalties.
A percentage of the monthly ASM charge can be paid back to, or retained by, the customer for failing to meet availability targets.
Availability targets are often banded with increasing penalties depending on the availability achieved. As an example:
Availability Service Credit
≥99.9% ≤100% 0 – above minimal level
≥99.5% ≤99.89% 1% of the Monthly Charge
≥99% ≤99.49% 5% of the Monthly Charge
≥98.5% ≤98.99% 10% of the Monthly Charge
≥98% ≤98.49% 15% of the Monthly Charge
≥97% but ≤97.99% 20% of the Monthly Charge
≥96% but ≤96.99% 30% of the Monthly Charge
≥95.01% but ≤95.99% 40% of the Monthly Charge
Equal to or Less than 95% 50% of the Monthly Charge - Approach to resilience
-
Our approach to resilience is flexible and can be tailored to meet buyer requirements. We offer options ranging from single-site deployments to multi-site, high-availability configurations with automated failover and disaster recovery.
Standard resilience includes hosting in Tier 3+ data centres with redundant power, cooling, and network connectivity. Enhanced resilience options, such as active-active replication across multiple availability zones, are available at additional cost.
Full details of resilience and disaster recovery options are available on request. - Outage reporting
-
Hosted customers are provocatively monitored via PRTG and other monitoring tools (network and IT infrastructure monitoring tool )
Email alerts are generated as per configuration
The majority of customers are hosted on the clients NHS owned infrastructure which does not provide a public outage dashboard or API.
Outage reporting follows NHS operational protocols and notifications communicated through NHS operational channels
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Public key authentication (including by TLS client certificate)
- Dedicated link (for example VPN)
- Username or password
- Access restrictions in management interfaces and support channels
-
Access Restrictions in Management Interfaces
Role-Based Access Control (RBAC)
Access to management interfaces is restricted based on job role and principle of least privilege.
Multi-Factor Authentication (MFA)
All administrative accounts require MFA.
Network Segmentation & VPN
Management interfaces are only accessible via secure VPN or dedicated management network.
IP Whitelisting
Access is limited to approved IP ranges for internal and authorized support personnel.
Logging & Monitoring
Identity Verification
Support requests require identity verification
Secure Communication
Support channels use encrypted protocols (TLS 1.2+)
Privileged Session Management
Remote support sessions are time-bound, monitored, and recorded for compliance.
No Shared Accounts - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
We operate an Information Security Management System (ISMS) aligned with ISO 27001:2022
Access Control – Role-based access, MFA, and least privilege principles.
Data Protection – Encryption in transit (TLS 1.2+) and at rest (AES-256).
Incident Management – Defined process for detection, escalation, and resolution within SLA.
Supplier Security – All third-party contracts include security clauses (aligned with ISO 27001 A.5.20).
Risk Management – Regular risk assessments and vulnerability scans.
Compliance – Adherence to GDPR, UK Data Protection Act
Board-Level Oversight: The Chief Information Security Officer (CISO) is a member of the Senior Management Teams.
Escalation Path: Incidents are escalated from Service Desk → IT → CISO → Board as required by the severity of the incident.
Roles and responsibilities are documented in our ISMS and reviewed annually.
Mandatory Training: All staff complete annual security awareness and GDPR training.
Audits & Monitoring: Internal audits every 6 months; external ISO 27001 audits annually.
Automated Controls: SIEM for continuous monitoring, alerting on anomalies.
Compliance Reviews: Regular compliance checks and audits against CCS and ISO standards.
Reporting & KPIs: Security metrics reported to senior management team - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
IMS follow structured configuration and change management process aligned with ITIL . IMS is certified to ISO 27001 & ISO9001 ensure service integrity and security.
Service components (software versions, infrastructure dependencies, configuration items) are recorded.
Version control for code and infrastructure is managed via GIT.
Each component is tracked throughout its lifecycle, with version control and audit.
Changes are logged and managed in our Jira ticketing
Every change request undergoes formal review.
Changes are assessed for potential security impact, including data protection, access control, and compliance with NHS and government standards.
Risk assessments and rollback plans are documented before implementation. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
IMS follows an ISO27001-aligned framework. Threats are assessed using CVSS scoring and continuous scanning via ManageEngine, which detects zero-day vulnerabilities, misconfigurations, and non-approved applications. External intelligence is sourced from CISA.GOV, NHS, Crowdstrike and other similar alerts.
Patching adheres to strict SLAs: Low severity within 12 weeks, Medium within 4 weeks, High/Critical within 14 days. Development servers patch automatically; production servers follow after one week for stability.
Mitigation includes patching, disabling services, adjusting access controls, and increasing monitoring. Vulnerabilities are escalated within 48 hours to ensure rapid response and compliance. This process safeguards services and minimises disruption. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- IMS MAXIMS uses PRTG-based probes and other similar monitoring systems in an ISO27001:2022-aligned solution to continuously monitor application performance, network connectivity, and security events. Potential compromises are detected through simulated user actions and anomaly alerts. When identified, incidents follow the ISMS Incident Management Procedure for immediate containment, investigation, and remediation, ensuring GDPR compliance. Actions include disabling affected services, applying emergency patches, and adjusting access controls. Critical incidents are addressed immediately, supported by contractual SLAs to restore service integrity and minimise disruption.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
We operate a documented incident management framework aligned with ITIL and GDPR. Users report incidents via the MAXIMS Service Desk portal, with options for phone or agreed support channels under contractual SLAs. All incidents are logged, tracked, and prioritised based on impact and urgency. Incident reports include status updates, resolution details, and root cause analysis where applicable. Customers receive resolution confirmation and, for major incidents, formal reports outlining actions taken and lessons learned. This process ensures transparency, compliance, and minimal service disruption.
Pre-defined procedures exist for common events, including service disruptions and security incidents, to ensure rapid containment and resolution. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
- Health and Social Care Network (HSCN)
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 10%
- Between £250,000 and £500,000
- 10%
- Between £500,001 and £1,000,000
- 10%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Nqa
- ISO/IEC 27001 accreditation date
- Friday 20 August 2021
- What the ISO/IEC 27001 doesn’t cover
- N/A everything is in scope
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Nqa
- ISO 9001 accreditation date
- Tuesday 20 March 2001
- What the ISO 9001 doesn’t cover
- N/A everything is in scope
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Aa483b5c-231f-4811-9baf-5dde93f857d2
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- Yes
- Any other security certifications
-
- NHS Data Security Protection Toolkit
- DTAC
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
-