MIG Shared Record Viewer (SRV)
MIG Shared Record Viewer is an independent web portal which provides healthcare professionals with instant access to the Medical Interoperability Gateway (MIG). It allows users to search for patients and view their medical records without an existing clinical system.
Features
- Responsive design, ideal for laptops and tablets
- Can be used in conjunction with any MIG datasets
- Internet browser based technology
- Fully auditable
- Smart card access not required
- Quick to implement
- Fully managed end to end service
- Cost effective
- Internet First: no HSCN or N3 access required
- Secure Multi-factor authentication
Benefits
- Implement without any development work
- Stand alone access, no dependency on existing clinical system
- Simple technology, quick and easy to deliver
- Can be used in any health or social care setting
- Tactical solution whilst systems or settings are accredited
- Perfect for data on the move
- Faster, improved decisions as access to real-time patient data
- Patients tell their story once
- Real-time sharing ensures clinical decisions are based on latest information
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 5 5 6 7 2 5 3 7 2 4 8 9 0 5
Contact
Enlivio Health
Bid Team
Telephone: 0113 380 3000
Email: info@emishealth.com
About your service
- Service categories
-
Applications
Production and operations
- Other operations
Service industry and public sector operations
- Healthcare
- Other
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- MIG consuming portal which allows the MIG shared record viewer to be embedded in EMIS Web frame a system provided by Optum.
- Cloud deployment model
- Public cloud
- Service constraints
-
There is a monthly maintenance window for 1 hour per month on a Wednesday between the hours of 12:00 and 13:00.
Relevant sharing agreements can be put into place. - System requirements
- Internet First: No HSCN or N3 access required
User support
- Email or online ticketing support
- Yes
- Support response times
- Support tickets raised via email within standard support hours (Monday to Friday 9am-5pm). Tickets raised outside of support hours, including weekends, will be responded to on the next working day.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- N/A
- Onsite support
- Yes, at extra cost
- Support levels
- Support levels will be provided as per the selected Service Management Model.
- Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
-
There is a tried tested approach to the deployment of MIG services. Within this context all the project management activity is based upon a tailored plan to meet the individual project requirements, taking into account the varied system estate and resource allocation, which can determine the rate and complexity of the implementation.
A project lead will be appointed to progress the project implementation of the services ordered. The MIG Project lead will organise a project initiation call or meeting with the customer. This expected outcome from this meeting is to discuss and agree the following:
• Roles and Responsibilities
• Commercial Review
• Project dependencies including Supplier Accreditation and Information Governance
Agree the Project Plan
• Discuss the Optum Implementation Process
• Support and Service arrangements
• Training Requirements
Optum will provide an Implementation Plan outlining the activities required by all stakeholders to enable a successful deployment; the project manager will update this plan as the project progresses. The project manager will ensure regular checkpoint calls are scheduled with all stakeholders to discuss progress, raise risks and/or issues and review progress in line with the implementation though the go live of the service - Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
-
- Microsoft Excel
- Microsoft Word
- End-of-contract data extraction
- As the MIG is a bi-directional brokering service it does not hold or store any data. The Shared Record Viewer does however store users and audit information. At the end of the contract the customer has the option to extract the users and audit information stored in the Shared Record Viewer. This is done by way of a CSV export facility. All data can be exported via the auditing export functionality.
- End-of-contract process
- At the end of a contract the Shared Record Viewer service will be decommissioned. On receipt of confirmation from the customer for decommission of the Shared Record Viewer, there will be one Auditor (customer) set up who’s responsibility it is to remove all of the data from the Shared Record Viewer. The customer will receive an email notifying them they have three months from this date to remove all of the data from the Shared Record Viewer. After two months has passed the customer will be notified that they have 1 month remaining. The final email will be notification of decommissioning and access will be removed. There is no additional cost for this process.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- There is no difference between the mobile and desktop service.
- Service interface
- No
- User support accessibility
- None or don’t know
- API
- No
- Customisation available
- No
Scaling
- Independence of resources
-
Optum infrastructure provides highly optimised services which have been designed to be horizontally scaled.
Each service call is initially load balanced across our service infrastructure to several potential service nodes so that any load is spread evenly across them.
The number of these service nodes has been chosen to far exceed our current load capacity expectations so that any spikes in service usage or long running requests won’t impact our expected response times.
All of our infrastructure components have been carefully chosen to be the best in practice where performance, scalability, and resilience are concerned.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Optum service metrics by way of a monthly report to customers on request . This demonstrates the total number of transactions for the reported period by organisation. This also includes a breakdown of those successful and failed transactions along with raw data for the period.
Enhanced reporting is available at an additional charge. Bespoke analytical reports are available from the service desk on request subject to availability. - Reporting types
-
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Physical access control, complying with another standard
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Degaussing
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
-
All data can be exported from the Shared Record Viewer using auditing functionality. Filter options are available;
Time - to select any, last hour, today and yesterday.
Date - to select a date range.
Users - to select the a single or multiple user
Actions -to the specific actions that you wish to view
Detail - to filter the actions by a detail combined with the Action filter applied above
Filter - The value that applies to the detail filter
There is an option to bulk export all information. - Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- Private network or public sector network
- Data protection within supplier network
- Legacy SSL and TLS (under version 1.2)
Availability and resilience
- Guaranteed availability
-
No level of availability is guaranteed, we use reasonable endeavours to provide at least 99% availability in respect of the relevant service during its standard support hours.
Service availability shall be represented as a percentage, calculated as follows:
actual minutes in month – planned downtime minutes = total service minute
total service minutes – unplanned downtime minutes /total service minutes * 100 = Availability
Service availability is measured at the end of each calendar month.
For the avoidance of doubt, issues and downtime caused by the acts or omissions of the customer or any third party caused outages or disruptions will be taken into account by Optum on an appropriate basis when determining the availability measure achieved.
Users are not refunded in the event of Optum not meeting SLAs - Approach to resilience
-
Optum operate the service from multiple availability zones to ensure redundancy in case of disaster.
Our application infrastructure is designed to provide resilience through multiple deployments of application nodes within each data centre. Each application node consists of multiple containers where we deploy our application services. This micro-service-based architecture pattern provides resilience through isolation as any failing service is highly unlikely to affect other running services on the same application node. All application nodes are backed by a cluster of databases where data is replicated between them and in the event of any failure, failover can take place to an alternative database. Databases use tiered storage structure to provide a facility to take snapshots at regular intervals to secondary storage so that, in case of any failures, we can restore all data to the last snapshot - Outage reporting
-
All outages and/or scheduled maintenance are reported to stakeholders using the Atlassian Status Page Software. This software is the method used for all Services provided by Optum by default all updates are also set to update the Service Delivery Twitter feed.
Stakeholders sign up for this reporting service using the webpage and from their can choose how they receive the alerts (email, text or RSS feed) specifically for them and how often.
The page is updated manually be the Service Delivery team at each stage of an outage (issue, monitoring, resolved) then a root cause analysis provided if appropriate. The API of this software is also linked to our Social Media account on Twitter should the stakeholder prefer this method of communication.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Username or password
- Other
- Other user authentication
- Token (MFA)
- Access restrictions in management interfaces and support channels
- Restricted access to our management interfaces is provided by a firewall IP whitelist. Once the firewall has established a users IP as valid, a user must also have valid username/password credentials to access any of the web portals developed for various elements of our infrastructure. We limit the ability to provide maintenance to a limited number of technical staff and whose access has been approved by heads of departments and elevated by a change process to an internal technical services team for review. The maintenance staff can only access lower levels of our infrastructure by using SSH public-key authentication.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Public key authentication (including by TLS client certificate)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- Between 1 month and 6 months
- How long system logs are stored for
- Less than 1 month
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Optum follow ISO 27001 methodology and are independently certified to the ISO/IEC 27001: 2013 standard.
Optum are committed to establishing, implementing, operating, monitoring, reviewing and maintaining an Information Security Management System.
Optum have an overarching information security policy with clear aims and objectives set throughout the business with robust processes in place, which are as follows;
• Information security risk assessment process that assesses the business harm likely to result from a security failure and the realist likelihood of such a failure occurring in the light of prevailing threats and vulnerabilities, and controls currently implemented;
• Defined security controlled perimeters and access controlled offices to prevent unauthorised access, damage and interference to business premises and information;
• Data classification and exchange guidelines, including compliance with regulations;
• Development and maintenance of an appropriate business continuity plan to counteract interruptions to business activities and protect critical business processes;
• Information security awareness guidance for all company employees;
• Incident management and escalation procedures for reporting and investigating security incidents and;
• A senior management team that supports the continuous review and improvement of the companies Information Security Management System. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- This is controlled by our Development policy where all releases and development work is risk assessed. This process is controlled and managed by the Development team, Product Owner and Clinical Safety Officer. Services are managed during the lifecycle by monitoring their usage, this task is performed by our Product team.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Optum have a vulnerability management programme, including a policy and supporting processes. Regular vulnerability scanning is conducted in internal and continuously on external IP's. Threat intelligence feeds are integrated into the processes including NHS Cyber alerts & CVE databases for emerging threats. Critical operating patches are applied within 14 days.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Optum perform regular PEN tests by external contractors that assess the accessibility of our application programming interfaces (API) against current security standards which are covered by Cyber Essentials, PCI Security Council Standards, CHECK, Crest, and TigerScheme accreditation's. The PEN tests are scheduled every year or upon any major API changes and any issues are categorised from low to critical. Any issues that are identified as high or critical are address immediately. All other issues are assessed and prioritised by the seriousness of their nature and if any clinical safety is involved and then scheduled into our normal development life cycle.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Optum have a predefined process in place for all incidents. Users will report this incident via a set template giving a description and severity of the incident this is then handled by the information security officer who will report back to user when the incident has been logged and resolved. During handling the information security officer will resolve the incident via the correct department and put in service improvement if required to prevent re-occurrence.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 1%
- Between £250,000 and £500,000
- 2%
- Between £500,001 and £1,000,000
- 3%
- Between £1,000,001 and £2,500,000
- 4%
- Between £2,500,001 and £5,000,000
- 7.5%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- BSI
- ISO/IEC 27001 accreditation date
- Wednesday 10 September 2025
- What the ISO/IEC 27001 doesn’t cover
-
Our Information Security Management System complies with the requirements of ISO/IEC 27001:2022 for the following scope:
The Information Security Management in relation to the provision and subsequent support in information and management systems to healthcare and non healthcare professionals. Information Security Management within the supply and deployment of ICT infrastructure and support services. - ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- BSI
- ISO 9001 accreditation date
- Friday 16 February 2024
- What the ISO 9001 doesn’t cover
-
Our Quality Management System complies with the requirements of ISO 9001:2015 for the following scope:
The design, planning, development and support if information technology software and services to the healthcare market and other public and private sector organisations. - Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 674cd1a3-3629-469c-b25f-d94897cd8771
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- Dc0f68d0-958d-42f3-8116-ad8ddc3fbe51
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
- Plans for positive actions with community groups.
- Measures to engage users and communities and build relationships to increase community integration build trust and influence how the contract is delivered
- Plans to respond flexibly and adapt approaches to community engagement and initiatives
- Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Working conditions which promote an inclusive working environment and promote retention and progression
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
- Other measures to offer development opportunities for the target cohort(s) in the contract workforce
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
- Understanding of issues relating to entering the contract workforce
- Creation of outreach activities to create a pipeline of employees for the future contract delivery
- Content of the outreach activity is designed to suit the target cohort
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
-