Compliance and Reporting Solution
MEDSU Compliance is an advanced compliance solution for the healthcare sector. Organisations benefit from an innovative system that enables tracking, validation and assures statutory and regulatory compliance data/requirements. Covers all major areas of healthcare professional compliance, including mandatory training, policy acknowledgement, occupational health, identity, criminal record, qualification, language checks.
Features
- Cloud based
- Secure access from anywhere
- 2FA Authentication available
- Whole workforce solution
- Integrated with MAP healthcare professional Appraisal
- Integrated with MEDSU Knowledge
- Integrated with External Verification + Notary Services
- Clear presentation of compliance obligations
- Mobile application available
- Easy update of compliance documents and data
Benefits
- Granular control of compliance requirements
- Compliance requirements by worker group (Invasive procedure, vulnerable adult, etc)
- Compliance requirements by professional group (Doctor, Nurse, Allied Health etc)
- Override group policy at individual worker level
- Comprehensive and flexible system
- Global library of common compliance and regulatory items
- Request custom/private compliance items for organisation
- Live dashboard of organisation and healthcare professional compliance
- Powerful reporting functionality
- 'Health Passport' Portable Solution for Professionals
Pricing
£3.00 to £15.00 a user a year
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 13
Service ID
3 8 0 3 3 9 9 3 7 5 1 4 6 7 8
Contact
MEDSU Ltd
Claire White
Telephone: 02071839544
Email: claire.white@medsu.org
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- None
- System requirements
-
- Internet Connection
- A modern Web Browser
User support
- Email or online ticketing support
- Email or online ticketing
- Support response times
- Within 2 hours during office hours Mon-Fri.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- First line support for administrators and healthcare professional users is provided by our own Freephone Helpdesk. 2 full days of Super user training as part of implementation plan / One day administrator/train the trainer training for up to four personnel. This is included in the implementation fee. After that we can provide live 1-to-1 training with administrators on an 'as required' basis throughout the contract, as part of the license fee. Users are primarily trained via a library of videos on different aspects of the system. Help Guides are also provided within each section of the system.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- As part of implementation, we can provide onsite training to users as required. We can provide ongoing training via webinars. Additionally, in site video help guides and documentation is provided.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- We provide data in standard file formats. Individuals can also download their data using the system tools within the contract period.
- End-of-contract process
- At the end of the contract, Individual users can download all files to their own computer/desktop or offered an opportunity to maintain their individual account with MEDSU directly. Data is maintained on our servers within the constraints of GDPR and in line with regulatory requirements in cases of investigation.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Internet Explorer 11
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- No differences.
- Service interface
- No
- User support accessibility
- WCAG 2.1 A
- API
- No
- Customisation available
- No
Scaling
- Independence of resources
- Access is load balanced over a pool of application servers based in the UK. Servers are monitored and scaled up or out as required based on usage.
Analytics
- Service usage metrics
- Yes
- Metrics types
- User login/log out records can be provided on request.
- Reporting types
-
- Real-time dashboards
- Reports on request
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Staff screening not performed
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 3.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- In-house
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Data sanitisation type
- Deleted data can’t be directly accessed
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v.30, CAS (Sanitisation) or ISO/IEC 27001
Data importing and exporting
- Data export approach
- PDF format Zip File
- Data export formats
- Other
- Other data export formats
-
- Zip File
- Data import formats
-
- CSV
- ODF
- Other
- Other data import formats
-
- MS Word
- MS Powerpoint
- MS Excel
- ODF/Other
- Picture files e.g. JPEG, PNG, TIFF
- Dedicated MAG PDF Import
- MP3 Audio / other audio formats
- MP4 Video / other video formats
- Cloud Drive Integration e.g. Google Drive
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- 99.9% up time guaranteed in SLA
- Approach to resilience
- System resilience is founded on a multiple server architecture with a continuous program of live migration, and immediate fail over switching. A layered approach to data storage utilising separate encrypted data repositories ensures enterprise standard data recovery and reconstruction. System code bases are maintained in a separate third party source control system. A documented system of recovery and contingency actions is in place with named individuals responsible for initiating recovery protocols. The documented recovery systems are reviewed on a minimum annual basis. Our UK data centers are regularly audited and have the following certifications\ISO 14001:2015, ISO 22301:2012, ISO/IEC 27001:2013, ISO 50001:2011, ISO 9001:2015, OHSAS 18001:2007, PCI DSS, SOC 1, SOC 2 Type 2
- Outage reporting
- Email Alerts
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- 2-factor authentication
- Username or password
- Access restrictions in management interfaces and support channels
- Within the system healthcare professionals have secure password-protected access to their own data. Those with role based access have access to data that is contemporaneously appropriate to their role and workflow.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- 2-factor authentication
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- UKAS/British Assessment Bureau
- ISO/IEC 27001 accreditation date
- 14/11/2016
- What the ISO/IEC 27001 doesn’t cover
- None
- ISO 28000:2007 certification
- No
- CSA STAR certification
- No
- PCI certification
- Yes
- Who accredited the PCI DSS certification
- Stripe
- PCI DSS accreditation date
- Not Known
- What the PCI DSS doesn’t cover
- Not Known
- Cyber essentials
- No
- Cyber essentials plus
- No
- Other security certifications
- No
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- ISO 27001 management standard audited and certified. A program of information governance and security training ensures that all staff are aware of our obligations in relation to GDPR,specific NHSE guidance on Appraisal and Revalidation, the role of the ICO, process for subject access requests, healthcare specific guidance such as Caldicott Policy covers use of personal devices/BYOD, removable storage media, mobile devices. Non secure networks, information recovery and disposal, process for information security, physical security, use of e mail and associated risks, social media/internet use and associated risks Policy is in place for incident management as described above All policies are reviewed on an minimum annual basis or as required.
Operational security
- Configuration and change management standard
- Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
- Configuration and change management approach
- System and service change is extensively planned and documented. A defined system of development workflow permission and testing ensures that changes are planned rigorously assessed for impact and tested before release. Where a change may cause any significant impact on an existing system client or user, appropriate action is taken to mitigate or eliminate such impact. Industry standard version control and change management tracking is deployed. An adverse change can be instantly traced and the system can be reverted if required.
- Vulnerability management type
- Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
- Vulnerability management approach
- Our servers are updated continuously to ensure we are running the latest patches and security updates. This is done on a bi weekly basis as minimum or immediately as new threats and issues emerge. We operate containerized production and development environments, so both the environments and the containers are updated during this process.
- Protective monitoring type
- Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
- Protective monitoring approach
- Automated scanning operates at the server and application level. Server level monitoring ensures we quickly detect application, service, or process problems, and system downtime is avoided. Application level monitoring is analysed. Suspicious system activity (outgoing traffic, system usage, repetitive access) generates alerts.Dedicated front end monitoring applications identify the majority of errors before they are reported by users, and client side errors are swiftly fixed. Our UK data centers are regularly audited and have the following certifications\ISO 14001:2015, ISO 22301:2012, ISO/IEC 27001:2013, ISO 50001:2011, ISO 9001:2015, OHSAS 18001:2007, PCI DSS, SOC 1, SOC 2 Type 2
- Incident management type
- Conforms to a recognised standard, for example, CSA CCM v3.0 or ISO/IEC 27035:2011 or SSAE-16 / ISAE 3402
- Incident management approach
- Incidents can be reported via any communication channel. Incidents are recorded, triaged and escalated through a defined management pathway. A defined and audited process is utilised to track issues through our investigation and management system until resolution. All staff are contractually obligated to report any information security event immediately and cooperate with investigation and management actions . We provide immediate and transparent reporting to system clients and system users of the nature and extent of any incident. Following investigation and analysis clients and system users are advised of any interim and longer term remedial, mitigating or preventative actions
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Social Value
- Fighting climate change
-
Fighting climate change
At MEDSU, we are committed to sustainability. Our operations are designed to get the most out of technology, without the need for more resources which impact our planet.
MEDSU is ISO:14001 accredited. Our Environmental Management system ensures we protect and improve the environment through good management, adopting best practices and greener alternatives wherever possible. We are audited annually to ensure our accreditation remains current and best practice is embedded.
Using resources efficiently to reduce waste:
- We ensure all purchasing/resourcing decisions adhere to our Sustainability and Environmental Policy
Playing our part to reduce emissions to improve health in the local community:
- Provide home-based virtual working opportunities to reduce travel/emissions.
- Efficient meetings: using video conferencing to meet virtually reducing the need for travel - Covid-19 recovery
-
Covid-19 recovery
Theme : helping local communities to manage and recover from the impact of COVID-19
The provision of outsourced governance services and information technologies in the healthcare sector is a new innovative industry. This enables us to Create employment, re-training and other return to work opportunities for those left unemployed by COVID-19,
Our focus on adapting to client organisation needs support organisations and businesses to manage and recover from the impacts of COVID-19, particularly where new ways of working have been needed to ensure the continued delivery of services.
Many of our services a related to frontline healthcare workers and we have adapted our approaches to ensure that the impact on these individuals is minimised, by offering additional support and guidance and allowing more time to complete required governance and regulatory obligations
Our well being orientated delivery of services support the physical and mental health of people affected by COVID-19. We have adopted the COVID 19 - well being focused Appraisal approach, advocated by NHS England
Our efficient cloud based services adopt the recommendations of the Pearson report which is aimed at reducing the demand on healthcare professionals. Again because of our cloud based approach to delivering services we provide effective social distancing, remote working, and sustainable travel solutions. - Wellbeing
-
Wellbeing
Improve Health & Wellbeing:
- MEDSU operates an ISO 45001 Occupational Health & Safety System
- We undertake quarterly Health & Safety Meetings which include stakeholder review of appropriate Health & Safety Policies.
- Launch of organisational ‘Welfare Champions’ available to discuss any health and wellbeing concerns of the MEDSU workforce.
- Weekly, quarterly meetings held by Team Leaders and attended by members of the Board of Directors.
- Re-establish face-to-face Support Team Meetings held locally to encourage engagement/foster caring workforce culture.
- Continued flexibility towards future working arrangements to support people’s work-life balance
- Team building activities and social events fostering inclusion/community values among the workforce
Pricing
- Price
- £3.00 to £15.00 a user a year
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
-
FREE TRIAL: Full system including implementation and training (depending on circumstances). Time period can be negotiated.
MEDSU’s Free Access in perpetuity Individual Access Model is intended to provide a superior replacement for the MAG or legacy cloud Appraisal systems and includes basic access system elements and components. - Link to free trial
- By Request