Skip to main content

Help us improve the Digital Marketplace - send your feedback

X-ON HEALTH LIMITED

X-on Omni Consultation

X-on Omni Consultation is a cloud-based triage solution, built within Surgery Connect, which uses multiple channels to gather structured patient data. Integrated with clinical systems (EMIS/TPP), it centralises patient medical requests into one dashboard, standardising access and reducing clinical call-backs by providing clear, actionable information.

Features

  • Omni-Channel Access
  • Unified Triage Dashboard
  • Clinical System Integration
  • Incomplete Patient Request Capture
  • Simplified Auditing
  • Transcription and Audio Recording (for Voice Submissions)

Benefits

  • Centralised Triage - no toggling between systems
  • Staff Time Savings - reduce burnout through automation
  • Equity of Access - total inclusivity for patients
  • Robust Compliance - audit trails and low-risk adoption
  • Standardised Data - every request in a single format

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at products@x-on.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

4 3 1 6 5 9 9 5 9 5 5 4 1 2 7

Contact

X-ON HEALTH LIMITED X-on Health Sales Team
Telephone: 0333 332 0000
Email: products@x-on.co.uk

About your service

Service categories

Applications

Production and operations

Service industry and public sector operations

  • Healthcare
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
X-on Health's services can be used as standalone, but they are primarily used as an extension to the core clinical systems used in UK primary care, such as EMIS Web, TPP SystmOne, Vision, and Medicus.
Cloud deployment model
Public cloud
Service constraints
No service constraints, outside of system/hardware requirements (which are all standard requirements e.g. Windows operating system, internet connectivity) - the service is designed for 24/7 availability with a target uptime of 99.99%. Routine and essential upgrades are included free of charge, maintenance is scheduled at non-peak times and conducted overnight to minimise disruption.
System requirements
  • Windows 10 (or above)
  • I3 Processor (as a minimum)
  • Internet Connectivity (4Mbps above)
  • 4GB RAM, 2GB disk space

User support

Email or online ticketing support
Yes
Support response times
24 hour support, responding to questions with instant automated acknowledgement, with the follow-up answer response sending ASAP. Response times DO NOT vary on weekends.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
No
Onsite support
Yes
Support levels
Minor and Serious Problem Level - Report via the X-on Support Portal 24/7 or report by phone in working hours.
Critical Problems (as defined in service agreement) - Report via the X-on support portal AND report by phone to Duty Engineer (separate phone number) available 24/7.
Escalations Paths - Phone Support Team Leaders, with further escalation paths direct to the Operations Director.

There is no cost involved in the support X-on provides to customers.
Each customer has their own dedicated account manager.
Support available to third parties
No

Onboarding and offboarding

Getting started
We ensure full user support from day one through a structured onboarding process, managed by a dedicated Customer Success Advisor (CSA), to guarantee a seamless transition and rapid, confident user adoption.

The process starts with a Welcome Session by the CSA to define user setup requirements. A specialist team then optimizes the service with a best-practice configuration tailored to your specific workflows.
Our flexible, blended training program minimizes the learning curve and includes:

Initial Training Session: A 1-hour, practical session (onsite or virtual), with one of our dedicated trainers, covering product basics and key best practice tips.
Online Training (Academy): Full access to self-service modules, with lots of courses suitable for different user roles and knowledge levels.
Supplementary Sessions: Additional daily "Lunch and Learn" training sessions are available for our users to drop-in as they wish.

During the critical launch phase, the CSA provides direct support on Go-Live day. This is followed by a post-launch check-in. Finally, a Customer Relationship Manager is assigned to deliver long-term strategic support.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
Patient & Service Data (e.g. Call Recordings): We support our customers with extracting all your data from our systems, including call recordings and any other service data. We provide this data in a common, secure, and machine-readable format (such as CSV or via a secure export) to facilitate migration to a new supplier or for your records. For data already integrated into the clinical system (e.g. contact history attached to a patient record), the user can also extract this directly from their own system.
Telephony Numbers: We follow the standard, regulated industry process for porting telephone numbers. This process is initiated by your new provider, and we will work with them to ensure all your practice's phone numbers are seamlessly and fully transferred.
Secure Deletion: Once you have confirmed in writing that you have successfully received your data, we will permanently destroy all your data from our live and backup systems, in line with your contract. We will provide a certificate of destruction upon request.
End-of-contract process
The customer must provide 3 months' written notice to terminate. At the end of the contract term, the agreement will auto renew for a period of 12 months unless terminated in writing prior to the end of the term. X-on Health is required to follow an agreed Exit Plan and cooperate with the customer’s new provider, where appropriate, to ensure a smooth transition.
Included in the Price is Data Extraction: X-on provides a downloaded copy of stored call recordings via a secure online transfer. Porting Support: Support for moving telephone numbers, including providing number lists and responding to "Letters of Authority," is included. General Transition: Cooperation regarding network connectivity and configuration information is provided at no extra cost.
Additional Costs: Post-Termination Diverts: Calls diverted to a new number after the contract ends are charged monthly in arrears. Non-Standard Data Copy: A specific fee applies if you request a "downloaded copy" service outside the standard free transfer. Rented equipment must be returned within 30 days, or the customer will be charged its market value.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
X-on's onboarding and offboarding documentation is primarily accessible online via URL links, ensuring easy retrieval for all necessary parties. The documentation can be downloaded in PDF format.
Onboarding documentation is typically available to new customers before the contract start date. This allows for early review of policies, completion of forms, and familiarity with processes.
Offboarding documentation is housed in the same way, acting as a systematic way for account managers to manage the customer exit process, including asset return, data transfers, and final instructions.
While not legally required, X-on is committed to creating this documentation with WCAG 2.2 Level AA accessibility regulations in mind.
This focus ensures the materials are:
Perceivable: Using high colour contrast and providing text alternatives for images.
Operable: Ensuring full keyboard navigation and functionality.
Understandable: Employing clear language and logical content structure (using headings and lists).
This commitment makes the documentation usable and robust for everyone, including those who use assistive technologies.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
Yes
Compatible operating systems
Windows
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
The Omni Consultation interface is a unified dashboard integrated directly into the X-on Phonebar. It consolidates patient requests from the Voice Agent, Web Forms, and Manual Staff Entry into a single, structured view. Within the Forms window, staff can manage the entire triage workflow by assigning clinicians, setting priority/severity levels, and adding SNOMED codes without using another system. It features dedicated tabs for Waiting, Triaged, and Incomplete requests, ensuring a robust audit trail and seamless integration with clinical records
Accessibility standards
WCAG 2.2 AA
Accessibility testing
Omni Consultation's interface is developed with a focus on inclusivity, aligning with DTAC and WCAG standards to meet NHS expectations for usability. Our approach ensures the platform remains functional for all staff, including those who rely on assistive technologies. Key areas of focus include: Navigation and Compatibility: Development prioritises keyboard-only operability and screen reader compatibility across the Phonebar and management consoles. This supports staff with visual or motor impairments in navigating the desktop environment efficiently. Visual Design: The interface utilises high-contrast elements and clear typography to assist users with low vision. These design choices aim to reduce cognitive load, making the software more manageable during busy periods. Equitable Access: By following industry-standard accessibility frameworks, the service is designed to be perceivable and understandable for users with diverse physical or sensory requirements. This commitment to standards ensures that both staff-facing tools and patient-facing features remain accessible.
API
No
Customisation available
Yes
Description of customisation
Access Control: Practices can toggle the online form on or off and set specific Active Times or days for submissions.
Holiday & Branding: Settings allow for automated disabling during Bank Holidays and customising the Form Display Name for patient-facing web forms.
Data Retention: Users can configure how long triaged data is held, with a retention period ranging from 24 hours to 2 years.
Staff Notifications: Individual users can enable Phonebar notification dots, or configure email notifications for users assigned responses.
Multi-Channel Capture: The data capture process is customisable across the Voice Agent, Web Forms, and Manual Entry by staff .
Triage Tailoring: Within the Phonebar, staff can apply item labels, assign specific members, and set manual Priority or Severity levels .
Clinical Output: Clinicians can select appropriate SNOMED codes and add internal comments before saving data to the patient record .

Scaling

Independence of resources
X-on Health guarantees service stability through a cloud-native, multi-tenant architecture featuring elastic auto-scaling and logical tenant isolation. Resources are dynamically provisioned to match real-time demand, ensuring traffic surges from one organisation never degrade performance for others.

Our infrastructure operates across geographically redundant data centres with automated load balancing and carrier-grade failover, securing 99.99% availability. By eliminating fixed channel caps and strictly isolating data processing queues, we prevent noisy neighbour contention. This ensures every user retains full, unhindered access to Intelligent Care Navigation services, regardless of concurrent usage across the wider network.

Analytics

Service usage metrics
Yes
Metrics types
X-on provides comprehensive service usage metrics through a dedicated reporting portal, live wallboards, and automated monthly management reports.

Customers can access real-time and historical data crucial for managing demand and resources. Key metrics include call volumes (inbound, answered, missed), queue statistics (average wait times, abandonment rates, busiest periods), and staff activity (calls per user, status timelines).

The service also specifically tracks and reports on key NHS metrics, such as time to answer, enabling practices to monitor performance against national standards and service level agreements. This data provides full "cradle-to-grave" visibility of all patient interactions.
Reporting types
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with another standard
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Users export data from the X-on Intelligent Care Navigation Reports Portal by following a straightforward process.
After navigating to the desired report dashboard (e.g. Surgery Connect Call Reports, Management Reports, or User Reports), the user selects the relevant time period.
A simple Export Icon, presented alongside the report data, allows the user to download the visible information. The data is saved in a common CSV spreadsheet format, for further analysis and record-keeping outside the system.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
99.99% Availability. If the service falls below the service availability level commitment, a service credit of up to 100% of the monthly rental charge, subject to the terms stated in 8.3.10 of Section 8 Pricing (in service agreement), will be applied to the following months charges.
Approach to resilience
X-on Health guarantees high availability and data sovereignty through hosting in UK-only Tier 3 data centres. These facilities ensure physical resilience through N+1 component redundancy, 24/7 monitoring, and staffed access control.
To eliminate single points of failure, critical data, including call recordings, is stored with quadruple-site redundancy. This ensures immediate failover capabilities and zero data loss in disaster scenarios.
Data retention is contractually defined, with secure destruction protocols upon expiry.
Our architecture employs robust cryptographic standards to resist interception. Data is fully encrypted at rest, while all transit communications are secured via TLS 1.2+, utilising certificates signed with 2048-bit RSA/SHA-256 algorithms.
We maintain strict logical data segregation to prevent cross-tenant interference. Operational resilience is further assured through a rigorous Software Development Life Cycle (SDLC), where all updates are validated in isolated non-live environments before deployment, protecting the stability of the live service.
Outage reporting
X-on Health employs a proactive, multi-channel notification framework to ensure users are immediately aware of any service degradation.
The primary source of truth is the Service Status Dashboard, accessible via our Support Portal. This page provides real-time, traffic-light visibility into the operational health of specific modular components, allowing users to instantly verify if an issue is local or platform-wide.
To protect active clinical workflows, we broadcast in-app banners directly within the Surgery Connect User Console. These alerts appear immediately at the top of the interface, warning active staff of potential connectivity or quality issues without requiring them to check external websites.
For high-severity incidents, registered System Administrators receive targeted email notifications detailing the impact and estimated resolution time.
Once service is restored, the status page on the Support Portal is updated to "Resolved." For major outages, X-on Health publishes a full Root Cause Analysis (RCA), providing a transparent technical explanation of the fault and the preventative measures implemented.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Strong Authentication: Access is limited to authorised users with strong password controls.
RBAC/Privilege: The service restricts user access to only the functions their security profile allows, preventing them from accessing or even seeing unauthorised menus or screens.
Compliance: Restrictions are governed by accreditations like ISO 27001 and compliance with NHS Data Security and Protection (DSP) Toolkit standards.
Auditing: All access and activity are logged and subject to audit, with real-time audit information available.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
The X-on information security management system (ISMS) aligns with ISO 27001 and Cyber Essentials Plus certification. X-on follows a robust set of policies, including:

- Access Control Policy: Enforces Least Privilege and requires Multi-Factor Authentication (MFA) for sensitive access, reviewed quarterly.
- Risk Management Policy: Systematically identifies, assesses, and treats risks, reviewed annually.
- Incident Management Policy: Provides structured procedures for detection, containment, and recovery from security incidents.
- Change Management Policy: Ensures all production changes are documented, reviewed, and approved.
- Vulnerability Management: Mandates regular internal scanning and annual external penetration testing.
- All new staff receive mandatory security training, this renews annually for all staff.

The Technology and Information Security Director, who reports directly to the Managing Director to ensure that security matters are visible and prioritised at the top level of the company, oversees the ISMS. They oversee a cross-functional Security Group - this includes representatives from all departments of the business - to review security performance, emerging risks, and overall compliance status.

X-on ensure policy adherence in numerous ways, namely through automated security monitoring (SIEM/DLP) and secure technical controls (e.g. encryption), regular internal audits and mandatory annual ISO 27001 certification audits to drive continuous improvement.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Every change to live systems is documented, risk-assessed, and approved by an Owner, Reviewer, and Approver, in a robust change management process.
The lifecycle is tracked in Jira, requiring a corresponding task in the deployments and releases project for all project-related changes. All CRs must include a monitoring plan and a rollback contingency.
Risk is assessed using a scoring matrix within the CR form. If the risk scores are red, a meeting with a senior manager is mandatory in order to appropriately assess the potential security impact. All changes must be tested on staging before live implementation to mitigate issues.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
X-on Health's vulnerability management is a continuous process driven by threat intelligence and a risk register.
Threats are categorised (Strategic, Tactical, Operational). IS systems flag threats against a baseline, and the IS Director documents significant threats in the Risk Register for wider review.
Information is gathered from diverse sources, including the NCSC, NPSA, CISA's Exploited Vulnerabilities Catalogue, and security vendor blogs (e.g. FortiGuard, CrowdStrike).
The risk-based priority of threats documented in the frequently reviewed Risk Register dictates the urgency of patch deployment. Critical severity = ASAP, High Severity= 24hrs to a week. Medium/Low = scheduled with normal update cycles.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Identification: Threats are detected via automated alert systems (e.g. failed actions e.g. logins or calls, suspicious file changes, intrusion detection) and continuous monitoring of strategic threats from various sources. Staff also report incidents internally.
Response: The process includes triage, immediate suppression (e.g. isolation, network removal), preservation of evidence , and system recovery.
Speed: X-on provides 24/7 support. Major issues are immediately escalated to administrators if outside normal working hours to ensure an efficient response and limit impact.
Incident management type
Supplier-defined controls
Incident management approach
The process outlines detailed procedures for incident investigations (determination, suppression, and evidence preservation), and for mitigation and recovery (system checks, connection validation, and system rebuilds).
Users report incidents through various channels, including a client call to the 24/7 support team. Internally, all employees are provided with the Information Security Incident Report Form for simple incident reporting.
X-on is committed to transparency and notifies affected clients and service providers immediately in the event of a security incident. A Post Incident Procedure (PIP) meeting is held to discuss the incident and detail lessons learned. Incident reports are published following the PIP meeting.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
10%
Between £1,000,001 and £2,500,000
15%
Between £2,500,001 and £5,000,000
20%
Over £5,000,001
25%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Citation Ltd.
ISO/IEC 27001 accreditation date
Thursday 24 July 2025
What the ISO/IEC 27001 doesn’t cover
The physical and environmental security of the underlying hosting infrastructure (e.g. AWS) is not covered by our certification. The provider maintains their own independent ISO/IEC 27001 certifications, which are reviewed as part of our supplier management process. Client-side infrastructure, including end-user hardware (PCs), local area networks (LAN), and internet connectivity used to access our digital solutions, are outside the scope of our certification.
Security management of third-party external platforms or APIs not managed by X-on Health, such as integrated clinical systems (EPRs) or third-party telecommunications carriers, is also not covered.
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
Citation Ltd.
ISO 9001 accreditation date
Thursday 24 July 2025
What the ISO 9001 doesn’t cover
The certification does not cover the manufacturing or hardware-level quality control of third-party end-user devices (e.g. handsets, headsets, or PCs) used to access our platforms.
While we ensure the quality of our system's logic, the accuracy and quality of clinical data hosted within external third-party systems (e.g. integrated EPR systems like EMIS or SystmOne) are not covered by our ISO 9001 certification.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
7421c82d-5c66-407b-888e-3f5ccc6a119e
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
64c90e06-ca79-4add-a60f-9d9a91c4e5df
Other security certifications
Yes
Any other security certifications
  • ISO 22301
  • NHSE DSPT 2024-25 "Standards exceeded"

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at products@x-on.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.