X-on Omni Consultation
X-on Omni Consultation is a cloud-based triage solution, built within Surgery Connect, which uses multiple channels to gather structured patient data. Integrated with clinical systems (EMIS/TPP), it centralises patient medical requests into one dashboard, standardising access and reducing clinical call-backs by providing clear, actionable information.
Features
- Omni-Channel Access
- Unified Triage Dashboard
- Clinical System Integration
- Incomplete Patient Request Capture
- Simplified Auditing
- Transcription and Audio Recording (for Voice Submissions)
Benefits
- Centralised Triage - no toggling between systems
- Staff Time Savings - reduce burnout through automation
- Equity of Access - total inclusivity for patients
- Robust Compliance - audit trails and low-risk adoption
- Standardised Data - every request in a single format
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 3 1 6 5 9 9 5 9 5 5 4 1 2 7
Contact
X-ON HEALTH LIMITED
X-on Health Sales Team
Telephone: 0333 332 0000
Email: products@x-on.co.uk
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- X-on Health's services can be used as standalone, but they are primarily used as an extension to the core clinical systems used in UK primary care, such as EMIS Web, TPP SystmOne, Vision, and Medicus.
- Cloud deployment model
- Public cloud
- Service constraints
- No service constraints, outside of system/hardware requirements (which are all standard requirements e.g. Windows operating system, internet connectivity) - the service is designed for 24/7 availability with a target uptime of 99.99%. Routine and essential upgrades are included free of charge, maintenance is scheduled at non-peak times and conducted overnight to minimise disruption.
- System requirements
-
- Windows 10 (or above)
- I3 Processor (as a minimum)
- Internet Connectivity (4Mbps above)
- 4GB RAM, 2GB disk space
User support
- Email or online ticketing support
- Yes
- Support response times
- 24 hour support, responding to questions with instant automated acknowledgement, with the follow-up answer response sending ASAP. Response times DO NOT vary on weekends.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- Yes
- Support levels
-
Minor and Serious Problem Level - Report via the X-on Support Portal 24/7 or report by phone in working hours.
Critical Problems (as defined in service agreement) - Report via the X-on support portal AND report by phone to Duty Engineer (separate phone number) available 24/7.
Escalations Paths - Phone Support Team Leaders, with further escalation paths direct to the Operations Director.
There is no cost involved in the support X-on provides to customers.
Each customer has their own dedicated account manager. - Support available to third parties
- No
Onboarding and offboarding
- Getting started
-
We ensure full user support from day one through a structured onboarding process, managed by a dedicated Customer Success Advisor (CSA), to guarantee a seamless transition and rapid, confident user adoption.
The process starts with a Welcome Session by the CSA to define user setup requirements. A specialist team then optimizes the service with a best-practice configuration tailored to your specific workflows.
Our flexible, blended training program minimizes the learning curve and includes:
Initial Training Session: A 1-hour, practical session (onsite or virtual), with one of our dedicated trainers, covering product basics and key best practice tips.
Online Training (Academy): Full access to self-service modules, with lots of courses suitable for different user roles and knowledge levels.
Supplementary Sessions: Additional daily "Lunch and Learn" training sessions are available for our users to drop-in as they wish.
During the critical launch phase, the CSA provides direct support on Go-Live day. This is followed by a post-launch check-in. Finally, a Customer Relationship Manager is assigned to deliver long-term strategic support. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
Patient & Service Data (e.g. Call Recordings): We support our customers with extracting all your data from our systems, including call recordings and any other service data. We provide this data in a common, secure, and machine-readable format (such as CSV or via a secure export) to facilitate migration to a new supplier or for your records. For data already integrated into the clinical system (e.g. contact history attached to a patient record), the user can also extract this directly from their own system.
Telephony Numbers: We follow the standard, regulated industry process for porting telephone numbers. This process is initiated by your new provider, and we will work with them to ensure all your practice's phone numbers are seamlessly and fully transferred.
Secure Deletion: Once you have confirmed in writing that you have successfully received your data, we will permanently destroy all your data from our live and backup systems, in line with your contract. We will provide a certificate of destruction upon request. - End-of-contract process
-
The customer must provide 3 months' written notice to terminate. At the end of the contract term, the agreement will auto renew for a period of 12 months unless terminated in writing prior to the end of the term. X-on Health is required to follow an agreed Exit Plan and cooperate with the customer’s new provider, where appropriate, to ensure a smooth transition.
Included in the Price is Data Extraction: X-on provides a downloaded copy of stored call recordings via a secure online transfer. Porting Support: Support for moving telephone numbers, including providing number lists and responding to "Letters of Authority," is included. General Transition: Cooperation regarding network connectivity and configuration information is provided at no extra cost.
Additional Costs: Post-Termination Diverts: Calls diverted to a new number after the contract ends are charged monthly in arrears. Non-Standard Data Copy: A specific fee applies if you request a "downloaded copy" service outside the standard free transfer. Rented equipment must be returned within 30 days, or the customer will be charged its market value. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
X-on's onboarding and offboarding documentation is primarily accessible online via URL links, ensuring easy retrieval for all necessary parties. The documentation can be downloaded in PDF format.
Onboarding documentation is typically available to new customers before the contract start date. This allows for early review of policies, completion of forms, and familiarity with processes.
Offboarding documentation is housed in the same way, acting as a systematic way for account managers to manage the customer exit process, including asset return, data transfers, and final instructions.
While not legally required, X-on is committed to creating this documentation with WCAG 2.2 Level AA accessibility regulations in mind.
This focus ensures the materials are:
Perceivable: Using high colour contrast and providing text alternatives for images.
Operable: Ensuring full keyboard navigation and functionality.
Understandable: Employing clear language and logical content structure (using headings and lists).
This commitment makes the documentation usable and robust for everyone, including those who use assistive technologies.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- Yes
- Compatible operating systems
- Windows
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The Omni Consultation interface is a unified dashboard integrated directly into the X-on Phonebar. It consolidates patient requests from the Voice Agent, Web Forms, and Manual Staff Entry into a single, structured view. Within the Forms window, staff can manage the entire triage workflow by assigning clinicians, setting priority/severity levels, and adding SNOMED codes without using another system. It features dedicated tabs for Waiting, Triaged, and Incomplete requests, ensuring a robust audit trail and seamless integration with clinical records
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- Omni Consultation's interface is developed with a focus on inclusivity, aligning with DTAC and WCAG standards to meet NHS expectations for usability. Our approach ensures the platform remains functional for all staff, including those who rely on assistive technologies. Key areas of focus include: Navigation and Compatibility: Development prioritises keyboard-only operability and screen reader compatibility across the Phonebar and management consoles. This supports staff with visual or motor impairments in navigating the desktop environment efficiently. Visual Design: The interface utilises high-contrast elements and clear typography to assist users with low vision. These design choices aim to reduce cognitive load, making the software more manageable during busy periods. Equitable Access: By following industry-standard accessibility frameworks, the service is designed to be perceivable and understandable for users with diverse physical or sensory requirements. This commitment to standards ensures that both staff-facing tools and patient-facing features remain accessible.
- API
- No
- Customisation available
- Yes
- Description of customisation
-
Access Control: Practices can toggle the online form on or off and set specific Active Times or days for submissions.
Holiday & Branding: Settings allow for automated disabling during Bank Holidays and customising the Form Display Name for patient-facing web forms.
Data Retention: Users can configure how long triaged data is held, with a retention period ranging from 24 hours to 2 years.
Staff Notifications: Individual users can enable Phonebar notification dots, or configure email notifications for users assigned responses.
Multi-Channel Capture: The data capture process is customisable across the Voice Agent, Web Forms, and Manual Entry by staff .
Triage Tailoring: Within the Phonebar, staff can apply item labels, assign specific members, and set manual Priority or Severity levels .
Clinical Output: Clinicians can select appropriate SNOMED codes and add internal comments before saving data to the patient record .
Scaling
- Independence of resources
-
X-on Health guarantees service stability through a cloud-native, multi-tenant architecture featuring elastic auto-scaling and logical tenant isolation. Resources are dynamically provisioned to match real-time demand, ensuring traffic surges from one organisation never degrade performance for others.
Our infrastructure operates across geographically redundant data centres with automated load balancing and carrier-grade failover, securing 99.99% availability. By eliminating fixed channel caps and strictly isolating data processing queues, we prevent noisy neighbour contention. This ensures every user retains full, unhindered access to Intelligent Care Navigation services, regardless of concurrent usage across the wider network.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
X-on provides comprehensive service usage metrics through a dedicated reporting portal, live wallboards, and automated monthly management reports.
Customers can access real-time and historical data crucial for managing demand and resources. Key metrics include call volumes (inbound, answered, missed), queue statistics (average wait times, abandonment rates, busiest periods), and staff activity (calls per user, status timelines).
The service also specifically tracks and reports on key NHS metrics, such as time to answer, enabling practices to monitor performance against national standards and service level agreements. This data provides full "cradle-to-grave" visibility of all patient interactions. - Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
-
Users export data from the X-on Intelligent Care Navigation Reports Portal by following a straightforward process.
After navigating to the desired report dashboard (e.g. Surgery Connect Call Reports, Management Reports, or User Reports), the user selects the relevant time period.
A simple Export Icon, presented alongside the report data, allows the user to download the visible information. The data is saved in a common CSV spreadsheet format, for further analysis and record-keeping outside the system. - Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- 99.99% Availability. If the service falls below the service availability level commitment, a service credit of up to 100% of the monthly rental charge, subject to the terms stated in 8.3.10 of Section 8 Pricing (in service agreement), will be applied to the following months charges.
- Approach to resilience
-
X-on Health guarantees high availability and data sovereignty through hosting in UK-only Tier 3 data centres. These facilities ensure physical resilience through N+1 component redundancy, 24/7 monitoring, and staffed access control.
To eliminate single points of failure, critical data, including call recordings, is stored with quadruple-site redundancy. This ensures immediate failover capabilities and zero data loss in disaster scenarios.
Data retention is contractually defined, with secure destruction protocols upon expiry.
Our architecture employs robust cryptographic standards to resist interception. Data is fully encrypted at rest, while all transit communications are secured via TLS 1.2+, utilising certificates signed with 2048-bit RSA/SHA-256 algorithms.
We maintain strict logical data segregation to prevent cross-tenant interference. Operational resilience is further assured through a rigorous Software Development Life Cycle (SDLC), where all updates are validated in isolated non-live environments before deployment, protecting the stability of the live service. - Outage reporting
-
X-on Health employs a proactive, multi-channel notification framework to ensure users are immediately aware of any service degradation.
The primary source of truth is the Service Status Dashboard, accessible via our Support Portal. This page provides real-time, traffic-light visibility into the operational health of specific modular components, allowing users to instantly verify if an issue is local or platform-wide.
To protect active clinical workflows, we broadcast in-app banners directly within the Surgery Connect User Console. These alerts appear immediately at the top of the interface, warning active staff of potential connectivity or quality issues without requiring them to check external websites.
For high-severity incidents, registered System Administrators receive targeted email notifications detailing the impact and estimated resolution time.
Once service is restored, the status page on the Support Portal is updated to "Resolved." For major outages, X-on Health publishes a full Root Cause Analysis (RCA), providing a transparent technical explanation of the fault and the preventative measures implemented.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
-
Strong Authentication: Access is limited to authorised users with strong password controls.
RBAC/Privilege: The service restricts user access to only the functions their security profile allows, preventing them from accessing or even seeing unauthorised menus or screens.
Compliance: Restrictions are governed by accreditations like ISO 27001 and compliance with NHS Data Security and Protection (DSP) Toolkit standards.
Auditing: All access and activity are logged and subject to audit, with real-time audit information available. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
The X-on information security management system (ISMS) aligns with ISO 27001 and Cyber Essentials Plus certification. X-on follows a robust set of policies, including:
- Access Control Policy: Enforces Least Privilege and requires Multi-Factor Authentication (MFA) for sensitive access, reviewed quarterly.
- Risk Management Policy: Systematically identifies, assesses, and treats risks, reviewed annually.
- Incident Management Policy: Provides structured procedures for detection, containment, and recovery from security incidents.
- Change Management Policy: Ensures all production changes are documented, reviewed, and approved.
- Vulnerability Management: Mandates regular internal scanning and annual external penetration testing.
- All new staff receive mandatory security training, this renews annually for all staff.
The Technology and Information Security Director, who reports directly to the Managing Director to ensure that security matters are visible and prioritised at the top level of the company, oversees the ISMS. They oversee a cross-functional Security Group - this includes representatives from all departments of the business - to review security performance, emerging risks, and overall compliance status.
X-on ensure policy adherence in numerous ways, namely through automated security monitoring (SIEM/DLP) and secure technical controls (e.g. encryption), regular internal audits and mandatory annual ISO 27001 certification audits to drive continuous improvement. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
Every change to live systems is documented, risk-assessed, and approved by an Owner, Reviewer, and Approver, in a robust change management process.
The lifecycle is tracked in Jira, requiring a corresponding task in the deployments and releases project for all project-related changes. All CRs must include a monitoring plan and a rollback contingency.
Risk is assessed using a scoring matrix within the CR form. If the risk scores are red, a meeting with a senior manager is mandatory in order to appropriately assess the potential security impact. All changes must be tested on staging before live implementation to mitigate issues. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
X-on Health's vulnerability management is a continuous process driven by threat intelligence and a risk register.
Threats are categorised (Strategic, Tactical, Operational). IS systems flag threats against a baseline, and the IS Director documents significant threats in the Risk Register for wider review.
Information is gathered from diverse sources, including the NCSC, NPSA, CISA's Exploited Vulnerabilities Catalogue, and security vendor blogs (e.g. FortiGuard, CrowdStrike).
The risk-based priority of threats documented in the frequently reviewed Risk Register dictates the urgency of patch deployment. Critical severity = ASAP, High Severity= 24hrs to a week. Medium/Low = scheduled with normal update cycles. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Identification: Threats are detected via automated alert systems (e.g. failed actions e.g. logins or calls, suspicious file changes, intrusion detection) and continuous monitoring of strategic threats from various sources. Staff also report incidents internally.
Response: The process includes triage, immediate suppression (e.g. isolation, network removal), preservation of evidence , and system recovery.
Speed: X-on provides 24/7 support. Major issues are immediately escalated to administrators if outside normal working hours to ensure an efficient response and limit impact. - Incident management type
- Supplier-defined controls
- Incident management approach
-
The process outlines detailed procedures for incident investigations (determination, suppression, and evidence preservation), and for mitigation and recovery (system checks, connection validation, and system rebuilds).
Users report incidents through various channels, including a client call to the 24/7 support team. Internally, all employees are provided with the Information Security Incident Report Form for simple incident reporting.
X-on is committed to transparency and notifies affected clients and service providers immediately in the event of a security incident. A Post Incident Procedure (PIP) meeting is held to discuss the incident and detail lessons learned. Incident reports are published following the PIP meeting. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 10%
- Between £1,000,001 and £2,500,000
- 15%
- Between £2,500,001 and £5,000,000
- 20%
- Over £5,000,001
- 25%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Citation Ltd.
- ISO/IEC 27001 accreditation date
- Thursday 24 July 2025
- What the ISO/IEC 27001 doesn’t cover
-
The physical and environmental security of the underlying hosting infrastructure (e.g. AWS) is not covered by our certification. The provider maintains their own independent ISO/IEC 27001 certifications, which are reviewed as part of our supplier management process. Client-side infrastructure, including end-user hardware (PCs), local area networks (LAN), and internet connectivity used to access our digital solutions, are outside the scope of our certification.
Security management of third-party external platforms or APIs not managed by X-on Health, such as integrated clinical systems (EPRs) or third-party telecommunications carriers, is also not covered. - ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Citation Ltd.
- ISO 9001 accreditation date
- Thursday 24 July 2025
- What the ISO 9001 doesn’t cover
-
The certification does not cover the manufacturing or hardware-level quality control of third-party end-user devices (e.g. handsets, headsets, or PCs) used to access our platforms.
While we ensure the quality of our system's logic, the accuracy and quality of clinical data hosted within external third-party systems (e.g. integrated EPR systems like EMIS or SystmOne) are not covered by our ISO 9001 certification. - Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 7421c82d-5c66-407b-888e-3f5ccc6a119e
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 64c90e06-ca79-4add-a60f-9d9a91c4e5df
- Other security certifications
- Yes
- Any other security certifications
-
- ISO 22301
- NHSE DSPT 2024-25 "Standards exceeded"
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
-