Intelogy Clinical Policies Management Tool
Our solution will manage SOP, guideline and policy documents within a clinical setting on Microsoft365. The solution manages the end-to-end document lifecycle, from creation, through authoring, review and approval processes, assignment of metadata and publication. Ultimately, it provides healthcare staff with a mechanism to retrieve trustworthy information quickly and efficiently.
Features
- Drafting of documents done via Microsoft Word with co-authoring
- Access to drafting area restricted to specific users
- Approval process predefined and configurable for each organisation
- All documents published as non-editable PDFs and linked supporting files
- All published content searchable via easy-to-use portal
- Administrator app used to manage complex back office processes
- Operates within the boundaries of the shared NHS tenant
- Deployable to other M365 tenants, independent of shared NHS tenant.
Benefits
- All content stored in Microsoft 365 (NHS or your own)
- Single library used to search for all content
- Advanced searching using filters e.g. organ , type, hospital site
- Familiar tools used for drafting and authoring documents
- Auto-conversion into immutable PDF records after approval
- Expiry dates trigger review workflow notifications
- Naming conventions for documents pre-defined, including unique ID
- Approval workflows notify pre-defined approvers with tasks
- Support for pre-scoped (e.g. hospital/department) searching
- Built-in versioning audit trail and update history
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 6 1 5 5 4 1 9 0 4 3 1 9 8 4
Contact
INTELOGY LIMITED
Andrew Tomlins
Telephone: 02037473506
Email: info@intelogy.co.uk
About your service
- Service categories
-
Applications
Content workflow and management
Content services
- Content Sharing and Collaboration Applications
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes
- What software services is the service an extension to
- Microsoft 365
- Cloud deployment model
- Public cloud
- Service constraints
-
Being a cloud service, the system relies on access to the internet. All modern browsers are supported.
It does require an Office 365 license to be in place for each user (such as the N365 licensing agreement already in place for 1.5M NHS users). - System requirements
-
- A licensed Microsoft 365 tenant is required
- Microsoft 365 licenses (E1/E3 for document authors and drafters)
- Power Apps licenses (for Admin users only)
- Microsoft Word (included with E3 licenses)
User support
- Email or online ticketing support
- Yes
- Support response times
- All tickets raised with our helpdesk are prioritised by impact and triaged accordingly. Our helpdesk operates during UK-based office hours (Mon-Fri 9-5). Tickets will be responded to in a priority order: P1 tickets within 2 hour; P2 within 4 hours; P3 and above 10 hours. Our service response targets are guidelines for resolution times for incident tickets which Intelogy intend to meet or beat.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- Support is provided as a service offering for the accelerator. This covers issue investigation and resolution where appropriate. Provision is also included for feature enhancements and change requests, which may (or may not) be prioritised into the product roadmap for future release. You will be provided with access to a named technical account manager.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- We run an initial workshop with the key stakeholders to define the required configuration for that particular organisation. This starts as a demo and then requirements gathering session to identify changes. The biggest challenge is usually then loading legacy content into the system and helping organisations to establish their actions for content owners. Beyond that we will run a pre-production validation session, user training webinars and discuss adoption strategies.
- Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- The customer's data will be stored within their own Microsoft 365 tenant and therefore they have control of it when the contract ends. Our value-add is the logic built into the system to manage the lifecycle of documentation in an appropriately governed manner. Therefore there is no data extraction process required on contract end.
- End-of-contract process
- At the end of the contract, our logic apps (the things that process workflows for approval, versioning, naming and publication) will cease to operate, but the library of published content will still operate and be available for searching as before. Documents in the drafting library will also be available but cannot be processed to publication via the same means as before.
- Documentation accessibility standard
- WCAG 2.2 A
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- N/a
- Service interface
- No
- User support accessibility
- WCAG 2.2 A
- API
- No
- Customisation available
- Yes
- Description of customisation
- Workflows, document naming conventions, document types, any meta data and search experience can all be customised at part of the deployment per organisation.
Scaling
- Independence of resources
- We use Microsoft Azure to host the application and can scale the performance using standard Cloud scaling controls.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Quarterly service reports from the helpdesk manager
- Reporting types
-
- Real-time dashboards
- Regular reports
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- Records Management Solutions Limited
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
- Physical access control, complying with CSA CCM v4.0
- Data sanitisation process
- No
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data importing and exporting
- Data export approach
- Should owners of the content wish to export data from the solution, this is possible and will only require the assistance of their own IT team (as it is their own Microsoft 365 tenancy).
- Data export formats
- Other
- Other data export formats
- Any format supported by Microsoft 365
- Data import formats
- Other
- Other data import formats
- Any format supported by Microsoft 365
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- We mirror Microsoft Azure's availability guarantee and will directly pass on any refunds provided by Microsoft if service levels fall below their publicly stated levels (99.9%). https://azure.microsoft.com/en-gb/support/legal/sla/summary/
- Approach to resilience
- The Microsoft Azure platform provides a 14 day restore to point in time. Further information is available on request.
- Outage reporting
- The following is available to us: - a public dashboard https://azure.microsoft.com/en-gb/status/ - an API - email alerts
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Other
- Other user authentication
- Access to configuration and triage data is controlled by permissions in Microsoft 365. As such, clients have full control to apply any security approaches that are provided by M365, such as MFA etc.
- Access restrictions in management interfaces and support channels
- Access to configuration and triage data is controlled by permissions in Microsoft 365. As such, clients have full control to apply any security approaches that are provided by M365, such as MFA etc.
- Access restriction testing frequency
- At least once a year
- Management access authentication
- Other
- Description of management access authentication
- Access to configuration and triage data is controlled by permissions in Microsoft 365. As such, clients have full control to apply any security approaches that are provided by M365, such as MFA etc.
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- No audit information available
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
- Cyber Essentials Plus
- Information security policies and processes
- We are working towards ISO27001 accreditation so we adopt the "Plan-Do-Check-Act" (PDCA) model, which is applied to all Information Security Management Systems (ISMS). We have a set of policies defined at a Board level and all staff are contracted to follow them. They are available via our internal ISMS and any breeches of policies should be reported to our Operations Director who will decide on the course of action. Our policies are reviewed and adapted annually. All changes are highlighted to staff via internal meetings.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- All changes are applied via standard processes. i.e. A set of potential changes are assessed for inclusion in a point release of a new version. Assessment of risk, value to the end users, technical feasibility and complexity are taken into account and changes batched into priorities as a result. Changes are conducted on an internal development environment and are subject to ongoing manual and automated testing. The update is then deployed by an authorised platform administrator to a staging environment, tested and signed off by a product manager, before repeating the process on a production environments.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- The ICPMT will be deployed to your M365 tenant as a site within your SharePoint environment and then managed by your IT team as an internal asset. Vulnerability management is therefore incorporated into your standard IT best practices.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Yes, we have a defined process for common events: 5.2 Detection * Identification and reporting of the incident. * Incident details must be captured. * Categorization of incident. * Classify the incident. High, Medium, Low * Identification of stakeholder who all should be involved for managing the incident 5.3 Response * Preventive action of the incident minimize the re-occurrence of the incident * Corrective Action 5.4 Analysis * Data collection * Root Cause Analysis of the incident 5.5 Report * Preventive action of the incident minimize the reoccurrence of the incident * Learning communicated to either whole organisation and stakeholders
- Incident management type
- Supplier-defined controls
- Incident management approach
- Users can report incidents via phone, email and the helpdesk service. Detection * Identification and reporting of the incident. * Incident details must be captured. * Categorization of incident. * Classify the incident. High, Medium, Low * Identification of stakeholder who all should be involved for managing the incident Response * Preventive action of the incident minimize the re-occurrence of the incident * Corrective Action Analysis * Data collection * Root Cause Analysis of the incident Report * Preventive action of the incident minimize the reoccurrence of the incident * Learning communicated to either whole organisation and stakeholders
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- If you meet our qualification criteria, we can offer a free trial for 60 days, for up to 2 predefined templates.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 10%
- Between £1,000,001 and £2,500,000
- 20%
- Between £2,500,001 and £5,000,000
- 30%
- Over £5,000,001
- 40%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 94fe1d5d-42c6-4fd1-9e8a-4354344ecdb4
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 2ea592d2-831b-45df-8786-117854e250a0
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
-