CareBrokerage
CareBrokerage, an easy to use, cloud-based software solution, streamlining care commissioning/brokerage processes, improving data collection allowing commissioners/brokers/care arrangers to take full control of the process from contracting->compliance->performance management. CareBrokerage stores multiple purchaser details (commissioning bodies/adult social care clients/self-funded service users). Purchasers and providers are allocated to geographical regions/subzones.
Features
- Streamlines care commissioning/placement processes and improves the collection of data.
- Stores details of multiple purchasers/funders, geographically.
- Commissioners/brokers/care arrangers can add new care packages to the system.
- No limit to the number of providers added.
- Providers only notified about (and see) their own care packages.
- New care package notifications sent by email/via provider dashboards.
- Open care packages dashboard has configurable tier/priority “count down” capability.
- New care packages can be requested by the providers.
- Awarded and requested but declined care packages clearly shown.
- Providers can see how long a package remains on offer.
Benefits
- Supports rapid, efficient care package placement, replaces emailing/spreadsheets/chasing by phone.
- Allows commissioners/brokers/care arrangers to take full control of the process.
- Supports efficient contract compliance and performance management including via reporting.
- Enables hybrid working.
- Care packages can be offered efficiently based on service requirements/types/geography.
- Enables contextual reference to supporting documents.
- New providers can be added very quickly.
- Efficient method for providers to request new care packages.
- Efficient method for providers to see awarded/requested/declined care packages.
- Reasons given by commissioner help reduce need for voice communication.
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 7 8 7 0 3 6 2 2 5 1 6 0 9 0
Contact
MAS NETWORKS LTD T/A CARELINELIVE
Peter Briggs
Telephone: 0330 088 5767
Email: sales@carelinelive.com
About the service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Adult Social Care
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- CareBrokerage cloud software is web-based, so it can be accessed from any suitable, Chromium-based browser enabled device, e.g. Chrome, Edge, Chrome preferred, with an internet connection.
- System requirements
-
- CareBrokerage: via secure internet Chromium-based browser login.
- Two latest versions of Chrome/Edge, latest version recommended.
- Desktop/laptops required for UI access.
User support
- Email or online ticketing support
- Yes
- Support response times
-
Issues raised by email: MAS Networks Ltd use best endeavours to determine (during Working Hours, i.e. Mon-Fri 9am - 5:30pm excluding public holidays in England, unless stated otherwise below) whether an issue affects protected functionality and into which priority category an issue raised falls. Priority categories:
Critical (reported 24x7)
High
Medium/Normal
Low
Target acknowledgement (email): 30 minutes.
Issue target response and fix times:
Critical: 2 hours response, 4 hours fix (24x7x365 clock)
High: 4 hours response, 2 working days fix
Normal: 8 hours response, 7 working days fix
Low: 3 working days response, future release fix - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
CareBrokerage Support Service operates 24x7x365 days p.a. for Critical (Cloud software service down, not due to customer specific localised issues affecting a customer such as failure of customer devices, mobile coverage, or local internet access etc.) issues, and during office hours (9:00 a.m. – 5:30 p.m., Monday to Friday excluding English public holidays) for all issues.
The Support Service is the first point of contact for all Customer enquiries and service-related issues, receives support requests via email to our support portal 24x7x365, or by phone during office hours. Support calls/emails/messages are logged, processed and followed up by our Support Service Staff for the cloud software SaaS prices quoted.
CareBrokerage Support Service also provides general advice and guidance on Service use, incident knowledge, workarounds and next release information.
Client management:
During implementation, MAS Networks’ Project Manager is responsible with escalation to the designated MAS Networks' Account Manager for the customer, and then MAS Networks' Operations Director or Managing Director if/when applicable.
Post implementation, MAS Networks' designated Account Manager and Contract Manager for the customer are responsible for BAU liaison and Contract and Performance reviews respectively, with escalation to MAS Networks' Operations Director or Managing Director if/when applicable. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
We provide business process guidance to aid customers define the most appropriate changes to their business process to obtain maximum benefit from our cloud software. Upon implementation CareBrokerage cloud software will then reflect the new business process requirements and workflow as configured. We then provide contextual online training, and user documentation (collectively onboarding), plus support via a designated project manager, and our Support Service.
Training and documentation
Comprehensive training is part of our onboarding process. - Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
-
MAS Networks will assist with the migration of data at the end of the contract, in a CSV Export format for CareBrokerage, with the following quite straightforward process which is our standard approach in this regard:
1. The Buyer provides written contract termination notice to: accounts@mas-group.co.uk
2. The Buyer will receive a written notification reply letting you know we have received the request. Our reply will include the end date.
3. MAS Networks will confirm at the same time what data we will be able to extract and deliver to you, please see the Service Definition for details.
4. The Buyer will be provided instruction on how to receive your data. The data comes in the form of CSV exports for CareBrokerage.
5. MAS Networks will delete the Buyer data in our hosting including any back-ups, within 3 months of the termination date, typically as stipulated in the Call-off Contract. - End-of-contract process
-
Our quoted cloud software SaaS charge normally includes sufficient time in each contract for our designated project manager (exit) to prepare and agree the exit plan with the customer, then manage the exit (supplier side) and for our technical services team to offboard the customer's data, preparing the CSV file exports, prior to deleting the customer's data in accordance with the following quite straightforward process which is our standard approach in this regard:
1. The Buyer provides written contract termination notice to: accounts@mas-group.co.uk
2. The Buyer will receive a written notification reply letting you know we have received the request. Our reply will include the end date.
3. MAS Networks will confirm at the same time what data we will be able to extract and deliver to you, please see the Service Definition for details.
4. The Buyer will be provided instruction on how to receive your data. The data comes in the form of CSV exports for CareBrokerage.
5. MAS Networks will delete the Buyer data in our hosting including any back-ups, within 3 months of the termination date, typically as stipulated in the Call-off Contract. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Onboarding and offboarding documentation would be shared via email on project commencement, and cessation respectively.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Chrome
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
-
CareBrokerage cloud software:
Browser based: instant access to the main functional areas of the CareBrokerage service via a vertical tool bar, and interactive dashboards. Multiple browser tabs can be kept open. Data entry/review is via configurable, auto verifying fields for data type at the point of saving if not before. Extensive use made of colours, graphic charts, fly by/hover over tips. - Accessibility standards
- WCAG 2.2 A
- Accessibility testing
-
Accessibility is managed internally by our Product Designer, QA Engineer, and Director of Development.
We use automated tools and manual testing by QA Engineer to establish, maintain and drive improvement in regards to accessibility.
Accessibility requirements are understood by our Product Designer, through experience of working in the industry, understanding the standards, and the use of automated tooling and manual testing is used to ensure compliance. - API
- Yes
- What users can and can't do using the API
-
We have several API endpoints in place or currently in development for fetching information, so we request that Buyers please contact us for the latest information in this respect. That said, our CareBrokerage API is in line with Gov standards: REST, OpenAPI documentation, HTTPS, UTF-8, JSON, authorisation will be via OAuth2; JSON response format.
Only push processing supported.
We would expect to work with the customer's analysts to develop a complete configuration blueprint that describes how the solution needs to be configured to deliver the full functionality.
Our consultants would work with the customer's and/or 3rd party system analysts using configuration tools supplied as part of the Solution to build the desired configuration into the base Solution, and to test completeness and accuracy. Typically, this work is scoped and priced within the contract value. - API documentation
- Yes
- API documentation formats
-
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Multiple elements of the CareBrokerage platform are configurable, including the following:
• Framework provider tier lists are configurable, providing a priority-based package distribution.
• Tier timing is configurable as well as pauses between tiers if applicable.
• Zone/region management allowing packages to be broadcast to only users configured for the zone/region.
• Working hours are configurable so that the tiered timing only runs during the working hours specified.
• Access control so user privileges can be set by role (Role Based Access Control).
• Email notifications can be configured.
• Care Options such as Domiciliary, Supported Living and Care Home can be adapted with subcategories by the support team.
• SysAdmin can configure broker access level and zone administration
Scaling
- Independence of resources
- CareBrokerage is built using a SQL database architecture, utilising PostgreSQL, and therefore is inherently fully scalable. In addition, CareBrokerage is hosted for UK customers by Amazon Web Services (AWS) in London (UK), a Tier 4 professional datacentre, using AWS High Availability, Multi-AZ and spot instances allowing the platform to grow automatically as required, on demand to suit any load. Hence, with this in-built spare capacity for large surges in activity, and by hosting on high availability servers, our AWS hosting scales and shrinks using spot instances.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Generally we would include the provision of the following service metrics and a review online with the customer on a quarterly basis:
1. Service availability levels.
2. Number of Customer-reported incidents at each priority level and fix times.
3. Number of supplier self-notified incidents at each priority level and fix times.
4. Any issues/support/breaches of the SLA.
5. Downtime periods.
6. Service availability figures and other relevant information to be provided to the Customer 5 days in advance of each meeting.
7. Product - issues and feature requests.
8. Product - new functionality exposure, anything in road map. - Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Supplier type
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Other
- Other data at rest protection approach
-
CareBrokerage:
• Architecture adheres to NHS public cloud guidelines.
• Public cloud supplier, currently hosted+processed on AWS Tier-4 professional datacentre in the UK (London).
• Single-tenancy environment.
• Utilises PHP 8.2+PostgreSQL 14+Kubernetes 1.26
• BC/DR Plan available
• Auto-scaling architecture
• Backup: PITR+31-day snapshot retention, off-site replication, replication+failover enabled.
• No fixed-IP addresses.
• Strict firewall rules.
• Zero-trust methodology.
• Anti-malware protections.
• Web Application Firewall protects against DDOS attacks+potentially harmful connections.
• Automated testing of new software/dependency versions pre-deployment.
• Data stored at-rest encrypted using AES_256_GCM, data in-transit encrypted using AES_128_GCM, supported by TLS 1.3 minimum SSL connections. - Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
-
CareBrokerage cloud software includes the provision of 6 standard reports.
Plus the cost options of:
Custom reports, feasibility subject to scope and specification. - Data export formats
- CSV
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- .doc
- .docx
- .xls
- .xlsx
- .jpg
- .jpeg
- .png
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- Other
- Other protection between networks
-
CareBrokerage complies with current National Cyber Security Centre (NCSC) guidance as follows. CareBrokerage:
• All data stored at-rest is encrypted using AES_256_GCM, and data in-transit is encrypted using AES_128_GCM, supported by TLS 1.3 minimum for SSL connections, and;
• The platform has minimum password requirements in place.
• Is accessible via public internet; SSL enforced.
• Disables SSL 2.0, SSL 3.0, TLS 1.0 and TLS 1.1 protocols.
• Web services conform to local authority encryption standards.
• Utilises Service accounts with complex 32 character passwords. - Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
-
CareBrokerage:
• Architecture adheres to NHS public cloud guidelines.
• Public cloud supplier, currently hosted+processed on AWS Tier-4 professional datacentre in the UK (London).
• Single-tenancy environment.
• Utilises PHP 8.2+PostgreSQL 14+Kubernetes 1.26
• BC/DR Plan available
• Auto-scaling architecture
• Backup: PITR+31-day snapshot retention, off-site replication, replication+failover enabled.
• No fixed-IP addresses.
• Strict firewall rules.
• Zero-trust methodology.
• Anti-malware protections.
• Web Application Firewall protects against DDOS attacks+potentially harmful connections.
• Automated testing of new software/dependency versions pre-deployment.
• Data stored at-rest encrypted using AES_256_GCM, data in-transit encrypted using AES_128_GCM, supported by TLS 1.3 minimum SSL connections.
Availability and resilience
- Guaranteed availability
- We propose a Service Level Agreement, which includes the Target Service Availability of 99.85% for our hosted services in any given 12-calendar month period, 24 hours per day, 7 days a week, 365 days per annum, planned maintenance periods excepted.
- Approach to resilience
-
CareBrokerage is an integrated solution, updating in real time, with all components developed by MAS Networks, hosted in the UK on AWS a Tier 4 professional datacentre, and we have 'automated' 24x7 monitoring.
As a consequence we have very high up-time records (to date showing 100% availability throughout 2024 & 2025, upto and including 28th Jan 2026 for MAS Networks Ltd CareLineLive care management suite cloud software solution!).
Indeed, we are classified as a Silver service by the NHS guidelines, reference this link: https://digital.nhs.uk/services/cloud-centre-of-excellence/cloud-security-good-practice-guide/9.-appendix-b-service-classifications
MAS Group also operate our own Business Continuity Plan, to maintain support to customers in the event of a threat to normal operations.
Consequently, we are pleased to confirm that we will provide our CareBrokerage solution with target availability of 99.85% (i.e. in the absence of P1 Critical system down, target availability is 99.85%, planned maintenance periods excepted). - Outage reporting
- CareBrokerage is being enhanced. Please contact MAS Networks Ltd for details in this respect when procuring.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Username or password
- Other
- Other user authentication
-
In accordance with current National Cyber Security Centre (NCSC) guidance CareBrokerage:
a) All data is encrypted in-transit and at-rest, protecting against interception as well as unauthorised access to the underlying servers and supported by TLS 1.3 minimum for SSL connections, and;
b) the CareBrokerage platform has minimum password requirements in place. These are:
• Must be at least 8 characters long
• Must not be compromised, meaning:
• Cannot appear in known data breaches
• Checked against databases of leaked passwords
• If password has been exposed before, it will be rejected even if it meets length rules - Access restrictions in management interfaces and support channels
-
MAS Networks Ltd has access to all data, because we will be hosting the database and file storage. However, appropriate and strict access controls in place ensure that only the MD/Director of Development can authorise access to the data. Data is encrypted in-transit and at-rest at all stages.
For customer support, if trouble-shooting requires access to data within a particular customer's environment, explicit permission is requested for access from the customer, then access is approved for a MAS Networks staff member by either the MD, Director of Development/Director of Operations. All access requests are logged for future audit purposes. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Username or password
- Other
- Description of management access authentication
-
CareBrokerage secure user management:
o Authentication of (admin) users to management interfaces and support channels
▪ 2FA is enforced for all admin users, complex password requirements.
▪ Management/support requests accepted via telephone, email, and support portal.
▪ ISO 27001:2013 and Cyber Essentials Plus (+Cyber Essentials) certified
o Separation with access control within management interfaces
▪ Each organisation is hosted in a logically separate environment.
▪ Authentication credentials are separately managed for each environment.
▪ ISO 27001:2013 and Cyber Essentials Plus (+Cyber Essentials) certified
Audit information for users
- Access to user activity audit information
- No audit information available
- Access to supplier activity audit information
- No audit information available
- How long system logs are stored for
- Less than 1 month
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
-
MAS Networks Ltd, part of MAS Group, has the following Certifications:
• ISO 9001/2700
• Cyber Essentials Plus (+Cyber Essentials)
• NHS Digital Security Protection (DSP) Toolkit registered
• DCB0129 compliant
• Registered with the Information Commissioners Office (ICO)
CareLineLive: an NHS England Digital Social Care Record (DSCR) assured solution. - Information security policies and processes
- MAS Group follow, maintain and uphold ISO 27001, and ISO 9001 information security policies and processes, are NHS Digital Security Protection (DSP) Toolkit registered, and are registered with the UK ICO.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
Managing changes covers requirement gathering, specification, coding, testing and release management with respect to the live CareBrokerage environment.
We adhere to a strict change control process, documented in the MAS Group ISO Secure Systems & Development Aspects Policy. Any change requests will be carefully considered, documented in a requirements specification documentation that has to be agreed and signed off by all stakeholders prior to resources being assigned.
Major changes: applied during planned maintenance window in consultation and with agreement of the customer typically during low traffic periods. Minor changes: applied during normal hours of business at MAS Group discretion. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
Appropriate patching controls ensure technical vulnerabilities are managed effectively: adherence to the Malware and Vulnerability Aspects Policy and Directive.
Controls (Anti-Virus software, hardware/software firewalls, Internet web traffic): scanned for malware, potential phishing threats are used to detect threats. Threats risk assessed, appropriate action determined by the ISMS committee, recorded in the risk register, risks mitigated depending on severity/impact.
Issues deemed critical: target resolution within two business days or as soon as possible.
Anti-Virus software, hardware/software firewalls, Internet web traffic scanned for malware, and potential phishing threats: Logs are checked regularly, any significant reports escalated to the ISMS Committee and investigated. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
MAS Group perform protective monitoring in accordance with our ISO policies and procedures, (clause A.12.4 refers) overview:
A12.4.1 Event logging: Event logs that record user activities, exceptions and information security events to be generated and retained for an agreed period to assist in monitoring access control and as evidence in potential information security investigations.
A.12.4.2 Protection of log information: Event logs and the systems and services used to generate them to be protected against unauthorised access or modification.
A.12.4.3 Administrator and operator logs: System administrator and operator activities to be recorded, with the logs protected and subject to review. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
Incident reporting uses our ISO9001 logging process, identifies the problem, possible source, etc. Threat assessment is done determining what impact is likely and escalated as required. All incidents are reported on ISO27001 logs which will be shared with the Customer. We report routinely monthly but if there is a serious incident e.g. a GDPR breach then this is reported and acted upon immediately to minimise or mitigate any damage. Where needed we will also report to the ICO and other bodies as required.
Incident management processes are in place and tested yearly as part of disaster recovery testing. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- ISO/IEC 27001 accredited by
- Citation ISO Certification Limited
- ISO/IEC 27001 accreditation date
- Tuesday 27 May 2025
- What the ISO/IEC 27001 doesn’t cover
- None to report.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- ISO 9001 certification accredited by
- Citation ISO Certification Limited
- ISO 9001 accreditation date
- Tuesday 27 May 2025
- What the ISO 9001 doesn’t cover
- None to report.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber Essentials Certificate Number
- 258881ab-07bf-46aa-ad96-9a7271326dc7
- Cyber essentials plus
- Yes
- Cyber Essentials Plus Certificate Number
- A3ea88c7-38c1-490f-8f0c-e701e546147c
- Other security certifications
- Yes
- Any other security certifications
-
- NHS DSP Toolkit, 2025-26 (version 8)
- Clinical Safety (DCB0129)
- Data Protection Act 2018
Social value
- Mission: Kick start economic growth
-
To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Plans for positive actions with community groups.
- Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
- Collaborating with anchor institutions and community groups to make facilities available for education, training or community events