MedLink
MedLink is a secure cloud-based platform enabling GP practices to deliver remote clinical reviews and digital patient communication. It automates recalls, collects structured health data, and integrates with NHS systems to support efficient chronic disease management, improve patient engagement, and reduce clinician workload while maintaining full data protection compliance.
Features
- Secure cloud-based platform for patient clinical reviews.
- Customisable digital questionnaires for chronic disease monitoring.
- Automated patient recall and reminder workflows.
- Structured data capture for clinical coding and audit.
- Role-based access controls for practice and admin users.
- Integration via clinical systems
- Dashboard for managing responses and pending reviews.
- Real-time progress tracking for practice recall performance.
- Accessible on any device with NHS-grade encryption.
- Built-in incident reporting and audit trail functions.
Benefits
- Saves clinician time by automating routine patient reviews.
- Improves patient engagement and accessibility to care.
- Enhances chronic disease management and QOF compliance.
- Reduces administrative workload through streamlined workflows.
- Supports remote, asynchronous reviews and hybrid working.
- Enables safe, structured patient data collection.
- Strengthens data quality and practice reporting accuracy.
- Helps practices meet NHS digital transformation targets.
- Improves communication between patients and care teams.
- Fully compliant with GDPR, DSPT, DTAC and NHS standards.
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 8 0 8 8 5 0 4 9 6 4 2 1 4 8
Contact
MEDLINK SOLUTIONS LTD
Johannes Lorenz Kemper
Telephone: 07930190356
Email: info@medlinksolutions.co.uk
About your service
- Service categories
-
Applications
Customer relationship management
- Marketing campaign management
- Customer service
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- MedLink is delivered as a browser-based Software-as-a-Service platform. The service requires a stable internet connection and a modern web browser (Chrome, Edge, Safari or Firefox). Planned maintenance or system updates are performed outside core working hours, typically between 00:00 and 04:00 GMT, with advance notice to clients. There are no hardware dependencies or local installations required. Service availability depends on external NHSmail and clinical-system connectivity for data exchange where applicable.
- System requirements
-
- Modern web browser (Chrome, Edge, Safari, or Firefox).
- Stable broadband internet connection.
- NHS-approved email address for secure communication.
User support
- Email or online ticketing support
- Yes
- Support response times
- MedLink responds to all support queries within one working day and aims to resolve issues within three working days, depending on complexity. Critical incidents are prioritised immediately upon receipt. Support hours are Monday to Friday, 9 am – 5 pm UK time (excluding public holidays). Queries received outside these hours are acknowledged next working day.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- No
- Support levels
-
MedLink provides a single comprehensive support level included in all subscriptions at no additional cost. Support is available Monday to Friday, 9 am – 5 pm (UK time), excluding public holidays. Queries can be raised by email or through our online support portal.
Issues are prioritised as:
Critical: complete loss of service – immediate response within 2 hours.
High: major feature or performance degradation – response within 1 working day.
Standard: minor issue or general query – response within 1–2 working days.
Each customer is assigned a dedicated account manager responsible for onboarding, configuration, and ongoing engagement. Technical escalation is handled directly by MedLink’s development and infrastructure engineers.
No separate support tiers or additional-cost packages apply; all users receive full access to operational, clinical-safety and data-protection support as defined in the MedLink Service Level Agreement (SLA). - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
MedLink provides a fully guided onboarding process for each new practice. Implementation support includes an online induction session covering system access, configuration, and patient-facing communication setup. Comprehensive user documentation, quick-start guides, and short training videos are supplied through the MedLink Manager portal.
Each practice is assigned an account manager who assists with initial configuration, recall schedule setup, and user-permission management. Additional support is available by email or through our online helpdesk.
No local installation is required; the service is web-based and accessible immediately once account credentials are issued. Optional refresher sessions or updates for new staff can be arranged on request. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
At the end of a contract, MedLink provides practices with full access to export their data before account closure. Authorised users can download structured response data and activity logs in standard, machine-readable formats (CSV or XLSX) through the MedLink Manager interface.
On request, MedLink can also provide a consolidated export of all patient responses, message histories and audit trails, delivered securely via encrypted transfer or NHSmail. Exports are designed to ensure that no patient information is lost and can be imported into local systems if required.
After confirmation that data extraction is complete, MedLink securely deletes all client data from production and backup environments in accordance with its Data Retention Policy and Data Processing Agreement. - End-of-contract process
-
At the end of a contract, MedLink provides written notice of termination and confirms the scheduled account closure date. During this period, practices retain full access to their data and can export all records and reports at no additional cost using standard export tools within the MedLink Manager interface.
Following confirmation that data extraction is complete, MedLink securely deletes all patient and practice data from production and backup systems in line with the MedLink Data Retention Policy and Data Processing Agreement. A deletion confirmation can be provided to the client on request.
There are no additional costs for data extraction, termination processing or account closure. Optional extended data hosting, or bespoke support beyond the standard termination process, may be provided by separate agreement if required. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- MedLink provides a secure, browser-based web interface accessible to patients and practice staff. Patients complete structured clinical questionnaires via a responsive, mobile-friendly interface, while practices manage submissions through an intuitive dashboard with role-based access. The interface supports accessibility features, clear navigation, and plain-language content designed for NHS digital inclusion standards.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- MedLink’s web interface follows NHS accessibility guidance and is designed to meet WCAG 2.2 AA standards. Accessibility is reviewed through patient feedback and usability testing. Formal testing with assistive technology will be completed and documented as part of our ongoing DTAC accessibility improvement plan.
- API
- No
- Customisation available
- Yes
- Description of customisation
-
Buyers can customise MedLink to suit local clinical and administrative needs. Authorised practice users can select which clinical review templates to activate, adjust messaging and recall settings, and tailor communication text sent to patients. Customisable elements include review frequency, reminder intervals, question wording (within approved templates), and practice contact details.
Customisation is completed via the MedLink Manager interface, with no coding or technical input required. Administrative users with appropriate permissions can apply changes instantly across the practice account. Where bespoke review templates or integrations are required, these can be discussed with MedLink’s support team for safe configuration and testing before deployment.
Scaling
- Independence of resources
- MedLink is hosted on scalable cloud infrastructure within UK data centres using Google Cloud Platform and AWS. Each customer operates within logically isolated environments with separate databases and access controls. The service automatically scales resources to meet demand, ensuring consistent performance even during peak usage. Continuous monitoring and load-balancing prevent individual client activity from affecting others. Regular performance testing and capacity reviews are conducted to maintain reliability and availability in line with our Service Level Agreement.
Analytics
- Service usage metrics
- Yes
- Metrics types
- MedLink provides practices with usage metrics including number of active patients, reviews sent and completed, completion rates by condition, and average turnaround times. Additional metrics cover message delivery, response status, and clinician review activity. Practices can monitor engagement trends and identify recall performance improvements through downloadable reports and dashboards.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- Users can export their data directly from the MedLink Manager interface at any time. Authorised practice users can download structured response data, audit logs and reports in standard formats such as CSV or XLSX. Exports include patient responses, message histories and status information. Data extraction requires no technical assistance and can be performed securely by the client. For bulk or full account exports, MedLink can provide encrypted data transfer via NHSmail or secure file link on request. All exports comply with NHS data protection and information governance standards.
- Data export formats
-
- CSV
- Other
- Other data export formats
- XLSX format
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
-
Within MedLink’s own cloud network (Google Cloud Platform and AWS), data in transit between internal components and services is encrypted using TLS 1.2 or higher, consistent with NHS and NCSC guidance.
Additional encryption and isolation controls are also applied — such as AES-256 encryption at rest, VPC (Virtual Private Cloud) segmentation, and firewall-based access restrictions
Availability and resilience
- Guaranteed availability
-
MedLink guarantees 99.9% service availability, measured monthly and excluding planned maintenance windows (typically scheduled between 00:00 and 04:00 GMT). The platform is hosted on resilient, UK-based cloud infrastructure with redundancy across multiple availability zones to minimise downtime.
Service availability is continuously monitored, and incidents are prioritised according to severity as outlined in the MedLink Service Level Agreement (SLA). In the unlikely event that guaranteed uptime is not achieved, MedLink investigates root causes and provides a written incident report. Where non-availability results from factors within MedLink’s control, proportionate service-credit adjustments or extensions to the subscription term may be offered on a case-by-case basis.
Planned maintenance notifications are issued to all clients in advance, and emergency updates are conducted only when required for security or performance reasons. MedLink’s hosting partners (Google Cloud Platform and AWS) provide enterprise-grade uptime SLAs, ensuring consistent reliability and compliance with NHS digital service expectations. - Approach to resilience
-
MedLink is designed for high resilience and availability through redundant, distributed cloud infrastructure hosted in UK data centres operated by Google Cloud Platform and Amazon Web Services. These environments provide multiple availability zones with independent power, networking and cooling, ensuring that a failure in one zone does not affect overall service availability.
All application and database components are replicated across zones, with automated failover and real-time data backup. Daily encrypted backups are retained in geographically separate locations within the UK. Continuous monitoring, load balancing and automated scaling protect against service degradation during peak demand.
Both cloud providers are certified to ISO/IEC 27001 and SOC 2, and comply with NHS Digital and NCSC guidance on cloud resilience. Business continuity and disaster recovery processes are documented in the MedLink Business Continuity and Cyber Incident Plan, which includes defined recovery time and recovery point objectives (RTO/RPO).
Detailed infrastructure and resilience documentation can be provided to authorised buyers on request. - Outage reporting
-
MedLink notifies customers of any service outage or degradation through direct email alerts to registered practice contacts and account managers. Planned maintenance notifications are issued in advance, and unplanned incidents trigger immediate alerts once confirmed by system monitoring.
Service status and uptime are continuously monitored using automated tools, and alerts are reviewed by MedLink’s technical and operations team. Updates on issue resolution and service restoration are provided by email throughout the incident and followed by a summary report where applicable.
At present, MedLink does not operate a public status dashboard or API for real-time outage information, but summary availability metrics are included in regular client reports.
All incidents are logged in accordance with the Incident Reporting Policy and the Business Continuity and Cyber Incident Plan, which outline root-cause analysis, recovery procedures and communication responsibilities. This ensures timely, transparent reporting and compliance with NHS data protection and continuity standards.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Other
- Other user authentication
- Practice users authenticate via username and password with multi-factor authentication. Patients access assigned questionnaires using secure, time-limited links unique to their verified NHS record. All authentication events are logged and protected using TLS 1.2+ encryption, with session timeout and access control enforced per user role.
- Access restrictions in management interfaces and support channels
- Access to MedLink management interfaces and support channels is strictly role-based and restricted to authorised personnel. Administrative access requires multi-factor authentication and encrypted connections (TLS 1.2+). Permissions are limited according to job function, with least-privilege access enforced. Support staff can view only the information necessary to resolve issues and have no access to patient-identifiable data unless explicitly authorised. All access is logged, monitored and periodically reviewed. Escalated support requests are handled through secure ticketing channels, and data sharing is subject to audit controls in line with MedLink’s System Security Policy and Data Processing Agreement.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
- MedLink Solutions Ltd is certified to Cyber Essentials Plus and has achieved DSPT Standards Exceeded status. These accreditations confirm that our security governance and technical controls meet NHS Digital and NCSC requirements for information security management and data protection.
- Information security policies and processes
-
MedLink maintains a comprehensive suite of information security policies aligned with NHS Digital, DSPT and NCSC guidance. Core policies include the System Security Policy, Data Protection Policy, Data Retention Policy, Incident Reporting Policy, and Business Continuity and Cyber Incident Plan. These define controls for data confidentiality, access management, encryption, change control, and incident response.
Overall responsibility for information security lies with Dr Graham Widgery, CTO and Director, who reports to the company board. The Data Protection Officer, Dr Lorenz Kemper, oversees compliance with UK GDPR and NHS data-governance standards.
All staff and contractors receive mandatory induction and annual refresher training covering data protection, cyber security and confidentiality. Compliance is monitored through internal audits, access-log reviews, and regular policy reviews at board level. Security incidents are reported directly to the DPO using formal incident forms and managed according to defined escalation procedures.
Policies are reviewed annually or following significant system changes, and updates are communicated to all employees via internal briefings and acknowledgement records. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- MedLink follows a defined change management process governed by the MedLink Change Policy. All system components are version-controlled and tracked through their lifetime using secure repositories and deployment logs. Proposed changes undergo risk and security assessment before approval by authorised engineers and directors. Security, data protection and performance impacts are reviewed prior to implementation. Changes are tested in a controlled environment before deployment to production. Full audit trails are maintained for traceability, and post-implementation reviews ensure configuration integrity and compliance with NHS DSPT and Cyber Essentials Plus requirements.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- MedLink identifies and assesses potential threats through regular automated vulnerability scans, penetration testing and continuous monitoring of vendor and NCSC advisories. Security updates are evaluated for impact and prioritised by severity. Critical patches are deployed within 24–48 hours; high or medium risks within seven days or during the next scheduled release. Information about new threats is gathered from NCSC, NHS Digital’s CareCERT alerts, cloud provider bulletins (Google Cloud and AWS) and industry threat-intelligence feeds. All remediation actions are logged, reviewed and verified through post-deployment testing and change-control processes.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- MedLink uses supplier-defined controls for protective monitoring. Security events, access logs and system performance are continuously monitored through cloud-native tools and internal processes. Alerts are reviewed by authorised engineers, with incidents escalated according to the MedLink System Security Policy and Business Continuity and Cyber Incident Plan. Hosting partners (GCP and AWS) maintain compliance with CSA CCM v4.0 and ISO 27001.
- Incident management type
- Supplier-defined controls
- Incident management approach
- MedLink has pre-defined processes for common events such as system outages, data breaches and security alerts, described in its Incident Reporting Policy and Business Continuity and Cyber Incident Plan. Users can report incidents via email or through the online support portal using a standard incident form. Each incident is logged, prioritised by severity and investigated by the technical team with oversight from the DPO and CTO. Root-cause analysis and corrective actions are documented. Incident summary and resolution reports are shared with affected clients and retained for audit and learning purposes.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
- Health and Social Care Network (HSCN)
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- A three-month free trial is available for EMIS Web, EMIS PCS and SystmOne practices in England. Welsh EMIS Web practices may trial the service for three months at 2.75p per patient plus VAT. Vision practices are not eligible for a trial. All trials include full functionality and standard technical support.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- You do not have a current and valid Cyber Essentials certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 0275a695-217d-4fa6-a60b-f5bb86733cdc
- Other security certifications
- Yes
- Any other security certifications
-
- NHS Data Security and Protection Toolkit (DSPT) – Standards Exceeded
- ICO Registration (ZA520573) – Data Protection Act 2018
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-