Streamlined Forensic Reporting Medical Service
The SFR Medical provides a cloud-based software service that enables UK police forces to securely request, manage, track and receive forensic medical evidence. The platform provides role-based access, secure workflows, audit logging and encrypted evidence delivery through a web-based SaaS solution.
Features
- Web-based, cloud-hosted SaaS platform accessible via standard browsers
- Secure request and case management for forensic medical evidence
- Multi-factor authentication for user access
- Encrypted data storage and encrypted data transfer
- End-to-end audit logging for evidential integrity
- Real-time request status tracking and workflow management
- No customer-managed infrastructure or local installation required
- Standardised evidential report formats
- Information governance: GDPR, Data Protection Act, ICO registration, Cyber Essentials
- A single, monthly invoice only charging for completed medical SFRs
Benefits
- Single point of contact for police officers’ medical evidence requests
- Speeds up delivery of medical evidence through streamlined workflows
- Urgent service for out-of-hours charging decisions, available 24/7
- Supports compliance with data protection laws and policing requirements
- Eliminates reliance on email-based evidence sharing processes
- Integrated images, body maps and 3D reconstructed images of wounds
- Provision of expert reports
- Reduced secondary harm to victims of violent crimes
- Management of a single supplier, improving operational efficiency
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 9 2 6 6 1 6 8 7 4 9 4 0 3 7
Contact
SFR Medical
Johann Grundlingh
Telephone: 07746646603
Email: contact@sfrmedical.com
About the service
- Service categories
-
Applications
Customer relationship management
- Customer service
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- The service is delivered as web-based SaaS solution and is accessed via standard, modern web browsers. Users must have an active internet connection and compatible browser to access the service. Planned maintenance and upgrades are carried out by the underlying SaaS platform providers (Microsoft Dynamics 365 and Azure). Where maintenance is required, it is scheduled outside normal operational hours to minimise service disruption. The service is hosted on Microsoft Azure and does not support on-premise or alternative cloud deployments. Access to service is restricted to authorised users using approved credentials and multi-factor authentication. No specialist hardware is required by buyers.
- System requirements
-
- Supported web browser (like Microsoft Edge, Google Chrome)
- Multi-factor authentication.
User support
- Email or online ticketing support
- Yes
- Support response times
-
Yes, we provide email-based support via our Service Desk.
Response times are prioritised based on incident severity:
Our Service Desk operates 24x7x365, including weekends and public holidays. Response times are consistent at weekends; however, for business operational services, the SLA response clock pauses at 19:00 and resumes at 07:00 the next working day. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- Not Applicable
- Onsite support
- No
- Support levels
- Streamlined Forensic Reporting Ltd provide ongoing support through a dedicated Client Relationship Manager who will work alongside Police Officers throughout the provision of our service. They will assist with technical support and process direct requests for streamlined forensic reports using the Microsoft Dynamics customer management system. We do not have differing, tiered support levels – all customers are provided the same high level of support.
- Support available to third parties
- No
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
- We provide PDF and video guides for different roles before onboarding a new customer. These guides are also available to the users of the service at any time and can be accessed directly through the SFR Medical portal. Moreover, we also offer and conduct training webinars for our services, which will be delivered live via video conferencing software by one of our Client Relationship Managers. Ongoing support is provided after go-live for any technical or operational issues.
- Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- All data is stored in line with Forensic Capability Network, NPCC and current legislative data retention standards. Upon contract expiry, the SFR Medical team will download and provide the data to the Police Force single point of contact (SPOC). Client SPOCs also have access to all the case related data through their login, meaning they can also download it manually prior to termination of their account, if they decide to bring their contract to an end.
- End-of-contract process
-
The contract will expire on the natural end date of any specific contract called off against the framework. If no renewal is agreed and the Customer continues to access the Contractor’s services, the terms of this agreement shall apply on a rolling basis until the overarching contract expiry date.
Persistent failure by the Contractor/Subcontractor to meet agreed service levels as specified within the SLAs and KPIs may lead to the contract being terminated or alternative Contractor(s) being appointed to maintain levels of service.
Prior to early termination the complaints and escalation procedure should be followed to attempt to resolve any issue. Should suitable resolution not be achieved, the Customer will be allowed to terminate the SLA immediately.
Existing requests for SFRs issued prior to notice of termination shall be completed as if the Agreement were still in force. No new request for SFRs will be issued after service of notice of termination unless specifically agreed between the parties.
Upon termination, data will be deleted if requested by the Police Force, and SPOCs will be able to download all force specific data into their systems. They can request for further granular data to be provided by SFR Medical upon termination. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The SFR Medical portal has been developed using responsive design, ensuring no loss of functionality as a mobile site. The portal can be accessed through mobile devices in the same way as the desktop version, ensuring it provides same services as the web portal.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The SFR Medical portal utilises a web-based visual interface, allowing easy navigation of service features and areas. Reports are visualised using the SFR template, now nationally approved following collaboration with the Forensic Capability Network (FCN). Medical evidence is a combination of medical records and medical statements. The medical statements produced are in the format of either an SFR1 (MG22B) and SFR2 (MG22C or MG22D) and in some circumstances an MG11. They are typed, jargon free, structured in an easy-to-read format and comprise all information from the multiple medical institutions and medical specialties a victim was assessed and treated by.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- Our web-based interfaced was developed in line with WCAG 2.1 AA standards, with a pilot program conducted during development alongside selected Police Forces to ensure compliance before the service was launched.
- API
- No
- Customisation available
- Yes
- Description of customisation
- Upon request, SFR Medical can customise some portal features for each Police Force. This includes changes to the logo, nomenclature, specialist documents required, and approver details. These changes and customisation options can be requested though the force’s Client Relationship Manager, who can be contacted directly through email or telephone.
Scaling
- Independence of resources
- Usage is based on licences. 5000 users can use the system based on one licence. The SFR Medical portal is designed to be scalable and, our IT team ensures that we are able to maintain the capacity to serve all SFR Medical customers without downtime or reliability issues
Analytics
- Service usage metrics
- Yes
- Metrics types
- User metrics available through the SFR Medical portal include analytics reports (aggregated), user logs (If requested through the Client Relationship Manager), and access logs with IP addresses if requested (real time accessible to SPOCs via the portal).
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Supplier type
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- Each Police Force’s single point of contact can export data based on a range of parameters, including date range, requesting officer, request progress and multiple other parameters.
- Data export formats
-
- CSV
- Other
- Other data export formats
- XLS
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- JPEG
- DOCX
- TIFF
- Other
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- Our service is available 100% of the time (day and night) specially to cover urgent requests. In case of any downtime, the services still continue with all necessary business continuity processes in place to shift from Portal to emails and phone calls in the meantime. We have reduced the average waiting time for medical statements from over 3 months to less than 10 working days. If there is a suspect in custody or if there is a trial in the next 7 days however, our urgent service endeavours to complete requests within 24 hours (and if relevant before the PACE clock ends). Our current turnaround time for our standard service is between 2 and 8 working days, and for our urgent service between 2 hours 48 minutes and 5 hours 30 minutes.
- Approach to resilience
-
Microsoft ensures that the data at its data centres (data at rest) and data in transit are encrypted to minimise security risks. Microsoft Dynamics follows industry standard encryption protocols and provides strong access management through multifactor authentication and Azure security centre. Microsoft Cyber Defence Operations Centre (CDOC) protects Microsoft’s Cloud infrastructure and customers from evolving threats.
We have business continuity and disaster recovery plans (tested regularly) in place to continue providing services in the event of disaster/ breach/ impact to regular processes.
All sensitive data is stored on an NHS One Drive/ Microsoft Dynamics UK data centres and accessed by authorised SFR Medical staff only via company provided security enabled laptops or Azure virtual machines (VMs). This ensures that:
• Users cannot copy or store any information outside of the Organisational network
• Access to emails and virtual machines is granted to only those who need it, and who have been approved by the CMO and CTO
• Multifactor authentication (per NHS digital guidelines) is enabled for emails, OneDrive, VM access and applications to ensure additional security against potential cyber-attacks. - Outage reporting
- Any outages are communicated to a Police Force’s SPOC. We have not had a scenario yet but in the event of an outage, we have procedure to publish it on the Portal.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Limited access network (for example PSN)
- Access restrictions in management interfaces and support channels
-
There are various roles defined within the SFR Medical Portal for the Police Officers, SPOCs, Supervisor etc. By default, a user, upon registration, has the Officer role which can be upgraded:
1. To a supervisor through a checkbox on the Portal and
2. To a SPOC by an email to the SFR Medical team from the Police Force existing point of contact - Access restriction testing frequency
- At least once a year
- Management access authentication
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users receive audit information on a regular basis
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- Between 6 months and 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- Pen Test, NHS Data Security & Protection (DSP) Toolkit and Cyber Essentials accreditation. All personnel are vetted to the NPPV2 or NPPV3 standard. Our service has been approved as a permitted method of emailing personal identifiable data (PID) or confidential data in the UK (NHS Digital).
- Information security policies and processes
-
The following are applicable to our Data Protection policies, operating in line with the Data Protection Act 2018 and GDPR; ISO/IEC 27001 standard clauses 5.2 and 5.3, ISMS Scope Document Risk Assessment, and Risk Treatment Methodology Statement of Applicability Register of legal, contractual, and other requirements. We have defined information classification, incident management processes and relevance access control, monitoring processes in place to ensure information security. We are certified with ISO 27001.
Responsibilities for the ISMS are undertaken by the following:
The Chief Technology Officer (CTO) ensures that the ISMS is implemented and maintained and for ensuring that all necessary resources are available.
The compliance officer must review the ISMS at least semi-annually, or each time a significant change occurs. The purpose of the management review is to establish the suitability, adequacy, and effectiveness of the ISMS.
The compliance officer will implement information security training and awareness programs for employees.
The protection of integrity, availability, and confidentiality of assets is the responsibility of the owner of each asset.
All security incidents must be reported to the CEO. CTO will define which information related to information security will be communicated to interested parties (both internal and external), by whom, and when. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Changes are tracked using Microsoft Planner (priority based) and are communicated and approved with all stakeholders via a call to the Change Approval Board. We also have update release communication sent over both email and Microsoft Teams channels to communicate any planned change and the migration status of the update. Changes are tested prior to release using unit and UAT testing. Changes migrate over non-working days unless urgent (Priority 1).
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Threats are identified in advance during our regular risk assessment process. Risk planning involves conducting a risk assessment, developing risk treatment methodology, and determining a risk mitigation plan. This is conducted by calculating the impact and likelihood of a risk and thus defining the severity to create a mitigation plan. The Microsoft Security Centre is also used for monitoring and addressing any potential risks in advance.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- SFR Medical has an Incident Tracking Register which is used to track any registered incidents requiring action. Incidents and issues can be reported through our Security email or through our Teams channel for internal report. Additionally, the Microsoft Security Centre will also flag up potential threats. We also have multiple communication lines for users to report an incident through the ‘Contact Us’ option, which has an SLA of 1 day or quicker based on severity.
- Incident management type
- Supplier-defined controls
- Incident management approach
- SFR Medical has an Incident Tracking Register which is used to track any registered incidents requiring action. Incidents and issues can be reported through our Security email or through our Teams channel for internal report. We also have multiple communication lines for users to report an incident through the ‘Contact Us’ option, which has an SLA of 1 day or quicker based on severity.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- There is an option which Police Forces can chose to take a free trial for a certain number of cases with us. We have also run some pilot programs with Police Forces as a test run for our finalised services. These pilots are highly feedback oriented.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 1%
- Between £500,001 and £1,000,000
- 2%
- Between £1,000,001 and £2,500,000
- 3%
- Between £2,500,001 and £5,000,000
- 4%
- Over £5,000,001
- 5%
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- ISO/IEC 27001 accredited by
- Approachable Certification
- ISO/IEC 27001 accreditation date
- Friday 20 December 2024
- What the ISO/IEC 27001 doesn’t cover
-
Physical infrastructure owned and operated by third-party cloud service providers, such as data centres and underlying hardware
The registered office location, which is used for administrative purposes only, as SFR Medical operates as a 100% remote-working organisation - ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber Essentials Certificate Number
- D608a3f4-1263-4a2a-9ef3-2760b3878a96
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- Yes
- Any other security certifications
-
- CHECK Penetration Testing
- NHS DSP Toolkit Compliance
Social value
- Mission: Kick start economic growth
-
To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Mission: Build an NHS fit for the future
-
That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce