DrDoctor patient engagement platform with delivery partner services
A patient engagement platform (PEP) with delivery partner services to redesign, implement and embed hybrid outpatient pathways at scale. Used by NHS Trusts to automatically schedule appointments, manage patient communication, scale remote follow-up/monitoring, the platform uses agentic automation and integrates with 20+ EPRs across diagnostic, inpatient, and outpatient care.
Features
- Deep Integration with NHS App for wider patient access.
- Self-service appointment scheduling suite with automatic EPR write-back.
- Attendance confirmations and reminders via SMS, email and NHS App.
- Scalable patient communications including digital letters and two-way messaging.
- PIFU, PROMs, remote monitoring to reduce face-to-face activity.
- Personal health records including care plans, symptom tracking, and more.
- AI solutions including DNA prediction, clinic optimisation and AVT.
- Configurable clinical pathways with automated triggers, tasks, forms, logic.
- Diagnostic consultancy to identify operational bottlenecks and improvement opportunities.
- Delivery partner services supporting pathway redesign, implementation and scaling adoption.
Benefits
- Provide a consistent, joined-up patient experience across care settings.
- Improve operational productivity through scheduling, communications, administrative task automation.
- Protect clinical time by reducing unnecessary face-to-face follow-up appointments.
- Reduce DNAs, triage waiting lists, and increase clinical capacity.
- Enable paperless services and reduce operational costs through digitisation.
- Safely deploy automation with ‘clinician-in-the-loop’ oversight and safeguards.
- Deliver flexible, hybrid patient pathways through remote follow-up and monitoring.
- Accelerate time-to-value through rapid integration and delivery partner support.
- Scale outpatient transformation consistently across services and secondary care.
- Gain diagnostic insight with delivery support to implement operational changes.
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 0 5 8 7 8 5 1 8 7 4 9 7 3 9
Contact
DrDoctor
Commercial Team
Telephone: +44 0330 321 1206
Email: sales@drdoctor.co.uk
About your service
- Service categories
-
Applications
Content workflow and management
Enterprise portals and digital workspaces
- Multi-Audience Portals
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Hybrid cloud
- Service constraints
- None
- System requirements
- Requires a modern, web-standards compliant browser
User support
- Email or online ticketing support
- Yes
- Support response times
- DrDoctor has a support desk that operates 5 days a week between 09:00-17:00 (excluding bank holidays). DrDoctor clients are also supported by a dedicated Transformation Manager (during implementation) and our Integrations team and ongoing usage and scaling support (post-implementation).
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- At this time we have not done any web chat testing with assistive technology users.
- Onsite support
- Yes
- Support levels
-
DrDoctor commits to ensuring all elements are in place to provide consistent service support and delivery to our clients. All client support includes a Transformation Manager and all technical support required.
More detail on support can be found in our SLA document.
Our SLAs are available to all clients and enhanced SLAs may be considered upon request, for an additional cost.
The severity if any reported issues will be assigned by DrDoctor upon triage, taking into consideration the information provided by our clients and the application of the description. DrDoctor will respond and resolve incidents within a fault resolution process. The time periods that apply are dependent on the severity of the incident and Support level agreed. - Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
- We provide onsite and online training as well as recordings and user documentation. A typical project implementation contains six key phases using an Agile delivery mechanism, wrapped in a PRINCE2 governance framework. Having a strong governance structure and dedicated resource assigned to every project are key components of a quick and successful implementation. Key milestones include project set up, operational set up, end-to-end testing, pilot, and transition to BAU with a focus on scaling and delivering impactful change. We believe in working in partnership with our clients to deliver meaningful transformation projects across the health service
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- Organisations can extract all data by exporting to CSV. Access to data contained in DrDoctor is available via a set of APIs.
- End-of-contract process
-
At the end of the contract, the service is ended (no further messages can be sent) and all user accounts are disabled after 30 days. Organisations should ensure they have downloaded any data they require within this time period.
An invoice/credit note is issued within 30 days to cover any under/over usage following the end of the contract.
Subsequent access or user support is charged at £500/day. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The patient element of the platform has been created to be digitally optimised for the device on which it appears, meaning screens are resized according to the device and page in use. The DrDoctor solution has no particular operating system requirements, all that is required is that the operating system can support a modern internet browser. Patients can also access DrDoctor via the NHS App.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The staff and patient user interface is designed to be simple and user-friendly. All that is required is a modern internet browser. Users are not required to create an account for the DrDoctor Portal. Patients can access immediately by providing their demographic information or access DrDoctor via the NHS App, and staff can use SSO. Further, those without smartphone or internet access can still interact with their care by SMS workflows e.g. reply back CHANGE, or CANCEL to amend an appointment. Staff can access the portal via login using their Trust SSO or DrDoctor user account.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
DrDoctor undertakes a combination of structured accessibility assurance and practical, hands on testing to ensure our interfaces are usable for people who rely on assistive technologies.
Our core Patient Portal has recently undergone an independent accessibility audit against WCAG 2.1 standards. The audit confirmed a strong baseline level of accessibility across key user journeys, with findings used to inform a prioritised improvement backlog. Actions arising from this audit are actively tracked and addressed as part of our ongoing product development and release management processes.
In addition to formal audit activity, our front end developers periodically test patient facing interfaces using common assistive technologies, including screen readers, to validate real world usability and navigation. While this testing is not conducted on a fixed schedule, it is embedded within development and quality assurance practices and supports adherence to established accessibility standards and design guidelines across the platform.
Accessibility considerations are also built into our development approach through the use of shared UI components and coding standards, helping ensure consistent, accessible behaviour across new and existing functionality. Areas identified for further enhancement, including specific modules highlighted through recent audits, are incorporated into our continuous improvement roadmap. - API
- Yes
- What users can and can't do using the API
-
APIs are available for self integration between DrDoctor and third party systems, local applications (e.g. clinical portals). Examples include:
Our Video API can be mapped into an electronic patient records (EPR) for a seamless interface. Clinical teams can see when a patient is waiting in a call, message the patient and join virtual appointments directly from their EPR.
Our Digital Assessment FHIR API allows patient responses and scoring to populate directly into the EPR or eDMS as structured data or PDF.
Our Digital Letters API can integrate with any hybrid mail provider and surface letters in the DrDoctor portal. Our read receipt API identifies if a patient has not viewed their letter within a timeframe and automatically dispatches a postal copy. - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- Other
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
DrDoctor is built on the concept of user control and configurability.
The Staff Portal allows the local teams to customise many aspects of each solution. E.g.:
• User profiles, access, and preferences.
• Rules for their clinics (in bulk or individually) e.g. turn off the ability to reschedule, turn on confirmation notifications, timing of reminders
• Customise content of appointment communications including notifications and reminders and pre appointment information.
• Customise cancellation reasons and cancellation workflows.
• Automate sending digital assessments e.g. before/after certain appointments
• Customise waitlist validation intervals and frequency.
• Configure digital patient initiated follow up pathways and customise onboarding, offboarding and reminder messages. - Customise Workflows and combine DrDoctor capabilities for efficient work streams
These changes can be instantly actioned by users (with permission) at any time without any involvement required by DrDoctor staff.
Scaling
- Independence of resources
-
DrDoctor is entirely cloud-hosted in Microsoft Azure data centres. Microsoft Azure’s cloud infrastructure can automatically scale to meet demand and has multiple connections to the internet backbone providing flexible performance and resiliency.
DrDoctor utilises service monitoring systems which capture page performance, availability and apdex scores, notifying the technical team of any highlighted issues and the system is adapted as needed.
Previous technical due diligence concluded that the infrastructure is capable of meeting expected growth goals and unexpected increases in demand for both the patient portal and staff portal.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
DrDoctor provides service metrics including:
•DrDoctor Insight Hub includes real-time dashboards showing analysis of appointments, DNAs, cancellations and individual solutions, such as Digital Letter analysis showing read rates. Analysis can be filtered by speciality, date and patient demographic. Dashboards include graphical charting of the data over time and are available 24/7 with the ability to export.
•A DrDoctor Regional Transformation Lead can assist with custom reports on request.
•DrDoctor’s Datashare module connects the Organisation’s public cloud platform with DrDoctor’s, enabling unrestricted back-end access at scale of all de-anonymised patient data, allowing users to build their own dashboard - Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Staff screening not performed
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with another standard
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- DrDoctor’s dashboards are accessible 24/7 giving users access to data from each solution, i.e. digital letters dashboard showing graphs of sent letters, number of letters read, patient print preference. Graphs/data sets can be adjusted/filtered by specific date, clinic codes/specialty. Data from dashboards can be exported anytime. Our Data Share option allows bulk exporting of SQL data on appointments, using Azure data features to copy across provider data enabling incorporation into existing Data Warehouse/BI solutions. Assessment writeback interface allows us to sendback structured data via HL7. Clients can access assessments data using DrDoctor's FHIR server and extract data (exporting to CSV).
- Data export formats
-
- CSV
- Other
- Other data export formats
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
DrDoctor is accessible 24/7 and achieves a 99.9% uptime of:
• The DrDoctor management portal.
• The patient facing websites.
• Our SMS, email and video services.
• Any other APIs or data endpoints.
Response time is 0.5 hours for all priority levels. DrDoctor have the following SLA's and an escalation process for dealing with these issues effectively:
• Service Level 1 (access to the Services is unobtainable or severely limited): Restoration time = 8 hours
• Service Level 2 (the services are malfunctioning but are still accessible and a workaround is not available): Restoration time = 24 hours
• Service Level 3 (there is disruption to the operation of the Services for which a workaround is available so that the Customer is able to fulfil its obligations to stakeholders): Restoration time = 168 hours
• Service Level 4 (Intermittent and minor operational inconveniences which do not affect the Customer’s ability to fulfil its obligations to stakeholders): Restoration time = 960 hours
• Service Level 5 - Prioritised accordingly.
We have an automatic alerting system monitoring performance and a dedicated support team that actively monitor our platform. A choice for advanced SLAs, including service credits, is available. - Approach to resilience
-
DrDoctor operates exclusively on Microsoft Azure, leveraging its resilient cloud infrastructure distributed across multiple data centers meeting industry standards like ISO/IEC 27001:2013 and NIST SP 800-53, as well as compliance with HIPAA, FedRAMP, SOC 1, and SOC 2. Transaction log backups occur every 15 minutes for DrDoctor databases and every 5-10 minutes for Azure PaaS SQLs. Data in Azure Storage is encrypted using 256-bit AES encryption and is FIPS 140-2 compliant. Regular spot checks, penetration testing, disaster recovery plans, and business continuity plans ensure data confidentiality and protection. Continuous monitoring ensures system availability and performance. User logins and system interactions are audited, and strict information governance policies are in place, validated by a DSPT assessment.
We also provide certain services using a microservice application, each module runs in separate services within a Kubernetes cluster, with a minimum of 1 and a maximum of 2 replicas per module. Kubernetes ensures continuous service provision by monitoring each service, providing high availability. With three attached hosts/nodes, Kubernetes automatically redistributes modules if a node fails. It is configured for horizontal scaling, automatically increasing capacity by 3-4x without service interruption. - Outage reporting
-
DrDoctor has a real-time error reporting system which notifies engineering teams immediately if service degradation occurs, both inside and outside of core support hours. Outside of core hours, a designated member of the engineering support team will still be alerted of the issue and will begin working on resolving it immediately.
DrDoctor has a live, 24/7 dashboard showcasing disruption or service degradation over the last seven days, including uptime percentage and downtime in minutes. It covers a variety of areas within DrDoctor such as the website and gateway endpoint. Each area can be drilled down further to show graphs on uptime and response time. This is accessible via the internet for the public to view and monitored by an external third party.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- Partial obfuscation, scale and only presenting information where necessary to users with elevated permissions. All access activities are auditable. Role-based access allows traceability and permission levels to be set for the users across the DrDoctor platform. System Administrators have the permissions to manage the access and addition of unlimited numbers of other staff users. During implementation, DrDoctor carries out role-based user training for each client and advanced superuser training for key individuals supporting the scaling processes.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Other
- Description of management access authentication
- Azure Virtual Desktop service is used in preference to a VPN, since it does not expose any ports externally, and applies Entra MFA controls on every log in.
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
-
Compliant with:
•NHS Data Security and Protection Toolkit – Exceeded Standards (Org code 8HY91)
•DTAC
•GDPR/UK Data Protection Act, ICO number (Z3313550).
•Compliant with NHS Standard DCB0129
•Dedicated IG Lead/Data Protection Officer
•ISO 27001 - Information security policies and processes
-
DrDoctor is compliant with the ISO27001 standard and has multiple information security policies and processes. We also have a legal and risk register to ensure the company is consistently aware of threats and risks that could impede the business. The Information Governance and Security Policy outlines many processes. We have an information governance team that reviews these policies at least annually and we perform internal audits provided by an external source. Data quality and accuracy is the responsibility of all employees, and every effort must be made to ensure the integrity of data whether it be collection of or inputting data. DrDoctor follow an incident management process that all employees are aware of and is covered in regular and onboarding training. DrDoctor are compliant with:
• NHS Data Security and Protection Toolkit – Standards Exceeded (Org code 8HY91)
• GDPR/UK Data Protection Act, ICO registration number (Z3313550). • NHS Standard DCB0129
• Access to Health Records Act 1990;
• Human Rights Act 1998;
• The Health Service (Control of Patient Information) Regulations 2002
• NHS Records Management Code of Practice 2023
• Data Protection legislation (Data Protection Act 2018/ UK GDPR)
• Common Law Duty of Confidentiality - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
DrDoctor engineers complete an Architectural Decision Records for significant architectural and infrastructure changes. Those changes are implemented using Infrastructure As Code (IaC) tools, which are stored centrally in our version control system (VCS). The VCS ensures changes are peer-reviewed, versioned and traceable.
Infrastructure is continuously monitored using Microsoft Defender for Cloud against the Microsoft Cloud Security Benchmark, a set of prescriptive best practices and recommendations assuring infrastructure security.
Other configuration/change management processes around potential security impacts include:
- risk assessments, the impact and benefit to wider systems and clinical safety reviews
-potential security impact assessments are considered throughout their lifetime - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
DrDoctor uses automated scanning to identify security vulnerabilities, allowing for notifications when vulnerabilities are identified:
• Synk
• Rennovate
• Pen Tests
• Static code analysis tools
• Azure tools
DrDoctor uses Common Vulnerability Scoring System to prioritise vulnerabilities and the different severities have the following timelines to fix:
• Critical (CVSS score >9.0) – 2 business days
• High (CVSS score 7.0-8.9) - < 4 weeks
• Medium (CVSS score 4.0-6.9) - < 6 weeks
• Low (CVSS score 0.1-3.19) – No timeline
For beta products these will be brought under the same level of commitment/processes in time. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- DrDoctor makes use of built-in Azure monitoring capabilities as well as Datadog and Splunk to identify potential compromises. Microsoft has a global, 24/7 incident response service that works to mitigate the effects of attacks and malicious activity. The incident response team follows established procedures for incident management, communication, and recovery, and uses discoverable and predictable interfaces with internal and external partners alike. The time that incidents are responded to is based on severity levels.
- Incident management type
- Supplier-defined controls
- Incident management approach
- DrDoctor’s Incident Management Policy clearly outlines processes for incident management. DrDoctor has logging, monitoring and alerting in place and our on-call engineering team are notified of any downtime as soon as it occurs so that the incident response team can be mobilised. Uptime status and incident reports can be viewed in a public dashboard at status.drdoctor.co.uk. Users can report an incident via the DrDoctor Support Desk via phone, live chat or email. Our SLAs are available on the DrDoctor website, outlining response times for incidents. Organisations will be notified in advance of any planned maintenance to prevent downtime.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
-
- Health and Social Care Network (HSCN)
- Other
- Other public sector networks
- NHS Network (N3)
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Alcumus ISOQAR
- ISO/IEC 27001 accreditation date
- Friday 21 June 2024
- What the ISO/IEC 27001 doesn’t cover
- - our Care Hub solution is not yet covered
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Aebfce95-7bf9-40ae-bea7-07768e048108
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- D6bc5659-bd6c-43f6-8d0b-11b3bc25d1a5
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-