Skip to main content

Help us improve the Digital Marketplace - send your feedback

THE ROYAL COLLEGE OF RADIOLOGISTS

iRefer

iRefer is a subscription-based, cloud-hosted digital reference service providing evidence-based radiology referral guidance. Accessible via web and mobile applications, it supports clinicians in selecting appropriate imaging investigations and meeting IR(ME)R requirements, without requiring integration with local electronic health record or ordering systems.

Features

  • Evidence-based radiology referral guidance covering all major clinical scenarios
  • Web and mobile applications with secure subscription-based access
  • Search powered by Azure AI Search for fast, relevant results
  • Relevance-based sorting using real world usage patterns
  • Offline access to downloaded guidance on supported mobile devices
  • Continuously updated guidelines reflecting latest evidence and practice
  • Guidance includes radiation dose and modality considerations
  • Accessible interface supporting screen readers, zoom and colour contrast
  • Supports use without integration with local clinical systems

Benefits

  • Helps clinicians find appropriate imaging guidance quickly and efficiently
  • Supports compliance with IR(ME)R at point of referral
  • Promotes evidence-based imaging decisions aligned with clinical best practice
  • Reduces inappropriate or duplicate imaging requests
  • Supports timely and appropriate diagnostic imaging decisions
  • Supports avoidance of unnecessary ionising radiation exposure
  • Supports efficient and appropriate use of imaging resources

Pricing

  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at irefer@rcr.ac.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

5 2 7 1 8 5 4 1 3 3 5 2 4 0 1

Contact

THE ROYAL COLLEGE OF RADIOLOGISTS Yash Chitale
Telephone: +44 20 7406 1713
Email: irefer@rcr.ac.uk

About your service

Service categories

Applications

Content workflow and management

Content services

  • Enterprise Content Management Applications
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
The service requires an internet connection for full functionality. Mobile applications support offline access to previously downloaded content. Planned maintenance may result in short periods of service unavailability, which are scheduled outside normal working hours where possible. The service is accessed via supported modern web browsers and mobile operating systems.
System requirements
  • Accessible via modern desktop, tablet and smartphone web browsers
  • Available as native iOS and Android mobile applications
  • Internet connection required for web-based access
  • Authentication required to access the service
  • Public internet access to service URLs required
  • IOS 14 or later required for mobile app
  • Mobile app requires iOS 14 or Android 11 and later

User support

Email or online ticketing support
Yes
Support response times
Support requests are handled via email during UK business hours, Monday to Friday, excluding public holidays. We aim to provide an initial response to support queries within one working day. Issues are triaged on receipt and progressed according to severity. Requests received outside business hours are responded to on the next working day
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
No
Support levels
The service includes a standard support level provided at no additional cost as part of the subscription. Support is delivered via email and phone during UK business hours, Monday to Friday, excluding public holidays. Queries and issues are triaged on receipt and responded to within one working day. There are no tiered support packages and no dedicated technical account manager or cloud support engineer provided as standard.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Users can get started using online guidance and documentation, including guidance on using the referral guidelines and tutorials for the mobile applications. Online demonstrations and training sessions are available on request at no additional cost to support organisational onboarding and user familiarisation.
Service documentation
Yes
Documentation formats
HTML
End-of-contract data extraction
Users can access usage and analytics information via the web interface during the contract term. On request at contract end, usage reports can be provided in a standard electronic format. The service does not store patient data or user-generated clinical content.
End-of-contract process
All activities associated with contract expiry, including changes to user access and data extraction where applicable, are included in the contract price. There are no additional costs associated with the end-of-contract process.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The mobile and desktop services provide the same core clinical guidance functionality. The user interface is optimised for different screen sizes and touch interaction on mobile devices. Mobile applications support offline access to previously downloaded guidance following initial authentication and synchronisation while online. Some administrative features, such as analytics and account management, are limited to the web interface.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
The service is accessed through a web-based user interface and native mobile applications for iOS and Android. Users interact with the service via a responsive interface designed for desktop, tablet and mobile devices, with consistent access to core clinical guidance functionality. The interface supports search, navigation, bookmarking and guideline sharing, with layouts optimised for different screen sizes and touch interaction on mobile devices.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
Accessibility considerations have been incorporated into the design and development of the service in line with WCAG 2.2 AA principles. Interface testing has been carried out internally by quality assurance engineers using assistive technologies such as screen readers, keyboard navigation and browser accessibility tools. User acceptance testing has also been undertaken to validate usability across supported devices and platforms. Formal third-party accessibility audits have not yet been completed, but accessibility testing forms part of ongoing development and quality assurance activities.
API
No
Customisation available
No

Scaling

Independence of resources
The service is hosted on a cloud infrastructure designed to scale to meet demand. Resources are provisioned and managed to support concurrent usage across organisations, with monitoring and capacity management in place to maintain performance. This ensures that increased demand from one group of users does not adversely affect the availability or performance experienced by other users.

Analytics

Service usage metrics
Yes
Metrics types
The service provides usage and engagement metrics via an analytics dashboard. Metrics include guideline views, most viewed guidelines, usage by category and subcategory, and activity over selectable date ranges. Metrics can be viewed at individual or organisational level, depending on user role. Additional usage metrics, such as user sessions, search activity and bookmarking events, can be provided on request. Service availability and uptime information can also be shared on request.
Reporting types
  • Real-time dashboards
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
Deleted data can’t be directly accessed / Cryptographic Erasure

Data importing and exporting

Data export approach
Users can export usage and analytics data via a dedicated analytics interface within the service. Data can be filtered by selectable date ranges and is available at both individual and organisational levels, depending on user role and permissions. Reports can be downloaded directly from the interface in CSV format for offline analysis and reporting.
Data export formats
CSV
Data import formats
Other
Other data import formats
Not Applicable

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Our service is hosted on Microsoft Azure using App Service in a production (Premium) tier. We target high availability in line with the underlying cloud provider’s SLA, which guarantees at least 99.95% uptime for Azure App Service. Availability is monitored, and we aim to minimise unplanned outages, excluding planned maintenance or events outside our control. If availability falls below the expected level, remedial actions and any service credits or refunds are considered in line with agreed contract terms.
Approach to resilience
The service is hosted on Microsoft Azure and is designed to be resilient through the use of managed cloud infrastructure. Core components include Azure App Service and Azure SQL Database, both of which benefit from built-in high availability, monitoring, and automated backup capabilities.

Database backups are taken automatically and can be restored to a previous point in time in the event of data loss or corruption. Application deployments and source code are managed using Azure DevOps, with retention policies in place to support recovery of deployed releases if required.

Service health and availability are monitored, and the platform can be restored using backed-up resources in the event of an incident. Further technical detail can be provided on request.
Outage reporting
Service outages or significant incidents are communicated to customers via email notifications. Internal monitoring and alerting are in place to detect issues promptly, and relevant updates are shared with affected customers as appropriate.

Identity and authentication

User authentication needed
Yes
User authentication
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
  • Other
Other user authentication
Users are authenticated using account-based credentials or federated identity providers. The service supports username and password authentication, as well as identity federation using single sign-on (including SAML-based SSO and supported social login providers). In addition, organisations may configure IP address–restricted access, allowing users accessing from approved IP ranges to be granted access under the organisation’s subscription without individual user accounts.
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is restricted to authorised staff only, based on role-based access control and least-privilege principles. Administrative access is limited to designated roles for specific functions, with additional security controls applied where appropriate. Access permissions are reviewed and managed to ensure that only approved personnel can administer systems or access sensitive operational and support functions.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
Other
Other security governance standards
Cyber Essentials Plus
Information security policies and processes
We maintain a comprehensive set of information security policies that ensure strong governance, operational security, and regulatory compliance. Our approach aligns with GDPR requirements, particularly around data minimisation, privacy‑by‑design, lawful processing, and secure handling of personal data. We are certified to Cyber Essentials Plus (CE+), demonstrating robust technical controls, vulnerability management, and secure configuration across our environment. In addition, we loosely follow the Cyber Assessment Framework (CAF) to guide risk management, incident response planning, and resilience practices.
Information security oversight is provided by senior leadership, with the Information Security Manager responsible for coordinating policy implementation, conducting risk reviews, and escalating issues where appropriate. Policies are enforced through mandatory staff training, technical safeguards, access control measures, and continuous monitoring.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
The service is developed and maintained using defined configuration and change management processes. Source code, infrastructure configuration, and application components are version controlled and managed through a central repository. Deployed releases are tracked through pre-production and production environments.

Changes are planned, reviewed, and assessed prior to deployment, including consideration of potential security and availability impacts. Updates are deployed using controlled release processes, with the ability to roll back changes if required. Regular updates are made to improve functionality, security, and performance while minimising disruption to users.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Potential threats to the service are assessed through external penetration testing, internal security reviews, and monitoring of the underlying cloud platform. External vulnerability assessments are conducted at least annually by a CREST-certified provider, with findings prioritised and remediated based on risk.

Security patches and updates are deployed via a controlled pre-production process before release to production, with higher-risk issues addressed as a priority. Information about potential threats is obtained from penetration testing reports, cloud provider security notifications, security advisories from third-party platform components, dependency advisories, and general industry security guidance.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Protective monitoring is implemented through platform and application monitoring, logging, and alerting. Potential compromises are identified through automated alerts for abnormal behaviour, availability issues, and security-related events, supported by review of logs and monitoring data.

When a potential compromise is identified, alerts are reviewed and investigated promptly to assess impact and determine appropriate remediation actions. Incidents are responded to during UK business hours, with higher-risk issues prioritised and escalated as required to restore service and address root causes.
Incident management type
Supplier-defined controls
Incident management approach
The organisation operates defined incident management processes for common events such as service outages, performance degradation, and security issues. Incidents may be identified through monitoring and alerting or reported by users via email or phone.

Reported incidents are logged, assessed, and prioritised based on impact and urgency. Customers are kept informed of progress as appropriate, and incident summaries or reports can be provided on request following resolution.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
The service provides a free tier available on sign-up, with no time limit. The free tier includes access to a limited set of guidelines, core navigation, and search functionality. Features such as bookmarking, guideline sharing, and access to the full guideline library are not included and require a paid subscription.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
19771446-7748-4721-9d42-99efe373114b
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
1357d567-ce40-4db2-b802-f8dfccb06776
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at irefer@rcr.ac.uk. Tell them what format you need. It will help if you say what assistive technology you use.