iRefer
iRefer is a subscription-based, cloud-hosted digital reference service providing evidence-based radiology referral guidance. Accessible via web and mobile applications, it supports clinicians in selecting appropriate imaging investigations and meeting IR(ME)R requirements, without requiring integration with local electronic health record or ordering systems.
Features
- Evidence-based radiology referral guidance covering all major clinical scenarios
- Web and mobile applications with secure subscription-based access
- Search powered by Azure AI Search for fast, relevant results
- Relevance-based sorting using real world usage patterns
- Offline access to downloaded guidance on supported mobile devices
- Continuously updated guidelines reflecting latest evidence and practice
- Guidance includes radiation dose and modality considerations
- Accessible interface supporting screen readers, zoom and colour contrast
- Supports use without integration with local clinical systems
Benefits
- Helps clinicians find appropriate imaging guidance quickly and efficiently
- Supports compliance with IR(ME)R at point of referral
- Promotes evidence-based imaging decisions aligned with clinical best practice
- Reduces inappropriate or duplicate imaging requests
- Supports timely and appropriate diagnostic imaging decisions
- Supports avoidance of unnecessary ionising radiation exposure
- Supports efficient and appropriate use of imaging resources
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 2 7 1 8 5 4 1 3 3 5 2 4 0 1
Contact
THE ROYAL COLLEGE OF RADIOLOGISTS
Yash Chitale
Telephone: +44 20 7406 1713
Email: irefer@rcr.ac.uk
About your service
- Service categories
-
Applications
Content workflow and management
Content services
- Enterprise Content Management Applications
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- The service requires an internet connection for full functionality. Mobile applications support offline access to previously downloaded content. Planned maintenance may result in short periods of service unavailability, which are scheduled outside normal working hours where possible. The service is accessed via supported modern web browsers and mobile operating systems.
- System requirements
-
- Accessible via modern desktop, tablet and smartphone web browsers
- Available as native iOS and Android mobile applications
- Internet connection required for web-based access
- Authentication required to access the service
- Public internet access to service URLs required
- IOS 14 or later required for mobile app
- Mobile app requires iOS 14 or Android 11 and later
User support
- Email or online ticketing support
- Yes
- Support response times
- Support requests are handled via email during UK business hours, Monday to Friday, excluding public holidays. We aim to provide an initial response to support queries within one working day. Issues are triaged on receipt and progressed according to severity. Requests received outside business hours are responded to on the next working day
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- No
- Support levels
- The service includes a standard support level provided at no additional cost as part of the subscription. Support is delivered via email and phone during UK business hours, Monday to Friday, excluding public holidays. Queries and issues are triaged on receipt and responded to within one working day. There are no tiered support packages and no dedicated technical account manager or cloud support engineer provided as standard.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Users can get started using online guidance and documentation, including guidance on using the referral guidelines and tutorials for the mobile applications. Online demonstrations and training sessions are available on request at no additional cost to support organisational onboarding and user familiarisation.
- Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
- Users can access usage and analytics information via the web interface during the contract term. On request at contract end, usage reports can be provided in a standard electronic format. The service does not store patient data or user-generated clinical content.
- End-of-contract process
- All activities associated with contract expiry, including changes to user access and data extraction where applicable, are included in the contract price. There are no additional costs associated with the end-of-contract process.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The mobile and desktop services provide the same core clinical guidance functionality. The user interface is optimised for different screen sizes and touch interaction on mobile devices. Mobile applications support offline access to previously downloaded guidance following initial authentication and synchronisation while online. Some administrative features, such as analytics and account management, are limited to the web interface.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The service is accessed through a web-based user interface and native mobile applications for iOS and Android. Users interact with the service via a responsive interface designed for desktop, tablet and mobile devices, with consistent access to core clinical guidance functionality. The interface supports search, navigation, bookmarking and guideline sharing, with layouts optimised for different screen sizes and touch interaction on mobile devices.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- Accessibility considerations have been incorporated into the design and development of the service in line with WCAG 2.2 AA principles. Interface testing has been carried out internally by quality assurance engineers using assistive technologies such as screen readers, keyboard navigation and browser accessibility tools. User acceptance testing has also been undertaken to validate usability across supported devices and platforms. Formal third-party accessibility audits have not yet been completed, but accessibility testing forms part of ongoing development and quality assurance activities.
- API
- No
- Customisation available
- No
Scaling
- Independence of resources
- The service is hosted on a cloud infrastructure designed to scale to meet demand. Resources are provisioned and managed to support concurrent usage across organisations, with monitoring and capacity management in place to maintain performance. This ensures that increased demand from one group of users does not adversely affect the availability or performance experienced by other users.
Analytics
- Service usage metrics
- Yes
- Metrics types
- The service provides usage and engagement metrics via an analytics dashboard. Metrics include guideline views, most viewed guidelines, usage by category and subcategory, and activity over selectable date ranges. Metrics can be viewed at individual or organisational level, depending on user role. Additional usage metrics, such as user sessions, search activity and bookmarking events, can be provided on request. Service availability and uptime information can also be shared on request.
- Reporting types
-
- Real-time dashboards
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- Users can export usage and analytics data via a dedicated analytics interface within the service. Data can be filtered by selectable date ranges and is available at both individual and organisational levels, depending on user role and permissions. Reports can be downloaded directly from the interface in CSV format for offline analysis and reporting.
- Data export formats
- CSV
- Data import formats
- Other
- Other data import formats
- Not Applicable
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- Our service is hosted on Microsoft Azure using App Service in a production (Premium) tier. We target high availability in line with the underlying cloud provider’s SLA, which guarantees at least 99.95% uptime for Azure App Service. Availability is monitored, and we aim to minimise unplanned outages, excluding planned maintenance or events outside our control. If availability falls below the expected level, remedial actions and any service credits or refunds are considered in line with agreed contract terms.
- Approach to resilience
-
The service is hosted on Microsoft Azure and is designed to be resilient through the use of managed cloud infrastructure. Core components include Azure App Service and Azure SQL Database, both of which benefit from built-in high availability, monitoring, and automated backup capabilities.
Database backups are taken automatically and can be restored to a previous point in time in the event of data loss or corruption. Application deployments and source code are managed using Azure DevOps, with retention policies in place to support recovery of deployed releases if required.
Service health and availability are monitored, and the platform can be restored using backed-up resources in the event of an incident. Further technical detail can be provided on request. - Outage reporting
- Service outages or significant incidents are communicated to customers via email notifications. Internal monitoring and alerting are in place to detect issues promptly, and relevant updates are shared with affected customers as appropriate.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Other
- Other user authentication
- Users are authenticated using account-based credentials or federated identity providers. The service supports username and password authentication, as well as identity federation using single sign-on (including SAML-based SSO and supported social login providers). In addition, organisations may configure IP address–restricted access, allowing users accessing from approved IP ranges to be granted access under the organisation’s subscription without individual user accounts.
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is restricted to authorised staff only, based on role-based access control and least-privilege principles. Administrative access is limited to designated roles for specific functions, with additional security controls applied where appropriate. Access permissions are reviewed and managed to ensure that only approved personnel can administer systems or access sensitive operational and support functions.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
- Cyber Essentials Plus
- Information security policies and processes
-
We maintain a comprehensive set of information security policies that ensure strong governance, operational security, and regulatory compliance. Our approach aligns with GDPR requirements, particularly around data minimisation, privacy‑by‑design, lawful processing, and secure handling of personal data. We are certified to Cyber Essentials Plus (CE+), demonstrating robust technical controls, vulnerability management, and secure configuration across our environment. In addition, we loosely follow the Cyber Assessment Framework (CAF) to guide risk management, incident response planning, and resilience practices.
Information security oversight is provided by senior leadership, with the Information Security Manager responsible for coordinating policy implementation, conducting risk reviews, and escalating issues where appropriate. Policies are enforced through mandatory staff training, technical safeguards, access control measures, and continuous monitoring. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
The service is developed and maintained using defined configuration and change management processes. Source code, infrastructure configuration, and application components are version controlled and managed through a central repository. Deployed releases are tracked through pre-production and production environments.
Changes are planned, reviewed, and assessed prior to deployment, including consideration of potential security and availability impacts. Updates are deployed using controlled release processes, with the ability to roll back changes if required. Regular updates are made to improve functionality, security, and performance while minimising disruption to users. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Potential threats to the service are assessed through external penetration testing, internal security reviews, and monitoring of the underlying cloud platform. External vulnerability assessments are conducted at least annually by a CREST-certified provider, with findings prioritised and remediated based on risk.
Security patches and updates are deployed via a controlled pre-production process before release to production, with higher-risk issues addressed as a priority. Information about potential threats is obtained from penetration testing reports, cloud provider security notifications, security advisories from third-party platform components, dependency advisories, and general industry security guidance. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Protective monitoring is implemented through platform and application monitoring, logging, and alerting. Potential compromises are identified through automated alerts for abnormal behaviour, availability issues, and security-related events, supported by review of logs and monitoring data.
When a potential compromise is identified, alerts are reviewed and investigated promptly to assess impact and determine appropriate remediation actions. Incidents are responded to during UK business hours, with higher-risk issues prioritised and escalated as required to restore service and address root causes. - Incident management type
- Supplier-defined controls
- Incident management approach
-
The organisation operates defined incident management processes for common events such as service outages, performance degradation, and security issues. Incidents may be identified through monitoring and alerting or reported by users via email or phone.
Reported incidents are logged, assessed, and prioritised based on impact and urgency. Customers are kept informed of progress as appropriate, and incident summaries or reports can be provided on request following resolution. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- The service provides a free tier available on sign-up, with no time limit. The free tier includes access to a limited set of guidelines, core navigation, and search functionality. Features such as bookmarking, guideline sharing, and access to the full guideline library are not included and require a paid subscription.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 19771446-7748-4721-9d42-99efe373114b
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 1357d567-ce40-4db2-b802-f8dfccb06776
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
-