Skip to main content

Help us improve the Digital Marketplace - send your feedback

CONCENTRIC HEALTH LTD

Concentric

Concentric is a digital consent to treatment (econsent) application supporting the informed consent process. Used trust-wide across over 35 NHS Trusts, it supports cross-specialty use, provides evidence-based consent templates, and integrates with other clinical systems, enabling clinicians to create, personalise and document consent, and patients to review and provide consent.

Features

  • Proven digital consent application used organisation-wide by over 25,000 clinicians
  • 3,000+ clinician-authored, evidence-based consent templates with PIF TICK governance
  • Clinician personalisation supporting Montgomery-compliant informed consent
  • Supports adult, paediatric, and capacity-based consent workflows
  • Remote patient review and consent with accessible text and illustrations
  • HL7 and FHIR EPR/TIE integrations for demographics, documents, context launch
  • Single sign-on (SSO) via Entra ID, NHS.net Connect, CIS2
  • Role-based access for clinicians, read-only users, and administrators
  • Tamper-detectable audit trail of patient and clinician actions
  • NHS DTAC, DSPT, Cyber Essentials Plus; DCB0129 compliant

Benefits

  • Improve consent documentation quality, legibility, and completeness
  • Enable two-stage consent and patient understanding through remote information review
  • Enhance shared decision-making through personalised, accessible consent information
  • Reduce consent-related medicolegal risk through consistent, auditable consent records
  • Prevent lost/unavailable consent forms through digital access and integration
  • Day-of-treatment delays linked to consent issues reduced
  • Deliver whole-pathway cost and carbon efficiencies from year one
  • Save clinician and administrative staff time managing consent processes
  • Support safer site and procedure confirmation through structured, legible consent
  • Achieve organisation-wide digital consent adoption with a proven implementation approach

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at hello@concentric.health. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

6 0 2 3 0 2 8 6 0 3 4 9 3 2 9

Contact

CONCENTRIC HEALTH LTD Concentric's support team
Telephone: +44 2922 947532
Email: hello@concentric.health

About your service

Service categories

Applications

Content workflow and management

Content services

  • Enterprise Content Management Applications
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
Concentric is delivered as a cloud-based service and does not require scheduled downtime for routine updates. Maintenance and updates are typically deployed without service interruption. On rare occasions where disruption is unavoidable, advance notice is provided. There are no material service constraints beyond standard system and connectivity requirements.
System requirements
  • Modern supported web browser, per published browser support policy
  • Internet connectivity suitable for secure web application access

User support

Email or online ticketing support
Yes
Support response times
Concentric responds to support queries within one working day, Monday to Friday. Queries received at weekends or public holidays are responded to on the next working day. Emergency technical support contact details are provided to buyers and can be contacted 24/7/365 for critical incidents.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
A single standard support level is included within the service. Support is delivered by the Concentric support team, with access to clinical, technical, and delivery specialists as required. There are no additional charges for standard support.

Support requests are logged via email and prioritised according to severity. Critical incidents are handled urgently in line with published support processes. Emergency technical support contact details are provided to buyers and can be contacted 24/7/365 for critical incidents.

During implementation and transition to business as usual, buyers are supported by named Concentric delivery contacts. Ongoing technical and application support continues as part of standard BAU support.

Service availability is monitored against a 99.95% service level objective. Planned maintenance and any service disruption are communicated in advance and recorded via the public service status page.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Clinician users are supported to start using the service through a structured implementation and onboarding approach, supported by Concentric Health’s delivery playbook (https://concentric.health/deployment/delivery-playbook/
). The delivery playbook provides project management guidance, clinician-facing resources, technical and integration documentation, and examples of good practice.

Clinician onboarding is supported by a combination of tailored resources and a train-the-trainer approach, enabling local deployment teams and clinical champions to support adoption alongside the provided materials. Onboarding resources include role-specific text and video user guides, information on local processes and integrations, and support details. Train-the-trainer sessions for deployment teams and clinical champions are delivered by the Concentric clinical operations team, generally remotely.

Project and service desk teams have direct access to the Concentric Health support team for the duration of the service.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
Concentric Health manages end-of-contract arrangements through a defined offboarding process (https://concentric.health/deployment/delivery-playbook/offboarding-plan/), which outlines how data access, retention, extraction, and deletion are handled in line with the buyer’s responsibilities as the data controller.

The recommended offboarding option is to retain data within Concentric under a legacy data processing agreement, which supports the buyer’s clinical, medicolegal, and records management requirements. In this scenario, access to the complete consent record, including lay descriptions and the audit trail, is preserved on a read-only basis at no cost, in line with agreed terms. Clinical data retention periods continue to be determined by the buyer in accordance with applicable health records guidance, local retention schedules, and Concentric Health’s data retention policy (https://concentric.health/standards-policies/data-retention-policy/).

Where data transfer is required, Concentric Health supports the secure return of tenant-level data. This consists of a raw database extract containing tenant-specific data, including the audit trail, and a final consent summary PDF for each episode in which a consent event has occurred. Following completion of data transfer, tenant-level data is permanently deleted from Concentric Health systems, and the buyer becomes the sole custodian of the transferred data assets.
End-of-contract process
Concentric Health manages end-of-contract arrangements through a defined offboarding process (https://concentric.health/deployment/delivery-playbook/offboarding-plan/). This begins with a preparation and communication phase to agree on the offboarding plan, including activities, responsibilities, dependencies, and key dates, and to communicate this to relevant stakeholders. This is followed by an operational transition phase, during which organisations move away from using Concentric as the default mechanism for recording consent and transition to their replacement process, typically stopping the creation of new consent episodes while allowing completion of episodes already started. A data retention approach is then confirmed, either continued read-only retention under a legacy data processing agreement (the recommended option) or secure return of tenant-level data and deletion. Integration decommissioning is planned after the operational transition and depends on the chosen data retention approach and local integrations.

The contract price includes the standard offboarding activities set out in the offboarding plan, including planning and coordination, support for the recommended legacy data processing agreement option, and a standard tenant-level data return where data transfer is required. Additional costs would apply only where buyers request support beyond the documented offboarding process.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The service is delivered through a responsive web interface and is accessible on desktop and mobile devices. Core functionality is consistent across form factors. Hardware signature pads are an optional signing method, supported on desktop browsers only, and are not required for the end-to-end consent workflow.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
The service includes a web-based support interface. Authorised buyer users can submit, view, and interact with support tickets for their organisation.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
Accessibility testing and assistive technology compatibility are undertaken by the support interface provider. Concentric monitors usability in practice and responds to accessibility issues raised by users.
API
Yes
What users can and can't do using the API
The service exposes standards-based interfaces to support integration with other clinical systems. This includes HL7 and FHIR interfaces for exchanging patient demographics and consent documentation.

Authentication and access are supported via standards-based identity protocols, including OpenID Connect, enabling single sign-on with NHS identity services. Patient-context launch is supported through agreed URL-based launch mechanisms rather than API configuration.

Buyers do not set up or configure the service directly through APIs. Initial configuration and integration are delivered by Concentric during implementation, working with the buyer’s technical teams.

Ongoing changes to integrations are managed through agreed change processes. Interfaces are not provided for general service administration or unrestricted third-party development.

Integration approaches and technical details are documented at https://concentric.health/deployment/technical/integration/.
API documentation
Yes
API documentation formats
  • HTML
  • PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
The service can be customised to reflect organisational requirements while maintaining clinical, information, and security governance. Customisation is available across identity and access settings, integrations, content governance, and reporting.

Designated organisational administrators define organisation-level requirements, including identity provider selection for single sign-on, session timeout and expiry parameters, and links to organisation-managed information for both patient and clinician users. These settings are configured by Concentric Health in line with agreed requirements.

Integration configuration is agreed upon during implementation. Buyers can specify which patient identifiers to display and which metadata to pass with consent documents to support downstream processing. These configurations are implemented and managed by Concentric Health in collaboration with the buyer’s technical teams.

Consent templates are governed by Concentric Health through a defined clinical and content governance process, using an evidence-based ontology to ensure consistency, version control, and auditability. Buyers can request updates through a defined governance process, described at https://concentric.health/deployment/delivery-playbook/consent-template-updates/. Organisations can link to locally managed patient information resources and content libraries to supplement Concentric-provided content.

Reporting dashboards and queries are configured by Concentric Health based on buyer requirements. Additional reporting views can be requested where required.

Scaling

Independence of resources
Concentric is delivered as a multi-tenant Software-as-a-Service hosted on Google Cloud infrastructure. The service is designed to ensure that demand from one organisation doesn't adversely affect others. Application components are monitored continuously and scale horizontally in response to demand, with capacity managed to maintain performance.

Concentric operates the service with planned resource headroom and uses automated scaling and monitoring to provide early warning of increased load. Demand patterns for digital consent are predictable, with usage typically aligned to planned clinical activity, allowing capacity to be managed proactively. Performance and availability are centrally monitored, with alerts enabling timely intervention when required.

Analytics

Service usage metrics
Yes
Metrics types
Concentric provides service usage metrics through an administrator application. Designated users can view organisational usage, including recent activity and trends over time, usage by specialty and procedure, clinician-level usage patterns, episode volumes, in-application patient feedback, and lists of users with access.

Metrics support operational oversight, adoption monitoring, and governance. Administrators can export data underpinning dashboards, charts, and episode lists in CSV, XLSX, or JSON formats for local reporting and analysis.

Further detail is provided in the administrator usage metrics guide: https://concentric.health/deployment/delivery-playbook/usage-metrics/.
Reporting types
Real-time dashboards
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Staff screening not performed
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
  • Other locations
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CHECK service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
Data Erasure

Data importing and exporting

Data export approach
Consent data is exported primarily through standard workflow integration as part of normal clinical use. Consent summary PDFs, together with associated metadata, are automatically sent to downstream systems, such as the EPR or an electronic document management system, via configured document integrations. Clinicians can also manually download consent summary PDFs directly from the application where required.

Designated administrative users can export raw data underpinning reporting dashboards and access audit trail information for individual consent episodes to support governance and reporting.

At contract end, tenant-level data export is supported through the defined offboarding process.
Data export formats
  • CSV
  • Other
Other data export formats
  • XLSX
  • JSON
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Concentric Health operates the service to a Service Level Objective (SLO) of 99.95% availability, equivalent to a maximum of 4.38 hours of unavailability per year. The service is designed to support near-zero downtime deployments, with planned releases typically delivered without interruption. On the rare occasions where this is not possible, any impact is managed and communicated in advance where practicable.

Service availability is monitored continuously. Current and historical availability, including incidents and planned maintenance, is published transparently on the public status page at https://concentric.statuspage.io/.

Concentric Health does not operate a financial credit or refund mechanism linked to availability. Availability commitments are managed through the published SLO, proactive monitoring, incident management, and transparent reporting.
Approach to resilience
Concentric is delivered as a multi-tenant Software as a Service hosted on Google Cloud infrastructure and is designed for high resilience and availability. The service is architected to tolerate individual component and server failures through automated monitoring, restart, and failover mechanisms, aiming to minimise disruption to users. For typical single-component failures, this design is intended to result in only short periods of unavailability. Deployments are designed to support near-zero downtime, and the service does not require routine scheduled maintenance.

Data recovery processes are in place for more severe scenarios. Database backups are taken regularly and retained for 28 days, and write-ahead log archiving supports point-in-time recovery for up to the previous 7 days. Infrastructure is managed using configuration and automation tooling to support restoration if required.

Further details on the service’s resilience and failure-handling approach are published at https://concentric.health/deployment/technical/technical-details/#resilience-to-failures.
Outage reporting
Service availability and incidents are reported via a public status page at https://concentric.statuspage.io/. The status page provides real-time information on incidents, maintenance, and historical availability. Users can subscribe to email alerts to receive notifications and updates for any incidents published on the status page.

The service is monitored continuously. When unavailability exceeds defined thresholds, alerts are automatically raised to the Concentric Health support team to initiate investigation and resolution. Buyer organisations are provided with operational and technical contact details, including an emergency technical contact route for use in the event of critical incidents.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Access to Concentric Health management interfaces is restricted by role and least-privilege principles. Access to security-sensitive operational systems is limited to authorised members of the technical team, requires multi-factor authentication, and is logged and auditable.

Buyer-facing administrative access within the application is controlled through role-based access controls and always requires multi-factor authentication. Only designated administrative users can access management functions.

Support tickets can be raised by users, but organisation-wide visibility and management of tickets is restricted to specified individuals nominated by the buyer, with access reviewed as part of normal service operation.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
Between 1 month and 6 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
Other
Other security governance standards
Cyber Essentials Plus, NHS Data Security and Protection Toolkit (DSPT), and NHS Digital Technology Assessment Criteria (DTAC).
Information security policies and processes
Information security governance at Concentric Health is overseen by the Chief Technical Officer and the Data Protection Officer, who are responsible for security policy, risk management, and incident response. Security risks and incidents are escalated through defined internal reporting and management processes.

Concentric Health maintains compliance with NHS and UK public sector information security requirements, including annual completion of the NHS Data Security and Protection Toolkit (DSPT) and Cyber Essentials Plus certification. Independent penetration testing is undertaken annually. Information security controls are supported by documented policies and procedures covering access control, incident management, data protection, supplier assurance, and secure development and operations. Compliance with NHS DCB0129 clinical safety standards is also maintained, with defined governance and assurance processes.

Policies are communicated and reinforced through staff onboarding and ongoing training. All staff complete mandatory annual data security awareness training, with completion monitored. Adherence to policies is supported through role-based access controls, operational procedures, monitoring, and regular review. Security policies and processes are reviewed and updated to reflect changes in risk, regulation, and service delivery.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Concentric Health operates documented configuration and change management processes covering application code, infrastructure configuration, and clinical content. Changes are tracked from request through development, testing, and versioned release. Releases undergo manual and automated testing and quality assurance of new and existing functionality, with release notes published following each release.

The potential impacts on information security, data protection, and clinical safety are assessed during the release process. Releases require Chief Technical Officer and Clinical Safety Officer approval prior to deployment. Deployment processes are designed to minimise risk and service disruption, with monitoring in place to identify and respond to post-release issues.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Concentric Health operates documented vulnerability management processes covering application code, infrastructure, and third-party dependencies. Potential threats are identified through automated vulnerability scanning, monitoring of security advisories, dependency update notifications, and annual independent penetration testing. Vulnerabilities may also be reported via responsible disclosure to security@concentric.health.

Infrastructure, base images, and application dependencies are kept up to date through regular patching and the standard release process. Security updates and patches are assessed, prioritised, and deployed based on risk, typically within two weeks or sooner where earlier action is required. Remediation is overseen by senior technical leadership.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Concentric Health operates protective monitoring processes to identify, investigate, and respond to potential security incidents. Application logs are collected centrally and monitored for unusual activity, including abnormal error rates, access patterns, and operational events. Alert thresholds are used to provide early warning of potential compromise.

When a potential security issue is identified, an alert is raised to the technical team. Incidents are assessed, contained, and remediated in line with defined incident management processes, with actions taken to limit impact and restore normal service operation.

The service is continuously monitored, with responses initiated promptly upon detection of a potential incident.
Incident management type
Supplier-defined controls
Incident management approach
Concentric Health operates defined incident management processes for common service and security events. The service is continuously monitored, with alerts automatically sent to the technical team when thresholds are exceeded. Pre-defined processes are used to assess and manage incidents based on severity.

Users report incidents via agreed channels provided to each buyer, including operational and technical contact routes. Emergency technical support is available for critical incidents.

Incident updates and service status are communicated via the public status page and email notifications where appropriate. Following significant incidents, investigation and root cause analysis are undertaken, with incident reports provided to affected buyers.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
93c6bed7-da3d-411a-8820-111854417644
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
0f635de7-55dc-4412-8381-064c370d68b9
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at hello@concentric.health. Tell them what format you need. It will help if you say what assistive technology you use.