CardMedic Connect
CardMedic provides a safe way of bridging healthcare communication barriers with patients and service users. CardMedic includes a portal to live interpreters and translation services, and a digital library of pre-scripted, pre-translated content replicating clinical conversations. Users can 'flex' CardMedic scripts to multiple languages, read-aloud, 'easy read' and BSL.
Features
- In-app single-click portal to live interpreters
- Live translation service
- Device agnostic, mobile and web
- Language service provider agnostic
- All content pre-scripted, validated and translated
- Includes Easy Read, Read Aloud, and Sign Language
- Always on
- Offline mode
- Telephone, video and F2F appointment booking
- Runs on Spark bedside devices
Benefits
- Improve patient outcomes
- Improve patient safety
- Improve health equity
- Reduce delays caused by communication barriers
- Reduce costs of language service provision
- Reduce risk of misdiagnosis and mistreatment
- Improve medication compliance
- Reduce risk of litigation
- Enable channel-shift from analogue to digital
- Ensure best value for money when using interpreters
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
6 0 7 2 5 0 4 5 8 9 0 8 7 4 2
Contact
CARD MEDIC LIMITED
Tim Grimaldi
Telephone: (01865) 570428
Email: contact@cardmedic.com
About your service
- Service categories
-
Applications
Content workflow and management
- Document
Content services
- Content Sharing and Collaboration Applications
Persuasive content management
- Video Platforms
- Digital Adoption Platform
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- The Platform is designed to be operational 24 hours a day, 365 days a year and, as such, can be fully utilized outside of the designated business hours. Card Medic Ltd will notify the Customer 48 hours prior to any planned downtime. Note that software releases do not require downtime and as such this would only happen in exceptional circumstances.
- System requirements
-
- Supported operating systems must be up to date
- Supported browsers must be up to date
- Firewall configuration may need to permit VoIP for Call function
- Devices used for Call function require microphone and speaker
User support
- Email or online ticketing support
- Yes
- Support response times
- Contact with the support desk initially happens via email. Email confirmation of receipt is immediate. Each customer has a human counterpart at CardMedic who helps the customer to achieve success. Business hours are Monday to Friday from 0900-1700, excluding public holidays. Issues raised are triaged as Critical or Non-Critical. CardMedic confirms the category. Every effort will be made to resolve critical issues within the shortest possible timescale. Non-critical Issues are reviewed and prioritised by CardMedic Product owners. Resolution will become a part of a scheduled or unscheduled release.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes
- Support levels
-
Support levels are:
Tier 1 (Included in the standard subscription) Monday to Friday, 0900 – 1700
Tier 2 = Tier 1 plus weekends 0900 – 1700 (enterprise subscriptions only)
Tier 3 = Tier 2 plus 24 hours (enterprise subscriptions only)
Support level pricing is calculated as a percentage surcharge over the subscription price:
Tier 1 = 0%
Tier 2 = 100%
Tier 3 = 500%
All tiers provide email access. Tiers 2 and 3 provide telephone support. Each customer has a human counterpart at CardMedic who looks after the account and helps the customer to achieve success. - Support available to third parties
- No
Onboarding and offboarding
- Getting started
-
Our Client Success team works with new customers to take them from zero to fully live, working to the customer's project goals in terms of where to start deploying and how rapidly to scale. The model cascades train-the-trainer style deployment support via clinical champions in each new department or specialty as they come online with CardMedic.
We start with template project plans for the initial year, with weekly client engagement support meetings at the start and monthly by year end. The initial project lead on the customer side needs to be available for a minimum of 0.2 FTE (i.e. at least one day per week) before go-live, and minimum 0.1 FTE thereafter (half a day per week). The greater the commitment, the faster the deployment.
The CardMedic Client Success team supplies new customers with training, collaterals for training, artwork for comms support (posters, QR codes, demonstration videos, etc.).
Training and client engagement meetings can take place online or onsite, however they usually happen online. Visits onsite to support deployments with floor-walking to socialise the proposition (and to survey staff and patients, if appropriate) is a standard part of most engagements. - Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
-
- In-app access to Help/FAQ
- Video
- End-of-contract data extraction
- The customer-specific data processed by Card Medic Ltd (the Data Processor) consists of user registrations for all persons permitted by the customer to use CardMedic, and the analysis of all usage by those persons of the CardMedic system over the course of the contract. All data is accessible by the customer for viewing and extraction in near real time (to 04.00 GMT of the current day). Customers access their data via secure logins to a business intelligence dashboard. The customer’s account manager at Card Medic Ltd can also schedule the extraction of data. The end-of-contract data extraction follows the same processes.
- End-of-contract process
- CardMedic operates in two primary modes: paid, and unpaid. The paid for mode enables subscribing customers to have access to the full content library, the Call function for live interpreters, and support for client engagement. The unpaid mode allows unsupported access to a limited content library. The end-of-contract process for CardMedic changes the permissions for all users registered with the customer from paid to unpaid, thus restricting the access by those users to unsupported access to a limited content library. For the Data Controller, the process may (optionally) incur an extra step of removing the app (or access to the app) from staff devices, and managing access via single sign on administration. Prior to taking this step, the Data Controller should alert all staff via communications that CardMedic will no longer be available. This communication step is in the interests of clinical safety as staff who have come to rely on CardMedic need to know that they will no longer be able to. There are no costs associated with the end-of-contract process.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
CardMedic is distributed as a Flutter application for Flutter web,
Android, and iOS platforms. Functionally all platforms are identical (UX/UI reflects the platform) with one difference: the mobile app works offline, the web app does not. In offline mode, only previously downloaded content will be available. - Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- CardMedic contains a content library of scripts replicating conversations between staff and patients or service users in healthcare settings. These scripts are presented as digital ‘flashcards’ (“Cards”). Users find cards via A-Z index, Search, and their Favourites folder. To bridge communication barriers, users navigate to the appropriate card and then ‘flex’ the card to use the content as appropriate: another language, read aloud, Easy Read, BSL. The service interface provides top level access to Cards, Favourites, Chat (live translate), Call (live interpreter), Introduce Me and Help/FAQs. The default interface provides the view of Cards.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
Gathering user feedback from patients, carers and staff has been essential in the development and reiterations of the CardMedic platform. CardMedic has worked closely with Alzheimer’s Society, Parkinson’s UK, Headway (acquired brain injuries), Include.org, clinical advisors from The Royal College of Speech and Language Therapists, and learning disabilities charities to host user experience focus groups to explore patients’ and carers’ thoughts, ideas, concerns, expectations and feedback.
An independent academic service evaluation by the University of Brighton and University Hospitals Sussex NHS Foundation Trust demonstrated significantly increased patient confidence from 67% to 95%. Results are likely significantly higher for those that are unwell, or with additional communication needs.
A PhD research project conducted by Dr Leslie Bright at Miami University explored the transformative impact of CardMedic on patient satisfaction by deploying CardMedic as an accessible, user-friendly and efficient mobile application for medical translation during urgent care visits.
The study found that CardMedic significantly increases patient satisfaction and experience scores (p = 0.001), enabling staff to strive for excellence in patient communication and improve outcomes. All areas of patient satisfaction showed marked improvement with the use of CardMedic. - API
- Yes
- What users can and can't do using the API
- CardMedic has APIs for content (cards), live translation, and the Call function. The content and Call function APIs enable CardMedic to serve content in language variations to other technologies on request, and to enable those technologies to digitally connect with Language Service Providers, thereby supporting the accessible information standards requirements of those technologies and providing access to live interpreters when needed. The live translation API connects CardMedic with appropriate AWS and Microsoft Azure services. The APIs are not publicly available, but access may be requested. The APIs enable commercially supported integrations to be developed with business partners providing complementary services such as digital consenting for healthcare procedures.
- API documentation
- No
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
-
The CardMedic content library is constantly growing at the behest of customers who need content not currently in the library to help them bridge communication barriers. There is a content creation, modification and review process shared with all customers. This allows customers to collaborate in the development of the most needed content. Where new content is generally applicable, it is made available in all the supported languages for all customers.
The content library can also be customised for individual customers. This allows CardMedic to contain scripts that are specific to the customer and exclusively visible to that customer. It is possible for CardMedic to create the customer-specific version of the content library on behalf of the customer. It is not currently possible for customers themselves to directly edit the content library, however.
Scaling
- Independence of resources
- CardMedic is built on a scalable AWS platform using AWS core services, including Cognito security management integrated with NHS SSO infrastructure. This scalability allows CardMedic to increase the user base quickly without impacting performance.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
The metrics describe user registrations, and the usage by those users of the CardMedic system over the course of the contract. Leadership boards and graphical KPIs support the metrics.
Users:
- name
- role
- email address
- create date
- account
- location
Usage (time-stamped access to cards):
- user
- categories and instances of cards
- translations
- read aloud
- easy read
- sign language
Usage (access to live interpreters):
- start time
- elapsed time
- language
- language service provider (LSP)
- LSP access details
- completion success - Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
- Physical access control, complying with SSAE-18 / ISAE 3402
- Data sanitisation process
- No
- Equipment disposal approach
- In-house destruction process
Data importing and exporting
- Data export approach
- All data is accessible by the customer for viewing and extraction in near real time (to 04.00 GMT of the current day). Customers access their data via secure logins to a business intelligence dashboard where all their data is visible. The dashboard supports filtering and sorting functions. Extraction is achieved by exporting the currently selected or filtered data to PDF, CSV or XSLX format files. The customer’s account manager at Card Medic Ltd can also schedule the extraction of data.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- XSLX
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
Guaranteed availability for contractual purposes = 99.9%. The support desk (see responses in "User Support" section) is available to all customers in business hours. CardMedic is designed to be operational 24 hours a day, 365 days a year and, as such, can be fully utilized outside of the designated business hours. CardMedic is not a constituent part of a mission-critical service. In the event that the service becomes unavailable, acceptable workarounds exist for the functionality provided by CardMedic. Up-time at the time of writing in the past 12 months = 100%. Refunds are therefore not provided.
The CardMedic Connect service level agreement (SLA) provided to customers describes the access to support and maintenance personnel and systems, and the support levels provided, for the triaging and fixing of issues or product enhancement requests identified by customers. - Approach to resilience
- CardMedic is built on a scalable AWS platform using AWS core services, including Cognito security management integrated with NHS Single Sign On (SSO) infrastructure. The resilience of the datacentre setup relies on these core AWS services. More information is available on request.
- Outage reporting
- CardMedic alerts customers to any service updates, including disruption or outages, via email.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Other
- Other user authentication
- Users of CardMedic Connect can be granted access via the customer's single sign on (SSO) administration, and should also self-register. The unique user ID is associated with the successfully registered email address. Successful registration completes upon a successful email validation loop. All users registered to a customer are visible to the customer in the service metrics. When self-registering, non-work email addresses are blocked by default. A whitelisting service allows manual intervention for email domains and individual addresses, which is managed by the CardMedic account management team. When registration is managed via SSO, authentication of employees is wholly the customer's responsibility.
- Access restrictions in management interfaces and support channels
-
The management interface for CardMedic customers is provided through password-protected access to the service metrics dashboard. Access requires an AWS Quick Suite registration. Customers must nominate the user or users who will be permitted to access the dashboard on their behalf. Access is set up, monitored and managed by CardMedic on behalf of the customer, and each individual concerned is required to complete the AWS Quick Suite registration.
Support channels are managed person-to-person and typically involve email and telephone interactions. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- No audit information available
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
- NHS DSP Toolkit / Cyber Essentials
- Information security policies and processes
- Card Medic Ltd has an Information Governance policy framework designed to be inclusive of all CardMedic staff and roles. Security training begins with onboarding and continues throughout. Policies cover Data Protection, Data Quality, Data Security and Record Keeping.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Change management is driven through our Product Roadmap and development process. Any required change is risk assessed prior to entering development. Where potential threats are identified, a Penetration test will be conducted prior to release.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Any change to the business or product environment is assessed for potential threat prior to deployment.
Hot fix patches can be deployed within 24 hours, if the fix is to roll back to a prior release this can be conducted within a short timescale.
A technical and security risk assessment of every change is undertaken. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Possible compromises are escalated immediately to the Managing Director and the incident management process is followed.
- Incident management type
- Supplier-defined controls
- Incident management approach
-
Notified incidents are reported through a Support Desk and triaged. Depending on the triage outcome, the issue follows a standard prioritisation into the development team for investigation and resolution.
Users are requested to notify incidents via a dedicated support desk email address. Incidents are triaged as Critical, or Non-Critical. Appropriate response and best-effort solution times are defined in the support service SLA per category. Users are informed of the receipt, triage, and progress to solution, and may feedback. Release notes describe resolved issues. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
-
The free version ("CardMedic Lite") includes: Emergency Content; Multiple languages; Read-Aloud; Online & Offline Access; Sign Language; Easy Read; Integrated Translation Tool; Personalisation - Photo & Role; Content Upgrades.
Not included: Call function for live interpreters; non-Emergency content.
CardMedic Lite is not currently time limited.
(See https://www.cardmedic.com/plans/) - Link to free trial
- http://app.cardmedic.com/signup
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 15%
- Between £250,000 and £500,000
- 15%
- Between £500,001 and £1,000,000
- 15%
- Between £1,000,001 and £2,500,000
- 15%
- Between £2,500,001 and £5,000,000
- 15%
- Over £5,000,001
- 15%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 0ee49b74-2332-466f-b1c0-68ea565dc2c9
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
- Other security certifications
- Yes
- Any other security certifications
-
- DSPT (Data Security and Protection Toolkit)
- Data Protection Registration Certificate
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
-