Skip to main content

Help us improve the Digital Marketplace - send your feedback

DLS HEALTH LIMITED

MedsMarket - Pharmaceutical Purchasing Automation & Intelligence

Built for buyers, it brings all suppliers and wholesalers into a single interface. Search once to instantly see product availability and pricing, including contract pricing, across your approved suppliers. Integrates with pharmacy systems (EMIS and System-C) to provide deeper insights, improved purchasing control and support cost savings at your organisational.

Features

  • View pricing and availability across all connected suppliers
  • Consistent product results regardless of supplier source
  • Integration with pharmacy systems for deeper insights and proactive reporting
  • Pricing that reflects your account, region and applicable contract pricing
  • Live search results showing current supplier data
  • Search by product name, supplier code or EAN
  • Support for multiple users and organisational structures
  • Designed for NHS secondary care and contract-based procurement

Benefits

  • Reduce time spent sourcing medicines
  • Minimise supplier phone calls and emails
  • Order with confidence using visible stock levels
  • Compare products in a consistent, standardised view
  • Sort and prioritise results to match local purchasing preferences

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at hello@dlshealth.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

7 1 3 0 8 2 7 0 8 2 0 1 9 9 5

Contact

DLS HEALTH LIMITED David Page
Telephone: 07387116979
Email: hello@dlshealth.uk

About your service

Service categories

Applications

Production and operations

Service industry and public sector operations

  • Healthcare
  • Adult Social Care
  • Children's Social Care
  • Other
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
Buyers must already have established relationships with pharmaceutical wholesalers and suppliers. The service does not facilitate the creation or onboarding of new supplier accounts.
System requirements
  • Requires an internet connection
  • Requires modern browser (Safari, Chrome, Edge)
  • Requires a modern, supported, Windows based operating system

User support

Email or online ticketing support
Yes
Support response times
DLS Health provides email and phone support, Monday to Friday, 9am until 5pm, excluding bank and public holidays.

Although highly unlikely, if ever a customer wanted to consider extended weekday hours support or support at weekends or on holidays, we would be happy to discuss, but there may be additional charges.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
None or don’t know
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Any issues that need to be raised to the DLS Health support team can be made via email, or phone. When possible, we would encourage that email is used as this method logs a ticket directly to the DLS Health online support portal that is monitored regularly.

Upon logging an issue, this will automatically create a support ticket on the DLS Health support portal for the support team to confirm the severity, and review and resolve the issue. Upon investigation, any updates and resolution will be automatically emailed to the user that logged the issue.

Issues logged are categorised by their severity and impact on operations. This categorisation helps prioritise responses and allocate resources effectively. The categories range from P1 (highest priority) to P4 (lowest priority). Here’s a detailed description of each category:

P1 - Response within 1 hour, target resolution 4 hours or less
P2 - Response within 4 hours, target resolution 24 hours or less
P3 - Response within 6 hours, target resolution 2-3 days or less
P4 - Response within 2-3 days, no target resolution provided
Support available to third parties
Yes

Onboarding and offboarding

Getting started
We provide comprehensive support for the setup and configuration of the MedsMarket solution.
Implementation is delivered often through a combination of onsite and remote engagement, with full training and support provided to ensure a smooth deployment and maximum customer benefit.

Training is available through multiple formats, including in-person sessions, webinars, online documentation, video resources and in-application help features.

During and after go-live, hyper-care support is provided, including weekly review calls and dedicated support for initial users of the solution.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
DLS Health can provide data extracts in standard industry formats such as CSV and will work with customers and their new suppliers to ensure data continuity and prevent data loss.

We recognise our responsibility in maintaining healthcare continuity and will support customers transitioning to another supplier, working collaboratively to ensure patient care and operational services remain uninterrupted.
End-of-contract process
Ahead of contract expiry or upon customer termination, DLS Health will work with the customer to agree data extraction requirements and service termination dates. Reasonable efforts will be made to support data extraction and migration for example;

Providing data extracts in agreed formats, supporting clarification of data structures, and coordinating with the customer or appointed supplier within standard support hours.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
Yes
Compatible operating systems
Windows
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
We have built MedsMarket to be adaptive to the device it is being accessed from, so there are no differences in access.
Service interface
No
User support accessibility
WCAG 2.2 A
API
Yes
What users can and can't do using the API
Users can access our full API infrastructure, with optional machine-to-machine API authorisation issued by DLS Health.
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
  • PDF
API sandbox or test environment
No
Customisation available
No

Scaling

Independence of resources
MedsMarket is built on modern cloud services that automatically scale to meet user demand.

As usage increases, the platform automatically adjusts capacity in the background to maintain performance during periods of high activity, without manual intervention. Auto-scaling is enabled by default and operates without interrupting users.

The service operates in an active-active model across multiple cloud regions for resilience, with the same auto-scaling approach applied consistently in each region.

Analytics

Service usage metrics
Yes
Metrics types
Service metrics are available for usage and login activity within each organisation.
Reporting types
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure

Data importing and exporting

Data export approach
DLS Health can provide data extracts in industry standard formats such as csv
Data export formats
  • CSV
  • Other
Other data export formats
  • Csv
  • Json
  • Xml
Data import formats
  • CSV
  • Other
Other data import formats
  • Xml
  • Csv
  • Json
  • Other agreed formats

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Our platform is hosted on Amazon Web Services and is designed in line with AWS best practices.

We use managed platform services by default, removing the need to manage servers and improving the overall security and resilience of the platform. Our service level agreement provides 99.95% availability, excluding planned maintenance.

The platform is engineered for high availability within the UK and operates across multiple physical locations. It follows an active-active design, meaning services continue to operate even if a component fails, with little or no impact on customers.

In the event of a service failure, DLS Health operates a credit-based refund mechanism, as defined within the contract.
Approach to resilience
In line with AWS best practice and the shared responsibility model, our services operate across more than one physical location and can be tailored to meet specific customer requirements.

Due to tour security posture, detailed architectural information is only provided on request to support assurance and governance requirements.
Outage reporting
In the unlikely event of a platform outage, and in line with our incident management policy, we notify customers via phone and email.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Username or password
Access restrictions in management interfaces and support channels
Our supporting tools and infrastructure are, where possible, federated with our single sign-on provider to enable centralised access management. This includes mandatory multi-factor authentication and conditional access policies. Where federation is not available, mandatory MFA is enforced.

Access to tooling is controlled through defined organisational roles, supported by a privileged access management policy that governs which staff are authorised.

Our support policy requires pre-approved customer administrators who are authorised to make decisions and, where necessary, share sensitive information when operating within support channels.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
CSA CSM version 4.0
Information security policies and processes
Documented information security, data protection, access control, incident management, patch management and business continuity policies are in place.

1. Policies are reviewed at least annually and following any material change.
2. All services are designed and operated in line with UK GDPR, ICO, DSPT and NCSC guidance.
3. Overall accountability for information security sits with senior management.
4. Regular employee refresher training is undertaken and logged, including completion of relevant Digital Care Hub eLearning modules.
5. Annual cyber security refresher training is mandatory for all staff.
6. Security risks, incidents and policy exceptions are recorded and tracked within an audit register.
7. Security incidents are managed through a defined incident response process, including customer and government notification where required.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
All proposed changes and configuration updates are reviewed and documented. Where appropriate, configuration is defined programmatically and maintained under version control. Changes are communicated, implemented and reviewed in line with our change management process, with lessons learned captured when required.

Automation underpins our security approach. We use multiple automated tools to continuously monitor, detect, remediate and alert across the platform, including:

Code scanning: to identify security vulnerabilities
Secret scanning: to detect exposure of sensitive information
Dependency monitoring: to identify components with known vulnerabilities
Security policy enforcement: to ensure secure working practices are consistently followed
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
1. We use an industry-standard endpoint protection suite across all corporate devices.
2. Our cloud services use security tools appropriate to each underlying technology.
3. Our third-party security response partner provides proactive monitoring and emerging threat alerts.
4. All services are registered with the NCSC Early Warning service.
5. We are a registered member of the NHS Cyber Associates Network.

Threats and vulnerabilities are assessed based on severity. As a baseline, we aim to deploy patches within 72 hours of vulnerabilities being identified.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Alerts within our cloud infrastructure align with CIS benchmarks, with changes and anomalous patterns, such as key network modifications, centrally monitored and alerted for review.

Each alert type has defined descriptions and indicators linked to runbooks to support effective response. Where required, escalation to our third-party incident response partner is available.

Alerts are reviewed immediately when triggered. Our engineering team includes designated personnel who continuously monitor security alerting across the platform.
Incident management type
Supplier-defined controls
Incident management approach
We follow UK regulatory requirements for incident reporting, including ICO guidance and NHS DSPT obligations.

A defined incident management policy is in place, supported by pre-approved communication templates and operational runbooks. The incident management process is regularly tested through drills, with lessons learned and improvements formally documented.

Incident reports are provided to customers where required.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
2.5%
Between £500,001 and £1,000,000
5%
Between £1,000,001 and £2,500,000
7.5%
Between £2,500,001 and £5,000,000
10%
Over £5,000,001
12.5%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
7aec6a09-3d1d-4096-aaf2-8dc113d87dca
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
00bdb921-5bb8-4580-b35c-aa6ce16e784d
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at hello@dlshealth.uk. Tell them what format you need. It will help if you say what assistive technology you use.