MedsMarket - Pharmaceutical Purchasing Automation & Intelligence
Built for buyers, it brings all suppliers and wholesalers into a single interface. Search once to instantly see product availability and pricing, including contract pricing, across your approved suppliers. Integrates with pharmacy systems (EMIS and System-C) to provide deeper insights, improved purchasing control and support cost savings at your organisational.
Features
- View pricing and availability across all connected suppliers
- Consistent product results regardless of supplier source
- Integration with pharmacy systems for deeper insights and proactive reporting
- Pricing that reflects your account, region and applicable contract pricing
- Live search results showing current supplier data
- Search by product name, supplier code or EAN
- Support for multiple users and organisational structures
- Designed for NHS secondary care and contract-based procurement
Benefits
- Reduce time spent sourcing medicines
- Minimise supplier phone calls and emails
- Order with confidence using visible stock levels
- Compare products in a consistent, standardised view
- Sort and prioritise results to match local purchasing preferences
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
7 1 3 0 8 2 7 0 8 2 0 1 9 9 5
Contact
DLS HEALTH LIMITED
David Page
Telephone: 07387116979
Email: hello@dlshealth.uk
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Adult Social Care
- Children's Social Care
- Other
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- Buyers must already have established relationships with pharmaceutical wholesalers and suppliers. The service does not facilitate the creation or onboarding of new supplier accounts.
- System requirements
-
- Requires an internet connection
- Requires modern browser (Safari, Chrome, Edge)
- Requires a modern, supported, Windows based operating system
User support
- Email or online ticketing support
- Yes
- Support response times
-
DLS Health provides email and phone support, Monday to Friday, 9am until 5pm, excluding bank and public holidays.
Although highly unlikely, if ever a customer wanted to consider extended weekday hours support or support at weekends or on holidays, we would be happy to discuss, but there may be additional charges. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Any issues that need to be raised to the DLS Health support team can be made via email, or phone. When possible, we would encourage that email is used as this method logs a ticket directly to the DLS Health online support portal that is monitored regularly.
Upon logging an issue, this will automatically create a support ticket on the DLS Health support portal for the support team to confirm the severity, and review and resolve the issue. Upon investigation, any updates and resolution will be automatically emailed to the user that logged the issue.
Issues logged are categorised by their severity and impact on operations. This categorisation helps prioritise responses and allocate resources effectively. The categories range from P1 (highest priority) to P4 (lowest priority). Here’s a detailed description of each category:
P1 - Response within 1 hour, target resolution 4 hours or less
P2 - Response within 4 hours, target resolution 24 hours or less
P3 - Response within 6 hours, target resolution 2-3 days or less
P4 - Response within 2-3 days, no target resolution provided - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
We provide comprehensive support for the setup and configuration of the MedsMarket solution.
Implementation is delivered often through a combination of onsite and remote engagement, with full training and support provided to ensure a smooth deployment and maximum customer benefit.
Training is available through multiple formats, including in-person sessions, webinars, online documentation, video resources and in-application help features.
During and after go-live, hyper-care support is provided, including weekly review calls and dedicated support for initial users of the solution. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
DLS Health can provide data extracts in standard industry formats such as CSV and will work with customers and their new suppliers to ensure data continuity and prevent data loss.
We recognise our responsibility in maintaining healthcare continuity and will support customers transitioning to another supplier, working collaboratively to ensure patient care and operational services remain uninterrupted. - End-of-contract process
-
Ahead of contract expiry or upon customer termination, DLS Health will work with the customer to agree data extraction requirements and service termination dates. Reasonable efforts will be made to support data extraction and migration for example;
Providing data extracts in agreed formats, supporting clarification of data structures, and coordinating with the customer or appointed supplier within standard support hours. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- Yes
- Compatible operating systems
- Windows
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- We have built MedsMarket to be adaptive to the device it is being accessed from, so there are no differences in access.
- Service interface
- No
- User support accessibility
- WCAG 2.2 A
- API
- Yes
- What users can and can't do using the API
- Users can access our full API infrastructure, with optional machine-to-machine API authorisation issued by DLS Health.
- API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- No
- Customisation available
- No
Scaling
- Independence of resources
-
MedsMarket is built on modern cloud services that automatically scale to meet user demand.
As usage increases, the platform automatically adjusts capacity in the background to maintain performance during periods of high activity, without manual intervention. Auto-scaling is enabled by default and operates without interrupting users.
The service operates in an active-active model across multiple cloud regions for resilience, with the same auto-scaling approach applied consistently in each region.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Service metrics are available for usage and login activity within each organisation.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
- DLS Health can provide data extracts in industry standard formats such as csv
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- Csv
- Json
- Xml
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- Xml
- Csv
- Json
- Other agreed formats
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
Our platform is hosted on Amazon Web Services and is designed in line with AWS best practices.
We use managed platform services by default, removing the need to manage servers and improving the overall security and resilience of the platform. Our service level agreement provides 99.95% availability, excluding planned maintenance.
The platform is engineered for high availability within the UK and operates across multiple physical locations. It follows an active-active design, meaning services continue to operate even if a component fails, with little or no impact on customers.
In the event of a service failure, DLS Health operates a credit-based refund mechanism, as defined within the contract. - Approach to resilience
-
In line with AWS best practice and the shared responsibility model, our services operate across more than one physical location and can be tailored to meet specific customer requirements.
Due to tour security posture, detailed architectural information is only provided on request to support assurance and governance requirements. - Outage reporting
- In the unlikely event of a platform outage, and in line with our incident management policy, we notify customers via phone and email.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Username or password
- Access restrictions in management interfaces and support channels
-
Our supporting tools and infrastructure are, where possible, federated with our single sign-on provider to enable centralised access management. This includes mandatory multi-factor authentication and conditional access policies. Where federation is not available, mandatory MFA is enforced.
Access to tooling is controlled through defined organisational roles, supported by a privileged access management policy that governs which staff are authorised.
Our support policy requires pre-approved customer administrators who are authorised to make decisions and, where necessary, share sensitive information when operating within support channels. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- CSA CSM version 4.0
- Information security policies and processes
-
Documented information security, data protection, access control, incident management, patch management and business continuity policies are in place.
1. Policies are reviewed at least annually and following any material change.
2. All services are designed and operated in line with UK GDPR, ICO, DSPT and NCSC guidance.
3. Overall accountability for information security sits with senior management.
4. Regular employee refresher training is undertaken and logged, including completion of relevant Digital Care Hub eLearning modules.
5. Annual cyber security refresher training is mandatory for all staff.
6. Security risks, incidents and policy exceptions are recorded and tracked within an audit register.
7. Security incidents are managed through a defined incident response process, including customer and government notification where required. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
All proposed changes and configuration updates are reviewed and documented. Where appropriate, configuration is defined programmatically and maintained under version control. Changes are communicated, implemented and reviewed in line with our change management process, with lessons learned captured when required.
Automation underpins our security approach. We use multiple automated tools to continuously monitor, detect, remediate and alert across the platform, including:
Code scanning: to identify security vulnerabilities
Secret scanning: to detect exposure of sensitive information
Dependency monitoring: to identify components with known vulnerabilities
Security policy enforcement: to ensure secure working practices are consistently followed - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
1. We use an industry-standard endpoint protection suite across all corporate devices.
2. Our cloud services use security tools appropriate to each underlying technology.
3. Our third-party security response partner provides proactive monitoring and emerging threat alerts.
4. All services are registered with the NCSC Early Warning service.
5. We are a registered member of the NHS Cyber Associates Network.
Threats and vulnerabilities are assessed based on severity. As a baseline, we aim to deploy patches within 72 hours of vulnerabilities being identified. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Alerts within our cloud infrastructure align with CIS benchmarks, with changes and anomalous patterns, such as key network modifications, centrally monitored and alerted for review.
Each alert type has defined descriptions and indicators linked to runbooks to support effective response. Where required, escalation to our third-party incident response partner is available.
Alerts are reviewed immediately when triggered. Our engineering team includes designated personnel who continuously monitor security alerting across the platform. - Incident management type
- Supplier-defined controls
- Incident management approach
-
We follow UK regulatory requirements for incident reporting, including ICO guidance and NHS DSPT obligations.
A defined incident management policy is in place, supported by pre-approved communication templates and operational runbooks. The incident management process is regularly tested through drills, with lessons learned and improvements formally documented.
Incident reports are provided to customers where required. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 2.5%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 7.5%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 12.5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 7aec6a09-3d1d-4096-aaf2-8dc113d87dca
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 00bdb921-5bb8-4580-b35c-aa6ce16e784d
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
-