IMX Platform
A platform with cloud deployed applications which can support EPR implementations, data archiving, PROMs, business continuity, integration, data migration and transformation. It's flexible, interoperable, and scalable, seamlessly integrating with existing ICT infrastructures. Suitable for use across any health and care organisation.
Features
- Patient Reported Outcomes Measures functionality
- Clinical Portal/Shared Care Record
- Archive Solution
- Electronic Document Management
- Interoperability Solutions
- Dashboards and Real time Reporting
- Business Continuity
- Support, Alerts and Monitoring
- Integration
- Integration Engine
Benefits
- Interoperable with any system
- Access and use on any device
- Highly configurable to support local processes
- Intuitive
- Secure with full RBAC access
- Modern microservices architecture
- Auditing and reporting functionality
- User led design
- Full compatibility between applications
- Flexible, agile and phased implementation approaches
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
7 1 3 7 5 3 1 9 8 0 7 3 6 2 5
Contact
RESTART CONSULTING LIMITED
Lorraine Edmunds
Telephone: 01392 363888
Email: commercial@restartconsulting.com
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Adult Social Care
- Children's Social Care
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
-
Can be launched in patient context or embedded within any system.
Compatibility across all IMX solutions regardless of the initial application deployed. - Cloud deployment model
- Private cloud
- Service constraints
- There are no service constraints that we are aware of.
- System requirements
-
- Integration Engine licence (if required for the specific IMX application)
- Document conversion licence (if required for the specific IMX application)
- EMPI/MDM software licence (if required for the specific IMX application)
- Database software licences (if required for the specific IMX application)
User support
- Email or online ticketing support
- Yes
- Support response times
- SLAs available on request and can be configured to suit an organisations requirements.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Support costs can vary between IMX applications and are dependent on the term of the contract selected by the organisation.
ReStart adopts a flexible pricing approach to suit any capital and revenue budgets and can modify pricing to fit any organisation's budget requirements. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- ReStart can support any training requirements. Our preferred approach is Train the Trainer but we can provide classroom training and documentation as required.
- Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- If the solution is within the organisation's data centre, they will retain the data. If ReStart are holding the data, it will be exported and provided to the organisation in agreed location.
- End-of-contract process
- If the system is being replaced we will work with the new supplier to do a sufficient hand over process. This process and the exit extract, if required, will not be at an additional cost.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- There is no difference. They are the same solution.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
-
IMX has a fully open API available to organisations and their partners.
IMX can communicate with any API used in other solutions. It is a fully interoperable platform. - Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- The IMX interface has been designed to be accessible for all users including those using assistive technology. All aspects of the solution have been user tested and approved for us by Health and Care organisations.
- API
- Yes
- What users can and can't do using the API
- User organisations can configure their internal systems to launch IMX via our openAPI.
- API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- All aspects of the solution can be customised to suit the organisation and their users needs.
Scaling
- Independence of resources
-
If IMX is hosted in the organisation's environment then ReStart can recommend that additional resources are added to the deployment environment if concurrency becomes an issue.
If IMX is hosted in ReStart's environment, the environment will be configured to add additional resource as required.
Analytics
- Service usage metrics
- Yes
- Metrics types
- IMX has a full suite of auditing and logging tools that provide complete metrics to appropriate users in the organisation.
- Reporting types
-
- API access
- Real-time dashboards
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- Qvera (QIE)
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
-
Users of IMX are clinicians. Should the data owner (patient/service user) require an export of their data, this can be obtained through a Subject Access Request to the data controlling organisation.
If the data controller is a health or care organisation then the process for exports will depend on local policy.
If the solution is hosted in ReStart's cloud, then users can place a subject access request with ReStart directly. - Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- 99% up time guaranteed with service credits associated with any breaches.
- Approach to resilience
-
IMX is a high availability solution with 99.9% up time. In terms of resilience, the IMX solution is composed of microservices running in Kubernetes. This allows us to scale the workload flexibly when demand changes. Kubernetes spreads the workload across multiple servers, providing resilience to server failures. On our Cloud environment, these servers and other resources such as databases are distributed across Availability Zones, providing resilience against availability zone failure.
The Kubernetes cluster configuration is kept up-to-date with security best practices and each container is frequently scanned for CVEs to ensure the IMX solution is kept secure. ReStart's resilience policy is available on request. - Outage reporting
-
Email alerts are used to report the majority of outages.
Within IMX one of the applications IMX Alert has a customer facing dashboard which reports any issues in an organisations integration environment.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Limited access network (for example PSN)
- Username or password
- Access restrictions in management interfaces and support channels
- Users are assigned roles based on RBAC principals. This allow access to interfaces and support channels to be managed.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Limited access network (for example PSN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
At ReStart ensuring the security and confidentiality of sensitive health data is paramount. We have established robust information security policies and processes to safeguard data integrity, protect against unauthorised access, and mitigate potential risks. All Restart's information security policies/processes are available on request. Some of these include:
- Data Protection Policy: This defines our procedures for handling, storing, and transmitting sensitive health information in compliance with relevant regulations such as GDPR (General Data Protection Regulation).
-Incident Response Plan: Outlines steps to be taken in the event of a security breach or data incident, including incident detection, containment, investigation, and reporting.
- Employee Training and Awareness: Requires regular training sessions and awareness programs to educate employees about information security best practices and their responsibilities in safeguarding sensitive data.
We conduct periodic audits and security assessments to evaluate compliance with information security policies and identify areas for improvement.
The reporting structure in place to ensure that policies are followed includes:
An Information Security Officer who oversees the development and implementation of information security policies and procedures.
Information Security Team: Responsible for monitoring systems, conducting risk assessments, and responding to security incidents.
Senior Management: Provides oversight and support for information security initiatives. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
We track components throughout their lifecycle and assess changes for security impact. Our version control processes ensure accurate tracking, while documentation provides clarity. Changes undergo formal requests, risk assessments, and security reviews. Vulnerabilities are addressed pre-deployment through testing and remediation. Our Change Control Board approves changes based on impact and alignment with goals. Post-Implementation Reviews capture lessons for improvement. These processes maintain the integrity and security of our solutions.
ReStart's configuration and change management policy can be made available on request. - Vulnerability management type
- Undisclosed
- Vulnerability management approach
- ReStart's vulnerability management policy is confidential and available to organisations on request.
- Protective monitoring type
- Undisclosed
- Protective monitoring approach
- ReStart's protective monitoring approach is confidential and available on request.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
We have predefined processes for common events, ensuring swift resolution. Users report incidents through various channels, including email, or phone.
Our incident response team triages and prioritises issues based on severity. Regular updates are provided to users throughout the resolution process via email or an agreed system such as Jira. Post-incident, detailed incident reports can be generated, outlining the root cause, impact, actions taken, and preventive measures. These processes ensure timely resolution and transparency. ReStart's Incident Management policy is available on request. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
- Health and Social Care Network (HSCN)
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 2.5%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 7.5%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 12.5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- C34aa8ff-6e71-4580-8952-c3f4b19be1aa
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- F37f0bda-a75d-44b1-ac15-8670de57b5dc
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
-