Cinnamon Immunisations
Cloud-based immunisation management system for school-aged immunisation services.
Includes electronic consent, NHS number tracing, clinical data capture, catch-up clinics, non-responders, notifications.
Integrated with Child Health and EPRs for accurate, auditable immunisation records and support information sharing.
Adaptable to changes in national and local requirements for operational flexibility and compliance.
Features
- Interoperable Clinical Integration
- Automated NHS Number Tracing
- Digital Consent Management for all Vaccinations
- Offline Clinical Recording
- Patient Self-Booking Integration
- Real-Time Digital Triage
- Specialised Immunisation Programme Modules
- Identification of non-responders including parent reminders
- Secure Access and Audit Controls
- School cohort management and session configuration tools.
Benefits
- Reduced Administrative Workload
- Operational Efficiency
- Improved vaccination Vaccination Coverage
- Accurate Patient Identification using PDS NHS Number
- Paperless, Compliant Consent
- Safer clinical decision-making through real-time triage
- Offline functionality for low internet coverage
- Fully integrated clinic module to manage catch ups
- Information Governance Compliance
- Integration across clinical systems for consistent NHS-wide Records
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
7 2 3 7 9 0 8 5 7 0 9 4 7 3 1
Contact
CINNAMON DIGITAL APPLICATIONS LIMITED
William Aspinall
Telephone: 07789483562
Email: waspinall@cinnamondigitalapplications.co.uk
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Education
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
-
Part of the Cinnamon eco system including:
Cinnamon Imms
Cinnamon Screening
Cinnamon Assess - Cloud deployment model
- Public cloud
- Service constraints
-
Operating systems currently in support:
Windows 11
iOS (latest 2 major versions)
Android (latest 2 major versions)
There are no specific hardware requirements. The system can run on 32b or 64b devices.
We recommend Microsoft Windows 11 laptop with office installed. For optimum screen performance we suggest a diagonal screen 14.0 Inches (35.56 cm) with a display resolution of 1366 x 768 Pixels.
The application is accessible in all default browsers including those shown below. We recommend the use of Microsoft Edge.
- Microsoft Edge
- Chrome
Latest two stable releases of each browser (automatic updates must be enabled). - System requirements
-
- Microsoft Windows 11
- Safari, Edge or Chrome Browser
User support
- Email or online ticketing support
- Yes
- Support response times
- We will provide ongoing support to all customers via our dedicated applications support helpdesk. This is available Monday to Friday 09:00 to 17:00.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
All customers can access our Mon-Fri 9am to 5pm support service.
Support costs are fully included.
Customer support queries are managed by our service desk and escalated to technical as required.
- Bug fix
- System developments
All - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
We will manage all aspects of the deployment using PRINCE2 principles. Our team will liaise directly with customer staff to deploy to the live environment within four weeks of contract signing.
We will provide multiple training sessions for all immunisations staff with additional sessions for admin. These are run remotely using Microsoft Teams.
We will provide all system documentation and learning materials.
We will attend/set up regular project team meetings to ensure customer get the very best value from our software. - Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
-
At the end of the contract all data on the system is extracted in csv format and returned to the customer using secure file transfer.
Data extracts are completed by Cinnamon. - End-of-contract process
-
Towards the end of a contact term, with a minimum 3 months before contract termination, we will provide a customer exit plan. This will set out exit governance and the activities required in the final months of the contract.
The exit plan will identify data assets to be transferred and any data migration requirements. It will also outline how this will be managed and any ongoing requirement for the suppliers software at the end of the contract term.
The exit plan will set out our chargeable services. Data extraction and migration are additional chargeable services. - Documentation accessibility standard
- WCAG 2.2 AAA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- None.
- Service interface
- No
- User support accessibility
- WCAG 2.2 AAA
- API
- Yes
- What users can and can't do using the API
- API access provided via SQL Integration engine. API is used for data read only.
- API documentation
- Yes
- API documentation formats
- Other
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
-
Customers have a multitude of customisable options. These include:
- Branding of consent forms
- URL designation
- Wording / choice of all clinical questions relating to consent
- Bespoke parent emails and SMS notifications
- Links to parent feedback
- Full configuration of lookup tables and reference data
Customisation options are available to customer administrative staff or managed by Cinnamon via our support desk.
Scaling
- Independence of resources
-
Cinnamon Immunisations is a high performing web application. Our environment can be scaled up at any time if demands on a customer resource are extended.
Our hosting model means that we are immediately able to extend the amount of resources required by the application.
Each customer application is continuously monitored with automated alerts for problems or issues.
Each customer is hosted in their own Silo instance meaning there is no interaction with other customer data or configuration settings. This means there are no limitations relating to the customer environment, training or testing.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Cinnamon contains a full suite of user reports. The reporting suite is custom made to provide immunisation teams with everything needed to support the delivery of all immunisation programmes. This includes:
Operational management
Planning
Commissioner reports
Operational delivery
The system contain several reports for each vaccination programme that are custom designed to carry all of the necessary NHSE reporting requirements. This includes monthly SAVS reporting, NIVS and IMMFORM.
All reports can be extracted via the front end to excel using a single click. - Reporting types
-
- Real-time dashboards
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Staff screening not performed
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Other
- Other data at rest protection approach
-
Connections within our environment are encrypted in transit using TLS 1.2+.
We restrict access using SQL firewall rules and IP allowlisting so only approved application endpoints and authorised sources can connect.
Database access is segregated by database with unique, least-privilege logins and tightly scoped permissions - Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
-
- Data Erasure
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
-
Data and reports on Cinnamon can be exported from the system in csv format.
This can be done using the system front-end by Immunisation staff using the data export buttons on screen. - Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Other
- Other protection between networks
-
All traffic to our web apps/APIs uses HTTPS with TLS 1.2+.
For approved third parties needing bulk access, we provide direct encrypted connections (TLS) and restrict network access using IP allowlisting/firewall rules. Access is segregated per database, using unique, least-privilege logins with permissions limited to the required datasets/operations. - Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
-
Connections within our environment are encrypted in transit using TLS 1.2+.
We restrict access to using firewall rules and IP allow listing so only approved application endpoints and authorised sources can connect.
Database access is segregated by database with unique, least-privilege logins and tightly scoped permissions
Availability and resilience
- Guaranteed availability
-
Agreed SLA uptime is 99%. This will be measured using our cloud service dashboard.
Cinnamon will provide service credits where the availability service level is not achieved:
Availability Service Credit
99% - 0%
95% - 2.5%
90% - 5%
Less than 90% - 10%
This excludes permitted downtime (4 hours per month). - Approach to resilience
- This information is available on request.
- Outage reporting
-
In the event of any outage we will information all customers directly by email.
We will also provide regular updates via our website or within the application.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Username or password
- Access restrictions in management interfaces and support channels
-
Our support desk logs all calls in our service desk system. This includes customer name and contact details.
Change requests and information requests are limited to key customer personnel to ensure that changes are understood by the customer and have already been through internal approval processes. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
-
NHS Data Security and Protection Toolkit
Cyber Essentials
Annual CREST approved penetration testing. - Information security policies and processes
-
We have a secure first culture. This means that we consider cyber security and GDPR before everything we do. Our compliance programme includes;
Full Data Privacy Impact Assessment (DPIA) for all projects
Completion of Information Asset Register (IAR)
Adherence to company policies including;
Data Quality Policy
Information Security Policy
Privacy Policy
Records Retention Policy
Subject Access Requests Policy
All our staff complete annual Cyber Security awareness training with additional, specific training for our company board members. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Cinnamon manages system updates and changes on behalf of customers, including bug fixes and feature enhancements.
Updates are issued weekly and applied out of hours to avoid disruption, with no expected downtime; if required, downtime is agreed and communicated in advance.
Change notifications are embedded inside the application and visible to all users.
Customer change requests follow a standard process: submission via support desk, logging and prioritisation, documentation, development and testing in a development environment, deployment to live, and customer notification. After release, updates are monitored for seven days using alerts and logging to detect potential issues. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
We subscribe to several national threat management services including Cyber Alerts from NHS England and the National Cyber Security Centre. Our development tools include in-built vulnerability identification.
We deploy security patches as soon as they are available and it is practical to do so. All potential threats are assessed for relevance, impact and likelihood.
We operate a cloud first model to ensure automated patching of underlying systems. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
We monitor our systems using automated tools to detect suspicious activity, attacks, misuse and malfunction. Our systems include detailed audit logs that are routinely screened by our technical team for potential threats.
We undertake annual external penetration testing by an approved supplier.
All potential threats are immediately assessed and acted upon based upon severity and impact.
Logging includes authentication to the service, system activities, IP address, user role, network flows and error/fault codes. - Incident management type
- Supplier-defined controls
- Incident management approach
-
Incidents are managed in a uniform process. All incidents are logged in JIRA by our customer support desk (email or telephone). Incidents can be raised by customers and our staff.
Log details include:
Reporter (name, email, telephone, role etc.)
Incident details
Key dates (create, logged, expected completion etc.)
Incident status
Outcome
Customers are issued regular updates and informed when fixes are applied.
Incident reporting is available to customers on request. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 2%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- E04f3fba-4326-44f3-905c-02abb0298bc3
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
- Other security certifications
- Yes
- Any other security certifications
- NHS Data Security and Protection Toolkit
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
-