Skip to main content

Help us improve the Digital Marketplace - send your feedback

CINNAMON DIGITAL APPLICATIONS LIMITED

Cinnamon Immunisations

Cloud-based immunisation management system for school-aged immunisation services.

Includes electronic consent, NHS number tracing, clinical data capture, catch-up clinics, non-responders, notifications.

Integrated with Child Health and EPRs for accurate, auditable immunisation records and support information sharing.

Adaptable to changes in national and local requirements for operational flexibility and compliance.

Features

  • Interoperable Clinical Integration
  • Automated NHS Number Tracing
  • Digital Consent Management for all Vaccinations
  • Offline Clinical Recording
  • Patient Self-Booking Integration
  • Real-Time Digital Triage
  • Specialised Immunisation Programme Modules
  • Identification of non-responders including parent reminders
  • Secure Access and Audit Controls
  • School cohort management and session configuration tools.

Benefits

  • Reduced Administrative Workload
  • Operational Efficiency
  • Improved vaccination Vaccination Coverage
  • Accurate Patient Identification using PDS NHS Number
  • Paperless, Compliant Consent
  • Safer clinical decision-making through real-time triage
  • Offline functionality for low internet coverage
  • Fully integrated clinic module to manage catch ups
  • Information Governance Compliance
  • Integration across clinical systems for consistent NHS-wide Records

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at waspinall@cinnamondigitalapplications.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

7 2 3 7 9 0 8 5 7 0 9 4 7 3 1

Contact

CINNAMON DIGITAL APPLICATIONS LIMITED William Aspinall
Telephone: 07789483562
Email: waspinall@cinnamondigitalapplications.co.uk

About your service

Service categories

Applications

Production and operations

Service industry and public sector operations

  • Healthcare
  • Education
Multi cloud support
No

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Part of the Cinnamon eco system including:

Cinnamon Imms
Cinnamon Screening
Cinnamon Assess
Cloud deployment model
Public cloud
Service constraints
Operating systems currently in support:

Windows 11

iOS (latest 2 major versions)

Android (latest 2 major versions)

There are no specific hardware requirements. The system can run on 32b or 64b devices.

We recommend Microsoft Windows 11 laptop with office installed. For optimum screen performance we suggest a diagonal screen 14.0 Inches (35.56 cm) with a display resolution of 1366 x 768 Pixels.

The application is accessible in all default browsers including those shown below. We recommend the use of Microsoft Edge.
- Microsoft Edge
- Chrome
Latest two stable releases of each browser (automatic updates must be enabled).
System requirements
  • Microsoft Windows 11
  • Safari, Edge or Chrome Browser

User support

Email or online ticketing support
Yes
Support response times
We will provide ongoing support to all customers via our dedicated applications support helpdesk. This is available Monday to Friday 09:00 to 17:00.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
All customers can access our Mon-Fri 9am to 5pm support service.
Support costs are fully included.

Customer support queries are managed by our service desk and escalated to technical as required.
- Bug fix
- System developments
All
Support available to third parties
Yes

Onboarding and offboarding

Getting started
We will manage all aspects of the deployment using PRINCE2 principles. Our team will liaise directly with customer staff to deploy to the live environment within four weeks of contract signing.

We will provide multiple training sessions for all immunisations staff with additional sessions for admin. These are run remotely using Microsoft Teams.

We will provide all system documentation and learning materials.

We will attend/set up regular project team meetings to ensure customer get the very best value from our software.
Service documentation
Yes
Documentation formats
HTML
End-of-contract data extraction
At the end of the contract all data on the system is extracted in csv format and returned to the customer using secure file transfer.

Data extracts are completed by Cinnamon.
End-of-contract process
Towards the end of a contact term, with a minimum 3 months before contract termination, we will provide a customer exit plan. This will set out exit governance and the activities required in the final months of the contract.

The exit plan will identify data assets to be transferred and any data migration requirements. It will also outline how this will be managed and any ongoing requirement for the suppliers software at the end of the contract term.

The exit plan will set out our chargeable services. Data extraction and migration are additional chargeable services.
Documentation accessibility standard
WCAG 2.2 AAA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
None.
Service interface
No
User support accessibility
WCAG 2.2 AAA
API
Yes
What users can and can't do using the API
API access provided via SQL Integration engine. API is used for data read only.
API documentation
Yes
API documentation formats
Other
API sandbox or test environment
No
Customisation available
Yes
Description of customisation
Customers have a multitude of customisable options. These include:
- Branding of consent forms
- URL designation
- Wording / choice of all clinical questions relating to consent
- Bespoke parent emails and SMS notifications
- Links to parent feedback
- Full configuration of lookup tables and reference data

Customisation options are available to customer administrative staff or managed by Cinnamon via our support desk.

Scaling

Independence of resources
Cinnamon Immunisations is a high performing web application. Our environment can be scaled up at any time if demands on a customer resource are extended.

Our hosting model means that we are immediately able to extend the amount of resources required by the application.

Each customer application is continuously monitored with automated alerts for problems or issues.

Each customer is hosted in their own Silo instance meaning there is no interaction with other customer data or configuration settings. This means there are no limitations relating to the customer environment, training or testing.

Analytics

Service usage metrics
Yes
Metrics types
Cinnamon contains a full suite of user reports. The reporting suite is custom made to provide immunisation teams with everything needed to support the delivery of all immunisation programmes. This includes:

Operational management
Planning
Commissioner reports
Operational delivery

The system contain several reports for each vaccination programme that are custom designed to carry all of the necessary NHSE reporting requirements. This includes monthly SAVS reporting, NIVS and IMMFORM.

All reports can be extracted via the front end to excel using a single click.
Reporting types
  • Real-time dashboards
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Staff screening not performed
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
  • Other
Other data at rest protection approach
Connections within our environment are encrypted in transit using TLS 1.2+.

We restrict access using SQL firewall rules and IP allowlisting so only approved application endpoints and authorised sources can connect.

Database access is segregated by database with unique, least-privilege logins and tightly scoped permissions
Data sanitisation process
Yes
Equipment disposal approach
In-house destruction process
Data sanitisation type
  • Data Erasure
  • Physical Destruction / Hardware containing data is completely destroyed

Data importing and exporting

Data export approach
Data and reports on Cinnamon can be exported from the system in csv format.

This can be done using the system front-end by Immunisation staff using the data export buttons on screen.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Other
Other protection between networks
All traffic to our web apps/APIs uses HTTPS with TLS 1.2+.

For approved third parties needing bulk access, we provide direct encrypted connections (TLS) and restrict network access using IP allowlisting/firewall rules. Access is segregated per database, using unique, least-privilege logins with permissions limited to the required datasets/operations.
Data protection within supplier network
  • TLS (version 1.2 or above)
  • Other
Other protection within supplier network
Connections within our environment are encrypted in transit using TLS 1.2+.

We restrict access to using firewall rules and IP allow listing so only approved application endpoints and authorised sources can connect.

Database access is segregated by database with unique, least-privilege logins and tightly scoped permissions

Availability and resilience

Guaranteed availability
Agreed SLA uptime is 99%. This will be measured using our cloud service dashboard.
Cinnamon will provide service credits where the availability service level is not achieved:
Availability Service Credit
99% - 0%
95% - 2.5%
90% - 5%
Less than 90% - 10%
This excludes permitted downtime (4 hours per month).
Approach to resilience
This information is available on request.
Outage reporting
In the event of any outage we will information all customers directly by email.

We will also provide regular updates via our website or within the application.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Username or password
Access restrictions in management interfaces and support channels
Our support desk logs all calls in our service desk system. This includes customer name and contact details.

Change requests and information requests are limited to key customer personnel to ensure that changes are understood by the customer and have already been through internal approval processes.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Dedicated link (for example VPN)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
Other
Other security governance standards
NHS Data Security and Protection Toolkit
Cyber Essentials
Annual CREST approved penetration testing.
Information security policies and processes
We have a secure first culture. This means that we consider cyber security and GDPR before everything we do. Our compliance programme includes;
Full Data Privacy Impact Assessment (DPIA) for all projects
Completion of Information Asset Register (IAR)

Adherence to company policies including;
Data Quality Policy
Information Security Policy
Privacy Policy
Records Retention Policy
Subject Access Requests Policy

All our staff complete annual Cyber Security awareness training with additional, specific training for our company board members.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Cinnamon manages system updates and changes on behalf of customers, including bug fixes and feature enhancements.

Updates are issued weekly and applied out of hours to avoid disruption, with no expected downtime; if required, downtime is agreed and communicated in advance.

Change notifications are embedded inside the application and visible to all users.

Customer change requests follow a standard process: submission via support desk, logging and prioritisation, documentation, development and testing in a development environment, deployment to live, and customer notification. After release, updates are monitored for seven days using alerts and logging to detect potential issues.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
We subscribe to several national threat management services including Cyber Alerts from NHS England and the National Cyber Security Centre. Our development tools include in-built vulnerability identification.

We deploy security patches as soon as they are available and it is practical to do so. All potential threats are assessed for relevance, impact and likelihood.

We operate a cloud first model to ensure automated patching of underlying systems.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
We monitor our systems using automated tools to detect suspicious activity, attacks, misuse and malfunction. Our systems include detailed audit logs that are routinely screened by our technical team for potential threats.

We undertake annual external penetration testing by an approved supplier.

All potential threats are immediately assessed and acted upon based upon severity and impact.

Logging includes authentication to the service, system activities, IP address, user role, network flows and error/fault codes.
Incident management type
Supplier-defined controls
Incident management approach
Incidents are managed in a uniform process. All incidents are logged in JIRA by our customer support desk (email or telephone). Incidents can be raised by customers and our staff.

Log details include:

Reporter (name, email, telephone, role etc.)
Incident details
Key dates (create, logged, expected completion etc.)
Incident status
Outcome

Customers are issued regular updates and informed when fixes are applied.

Incident reporting is available to customers on request.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
2%
Between £500,001 and £1,000,000
5%
Between £1,000,001 and £2,500,000
10%
Between £2,500,001 and £5,000,000
10%
Over £5,000,001
10%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
E04f3fba-4326-44f3-905c-02abb0298bc3
Cyber essentials plus
No
Cyber Essentials Alternative
You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
Other security certifications
Yes
Any other security certifications
NHS Data Security and Protection Toolkit

Social value

Section B - Commitment for Future: Delivery
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at waspinall@cinnamondigitalapplications.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.