Ozone.healthcare
Ozone.healthcare is a digital telemedicine solution transforming and shaping patient care within the NHS. It provides secure remote consultations across a wide range of specialties, including advice and guidance. Additional services include referral validation and the delivery of virtual clinics for diverse healthcare providers.
Features
- Full digital telemedicine consultation with a specialist
- Secure digital weblinks to provide patient images and data
- Secure clinical photography stored on platform not local devices
- eRS referrals made via dedicated support staff
- Triage and validation responses for patient care
- Built in patient and symptom monitoring
- Guaranteed 48 hour referral turn around
- Dedicated support team providing referral monitoring
- Accessible via web and mobile
- Alert system for updates and new patient data
Benefits
- Reduces secondary care waiting lists ensuring patients are seen sooner
- Empowers primary care with comprehensive treatment plans plans
- Specialist consultant-led care improves care for patients
- Enables equity of access for complex patient care
- Network of consultants enables collaboration and second opinions
- Integrated image service ensures patient data accuracy
- Specialist provides clinical opinion giving secondary care service within practices
- Speed of referral response allows safe management of complex cases
- Dedicated support team ensure eRS referrals dealt within 24 hours
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
7 3 4 1 0 7 3 4 3 7 0 7 8 1 5
Contact
OZONE HEALTH LTD
Dr James Britton
Telephone: 01482908208
Email: support@ozonehealth.co.uk
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- There is a fortnightly maintenance window taking place on a weekend evening with loss of service for under 5 minutes. The service can be used via most internet browsers and is compatible with most devices.
- System requirements
-
- Internet connection
- Web browser, e.g. Chrome, Firefox, Edge or Safari
User support
- Email or online ticketing support
- Yes
- Support response times
-
Our Support Team have a dedicated email address, which is monitored throughout office opening hours, with an on-call team member picking up any emergencies out of hours. We endeavour to resolve all support requests within 24 hours, but where that is not possible, the Support Team will contact the user with regular updates throughout the resolution process.
Our support phone line is available 9am-5pm, Monday to Friday (except Bank Holidays), and any messages left outside of these times will be responded to at the earliest opportunity. - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Each contract lead has a senior member of staff available for any contract support needed throughout the lifecycle of the service. Our Support Team is available to any user of the service, who have access to management and board level employees for more complex support needs.
Users are surveyed biannually, where they are given the opportunity to offer feedback, and this is collated and acted upon at board level.
Our Support Team offer online training to new and existing users, where a team member will demonstrate the platform on a one-to-one or small group basis, with the opportunity offered to ask questions. We also provide comprehensive documentation, and our team are available for any queries via telephone or email. Due to the online nature of our product, onsite support is not usually needed. However, this is available on request.
Support and training are provided by our team at no additional cost. - Support available to third parties
- No
Onboarding and offboarding
- Getting started
- Ongoing online training and user documentation is provided by the service.
- Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- At the end of a contract as we are not the primary care provider, the ongoing patient care pathway is stored on the NHS spine. However we do continue our duty of care and due diligence until patients are discharged and the service users can download any images or documents from the system to store securely if needed.
- End-of-contract process
-
At the conclusion of a contract, as we are not the primary care provider, all ongoing patient care pathways remain stored within the NHS Spine and primary care clinical systems. We continue to uphold our duty of care and due diligence until all patients have been discharged. Service users may download any images or documents from our system for secure storage if required.
We also conduct a formal contract debrief to finalise any outstanding handover requirements and review contract performance, including the reasons for its conclusion. All feedback and data are recorded and analysed as part of our quality management process to identify opportunities for improvement and determine whether any changes could have supported contract retention. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
Once our service has been commissioned, all data-sharing and clinical risk considerations will have already been addressed. Activation/ roll out is a simple process for practices and users: an initial call to our support desk will enable account setup and user access, which can be completed in just a few minutes. The primary account holder can then easily add additional users as required. Users can immediately access support via a link from our platform, email, or phone. Our Engagement and Compliance team is available to answer day-to-day queries and assist commissioners in maximising service uptake and patient benefits.
Our platform is intuitive, and user feedback indicates that formal training is rarely required. However, our Compliance and Engagement team offers new user and refresher training sessions via Microsoft Teams, which can be conveniently scheduled through our online booking system. Additionally, video tutorials and guidance documents are available on our platform and through the Support Team.
We also provide targeted treatment plans for certain common skin conditions for primary care users.
To keep users informed, we publish regular updates highlighting enhancements and changes to functionality.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Mobile remote links are sent to patients which allows them to directly upload their symptoms and images onto the platform rather than having to visit their GP practice. The platform is mainly designed to be used on a desktop but can still operate via mobile devices.
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- Ozone.healthcare has an intuitive service interface which is easy to navigate and use without medical training. This means that any practice staff member can be trained to input data into the platform (patient's Health File) along with relevant information and images. This reduces the pressure on General Practitioners allowing them further capacity for patient care.
- Accessibility standards
- None or don’t know
- Description of accessibility
- The platform uses a high level of colour contrast to ensure that visually impaired users can still make use of the service. Text on the platform can also be increased in size to assist reader use.
- Accessibility testing
- When testing the Technical team ensure navigation buttons are consistent throughout the platform. It is our policy to acknowledge and act upon accessibility issues raised to us.
- API
- No
- Customisation available
- Yes
- Description of customisation
- Workflow changes can be made in consultation with the service provider from an authorised person after relevant discussion with the Compliance Manager or other person in authority. Access by users is relevant to role-based access controls.
Scaling
- Independence of resources
- Our service is a resilient scalable cloud based system. We continually monitor the load on our system, to ensure the current usage does not exceed the available allocated resources at any one time, thus ensuring there is no degradation in the user experience.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Audit trails of user access to system resources and clinical data.
- Reporting types
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
- We provide pseudonymised data for ICB analysis and reporting.
- Data export formats
- CSV
- Data import formats
- Other
- Other data import formats
-
- Images (PNG, JPEG)
- DOC, DOCX
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- We provide an SLA of 99.98% which is due to the servers being maintained out of service users hours and therefore does not impact on the use of the platform. As we charge per clinical outcome, service being unavailable means there will be no charge to the service user.
- Approach to resilience
-
Our system is cloud based and multi-zonal with replication and off-cloud backup on our private server in a UK based data centre. This hybrid architecture provides a robust platform to ensure data protection, along with our ISO 27001 accreditation.
Details available upon request. - Outage reporting
- We constantly monitor our systems for errors and unusual activity which allows us to alert our service users via email or telephone to ensure they have continual access to the platform. The engagement and compliance team actively engage with the service users to ensure good communications regarding status of the platform.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- Role based access control along with MFA and password hacking protection. Support is always through a management access role.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- NHS, DSPT, Cyber Essentials Plus
- Information security policies and processes
-
We maintain a comprehensive and robust information security framework designed to safeguard data integrity, confidentiality, and availability across all operations. Our policies and controls are fully aligned with ISO 27001. This ensures a systematic approach to managing sensitive information, addressing risks, and implementing best practices for continuous improvement.
In addition, we adhere to the NHS Data Security and Protection Toolkit (DSPT) requirements, which provide assurance that we meet the highest standards for handling health and personal data within the UK healthcare environment. This includes strict compliance with data protection legislation, secure processing of patient information, and rigorous governance measures.
Our framework encompasses risk assessment, incident management, access control, encryption, and staff training to maintain resilience against evolving cyber threats. Regular audits and monitoring reinforce accountability and transparency, while documented procedures ensure consistency and compliance across all departments.
By integrating ISO 27001 principles with NHS DSPT obligations, we deliver a security posture that not only meets regulatory requirements but also builds trust with stakeholders, patients, and partners. - Software Security Code of Practice
- No
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- All service changes and component modifications are tracked throughout their lifecycle in the Change Control Register, providing full visibility from initiation to closure. Change requests are formally submitted through the Support Desk following the defined policy. Each change undergoes comprehensive impact assessment on operations and information security, including confidentiality, integrity, and availability. Security reviews are conducted by the Technical Director or Information Assurance Director. Detailed rollout and back-out plans are documented, and major changes are managed as IT projects. Testing is performed in controlled environments prior to implementation. The Change Control Board validates effectiveness to ensure security and operational integrity.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Our process involves trusted continuous vulnerability and monitoring sources, including NHS Cyber bulletins, NCSC updates, and third-party security websites. Vulnerabilities are prioritized by CVSS scores and internal risk assessments, with remediation timelines: Critical (24–72 hrs), High (7 days), Medium (30 days), Low (scheduled maintenance). The Technical Director manages Linux server patching, while the Support Team handles workstations. The Information Governance Team oversees compliance, approves exceptions, and enforces policy. Exceptions require documented risk assessments and compensating controls. Post-remediation scans verify resolution, ensuring robust protection and adherence to security standards.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- We use an approved third party supplier to proxy our sites and provide protection against Botnet and AI crawlers plus standard Open Web Application Security Project (OWASP) security risks and DDOS attacks. This subsequently alerts us to these events 24/7 allowing us to respond to avoid significant disruption to the platform.
- Incident management type
- Supplier-defined controls
- Incident management approach
-
Any incidents regarding the system should be reported to our Support Team at their dedicated email address. These incidents will be passed to Ozone Health's Incident Response team, who will carry out an internal investigation and complete an incident form, which will be made available on request to the user reporting the incident. Regular contact will also be kept with the user to inform them of our findings and/or resulting changes.
If any external bodies need to be informed, the Management Team will determine who should contact the relevant organisation. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- NQA
- ISO/IEC 27001 accreditation date
- Monday 4 August 2025
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 7f99f91f-0ce4-481a-88e8-bd8a0e00539f
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 543faf4d-c191-4b5a-88be-d3435ecfc630
- Other security certifications
- Yes
- Any other security certifications
-
- DCB0129 Clinical Risk Management
- NHS DSPT (Organisation Data Services Code: DCF)
- Digital Technology Assessment Criteria (DTAC)
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
- Advertising of supply chain opportunities openly and to ensure they are accessible to a diverse range of businesses, including advertising all subcontracting opportunities on Contracts Finder
- Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
- Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
- Plans for positive actions with community groups.
- Measures for making facilities used in the delivery of the contract available for community groups, education or training
- Measures to engage users and communities and build relationships to increase community integration build trust and influence how the contract is delivered
- Plans to respond flexibly and adapt approaches to community engagement and initiatives
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Working conditions which promote an inclusive working environment and promote retention and progression
- Other measures to provide equality of opportunity for disabled people and those with health conditions into employment, including becoming a Disability Confident employer and inclusion of supported businesses in the contract supply chain
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Other measures to offer development opportunities for the target cohort(s) in the contract workforce
- Understanding of issues relating to entering the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
-