PhenoTips
PhenoTips is a cloud-based genomic health record built for genetics. It enables clinicians, and researchers the ability to collect structured phenotype and family history data, generate pedigrees, assess genetic risk, and collaborate efficiently within and across departments. Delivered as a SaaS platform it integrates with EHRs and external systems.
Features
- Advanced and inclusive digital pedigree creation
- Pre-visit patient family questionnaires that auto-draw pedigrees
- Built-in Cancer risk assessment tool
- Integrate with multiple systems via FHIR, HL7v2, RESTful APIs
- Deep Phenotyping with HPO terms and NLP
- Family record linking
- Unified genomic health record support
- Searchable structured data
- Regional & National Multi-Trust Access
Benefits
- Draw and edit standardised, complex pedigrees in-browser.
- Reduce wait-lists by optimizing patient triaging
- Save 10–20 minutes of clinical time with embedded risk assessments
- Automate data flow from multiple systems to reduce duplicate entry
- Auto-suggest HPO terms from clinical notes using NLP.
- Collaborate with co-workers and access remotely
- Unified view of phenotype, genotype, diagnosis and clinical history
- Advanced search by phenotype, diagnosis, gene, or status.
- Reduce administrative burn out and administrative data entry work
- Increase number of patients seen and reduce costs
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
7 4 1 7 0 9 9 4 7 5 6 4 9 4 8
Contact
Gene42 Inc.
Paweł Buczkowicz
Telephone: 18886825252
Email: pawel@phenotips.com
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
-
PhenoTips is:
• Often integrated with other EPR systems (e.g. Epic, Cerner, E-MIS) via HL7v2, FHIR, or contextual launch to provide a genomics add-on to existing EPRs.
• Capable of operating independently as a complete Genomic Health Record platform, without requiring an EPR integration - Cloud deployment model
- Private cloud
- Service constraints
-
- Planned maintenance occurs during off-peak hours with advance notice; downtime is minimal.
- Web-based platform requires a modern browser; no local installation needed.
- Concurrent editing is restricted — users are notified if a record is in use.
- Real-time use requires internet access; performance depends on network latency. - System requirements
-
- Modern web browser required
- Internet access required
User support
- Email or online ticketing support
- Yes
- Support response times
-
- We respond to all support queries within 1 business day.
- Weekend queries are triaged and responded to on the next business day.
- Urgent issues may receive faster response depending on severity and SLA. - User can manage status and priority of support tickets
- No
- Phone support
- No
- Web chat support
- No
- Onsite support
- No
- Support levels
-
PhenoTips provides a single, all-inclusive support level with no additional cost. Support includes:
• Unlimited email and ticket support
• Virtual support may be provided via videoconferencing as needed
• A dedicated Customer Success Manager for each client
• Access to technical support engineers for integration and infrastructure issues
• Ongoing updates, bug fixes, and usage optimization support
Every customer is assigned a dedicated Customer Success Manager who coordinates onboarding, user training, integration (e.g. Epic, Cerner via HL7/FHIR), and issue resolution. During implementation, clients also work with a Project Manager and relevant technical staff.
We do not offer tiered or paid support plans. All support services are included in the annual subscription and implementation fees, with no per-incident charges.
Support is available during business hours, and response times are typically within one business day. Weekend requests are handled on the next business day. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
PhenoTips provides a comprehensive onboarding process to support successful adoption. Each implementation includes a dedicated Project Manager and Customer Success Manager who work closely with the buyer’s clinical and technical teams.
We offer the following support to help users get started:
• Online training sessions, including role-specific and workflow-based training
• Train-the-trainer model, enabling internal champions to support scaling
• Step-by-step user documentation and recorded tutorials
• Configuration workshops to align the system with local workflows
• Implementation support including data migration and integration setup
All training and onboarding materials are tailored to the buyer’s use case, such as rare disease, cancer genetics, or inherited cardiovascular conditions. - Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
-
At the end of the contract, PhenoTips provides full data extraction support to ensure a smooth transition. Buyers may request their data in standard, machine-readable formats including:
• JSON, PED, or CSV for patient, family, and pedigree records
• PDF for clinical reports and pedigrees
• HL7v2 or FHIR bundles if applicable for integrated environments
Data can be securely exported by the buyer’s internal team (if permissions allow) or extracted by the PhenoTips support team in coordination with the buyer.
PhenoTips will work with the buyer to define the extraction scope and schedule. - End-of-contract process
-
At the end of the contract, PhenoTips initiates a structured offboarding process in collaboration with the buyer. This includes:
• Secure data extraction in standard formats (e.g. JSON, CSV, PDF)
• Confirmation of data transfer completion and deletion of hosted data upon written instruction
• Revocation of user access and credentials
These activities are included in the contract price, provided data is extracted in standard formats and no custom transformation is required.
PhenoTips ensures full cooperation with buyer IT and clinical teams to enable a compliant, secure, and timely exit. Data will be retained only as long as contractually or legally required, then permanently deleted from all systems. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
PhenoTips provides onboarding and offboarding documentation in clear, structured formats designed to support a wide range of users. Documentation is delivered in web-based and PDF formats, using plain language, clear navigation, and consistent structure to enhance usability. Content includes step-by-step instructions, screenshots, recorded training sessions, and links to additional resources.
While the documentation is designed with usability in mind, we have not formally certified it against WCAG 2.2 or EN 301 549 accessibility standards. We are committed to improving accessibility and can work with buyers to provide materials in alternative formats upon request (e.g. large print or accessible PDFs).
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Our patient-facing questionnaire is designed for use on mobile devices and browsers. Our clinician portal is not designed for mobile use.
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- PhenoTips provides a secure, web-based interface accessible through modern browsers. Users can create and manage patient and family records, draw pedigrees, record phenotypes using HPO terms, assess cancer risk, and search clinical data. The interface supports role-based access and integrates with EPR systems via HL7v2, FHIR, or contextual launch. No installation is required.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
We worked with a visually impaired user on our Pre-visit Patient Questionnaire (our patient-facing application) who performed testing using several different screen-reader technologies (JAWS and NVDA). With their feedback, we implemented updates to ensure smooth usage of our patient-facing application.
Note that our clinician portal has not been tested by users of assistive technology. - API
- Yes
- What users can and can't do using the API
-
PhenoTips provides a RESTful API that allows users to programmatically interact with the platform. Through the API, users can create, read, update, and delete patient records, phenotypes, genotypes, family records, and clinical notes. The API supports integration with EPR systems and can be used to automate data entry, fetch patient data, or link external tools.
Service setup, including user and role configuration, is not currently supported via API and must be completed through the admin interface. Similarly, API access must be enabled and secured by the PhenoTips team during implementation.
Limitations include restricted write access to certain sensitive fields and no support for real-time streaming or webhooks. All API interactions require authentication and are governed by the same access controls and audit logging as the user interface. - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
PhenoTips allows extensive customisation to support diverse clinical and research workflows. Buyers can customise:
• Pre-visit patient questionnaires (PPQs) for different specialties (e.g. cancer, cardiology)
• Pedigree templates and symbols, including inclusive or specialty-specific layouts
• Clinical forms and data fields, such as phenotyping checklists and ontology settings
• User roles and permissions, aligned with department or clinician responsibilities
• Integrations with HL7v2, FHIR, or contextual launch to/from EPRs and LIMS
• Risk models, exports, and reports based on clinical requirements
• General features and functionality
Customisations are implemented during onboarding or as enhancements post-deployment. Some changes (e.g. questionnaires) can be managed by trained buyer administrators. More advanced or technical changes require support from the PhenoTips team.
All customisations require a Statement of Work (SOW) and will incur additional costs based on the scope of work. Pricing and timelines are finalised following a joint requirements-gathering phase.
Scaling
- Independence of resources
- PhenoTips is hosted on secure cloud infrastructure (AWS preferred, Azure supported if required) with logically separated environments for each buyer. Each deployment is securely isolated to prevent cross-tenant access. This architecture ensures that one buyer’s usage or data load does not affect another. Specific compute and storage resource allocation (e.g. CPU/memory guarantees, storage volumes) are configured based on customer needs and workflows.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
- User activity tracking (e.g. last author, record creation/modification dates)
- Audit logs of access and changes to patient records
- Support for usage metrics relevant to reporting and compliance (e.g. number of active users, patient records managed) - Reporting types
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Other
- Other data at rest protection approach
- We utilise AWS and/or Azure data centres; physical access control is managed by them
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
- Users can export their data directly through the PhenoTips interface or via API. Supported formats include JSON, CSV, PED, PDF, and BOADICEA (CanRisk). Users with appropriate permissions can export individual records or batches of patient, family, and pedigree data. Exports can be redacted to remove personal identifiers or comments.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- JSON
- XAR
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- JSON
- PED
- GEDCOM
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
PhenoTips guarantees 99.5% availability for its hosted SaaS platform, excluding scheduled maintenance periods. Availability is measured monthly and monitored continuously.
Service uptime includes access to core functionalities such as patient record management, pedigree drawing, phenotype capture, and integrated tools. Scheduled maintenance is communicated in advance and typically occurs during off-peak hours.
In the event that PhenoTips does not meet the guaranteed availability level, service credits or contract extensions may be offered, subject to terms defined in the buyer’s contract or call-off agreement. Specific remedies are agreed during procurement and may vary depending on hosting, support model, and integration complexity. - Approach to resilience
-
PhenoTips is hosted in cloud environments (AWS or Azure) that are designed for high availability and fault tolerance. Services can be deployed across multiple availability zones within a selected region to ensure continuity in the event of infrastructure failure.
The platform supports automated failover, data replication, and regular encrypted backups. Infrastructure is monitored 24/7, with alerts for service degradation or failure. Backup and disaster recovery procedures are tested regularly to ensure recoverability.
Resilience is supported at the application and data layers, with architecture designed to minimise single points of failure. Services can be scaled horizontally to meet increased demand without impacting performance or stability.
Datacentre resilience including physical redundancy, power, cooling, and network connectivity is managed by the hosting provider and aligns with ISO/IEC 27001, SOC 2, and CSA CCM standards. - Outage reporting
-
PhenoTips reports service outages directly to customers via email alerts and ticketing system notifications. In the event of an unplanned outage, affected users are notified with:
• Acknowledgement of the issue
• Ongoing status updates
• Estimated time to resolution
• Confirmation of service restoration
Outage communications follow predefined escalation procedures managed by the PhenoTips support team. For hosted deployments, outage impacts are also tracked internally via monitoring tools.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to PhenoTips management interfaces is restricted to authorised personnel using RBAC, least privilege, and MFA. Support access is time-limited, logged, and monitored. All access follows defined change and incident protocols.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- PhenoTips follows a structured, risk-based approach to security governance. Policies and procedures align with recognized best practices, including data minimization, access controls, audit logging, and regular penetration testing. The platform complies with NHS DSPT, GDPR, HIPAA, and Cyber Essentials Plus standards. Security responsibilities are assigned across the organization, and all deployments are monitored, reviewed, and supported by documented incident response and data protection protocols. Customers may request internal security documentation under NDA.
- Information security policies and processes
-
PhenoTips maintains a comprehensive set of information security policies covering access control, data protection, encryption, secure development, and incident response. These policies align with GDPR, NHS DSPT, HIPAA, and Cyber Essentials Plus standards.
Security oversight is led by the Data Protection Officer (DPO) and technical leadership team. Roles and responsibilities are clearly defined, with regular reviews and updates to security policies. All employees receive security training and must acknowledge adherence to the organisation’s security and privacy policies.
Compliance is enforced through:
• Regular internal audits
• Access reviews
• Activity logging
• External penetration testing
• Secure development lifecycle practices
Security incidents are escalated through a defined chain of command, with formal procedures for investigation, notification, and resolution. Customers may request policy documentation or details of security controls under NDA. - Software Security Code of Practice
- No
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- PhenoTips follows a structured change management process. Software components are version-controlled and tracked across their lifecycle. All changes are peer-reviewed, tested in staging, and approved before production deployment. Changes are assessed for security risk, logged, and monitored post-release. Rollback is supported.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- PhenoTips monitors multiple threat intelligence sources, including vendor bulletins, CVE databases, and NHS advisories. Internal scans and annual third-party penetration tests identify vulnerabilities. Threats are risk-assessed based on severity and impact. Critical patches are deployed within 24–72 hours; others follow structured change control. Updates are tested in staging before production release. The approach aligns with NHS DSPT and Cyber Essentials Plus (CE+) requirements. Underlying cloud platforms (AWS/Azure) provide continuous monitoring, infrastructure patching, and threat detection, further strengthening the platform’s security posture.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- PhenoTips uses continuous monitoring and alerting to detect unusual activity, system anomalies, and potential compromises. Logs from application, infrastructure, and access controls are collected and reviewed. Threats are assessed using predefined rules and threat intelligence sources. When a potential compromise is identified, the incident response plan is activated, including containment, investigation, and remediation. High-priority incidents are responded to within 1 business day, with customer notification as required. All incidents are logged, reviewed post-resolution, and reported in line with NHS DSPT and Cyber Essentials Plus requirements. Penetration testing and audit trails further support compromise detection.
- Incident management type
- Supplier-defined controls
- Incident management approach
- PhenoTips has pre-defined incident response processes covering common events such as data breaches, access violations, and service disruptions. Incidents are logged, triaged, and escalated based on severity. Users can report incidents via email or support ticketing. Each reported incident is acknowledged, investigated, and resolved following internal SLAs. Root cause analysis is conducted where applicable. Customers are notified of high-severity incidents and can request a formal incident report, which includes timeline, impact, actions taken, and mitigation steps. The process aligns with NHS DSPT, HIPAA, and Cyber Essentials Plus requirements.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 10%
- Between £250,000 and £500,000
- 12%
- Between £500,001 and £1,000,000
- 15%
- Between £1,000,001 and £2,500,000
- 20%
- Between £2,500,001 and £5,000,000
- 20%
- Over £5,000,001
- 20%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- B9c745fe-86c5-41dd-ba98-1bde1b6a9a2c
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- D6a78256-bba6-4a4b-9d87-3fa68ef7b765
- Other security certifications
- Yes
- Any other security certifications
- Data Security and Protection Toolkit (DSPT Organisation code: T4C4F)
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-