PRIMIS Primary Care Clinical Data Specification
Development, review and quality assurance of data specifications for reporting of data from GP clinical IT systems, to meet the requirements of a national programme (for example, the seasonal 'Flu Vaccination uptake Programme) or a specific customer requirement. Specifications consist of clinical code groups and logical business rules.
Features
- Tailored for local or national reporting or clinical requirements
- Clinical concept definition (RV2, CTV3, SNOMED CT)
- Expert knowledge of primary care clinical system environment
- Can be implemented across multiple clinical systems
- Plain English Definition of specification
- Clinical review and collaboration
- Formal version of specification - coded Business Rules
- Can be implemented across multiple data extraction tools
Benefits
- Access to expert clinical and health informatics advice
- Comparable returns from different clinical systems/ extraction mechanisms
- Shared understanding of what will be extracted
- Shared understanding of data outputs and returns
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
7 6 3 1 3 8 6 1 4 6 0 5 6 6 1
Contact
UNIVERSITY OF NOTTINGHAM (THE)
Kerry Oliver (PRIMIS)
Telephone: 0115 951 5151
Email: enquiries@primis.nottingham.ac.uk
About your service
- Service categories
-
Application Development and Deployment
Analytics and business intelligence
- Advanced and predictive analytics
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- This is part of the Primary Care Data Solutions service, but can be offered as a standalone service.
- Cloud deployment model
- Private cloud
- Service constraints
- None
- System requirements
- MS Office licence
User support
- Email or online ticketing support
- Yes
- Support response times
- Within 72 hours (Monday to Friday except Public Holidays and University of Nottingham closure days)
- User can manage status and priority of support tickets
- No
- Phone support
- No
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- We provide an email helpdesk service, supported by remote dial-in facilities. We provide customised training and consultancy services. The service will have a nominated project manager who will coordinate the input from PRIMIS clinical and technical teams. The project manager will agree a reporting schedule with each customer and will involve the appropriate members from the clinical and technical teams as required. All costs are dependent upon requirements and charged according to the Rate Card.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Customers can begin using the service quickly through a structured, transparent onboarding process designed to ensure a smooth transition into live use. All onboarding activities are delivered within our ISO 9001‑certified Quality Management System, ensuring consistency, auditability, and continuous improvement.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
-
- MS Word
- MS Excel
- End-of-contract data extraction
-
When the contract ends, users retain full control over their data. We provide a structured, secure process to ensure all customer data can be extracted, transferred, or retrieved without disruption. All activities follow documented procedures within our ISO 9001‑certified Quality Management System.
Where relevant, we provide specification files, code sets, configuration documents, or metadata required for continuity of service.
A named contact is available to support users through the extraction process. - End-of-contract process
-
At the end of the contract term, a structured and compliant closure process is followed to ensure continuity, transparency, and orderly transition. All activities are delivered within an ISO 9001‑certified Quality Management System, ensuring they are monitored, documented, and continuously improved.
This includes service wind-down, data management, knowledge transfer, financial closure, reporting and governance and post-contract obligations. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
Our onboarding and offboarding documentation is designed to be fully accessible, easy to navigate, and compliant with recognised accessibility standards. All materials are produced and maintained within our ISO 9001‑certified Quality Management System, ensuring consistency, version control, and continuous improvement. Documentation is provided in clear, structured digital formats that are compatible with common assistive technologies.
Content is written in plain English, following best‑practice guidance for readability and comprehension.
Documentation is shared through secure, user‑friendly channels agreed with the customer during onboarding.
Users receive clear instructions on how to access, download, and store the materials.
Version‑controlled updates ensure customers always have access to the latest approved documentation.
A named contact is available during onboarding and offboarding to support users with any accessibility queries.
Feedback on accessibility is reviewed as part of our ISO 9001 continuous improvement process.
Using the service
- Web browser interface
- No
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- No
- User support accessibility
- None or don’t know
- API
- No
- Customisation available
- Yes
- Description of customisation
- The service scope is agreed with the customer in advance and can be adjusted subject to appropriate change control.
Scaling
- Independence of resources
-
Demand on this service is not volatile and is monitored on a regular basis to ensure availability.
Capacity planning, performance management, and service monitoring are delivered within our ISO 9001‑certified Quality Management System.
This ensures consistent oversight, documented procedures, and continuous improvement. Capacity is continuously monitored, and additional resources are provisioned proactively to maintain service levels.
Analytics
- Service usage metrics
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Supplier-defined controls
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- Practices export their data using the search and report functionality within their GP IT systems. The aggregate data is exported to PRIMIS as a CSV file using a variety of means, including via NHS mail and upload during a remote dial in session using NHS Remote Access facilities.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- Availability will be agreed with the buyer during project mobilisation. We will use reasonable endeavours to provide advance notice of any scheduled maintenance or planned downtime, and to minimise both the frequency and duration of any service suspension or restriction.
- Approach to resilience
-
Our service is designed to be resilient, secure, and fully aligned with National Cyber Security Centre (NCSC) cloud security principles. The technical architecture is built to maintain continuity and withstand faults, cyber threats, and fluctuations in demand. Core components are deployed without single points of failure, supported by redundancy and automated failover to ensure the service remains available even if individual elements are disrupted.
Continuous monitoring provides real‑time visibility of system health, performance, and potential security threats. Alerts enable rapid response to emerging issues, helping prevent incidents from escalating. Capacity and performance are actively managed, with resources scaled proactively to maintain stability during peak usage.
All updates, patches, and configuration changes follow a controlled, documented change‑management process aligned with NCSC best practice. This reduces the risk of service impact and ensures updates are tested before deployment.
Business continuity and disaster recovery arrangements are in place to support rapid restoration of service following a major incident. These plans are reviewed and tested regularly to ensure effectiveness.
Change and incident management processes are delivered within our ISO 9001‑certified Quality Management System, ensuring consistent application, auditability, and continuous improvement across the service lifecycle. - Outage reporting
-
University of Nottingham IT Service Service Status public dashboard - https://status.nottingham.ac.uk/
Email alerts and via the PRIMIS website.
Identity and authentication
- User authentication needed
- No
- Access restrictions in management interfaces and support channels
- Configuration and management operations are performed by members of the University's Digital Technology Service only. Support is provided by members of the PRIMIS team. Privileged access is strictly limited to individuals who require it as part of their role.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
-
Cyber Essential Certification. Certificate ID f1b363f5-8cfa-4513-bb0c-bde93ba6fe86
Cyber Essentials Plus Certification. Certificate ID e83ea192-88f1-4259-ba1f-9a48d2d14546. - Information security policies and processes
-
The University of Nottingham has a structured governance framework to ensure information security is managed effectively and incidents are reported through the correct channels. The University’s Information Security Policy and related processes are available at:
https://www.nottingham.ac.uk/governance/records-and-information-management/policies-and-guidance/policies-and-guidance.aspx
Key Roles and Responsibilities
Chief Information Security Officer (CISO) - leads the creation, maintenance, and enforcement of the Information Security Policy and oversees incident response and manages major information‑security breaches.
Chief Digital Officer (CDO) - accountable for the oversight and management of all digital services and ensures appropriate security measures are in place to protect University systems and digital resources.
Head of Cyber Security - responsible for securing University‑owned systems, including hardware, software, networks, and devices and provides operational cyber‑security leadership and technical controls.
Information Management and Security Steering Committee (IMSSC) - oversees the implementation, performance, and ongoing maintenance of the Information Security Policy, and provides governance, assurance, and strategic direction.
Faculty Pro‑Vice Chancellors and Directors of Professional Service - accountable for the security of information and systems within their faculty or department and ensures local compliance with University policies and reporting requirements.
Senior Information Risk Owner (SIRO) – Managing Director of PRIMIS acts as SIRO for PRIMIS. - Software Security Code of Practice
- No
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- PRIMIS uses the University of Nottingham's request form template which sets out the title, description and level of proposed change, interruption to services, risk level and impact, start/end dates, communications and testing required, back-out-plan, approvals and sign-offs. This process is fully managed within the PRIMIS ISO 9001‑certified Quality Management System, ensuring consistent application, documented controls, and auditable governance throughout.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
The University operates a proactive, risk-based vulnerability management process designed to identify, assess, remediate and monitor security vulnerabilities across our services, infrastructure and supporting systems.
Daily monitoring of software vendor feeds and other security vulnerability news feeds to identify issues that may affect University systems.
Monthly scans and key IT systems. Annual external perimeter penetration test with remedial plans put in place.
All vulnerabilities are remediated based on the risk they pose to the University network using a CVSS (Common Vulnerability Scoring System) to drive the required remediation timescale. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Systems which contain restricted data or which can perform sensitive or business-critical actions have logging capabilities enabled in order to monitor both successful and unsuccessful access. The Information Security Policy defines what should be logged, the required minimum dataset, which should be retained for 12 months. Log reviews take place manually and via automated alerts to detect suspicious activity, failure of security controls, unauthorised use or access, exfiltration of critical data and unauthorised changes to security settings or configurations. Issues identified are handled using a scoring system that drives the required remediation action.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Staff and students are signposted to report any data breaches or potentially malicious incidents via an online portal, and are required to undertake annual training, and the process for incident reporting is covered. The incident is either cascaded to the University IT Security team or the Information Compliance Team (if data breach). Standardised online forms are used. The University uses iCasework to record incidents, which allows for automation of processing, streamlining, and the consistent management of incidents and management reports to be generated and provided. Incident management processes are delivered within our ISO 9001‑certified Quality Management System.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
- Health and Social Care Network (HSCN)
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- BSI
- ISO 9001 accreditation date
- Tuesday 7 January 2025
- What the ISO 9001 doesn’t cover
- The certificate covers the PRIMIS service only and relates specifically to the provision of health informatics support and applications (covering the three services offered).
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- F1b363f5-8cfa-4513-bb0c-bde93ba6fe86
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- E83ea192-88f1-4259-ba1f-9a48d2d14546
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Ensuring new workers are informed of their right to join a trade union
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
- How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
- How the supplier will work with NGOs, trade unions or other businesses to address modern slavery risk
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Introducing transparency to pay and reward processes
- Working conditions which promote an inclusive working environment and promote retention and progression
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-