Cinapsis Photo Consult
Cinapsis Photo Consult allows patients, clinicians and other users to easily and safely capture images.
These are stored securely within our cloud based system and can be uploaded into EMIS Web, SystmOne and other platforms in order for them to be integrated with eRS and other systems.
Features
- Simple image capture using smartphones and other digital devices
- Secure image and data storage accessible from any device
- Patient Image upload facility and Patient Questionnaire Management
- Built to support AI
- Instant messaging
- Integrate with Electronic Medical Records
- NHS spine integration, HL7, FHIR
- NHS eRS integration
- Compatible with Windows, IOS and Android systems
- Option to include Virtual Consultations
Benefits
- High quality images ensures very low rate of rejection
- Improved security and storage of image capture
- Flexible options allow users to use shared or personal devices
- Enables patients to share images and data
- Very low image rejection rates
- Integration with NHS Spine ensures integrity of data
- Integration enables easy access to data from existing systems
- Enables remote management of patients
- Allows patients to be more involved in their care
- Option to deliver virtual video consultations if required
Pricing
£280 to £400 a licence a year
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 14
Service ID
7 9 3 6 0 7 1 3 5 2 5 2 1 5 4
Contact
Cinapsis
Dr Owain Rhys Hughes
Telephone: 0203 858 0124
Email: info@cinapsis.org
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
- There are no specific service constraints, Our software is designed to work with a huge range of devices / operating systems. However, in order for users to remain fully protected and in line with Cyber Essentials Plus we suggest that users utilise devices that run the most recent or previous major versions of their operating system.
- System requirements
-
- Processing speed equal or greater than 2GHz Intel or comparable.
- JavaScript enabled browser.
- Cookies enabled browser.
- Microsoft Office 2000 or later.
User support
- Email or online ticketing support
- Email or online ticketing
- Support response times
- We respond to all customer queries, regardless of priority, within 60 minutes during office hours or within 60 minutes of the start of the next business day if out of hours. Urgent, mission critical queries will be answered as a priority.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.1 AA or EN 301 549
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Web chat
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.1 AA or EN 301 549
- Web chat accessibility testing
- Formal testing scheduled in this financial year.
- Onsite support
- Onsite support
- Support levels
-
We provide a service level agreement to each customer committing to 99.9% availability as standard and prompt resolution of any issues.
Each customer has access to our support desk during office hours 9am until 6pm Monday to Friday as standard. High priority issues are identified and responded to 24/7/365.
Each customer also has access to a dedicated Customer Success Manager who offers ongoing support to ensure maximum benefit is achieved from our solution.
We also offer pro-active support in identifying sub-optimal activity or performance to ensure that the quality of cases remains high and patient care excels.
We support on-site and virtual training events to ensure that clinicians remain engaged and understand best practice. In addition we remain active with key users to reconfigure the system as required to ensure that maximum benefit is created for our users. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Users receive an invitation to onboard via email. They can complete the process themselves within 60 seconds.
This can be scaled quickly across an organisation or organisations at any scale and with any roles. - Service documentation
- Yes
- Documentation formats
-
- HTML
- ODF
- Other
- Other documentation formats
- Video tutorials
- End-of-contract data extraction
- At the end of the contract the customer organisation will be able to extract all data controlled by them through their administrator account.
- End-of-contract process
- We will provide the ability for the customer to extract all data they control from the system. Cinapsis will provide 1/2 days support to assist with this process if necessary. Additional support will be charged at our standard day rate.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Internet Explorer 11
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- MacOS
- Windows
- Windows Phone
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- All functionality is available via the app, web browser, and desktop toolbar that integrates with Primary Care patient record systems.
- Service interface
- Yes
- User support accessibility
- WCAG 2.1 AA or EN 301 549
- Description of service interface
-
Customers can view, edit and delete all clinical data as defined by Role Based Access Controls (RBAC) from the service interface.
Cinapsis PhotoConsult is configurable through the service interface. Local administrative users can manage RBAC for each user within their organisation.
Authority (ICB or similar) access is also available to help support and manage users across all organisations within their area. - Accessibility standards
- WCAG 2.1 AA or EN 301 549
- Accessibility testing
- Formal testing with users of assistive technology will be completed in this financial year.
- API
- Yes
- What users can and can't do using the API
-
Through our APIs customers can integrate with with GP Systems (EMIS & SystmOne), their Electronic Patient Record systems (EPRs) and Patient Administration Systems (PAS).
Business Intelligence reporting is also available via the API.
Cinapsis API's support HL7 & FHIR integration in to third party systems. Additional charges may apply for each non-standard interface. - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Cinapsis PhotoConsult can be customised in the following ways:
User roles and access to functions and data.
Reporting configuration and output.
Users are provided with a graphical interface for making these changes to the system. Any user with appropriate administrative permissions will be able to make these changes.
Scaling
- Independence of resources
-
Cinapsis servers are deployed as multi-machine clusters in a load-balanced fashion. User demand on Cinapsis SmartReferrals is continuously monitored and is responsively scaled horizontally by adding additional application servers to the cluster to handle request loads.
In the last 6 years, Cinapsis has provided >99.9% system availability for all of it's customers.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Cinapsis allows users to identify service metrics from within Cinapsis or by exporting data.
Users can flag images of interest that can be reviewed later for educational or training purposes as a team. Other metrics available include the number of users, organisation types and numbers, including those who are live or pending activation.
Reports can be created on demand by Cinapsis users. Cinapsis also provide support to users for reporting functionality. - Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Up to Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 3.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a Tigerscheme qualified provider or a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v3.0
- Physical access control, complying with SSAE-16 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Data sanitisation type
-
- Explicit overwriting of storage before reallocation
- Deleted data can’t be directly accessed
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v.30, CAS (Sanitisation) or ISO/IEC 27001
Data importing and exporting
- Data export approach
- Users with administration account permissions can export data from Cinapsis. Integration with our APIs for automatic data extraction is also possible.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- Excel
- Data import formats
-
- CSV
- ODF
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
System will be available 99.9% of the time.
If availability were to fall below this threshold over the lifetime of the contract, then service credits would be applied accordingly. - Approach to resilience
- Information available on request.
- Outage reporting
- A user dashboard and email alerts.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- 2-factor authentication
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Limited access network (for example PSN)
- Dedicated link (for example VPN)
- Username or password
- Access restrictions in management interfaces and support channels
- Management functions are controlled by the Role Based Access Controls (RBAC). Users are granted the minimum set of management roles to restrict actions and access to information.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- 2-factor authentication
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Limited access network (for example PSN)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2007 certification
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber essentials plus
- Yes
- Other security certifications
- Yes
- Any other security certifications
-
- Digital Technology Assessment Criteria (DTAC) Compliant
- Data, Security & Protection Toolkit (DSPT) standards exceeded
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
- Cyber Essentials certified by NCC Group. Cyber Essentials Plus certified. NHSX DTAC compliant. ISO 27001 certification pending.
- Information security policies and processes
-
We work to the standards of ISO27001. We are are registered with the Information Commissioners Office (ICO), staff receive annual Information Governance training and pass rates are established to ensure that all staff have an excellent understanding of their responsibilities to ensure that risks to data are recognised and understood. Cinapsis has completed the NHS Data Security and Protection Toolkit which mirrors the National Data Guardian, data security recommendations. We have demonstrated compliance with all mandatory security processes. In addition to exceeding the data security and protection toolkit standards, the company also has Cyber Essentials Plus certification.
We have a range of policies in place to ensure that at all times, our customers data remains secure and available, these include:
Disaster Recovery Policy
Business Continuity Policy.
Cinapsis is protected by Firewalls and antivirus software.
Data is encrypted in transit (TLS 1.3) and at rest (AES256). No data remains on personal devices and access to Cinapsis data is only possible via username and password with 2-Factor Authentication enabled by default.
Operational security
- Configuration and change management standard
- Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
- Configuration and change management approach
-
We work to the standards DCB0129 Clinical Risk Management: it’s Application in the Manufacture of Health IT Systems. We have appointed a Clinical Safety Officer and a Caldicott Guardian.
Each major version of our system undergoes internal testing and user acceptability testing before being deployed to production.
Customers will be provided with a DCB0129 Clinical Safety Case Report and Hazard Log. Cinapsis PhotoConsult is compliant with the NHS DTAC requirements, Cyber Essentials Plus and have exceeded all of the mandatory requirements for the NHS Digital Data Protection and Security Toolkit. - Vulnerability management type
- Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
- Vulnerability management approach
-
The company undertakes annual penetration testing, and test output identifies vulnerabilities. All vulnerabilities are evaluated and necessary protective measures are put in place.
All network devices are set to automatic updates. Our policy is not to go beyond two weeks before patches are applied from release.
The company receives alerts and updates via its anti-malware/virus service provider. The company is registered for MS-ISAC (https://www.cisecurity.org/ms-isac/) alerts and monitor the National Cyber Security Centre threat reports (https://www.ncsc.gov.uk/section/keep-up-to-date/threat-reports). - Protective monitoring type
- Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
- Protective monitoring approach
- The company’s virus checker alerts and reports on all threats identified. We also have a spam filter applied to all email traffic and we receive frequent spam reporting. Typically, all threats are managed automatically, via anti-malware/virus checker. In the case of critical patch notices, the IT manager ensures all devices receive security updates immediately. We apply an agile methodology to our work and would typically respond the same day to any incident.
- Incident management type
- Conforms to a recognised standard, for example, CSA CCM v3.0 or ISO/IEC 27035:2011 or SSAE-16 / ISAE 3402
- Incident management approach
- We work to the standards DCB0129 Clinical Risk Management. Under the Data Security and Protection Toolkit, we adhere to best practice under GDPR, and support customers with immediate notification on incidents/data breaches. Customers are provided with a incident reporting tool and incidents are escalated to: account manager, CEO and Data Protection Officer. This is communicated via our automatic systems and via email. The Data Protection Officer maintains a log of all incidents. As appropriate, the company records incidents within its risk register and records mitigations. All incidents are also reported to the customer's contract manager.
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
-
- NHS Network (N3)
- Health and Social Care Network (HSCN)
Social Value
- Social Value
-
Social Value
Fighting climate changeFighting climate change
Cinapsis is committed to actively supporting its NHS Commissioners, partners & providers to reach net-zero reduction targets of greenhouse gas emissions by 2030. We will support this achievement by helping NHS organisations to modernise the way they manage image capture options for clinicians.
Everything about Cinapsis is carbon neutral. Throughout our successful 5-year history of providing NHS contracts, we have delivered a huge shift from face2face OPD to A&G care (>200,000 cases to date) and significant numbers of images that are captured remotely from patients, or by clinicians without the data risk involved with using personal devices for image capture or the need to print images. Each new user onboarded onto Cinapsis & each image that’s captured by patients delivers a local carbon neutral benefit. We report on direct CO2 savings to each ICB for all activity to provide evidenced, high-impact steps towards reaching the NHS’s 2030 Net-Zero Greenhouse Emissions Plan.
Following appointment, in partnership with the customer we implement the following carbon reduction strategies & activities:
Provide an effective image capture solution that maximises care in Primary Care and streamlines the process of obtaining images, driving CO2 emissions saved by reducing travel by patients to their GP Surgery.
We co-produce with Commissioners an Environmental Sustainability Plan to guide on improvement activity & evidence carbon reduction progress against our targets to Commissioners. Mutually we will agree baseline carbon footprint metrics with Commissioners for Year 1 and agree new targets for each year of contract after. We will evidence our carbon reduction performance against mutually targets every year of contract thereafter.
Cinapsis Staff further protect the environment by:
Selecting local service suppliers with outstanding environmental credentials & emission reduction policies
Encourage use of cycling to walk/public transport for staff
Maximising use of Microsoft Teams for meetings & training sessions
Pricing
- Price
- £280 to £400 a licence a year
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
-
Full access to image capture from any supported device.
Does not include integrations into eRS, EMIS or SystmOne.
Access available for 14 days.