Vyne Online
Vyne Online is a secure SaaS platform enabling healthcare professionals to register patients and order prescribed medical devices digitally. Used in acute discharge and community settings, it supports continence, urology, ostomy, and wound care pathways, streamlining workflows, improving accuracy, and accelerating access to essential products across NHS services nationwide safely.
Features
- 24/7 web-based access for patient registration and prescription device ordering
- Standardised Search simplifying ordering by filtering to approved formulary products
- Real-time order tracking from submission through prescription to delivery confirmation
- Patient account providing visibility of orders, history, and delivery status
- Rapid patient self-reordering functionality with minimal clicks and validation checks
- Bespoke Insights dashboards covering compliance, usage trends, and carbon reporting
- Bridge referral tools linking acute discharge process to community teams
- Built-in messaging with Customer Care team for order queries
- Near real-time StockChecker displaying product availability before ordering decisions
- Team-based accounts enabling shared access to patients and order histories
Benefits
- Register patients and place orders anytime, reducing delays and administration
- Quickly find correct products, reducing errors and improving prescribing confidence
- Track orders end-to-end, improving traceability, accountability, and service transparency overall
- Empower patients with visibility, supporting continuity of care and self-management
- Enable fast patient reordering, reducing inbound calls and administrative workload
- Access actionable insights to support compliance, optimisation, and sustainability reporting
- Prevent patients being lost between settings through integrated acute-to-community referrals
- Resolve queries faster through direct messaging with dedicated Customer Care
- Save clinician time, averaging seven minutes per registration versus telephone
- Improve team collaboration through shared records, reducing duplication and miscommunication
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
7 9 9 3 2 0 5 2 1 5 4 9 1 2 6
Contact
OPTIMUM MEDICAL SOLUTIONS LIMITED
Thomas Bailey
Telephone: 07776154526
Email: tenders@optimummedical.co.uk
About your service
- Service categories
-
Applications
Customer relationship management
- Customer service
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
-
The Vyne Online app is limited to iOS version 15 and above, and Android version 7 and above.
The Vyne Online website will run on all modern web browsers, including mobile browsers. - System requirements
- Modern web browser (e.g. Chrome, Edge, Safari, Firefox)
User support
- Email or online ticketing support
- Yes
- Support response times
- Contact us via email and we will respond within 24 hours during business days.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes
- Support levels
-
During project setup an implementation manager can be made available to assist with user training and web browser or device setup.
This will depend on agreements within the contract. - Support available to third parties
- No
Onboarding and offboarding
- Getting started
- We support users through a structured but flexible onboarding approach. This includes onsite and remote training, supported by clear user documentation, step-by-step guides, and recorded walkthroughs. Training can be delivered one-to-one, in groups, or via onsite drop-in sessions to accommodate clinical schedules.
- Service documentation
- No
- End-of-contract data extraction
-
Patients and clinicians may continue to use the Vyne service regardless of the contractual status of an NHS trust or ICB. Therefore, patient and clinician data is stored in-line with the GDPR and removed from Vyne systems as per the stated requirements.
However, in-line with GDPR requirements, a patient or clinician can request a copy of their data or that their account be removed from the Vyne systems.
It is worth noting that the data shared with Vyne will continue to be available after the contract ends because access to the service will not be terminated. Modules may be disabled, but access to patient and order data will continue to be available to the registered users.
Additionally, data is shared with the contracted users on a regular basis through the Insights module. - End-of-contract process
-
The Vyne Online contract allows access to all modules available within the Vyne service, including, but not limited to:
Standardised search (aligning product selection to formulary)
- Bridge (referring patients to the community)
- Messenger (allowing clinicians to contact customer care)
- EPR integration (integration with an electronic patient record service such as Epic or Oracle Health)
The contract also includes, as required by the contracting authority, access to an implementation manager who will carry out initial scoping and training needs.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
When running as a website the service is identical between mobile browser and desktop browser. There may be some layout differences to adapt to a smaller screen, but otherwise the functionality and behaviour are consistent across mobile and desktop.
The Vyne Online mobile app, available on iOS and Android, has identical functionality as the browser based service, but again the layout will be different to align with design expectations of a mobile app (e.g. button bar at the base of the screen). - Service interface
- No
- User support accessibility
- None or don’t know
- API
- No
- Customisation available
- Yes
- Description of customisation
-
Individuals can configure security controls that include:
- 2-factor authentication via an authenticator
- Screen lock to hide entered details from people nearby
Additionally, Clinicians that are registered on the service can choose to be part of a Vyne Online Team allowing shared ordering functionality.
There are multiple modules available that can be enabled or disabled for a Vyne Online Team, including:
- Standardised search (aligning product selection to formulary)
- Bridge (referring patients to the community)
- Messenger (allowing clinicians to contact customer care)
- EPR integration (integration with an electronic patient record service such as Epic or Oracle Health)
Modules can only be enabled or disabled by Vyne Online support. Clinicians cannot action module changes themselves.
Scaling
- Independence of resources
-
The Vyne Online service includes intelligent data caching so that the user has quick access to their data at the edge.
Additionally, data requests are monitored to ensure service standards are maintained.
Finally, for all data submissions to Vyne Online, the service will only show a success message to the user when all data has been fully stored and validated on the back-end systems.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Vyne Online provides comprehensive service usage metrics through configurable Insights reports. Metrics include staff usage, formulary compliance, patient ongoing usage, product trends, and operational performance such as order processing and delivery times. Financial metrics cover cost savings achieved through formulary compliance, year-on-year and month-on-month prescription spend. User experience metrics include patient and customer feedback. Environmental metrics report estimated carbon emissions associated with ordering activity. Reports can be provided daily, weekly, or monthly, with near real-time dashboards in development.
- Reporting types
- Regular reports
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
- Physical access control, complying with SSAE-18 / ISAE 3402
- Data sanitisation process
- No
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data importing and exporting
- Data export approach
-
There is no facility for users to export their data other than the provisions provided for in GDPR.
This is to restrict security risk due to the storage of patient information that must not be shared any wider than required.
If there is a compelling use case to allow data export then it will be strongly considered, but currently no such use case has been suggested. - Data export formats
- Other
- Other data export formats
- N/A
- Data import formats
- Other
- Other data import formats
- N/A
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- N/A
- Approach to resilience
-
Vyne Online uses the Oracle cloud with the resiliency naturally built into the platform, including the highly scalable Autonomous Database.
Data is stored at rest in the Oracle NetSuite system with the resiliency naturally built into that platform.
We do not store or process any data on-premises. - Outage reporting
- Email alerts will be sent to the contracting authority for prolonged outages.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
-
Registered clinicians and patients will only be able to see the data that they have entered. If a clinician has registered through an email address that is not verified then they will only be able to view the last 90 days of orders.
Clinician email addresses need to be re-verified every 90 days to ensure they still have access to the email account.
Vyne Online Teams have designated admins who invite other clinicians to their Team. Admins can remove clinicians from the Team at any point. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- Less than 1 month
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- Less than 1 month
- How long system logs are stored for
- Less than 1 month
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
-
War games carried out annually to review security protections in place across the business
Monthly automated penetration testing against company endpoints and website, and annual CREST certified penetration test.
Healthcare IT system risk management process with hazard log approved by Clinical satefy officer (CSO).
Data breach policy in place and trained to all employees.
Private repository for code with controlled access.
All code reviewed by development team before PR merge.
Third-party plugin vulnerability scanning on releases.
Role based access to code and deployment processes. - Information security policies and processes
-
We follow the Healthcare IT system approach which includes:
- A risk management system
- A hazard log
The hazard log is reviewed quarterly, or on a major functional update, by interested parties including the clinical safety officer.
Full data breach policy in-line with GDPR requirements - Software Security Code of Practice
- No
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
All code changes must be code reviewed before release.
Weekly automated penetration testing is run against the latest code.
Test plans are followed for each major release.
Code is developed in-house, reducing security concerns.
Quarterly hazard log reviews with the clinical lead are carried out as per the Healthcare IT systems guidance, and before major functionality changes. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Vulnerability scanning is run on software dependencies before each release.
Oracle CloudGuard is run regularly to check the cloud security posture and vulnerabilities.
Local device scanning is performed to ensure vulnerable software is not running on developer devices. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Oracle Cloud Guard is run regularly to check the cloud security posture and vulnerabilities.
Weekly automated penetration testing is run against the Vyne Online service.
Critical security issues are resolved within 72 hours where possible.
High security issues are resolved within 14 days where possible.
Other security issues are assessed and resolved as required. - Incident management type
- Supplier-defined controls
- Incident management approach
-
Automatically discovered incidents that were discovered on a client device are raised through our Sentry system
Automatically discovered incidents that occurred in our cloud will raise a case on our NetSuite case management system
Incidents reported by contracted users of the Vyne Online system will be logged in our NetSuite case management system. Incidents are reported via email.
Updates will be sent to users via email. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
-
The Vyne Online service is available to all patients, clinicians and care homes using direct registration from the website or through the iOS and Android apps.
The Vyne Online Teams functionality is available as part of this direct registration, but module enablement is restricted to contracted services. - Link to free trial
- https://px.vyne.co.uk
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 11b1d111-8c71-4b08-9e76-fe502d5703f5
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- D10d6a69-09ff-4c93-8dfd-ef99fea2f742
- Other security certifications
- Yes
- Any other security certifications
- Data Security and Protection Toolkit
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-