Dragon Medical One (DMO) AI-Powered Speech Recognition
Cloud-based clinical speech recognition for documenting care in the EPR.
Dragon Medical One (DMO) is a cloud-based, GDPR-compliant speech recognition solution that enables clinical documentation to be completed from any location. It allows clinicians to use their voice to securely capture the patient story more naturally and efficiently-anywhere, anytime.
Features
- AI-driven clinical speech recognition with accuracy up to 99%
- Medical dictionary including over 60 specialty and sub-specialty topics
- No speech profile training required
- Supports dictation into EPR's, clinical and non-clinical Windows applications
- Installs in minutes on any clinical workstation or laptop
- Supports enterprise deployments through virtual environments with thin-zero clients
- Built-in analytics provide usage and adoption dashboards and user metrics
- Speech-related data securely communicated over 256-bit encryption channels
- PowerMic app turns clinician’s Smartphone into a secure wireless microphone
- Supports customised vocabulary, auto-texts and voice commands
Benefits
- Doctors are more productive with fast, accurate, and responsive dictation
- No speech profile training ensures optimal clinician experience immediately
- More complete narratives mean improved decision-making and quality of care
- Compatible with all leading EPRs; designed with virtualisation in mind
- Easy to install and maintain: one-click installation and automatic updates
- Budget-friendly: Affordable subscription-based pricing with little up-front capital investment
- Healthcare compliant hosting that supports security demands of the NHS
- Access to data, analytics, and insights to inform better decisions
- Flexibility to use your smartphone as a microphone
- Consistent documentation process is personalised across platforms & devices
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 0 2 8 8 2 4 9 8 0 6 6 1 2 4
Contact
CRESCENDO SYSTEMS LIMITED
John Bendall
Telephone: 01932 789433
Email: admin@crescendosystems.co.uk
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- No constraints other than technical specifications.
- System requirements
-
- 32-bit: Microsoft Windows 10
- 64-bit: Microsoft Windows 10 and Windows 11
- 64-bit: Microsoft Windows Server 2016, 2019 and 2022
- Microsoft .NET Framework 4.7.2 (or higher)
- Minimum processor speed: 1.7 Ghz, Recommended: 2.8 Ghz
- Minimum RAM: 512 MB, Recommended: 2 GB
- Network latency < 50ms
- Web Browser: Microsoft Edge & Google Chrome
- Port Communication: Ports 443
- Microphone: Android/iOS Smartphone, or Nuance approved microphone
User support
- Email or online ticketing support
- Yes
- Support response times
-
Support is available Monday to Friday 9am to 5pm, out of hours support available at an additional charge.
Response time depends on SLA level.
For level I
Emergency and level 2 urgent situations Crescendo offers a one-hour response to support calls.
For level 3 faults Crescendo will respond within four hours and for level 4 faults response time will be
within one business day. - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 A
- Web chat accessibility testing
- No direct testing but chat is used by customers on a daily basis.
- Onsite support
- No
- Support levels
-
Crescendo Support Services are included within the (Annual/Monthly)
Dragon Medical One (DMO) Subscription Fee.
The DMO solution is supported by Crescendo’s full time technical support team who operate the
Customer helpline and support centre in the UK. The technical support team’s normal hours are Monday-Friday, 9am-5pm GMT
Crescendo SLA:
Crescendo also extends industry-standard 24 x 7 emergency support to its customers. For level 1 Emergency and level 2 urgent situations Crescendo offers a one-hour response to support calls. For level 3 faults Crescendo will respond within four hours and for level 4 faults response time will be within one business day. - Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
Prior to a customer purchase we provide online or onsite demonstrations to familiarise the organisation with the service features.On receipt of a PO we co-ordinate delivery of the software with the Clients IT team, checking specification and any other relevant factors.
In parallel, we will liaise with the project team to ensure that goals are achieved and that workflow is consistent with the organisations expectations. Planning Services include project management activities such as definition and management of project goals; development and tracking of implementation plans; training plans and scheduling; change management; managing and driving resolution of issues log; regular status calls and post training follow up activities; strategic alignment to make sure the project is aligned to the organisational goals. Once the software is delivered we offer both onsite and online training modules, dependent upon the customers requirement (this can also include a Train-the-Trainer course if the client wishes to train internally). Online training cost £150 + VAT per 2 hour module, Onsite training £650 + VAT per day and a 3-day Train-the-Trainer at £1950 + VAT. We also supply electronic 'Quick Start' training materials at no extra cost. - Service documentation
- Yes
- Documentation formats
-
- Other
- Other documentation formats
- Video
- End-of-contract data extraction
- When a contract terminates all user data is deleted. There is no requirement to extract the data as this was simply the audio to create the text which is not kept in the system for future reference. The resultant text remains stored in the customer's EPR or other clinical system.
- End-of-contract process
-
Upon termination of the contract the organisations users no longer have access to the speech recognition software, DMO, (and microphones if bought on subscription) and would not be able to use the software to dictate in to their computer.
The contract price includes the access to the software and the updates during the contract period, all of which ceases at the end of the contract. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
All documentation is available electronically and supplied directly to customer.
There is also documentation available from CrescendoSystems website at https://crescendosystems.co.uk/support-guides/
Using the service
- Web browser interface
- No
- Application to install
- Yes
- Compatible operating systems
-
- MacOS
- Windows
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- The interface is a simple, small menu bar (Dragon Tool Bar) which displays a microphone icon to show user whether it is on or off, together with a drop down list of features and help menus. The Dragon tool bar can be moved or hidden.
- Accessibility standards
- None or don’t know
- Description of accessibility
- Dragon Medical One isn't typically certified as WCAG, but it supports accessibility and helps users meet WCAG/accessibility goals by enabling voice control for systems, letting users dictate, navigate, and code hands-free, which is crucial for users with disabilities or needing workplace adjustments under laws like the Equality Act 2010.
- Accessibility testing
- We provide Dragon Medical One Speech Recognition to a wide variety of users who require assistive technology. Examples of these include Access to Work, DSA schemes and 'Reasonable Adjustments' requests.
- API
- Yes
- What users can and can't do using the API
- The API is designed for healthcare IT partners and developers to embed speech recognition and AI capabilities into their own applications and Electronic Health Record (EHR) systems
- API documentation
- No
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
-
The solution can be customised to suit end users workflow and documentation requirements through the implementation of autotexts and step-by-step commands.
AutoTexts:
Customised voice commands which allows the user to insert frequently used text into their documents. These can also be customised with variable fields which allow the clinician to dictate information into specific fields. Fields can also contain default values and can be amended on a case by case basis.
Step-by-step commands:
Customised macros that can be setup into a users profile. You can start with simple commands to do things like insert text, open a document or program and even combine them into more advanced functions.
AutoTexts and step-by-step commands can be setup and customised by end users and system administrators.
Scaling
- Independence of resources
- This is a highly scaleable solution, housed in a secure UK Microsoft Azure data centre environment, which enables thousands of users from single organisations to be active on the system concurrently.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
The customer has access to DMO's built-in administration, analytics and insights, a web-based admin portal that simplifies system management and offers data insights to ensure doctors are using the solution as effectively as possible.
DMO feeds data into an analytics portal so the organisation can make more informed decisions. This comprehensive portal provides access to an intuitive dashboard that displays key metrics and trends, like active users, hours of audio and peak usage. Usage details allow you to drill down to user level utilisation statistics to provide a good indicator of individual user efficiency, voice command usage, AutoText usage, etc. - Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- Microsoft Nuance
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Not necessary. The textual data generated by the software is created directly into the customers systems/applications so no export is necessary.However, some user details and analytics can be exported as a csv file if needed.
- Data export formats
- Other
- Data import formats
- Other
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- 24/7 365 days a year. Microsoft Azure Data Centre provides up to 99.95% availability.
- Approach to resilience
- Microsoft Azure UK regions (UK South, UK West) with Availability Zones for high availability, redundancy, and disaster recovery.
- Outage reporting
-
We developed a real-time Service Status Page to provide more transparency to our end users/IT administrators in the event of a service disruption. The page shows an up-to-the-minute status on the health of our Dragon Medical Cloud services. In the event of a service disruption, administrators and users can go to this page to review the services affected. We encourage users to bookmark the status page URLs:
UK: https://status.uk.dragon.com/
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Username or password
- Other
- Other user authentication
- Active Directory Authentication
- Access restrictions in management interfaces and support channels
-
Via username and password.
- Nuance enforces two-factor authentication/jump hosts. When accessing the data centre, all Nuance employees are required to use two-factor authentication. In addition, all production access is via an intermediate “jump host,” which provides an extra level of insulation.
– Nuance has deployed Trend Micro anti-virus to proactively protect the Nuance cloud services from virus or malware infection.
– Intrusion detection and protection system (IDPS). Nuance leverages Trend Micro’s IDS solution, which examines every packet that is transmitted to the data centre for potential irregularities. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Limited access network (for example PSN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- Between 1 month and 6 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- Between 1 month and 6 months
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- CSA CSM version 4.0
- ISO/IEC 27001
- Information security policies and processes
-
Nuance (a Microsoft company) operates a "defense-in-depth" security strategy, ensuring Dragon services meet rigorous UK public sector standards.
Technical Controls:
Encryption: Data is secured in transit via HTTPS/TLS 1.2+ (256-bit AES) and at rest using Azure Storage Service Encryption (SSE) and SQL Transparent Data Encryption (TDE).
UK Sovereignty: Cloud services (e.g., Dragon Medical One) are hosted in UK-based Microsoft Azure data centers, ensuring compliance with UK GDPR and Data Protection Act 2018.
Identity Management: Supports Multi-Factor Authentication (MFA) and Single Sign-On (SSO). Administrative access uses secure "jump hosts."
Governance & Compliance:
Certifications: Maintained standards include ISO 27001, ISO 27017, ISO 27018, SOC 2 Type II, and Cyber Essentials Plus.
Healthcare Standards: Fully compliant with the NHS Data Security and Protection Toolkit (DSPT) and DCB0129 accreditation.
Secure Development: Follows a Secure SDLC (Microsoft SDL), including threat modeling and static code analysis.
Operational Assurance:
Vulnerability Management: Weekly automated internal/external scans and annual third-party penetration testing.
Resiliency: Active/active configurations across redundant regions provide 99.9% availability.
Monitoring: 24/7 security operations center (SOC) monitoring with integrated intrusion detection (IDPS). - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Dragon Medical One follows a well-defined change management process for handling changes within the production environment. Updates are carefully tested before being applied to the data centre. These updates undergo pre-testing in an external environment to ensure compatibility. Additionally, all changes made to the live environment are internally monitored and tracked to ensure any issues are quickly identified and resolved.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Vulnerability scans and penetration tests are performed. Vulnerability scans are done weekly, the results are evaluated, and corrective actions are taken based on risks. Certified third-party penetration tests are performed annually. Microsoft Azure provides denial of service and intrusion detection and performs routine penetration testing. System monitoring is in place and leverages internally developed tools as well as industry standard tools. Alerts generated by these tools are routed to pagers, which are covered 24x7 by Nuance Data Center Operations staff.
All aspects of the Solution are within the scope of penetration tests. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- System state is monitored 24/7 by our Site Reliability Center (SRC). SRC monitors MS Azure via a tool called System Center Operations Manager (SCOM). Microsoft Network Monitoring is utilised to detect changes in network loss, latency, and the availability of devices in Nuance’s network topology; SRC monitors these alerts. Monitoring includes virtual machines and storage. Heartbeat monitoring is used to monitor remote hosts. Microsoft Azure monitoring provides denial of service and intrusion detection and performs routine penetration testing. Alerts generated by tools are automatically routed to mobile phones which are covered 24x7 by Nuance Data Center Operations staff.
- Incident management type
- Supplier-defined controls
- Incident management approach
- The Nuance Critical Incident, Privacy and Security Event Response Process specifies the actions to be taken in the event that a new threat is detected, an attack is attempted or a breach is detected. The Healthcare Critical Incident management process is a cross functional initiative to realize a step change in the strategic planning of critical incidents through standardisation and adoption across Global Healthcare Operations. There are Incident Managers that serve as the single process owner and one consistent status provided to customers. Incident Managers cover 24/7, 365 days a year coverage.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
- Health and Social Care Network (HSCN)
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
-
30-day trial of software for up to 10 users (licenses).
Online training overview and trial support included but individual training is an additional cost. Trialists may need to purchase a microphone - Link to free trial
- https://crescendosystems.co.uk/free-trial/
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 5.0%
- Between £250,000 and £500,000
- 5.0%
- Between £500,001 and £1,000,000
- 10.0%
- Between £1,000,001 and £2,500,000
- 10.0%
- Between £2,500,001 and £5,000,000
- 20.0%
- Over £5,000,001
- 20.0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- E14bfe8a-e51a-4494-a377-8c82e6e01d49
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
-