Digital Dictation, Speech Recognition, Outsourced Transcription, and AI solutions
We are a UK based provider of digital dictation, outsourced transcription, speech recognition and AI solutions, supplying NHS customers since 2003. Our solutions are applicable to all healthcare settings including GP practices, pharmacies, acute hospitals, mental health trusts and many more.
Features
- 99% accurate speech recognition
- Fully cloud based
- Solutions exceed standard NHS security requirements
- Integrates with existing equipment
- Real-time dictation and summarisation
- Retain existing individual workflow
Benefits
- Reduced admin burden
- Dictate anywhere
- Speeds up clinical and secretarial day-to-day tasks
- Enhanced document quality
- Frees up time for patients
- Improves Letter Turnaround Times
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 8 2 2 8 5 7 2 7 3 3 1 1 6 0
Contact
DICTATE IT LIMITED
Tenders@dictate.it
Telephone: 0203 307 1500
Email: Tenders@dictate.it
About your service
- Service categories
-
Application Development and Deployment
AI platforms
AI software services
- Conversational AI Software Services
- Generative AI Software Services
- Document AI Software Services
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
- None
- System requirements
-
- Web based application runs on modern browsers
- Optional Windows desktop component
User support
- Email or online ticketing support
- Yes
- Support response times
- Within 24 hours
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- None or don’t know
- How the web chat support is accessible
- Chat bot available online from website. Direct connection to a human within the support department. Users can discuss technical issues, functionality questions, training and updates on currently open support cases.
- Web chat accessibility testing
- Testing with limit customers that require AT. Speech recognition is supported within the chat application, for example.
- Onsite support
- No
- Support levels
-
Support costs are built into the customer contract and SLA is bespoke to each customer's requirements.
Support is available for unlimited (non P1) third-line support queries such as network functioning problems, system problem and system modifications from 08:00 – 17:30, weekdays, including bank holidays. Support cases raised outside these hours will be automatically logged ready for action the following day. The helpdesk work to KPIs that include resolving 80% of in-scope cases in 24-hours and 100% of in-scope cases in 72-hours of receipt. This is measurable and reportable.
Support agents are all ITIL certified and experienced in all aspects of the system. Each customer is allocated an account manager and has access to the customer support manager for escalations.
Dictate IT categorise each support case by Priority levels, based on severity (1-5). P1/P2 are classed as HIGH with response time within 1hr and resolution within 4 hours, as an example.
Dictate IT’s monitoring software will automatically alert the production support team if it detects any critical incidents affecting the availability of the platform. Out of hours, the receiver of the alert will validate whether the alert is a P1 critical issue and will then invoke the critical incident process. - Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
- We offer onsite training, online training. Also customised User Guides and a e-learning platform which includes videos and feature cards.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
-
- Word
- Powerpoint
- End-of-contract data extraction
- Request is put to our IT team as the contract is ending, which is then discussed in terms of method of extraction, where it needs to be sent to etc.
- End-of-contract process
- Archive data is still available via the platform and will deleted when the contract has ended. Dictate.IT will provide a copy of the data, if requested, prior to deletion.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Users can access the e-learning platform within the product itself or via a separate URL
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Windows
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- All core functionality is available by the mobile application.
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- The service interface is used by end user and administrative users use and manage the application. There are multiple service interfaces including web, mobile and desktop applications which the user can choose is the most suitable for them.
- Accessibility standards
- None or don’t know
- Description of accessibility
- The service is regularly tested against industry standard tools (such as Lighthouse for web applications), and these outcomes are fed into the application development process on an ongoing basis.
- Accessibility testing
- The application development process supports a UAT phase for each release and where our users have access to test and raise any issues found during interface testing.
- API
- Yes
- What users can and can't do using the API
-
There are variety of APIs available with this service. These range from Active Directory integration to support user management, patient and demographic data feeds to support patient specific document creation and variety of APIs that support the export of data from the application to downstream systems such as EPR, EDMS, etc.
Additionally the core speech recognition and AI services are also available as APIs to facilitate integration with a customers own workflow solution. - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- There are a variety of customisations available within the application which are available via the customer administration site with many of these optionally available for individual users to customise themselves. Typical customisations include organisational structures, user management, letter templates, workflows, AI templates, UI preferences, available services, organisational/user defined canned text, keyboard shortcuts, etc.
Scaling
- Independence of resources
- Application usage and resource demand is monitored via a variety of tools that give real time and historical trend analysis. The application is deployed with a 50% tolerance for forecast demand and where appropriate, automated autoscaling capabilities are enabled to react to real time increases in unforecasted demand.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Reporting Platform includes -
- Turnaround Times
- Admin Productivity
- Letter and Distribution Statuses - Reporting types
-
- API access
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- Our approach is to remove the need for users to export their data by integrating with required 3rd party applications to automate this process to reduce administrative overhead and reduce data transfer risks. We have extensive experience in this area and have integrated with a variety of 3rd party systems to achieve this.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- XML
- JSON
- DOCX
- TIF
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- HL7
- XML
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- SLA guarantees system availability: Available 99.9% of time
- Approach to resilience
-
All our services are GDPR and ISO 27001 accredited. This ensures the service resilience deals with vulnerability management and policies & procedures are in place. Our ISO management system is in place to identify, triage and mitigate any vulnerability.
Hosting services at datacentres are accounted for in our management system with protective monitoring processes being compliance with our ISO 27001 certification
Incident management policies and procedures are in place and conform to ISO 27001 requirements. These are regularly audited internally and externally.
Full policies are available on request. - Outage reporting
-
Outage reporting is via numerous mechanisms, including email alerts, in-product notifications, key customers phone calls, service review meetings and updates.
Planned and unplanned outages are communicated both internally and externally.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Limited access network (for example PSN)
- Dedicated link (for example VPN)
- Username or password
- Access restrictions in management interfaces and support channels
- All administrative interfaces require a username and password as well as MFA in order to access. The configuration of users with access to management interfaces is managed by the customer.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Our information security policies are all GDPR compliant and follow our ISO27001 accredited management system. All policies follow these standards and are reviewed and updated continuously. Policies are available to all staff and regular training internal staff training ensures they are understood and followed.
The information secuirty Management System is owned by senior managements who conduct regular management review meetings. This information security management team is made up of Board members, senior managers and team leads. The management team reviews and escalates any issues accordingly
The information security processes and polices are internally and externally audited through our ISO certifications. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
For configuration management, a version-controlled repository for all code, configs, and infrastructure is maintained with environment-specific configuration files (dev, staging, production). Secrets are stored in secure vaults, never in code. All configuration parameters and dependencies are documented.
For change management, all change and release require stakeholder approval and risk assessment. All changes are documented in internal and external release notes. Deployment checklists with testing gates are used with key metrics monitored post-release. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Threats to the service are monitored using internal vulnerability assessment tools that are executed monthly as well as annually executed independent security assessments. Critical issues identified with the service will be patched within 14 days maximum or sooner if possible. A threat intelligence report is updated weekly using internal data sources and information from external providers.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Our internal threat intelligence reports collates threats from internal and external provider sources. Any findings are logged in our internal information governance portal where they are assigned to the relevant team to action. All critical issues will be addressed as soon as possible but as a minimum within 14 days.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Our incident management processes are document as part of our ISO27001 processes. Internal users report incidents to the DPO and external users reports incidents through the customer helpdesk. All incidents will be reviewed by the Information Governance Steering Group and a root cause analysis provided which is available to customers.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
- Health and Social Care Network (HSCN)
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- Free Trial varies by Customer Type, Size, Product etc.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 5%
- Between £250,000 and £500,000
- 5.5%
- Between £500,001 and £1,000,000
- 6%
- Between £1,000,001 and £2,500,000
- 7%
- Between £2,500,001 and £5,000,000
- 8%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Amtivo Group Limited T/A British Assessment Bureau Ltd
- ISO/IEC 27001 accreditation date
- Thursday 17 April 2025
- What the ISO/IEC 27001 doesn’t cover
- All was in Scope
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Amtivo Group Limited T/A British Assessment Bureau Ltd
- ISO 9001 accreditation date
- Thursday 17 April 2025
- What the ISO 9001 doesn’t cover
- All was in Scope
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- A49adfd3-ca01-41fe-85d9-9400fd86c8a2
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 778233b7-8471-4576-a4ef-0412446d7714
- Other security certifications
- Yes
- Any other security certifications
-
- DSP Toolkit
- DTAC
- DCB0129
- DCB0160
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
-