Sangix Appointments
Sangix Appointments: Secure platform for healthcare & other sectors. Supports 100% walk-in, pre-booked, or mixed clinics. Book via online portal or automated phone system. Includes calendar templates & reports. Supports Single Sign-On (SSO) and integrates with PAS.
Features
- Book, view, cancel appointments on-line and by automated phone line
- Reduce patient waiting time and eliminate staff overtime
- One-click reporting, i.e. GP and ICB rebilling
- Secure and stable cloud technology
- Integrates with existing systems
- Patient web Portal for patients to manage their appointments
- Pre-booked appointments, walk-in and a mix of both
- Efficient queue management
- Call-in Screens and Self Check-in Kiosks
Benefits
- Eliminate need for reception and staff dedicated to booking appointments
- Remove hygienic risks related to paper-based systems
- Prevents crowded waiting areas
- Multiple check-in options including mobile app, kiosk, and reception desk
- New features get released every quarter responding to customer feedback
- Supports Single-Sign-On (SSO) - log in using existing Trust username
- Patients can book online from their phone or PC
- Patient web portal: patients can manage their appointments and data
- Support for family accounts
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 8 3 5 7 6 6 3 4 5 8 2 3 2 1
Contact
Portals UK ltd
Jiri Blazek
Telephone: 07531234264
Email: vasuki.sanjeevan@sangix.co.uk
About your service
- Service categories
-
Applications
Production and operations
- Other operations
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- N/A
- System requirements
-
- Requires stable internet connection to public Cloud services
- Latest version of a modern browser required for full functionality
- Users need a PC or tablet with internet connection
User support
- Email or online ticketing support
- Yes
- Support response times
- Response time is 2 working days.
- User can manage status and priority of support tickets
- No
- Phone support
- No
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
We provide support during standard business hours on UK working days.
Remote Go-Live support via Microsoft Teams, or on-site if required, is included at no additional cost.
Ongoing operational support is provided through email and our service desk ticketing system as part of the annual subscription.
Additional on-site support after Go-Live is available at £800 per day. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Prior to Go Live - Online Training & User documentation
Go Live- On-site (or online) hands-on training during the first day of operation. - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
-
The data are extracted from the database by vendor and provided to the client in a computer readable format.
Patients can add, update or remove their personal and appointment data from the web portal. They can also remove their account from the web portal. - End-of-contract process
- Sangix Appointments is provided as an annual subscription. When the subscription expires, all data are extracted and provided to the client free of cost upon request in a computer readable format.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
Patient experience is mobile first.
Staff portals can be used on mobile but is designed to work on desktops first. - Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The service provides a secure web-based interface accessible through any modern browser. Staff use an intuitive administrative dashboard to manage appointments, queues, check-ins, users, and reporting. Patients access a dedicated web portal to view, book, and manage appointments. A kiosk interface supports on-site self check-in and arrival confirmation. All interfaces are responsive, accessible, and optimised for desktop, tablet, and mobile use. Role-based access controls ensure users only see appropriate functions. The service also exposes API endpoints for approved system integrations, enabling automated booking updates and external system connectivity.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- N/A
- API
- Yes
- What users can and can't do using the API
- API supports working with StarPrinterOnline service to print tickets and with an automated Telephone service so users can book, cancel and view appointments using automated phone service.
- API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
- The solution is highly customizable via staff portal.
Scaling
- Independence of resources
- The service is deployed on Google Cloud Platform using auto-scaling, fully managed serverless infrastructure. Compute resources scale independently based on each customer’s usage, ensuring that increased demand from one organisation does not affect others. Database resources are provisioned with performance isolation, and traffic is load-balanced across multiple instances. Multi-tenant data separation and rate-limiting ensure fair resource consumption across all users. Continuous monitoring automatically detects abnormal load and scales capacity as required. This architecture guarantees consistent performance and responsiveness regardless of demand from other users.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Staff users can use a range of configurable reports.
- Reporting types
-
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- Less than once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
-
Patients can copy their data from patient portal.
Staff can use built-in reports to export data. - Data export formats
- Other
- Other data export formats
- Excel - XLSX
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- We provide a 99.5% availability per year.
- Approach to resilience
- Our service running on Google Cloud Platform (GCP) is designed to be resilient through scalable architecture, redundant components, fault-tolerant design, automated monitoring, and healing mechanisms. We prioritize data protection with robust backup strategies.
- Outage reporting
- Email alerts, Slack notifications and texts
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Staff users have different user roles that grant them access only to data and pages they need to see.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- Between 1 month and 6 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- Between 1 month and 6 months
- How long system logs are stored for
- Between 6 months and 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
We follow the ISO 27001:2022 Information Security Policy and the following sub-policies:
Acceptable Use of Assets Policy
Access Control Policy
Backup Policy
Clear Desk and Clear Screen Policy
Communication Policy
Cryptographic Controls Policy
Information Classification, Labelling and Handling Policy
Mobile Devices Policy
Physical and Environmental Security Policy
Protection from Malware Policy
Protection of Personal Information Policy
Suppliers Policy
Remote Working Policy
Use of Intellectual Property Policy
Use of Software Policy
Microsoft 365 Acceptable Use Policy
Threat Intelligence Policy
Configuration Management Policy
Operational Controls Policy
Policy Review - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Our configuration and change management processes involve meticulously tracking the lifecycle of our software solution and evaluating changes for potential security implications. We maintain detailed records to monitor the evolution of each software version, ensuring transparency and accountability. Prior to release of a new version, all changes undergo rigorous testing and security assessments to safeguard against potential vulnerabilities and maintain the integrity of our systems.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Our vulnerability management process involves continuous assessment of potential threats to our services. We promptly deploy patches to address identified vulnerabilities, prioritizing the security of our systems. We stay informed about potential threats through a variety of sources, including security advisories, threat intelligence feeds, and industry best practices.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Our protective monitoring processes involve vigilant identification of potential compromises through continuous monitoring of system activities. In the event of a potential compromise, we promptly respond by investigating the incident, containing the threat, and initiating appropriate remedial actions. Our goal is to swiftly address incidents, minimizing their impact, and ensuring the security and integrity of our systems.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Our incident management processes encompass pre-defined procedures for common events, ensuring a structured and efficient response to incidents. Users can report incidents to our service desk via an email or electronic form, allowing for timely escalation and resolution. Following incident resolution, we provide comprehensive incident reports to stakeholders, fostering transparency and continuous improvement in our security practices.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- Free trial of up to 6 months can be provide upon request.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 8%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 15%
- Over £5,000,001
- 20%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Amtivo Group Limited T/A British Assessment Bureau Ltd.
- ISO/IEC 27001 accreditation date
- Wednesday 4 June 2025
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- You do not have a current and valid Cyber Essentials certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-