Genome
Genome is an advanced, integrated quality assurance and improvement software supporting senior clinical teams, managers, and executives in healthcare organisations to improve the quality of patient care. It's a digital platform accessible through mobile and desktop applications, facilitating streamlined auditing processes and enhancing the value of complex QA frameworks.
Features
- Intuitive auditing system
- Real-time ward to board reporting
- Advanced data visualisations
- Automated data processing
- Photos and comments
- Multiple customisations
- Task management system
- Guidance for each audit question
- Data rich, customisable metrics
Benefits
- Quicker auditing, more time to care
- Clear organisational performance visibility
- Increased productivity
- Quantitative data enrichment with qualitative elements
- Trust-specific content resulting in most relevant data presentation
- Better organised auditors' work
- Enhanced situational awareness
- More accurate data collection
- Quick response to request for changes
- Empowering staff
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 9 1 0 9 8 0 4 9 0 5 9 7 1 7
Contact
GENOME
Stacey Hatton
Telephone: +44 (0) 114 312 4661
Email: g-cloud@xgenome.co.uk
About your service
- Service categories
-
Applications
Enterprise resource management
- Enterprise performance management
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- Scheduled maintenance is performed on Thursdays between 4 am and 6 am. Emergency maintenance may be carried out at any time. If emergency maintenance is required, Genome will provide a customer with appropriate advanced notification.
- System requirements
-
- Devices capable of running a supported version of Microsoft Edge.
- Devices capable of running a supported version of Chrome.
User support
- Email or online ticketing support
- Yes
- Support response times
-
Support is available 8:00 - 18:00 (UK time), five days a week. Genome operates a unified severity-driven customer support model.
The response time depends on impact severity as described in the SLA:
- Severity 1 - response within 1 business hour
- Severity 2 - response within 2 business hours
- Severity 3 - response within 24 business hours
- Severity 4 - response within 5 business days - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- Genome provides operational support via the helpdesk. The support is free of charge and includes, amongst others, changes to the auditing tools, account management, and full technical assistance provided by our technical account manager.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Onboarding support is provided for configuration, training, deployment, and user testing. The training involves:
1. Remote sessions through video conferences.
2. On-site training - demonstrations and hands-on workshops.
3. User guide documentation.
Genome is aiming for a full onboarding process to take less than one month for an average-size Trust. - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- The data can be extracted by exporting PDF and CSV files.
- End-of-contract process
-
1. The data is extracted.
2. The user access is revoked.
3. The server is deleted - Documentation accessibility standard
- WCAG 2.2 A
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Chrome
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Mobile devices are used as data acquisition and visualization tools. The desktop application's predominant function is to provide advanced aggregate data visualization capability.
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
-
Genome delivers app-based interfaces for executing all tasks within the system.
Access is controlled by unique user names and passwords and is determined by senior decision-makers in the organisations. - Accessibility standards
- None or don’t know
- Description of accessibility
- Compliance with most WCAG 2.2 AA criteria has been achieved.
- Accessibility testing
- Genome is in the process of ongoing development to ensure that we meet the WCAG guidelines for accessibility standards. The software is being rigorously tested by our clients and suggestions for interface improvements are being introduced on an ongoing basis.
- API
- Yes
- What users can and can't do using the API
- Genome QA API allows interaction with key functionalities of the application. Users have secure access to their analytics data gathered on the server. Data retrieval is protected by secure delegated access standards.
- API documentation
- Yes
- API documentation formats
- Other
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
-
Genome is a highly customisable solution that enables users to adapt the software to their specific needs. Examples of customisable elements include:
1. Audit structure
2. Audit locations
3. Audit questions
4. Question guidance
5. Audit guidance
6. Question grouping
7. Multi-level organisation structure.
Customer representatives, in cooperation with Genome’s customer support, can customise Genome at the onboarding stage by filling out predefined forms. Requests for change can also be made while the system is operational.
Scaling
- Independence of resources
- Genome cloud provider monitors the usage and automatically adjusts capacity to maintain appropriate performance in line with customer requirements.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Our software provides usage metrics focused on identity and access management. These include sign-in counts, success and failure rates, conditional access evaluations, and MFA usage. It also tracks authentication and security data such as risky sign-ins, risky users, and password reset activity, along with registration for authentication methods. Licensing and provisioning metrics cover active users and app provisioning status, while application usage reports app sign-ins and consent activity. Audit logs capture directory changes and policy updates. Other metrics are available upon request.
- Reporting types
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
-
The users can obtain CSV or PDF files with their data free of charge. We will provide full support to the customers in performing any extraction activities, including extracting data in other formats requested by the client.
Extracting data in formats other than CSV or PDF will be treated as an additional service and incur costs subject to prior agreement with the client and a quote by Genome. - Data export formats
-
- CSV
- Other
- Other data export formats
-
- CSV
- Data import formats
-
- CSV
- Other
- Other data import formats
- Excel
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- Genome can guarantee 99% service availability. In respect of each calendar month during which the services' uptime is less than the commitment specified, the Customer will receive a refund. Please see the Terms and Conditions document for specifics.
- Approach to resilience
- Available on request.
- Outage reporting
- Reports of outages are delivered via email alerts.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- The access is restricted by username and password authentication. Genome staff provides user permissions and role based access in support channels and management interface.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Genome adopts policies, procedures and processes created in accordance with the General Data Protection Regulation (GDPR) and ISO/IEC 27001 standards.
The information security documentation is being reviewed on a regular basis, ensuring the company is compliant with all aspects of information security. Internal and external audits of Genome’s Information Security Management System (ISMS) are carried out periodically.
Any information security issues or breaches are acted upon by following the correct escalation routes as per the documented processes.
All employees and contractors of Genome have a contractual duty to follow Genome’s information security policies and procedures. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Genome applies a systematic approach to managing change.
Genome’s change management procedures are led by the CTO and Information Security Manager.
Every change undergoes a risk assessment to identify and mitigate any potential security impact the change may produce.
Changes impacting customer services are reviewed, tested, approved, and communicated. Should the change pose any risks once in the live environment, rollback or hot fixing procedures are available. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Genome subscribes to vulnerability email alerts from Cybersecurity and Infrastructure Security Agency (CISA).
Advisories that relate to Genome’s services are risk assessed, escalated to the Information Security manager, and filtered to the team as necessary.
Genome ensures that action is scheduled and installing patches required for known vulnerabilities is conducted according to the change control procedure. Routine patches are applied on a quarterly basis. Any vulnerabilities deemed higher risk are applied more frequently based on the risk assessment. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- We monitor server activities to identify malicious, unauthorized, or unexpected behaviour that may indicate a potential attempt to breach the service. Upon identification of breach or breach attempt, Genome’s Information Security Manager, together with CTO will perform a risk assessment, notify any customers that may have been affected, notify the UK authorities and block the source of the attempted breach.
- Incident management type
- Supplier-defined controls
- Incident management approach
-
Genome has incident management processes in place to ensure the company is equipped to respond to a wide range of unexpected events that may affect the delivery of the service to the customers. Genome responds to incidents in accordance with the Business Continuity Incident Response Procedure and Information Security Incident Management Policy.
A defined process and contact route are in place for reporting security incidents by the clients.
Genome reports security incidents of relevance to the suppliers or customers within acceptable timescales in accordance with service level agreement. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- The full version of Genome is included as a free trial for a period of 3 months.
- Link to free trial
- https://xgenome.co.uk/request-a-demo/
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 10%
- Between £500,001 and £1,000,000
- 20%
- Between £1,000,001 and £2,500,000
- 30%
- Between £2,500,001 and £5,000,000
- 40%
- Over £5,000,001
- 50%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Alcumus ISOQAR
- ISO/IEC 27001 accreditation date
- Wednesday 16 August 2023
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- C4c7fb08-2c09-4c1a-b990-df9463812028
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 44aa364d-2b4b-4ed1-9ab9-b455d7550e66
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of issues relating to entering the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-