Skip to main content

Help us improve the Digital Marketplace - send your feedback

Solventum UK

Solventum Medicode Cloud

Solventum™ Medicode Cloud is a secure, Cloud hosted clinical coding platform designed to improve accuracy, speed, and compliance. It offers intelligent analytics, real-time prompts, and audit tools to optimize workflows, ensure accurate reimbursement, and support service planning, forecasting, and population health management—all with minimal IT burden and high reliability.

Features

  • Cloud-based SaaS architecture ensures scalability, security, and UK compliance.
  • Live interface passing patient episode details to and from PAS/EPR
  • Multi-search functionality for clinical terms and codes
  • Coding workflows featuring prompting and simple navigation
  • HRG production and assistance
  • Template Coding - predefined code sequence deployment
  • Medical History Assurance - comorbidity recording
  • Data Quality Analytics - with user prompting and recording
  • Integrity Plus - clinical coding audit

Benefits

  • Centralise software updates for coding updates and iterative functional improvements
  • Seamless access for clinical coding and HRG grouping and tariffs
  • Efficient and accurate clinical code allocation, to speed coding departments
  • Increase coder throughput and accuracy via intuitive prompting
  • Produce accurate HRG's ensuring accurate and maximised financial compensation
  • Deploy multiple codes within adjustable templates for speed and accuracy
  • Capturing comorbidities otherwise missed ensuring true reflection of case mix
  • Reduces error and promotes clinical documentation improvement via actionable data
  • Seamless audit of coding, error key assignment and report generation

Pricing

  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at mcole3@solventum.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

9 2 6 6 1 2 9 5 4 3 2 8 7 3 2

Contact

Solventum UK Megan Cole
Telephone: +44 (0) 7385397266
Email: mcole3@solventum.com

About your service

Service categories

Applications

Production and operations

Service industry and public sector operations

  • Healthcare
Multi cloud support
No

Service scope

Software add-on or extension
Yes
What software services is the service an extension to
Medicode Cloud will interface with an EPR to send episode information to and from the patient record. We work with all major EPR providers
Cloud deployment model
Public cloud
Service constraints
Updates to clinical coding information such as classification updates, coding standard updates, HRG updates, and tariff updates are reliant on timely release from the NHS. All updates to such areas need to be incorporated into the software and thoroughly tested before being made available to clinical coding departments.
System requirements
  • Windows 11 operating system for desktop workflows.
  • Modern browser support
  • HL7 and FHIR interfaces for EHR integration and scheduling feeds.
  • Single Sign-On (SSO) or Active Directory authentication capability.
  • TLS 1.2 or higher encryption for all data transmissions.

User support

Email or online ticketing support
Yes
Support response times
Solventum provides Mon-Fri 9-5 support
Severity 1 – Critical Impact - Initial response 30 mins. Resolution Response - 4 hours.

Severity 2 – High Impact
Production impaired or time-sensitive issue affecting productivity.
Response: Within 30 minutes
Resolution: Typically same day during business hours

Severity 3 – Moderate Impact
Important but non-critical issues.
Response: Standard business hours (Mon–Fri, 9am–5pm)
Initial response time - 2 hours.
Resolution response time - 4 working days.

Severity 4 - Minor - Initial response time - 8 hours.
Resolution response time - 6 working days.
Severity 5 - Low/Enhancement.
General request Initial Response - 24 hours.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes
Support levels
Solventum provides tiered support aligned to issue severity, ensuring rapid response and resolution:

Severity 1 – Critical Impact - Initial response 30 mins. Resolution Response - 4 hours.
System down or immediate work stoppage threatening production.

Severity 2 – High Impact
Production impaired or time-sensitive issue affecting productivity.
Response: Within 30 minutes
Resolution: Typically same day during business hours

Severity 3 – Moderate Impact
Important but non-critical issues.
Response: Standard business hours (Mon–Fri, 9am–5pm)
Initial response time - 2 hours.
Resolution response time - 4 working days.

Severity 4 - Minor (Single user impact) - Initial response time - 8 hours.
Resolution response time - 6 working days.

Severity 5 - Low/Enhancement.
General request Initial Response - 24 hours.

Support for Medicode Cloud is offered Monday-Friday 9-5.
Support available to third parties
No

Onboarding and offboarding

Getting started
Solventum will provide a comprehensive onboarding program to help users start using Medicode Cloud quickly and confidently. We offer onsite training during implementation and go-live phases, including floor-walking and/or open Microsoft Teams sessions to give new users the support they may need and to gather user feedback. For flexibility, we also provide online training through a “Train the Trainer” model, enabling Trust trainers to cascade knowledge internally.
To complement live sessions, Solventum delivers interactive eLearning modules, short video tutorials, and web-based user guides covering setup, workflow navigation, and best practices. These resources allow clinical coding teams to learn at their own pace and revisit materials as needed.
Beyond initial training, Solventum assigns a dedicated Key Account Manager and subject matter expert contact information for the life of the contract. This account manager and subject matter expert team monitors adoption, provides optimization recommendations, and acts as an escalation point for support. Combined with proactive adoption services, this approach ensures a smooth transition, rapid uptake, and sustained success for all users.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
At the end of the contract, Solventum ensures a secure and compliant process for data extraction. All customer data is stored within Solventum’s cloud infrastructure during the contract term. When the agreement concludes, users can request a full export of their data in standard, interoperable formats such as HL7 CDA, FHIR objects, or PDF, ensuring compatibility with downstream systems and EHRs.
The extraction process is managed through Solventum’s professional services team, working closely with the Trust’s IT and Information Governance teams to meet local compliance requirements. Data is transferred via secure, encrypted channels (TLS 1.2 or higher) and can be delivered through secure file transfer protocols or physical encrypted media if required.
Solventum guarantees that all retained data is purged from its systems following confirmation of successful extraction, in line with GDPR and NHS DSPT standards.
By providing structured, standards-based outputs and a fully managed extraction workflow, Solventum ensures continuity, security, and transparency when transitioning away from the service
End-of-contract process
When the contract ends, Solventum follows a structured offboarding process to ensure compliance and continuity. All customer data remains securely stored in Solventum’s cloud until extraction is complete. The Trust can request a full data export in standard formats such as HL7 CDA, FHIR objects, or PDF for interoperability with EHR systems. After confirmation of successful transfer, Solventum performs secure data deletion and issues a formal certificate of destruction to meet GDPR and NHS DSPT requirements.

What’s Included in the Price

Core Software Licenses: Medicode Cloud and any additional purchased modules
Cloud Hosting & Security: infrastructure, encryption, compliance
Implementation Services: Project management, configuration, and initial workflow setup
Training: Train-the-Trainer sessions, eLearning, and onboarding documentation
Support: 9-5 helpdesk, adoption monitoring throughout the contract

Additional Costs

Professional Services: Custom integrations
Extended Training: Beyond standard onboarding or additional onsite sessions
Future Enhancements: New features outside contracted scope or major upgrades
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Solventum ensures onboarding and offboarding documentation for Medicode Cloud is fully accessible and user-friendly across multiple formats. All materials are provided digitally via a secure, web-based portal, allowing users to download comprehensive guides in PDF format for offline use. These include step-by-step setup instructions, workflow diagrams, and troubleshooting guides.
Interactive eLearning modules and short video tutorials complement written guides, catering to different learning styles and ensuring flexibility for busy clinical coding teams.
Role-based access ensures the right content reaches the right audience: managers receive Medicode Management guidance and workflow tips, while coders and auditors can access training relevant to their roles and functions they will use within the software.
Combined with live training and ongoing adoption support, this approach ensures onboarding and offboarding documentation is always available, easy to navigate, and tailored to user needs.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
Yes
Compatible operating systems
Windows
Designed for use on mobile devices
No
Service interface
No
User support accessibility
None or don’t know
API
No
Customisation available
Yes
Description of customisation
There are several areas in which the software can be customised. There are generalised system settings enabling customer sites to adjust workflows to best suit their needs e.g. specific code pair prompts or disabling the save function if the episode is generating a UZ HRG. There is also the concept of roles, where a site can determine the access level of each of it's users e.g. ability to run reports or ability to use the system as an auditor. User profiles can also be amended to toggle on/off access to specific functions such as being able to deploy templates or use the repeat coding functionality. All of the above is managed by Medicode Manager profiles at the user site, either within settings pages within the application itself or via our foundation services tool with it's own separate login. Aside from this, Solventum will be able to control access to certain functions related to modules associated with additional cost, such as the Medical History Assurance or Data Quality Analytics modules.

Scaling

Independence of resources
Solventum guarantees consistent performance through its cloud-based, multi-tenant architecture hosted data centres. The platform is designed for elastic scalability, meaning resources automatically adjust to demand without impacting individual users. Each customer operates within a logically isolated tenant, ensuring workloads are segregated and performance remains stable even during peak usage. Advanced load balancing and auto-scaling mechanisms distribute processing efficiently across servers, while proactive monitoring by Solventum’s operations team prevents bottlenecks. This approach ensures coding teams experience real-time responsiveness, regardless of concurrent usage by other organizations.

Analytics

Service usage metrics
Yes
Metrics types
The solution offers reporting capabilities allowing management staff to review worker throughput, both in episodes and coding depth, amongst others.
Reporting types
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
European Economic Area (EEA)
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
In-house
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
Data Erasure

Data importing and exporting

Data export approach
Users can export their data via our reporting tool in csv format
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Solventum guarantees high availability through its cloud-based encoder platform, designed for resilience and scalability. Medicode Cloud and it's associated modules are delivered via a fully managed SaaS model hosted in Solventum Cloud data centres, ensuring compliance with NHS Digital, GDPR, and ISO27001 standards. The platform is architected for 24/7/365 operation, supporting coding teams across multiple specialties without downtime. Automated updates, multi-tenant architecture, and proactive monitoring safeguard performance and minimize disruption.
Service Level Agreements (SLAs): Solventum commits to 99.9% uptime, excluding scheduled maintenance. Severity-based response times are embedded in our support model:

Critical Impact: Response within 30 minutes; resolution within 4 hours.
High Impact: Response within 1 hour; resolution within 8 hours.

Support is available through a 9-5 Monday-Friday toll-free line, and dedicated Adoption Services team for the life of the contract.
Approach to resilience
Medicode Cloud is engineered for resilience, ensuring uninterrupted performance and secure clinical documentation workflows. The solution is delivered as a fully managed SaaS platform hosted in the Solventum Cloud EEA region (Germany), leveraging a multi-tenant architecture with automated failover and elastic scalability to handle peak workloads without degradation. This cloud-native design provides high availability and disaster recovery capabilities, supported by redundant infrastructure and proactive monitoring.
Data security underpins resilience: all data in transit and at rest is encrypted using TLS 1.2+ and AES-256, with logical tenant separation and robust firewall protections. Compliance with NHS Digital DTAC, ISO27001, and GDPR standards ensures operational integrity. In the event of connectivity loss.
Continuous monitoring and automated updates maintain system health and deliver enhancements without downtime. Solventum hosting adds geographic redundancy and disaster recovery protocols, minimizing risk of service disruption. Combined with Solventum's Mon-Friday 9-5 support and severity-based SLAs, these measures guarantee a resilient, secure, and scalable service that clinicians can rely on for real-time ambient documentation across diverse care settings.
Outage reporting
Medicode Cloud provides proactive outage reporting through multiple channels to ensure transparency and rapid communication. The service is hosted in the Cloud and is monitored continuously for performance and availability. When an outage or service degradation occurs, Solventum initiates alerts via email notifications to designated client contacts, detailing the nature of the issue, impact, and estimated resolution time. These alerts follow severity-based SLAs, ensuring critical issues receive immediate attention.
All notifications and updates are logged for audit purposes, and clients can opt for scheduled reports summarizing uptime and incident history.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Username or password
Access restrictions in management interfaces and support channels
Solventum enforces strict access controls across management interfaces and support channels. Access is restricted using role-based access control (RBAC), ensuring only authorized personnel can perform administrative tasks. Authentication is managed through Single Sign-On (SSO) or Active Directory integration, with multi-factor authentication (MFA) applied where required. Verified client contacts are the only users permitted to raise tickets or view case details via the secure support portal. All actions are logged for audit purposes, and permissions undergo regular reviews. Administrative changes follow documented approval workflows within our secure development lifecycle (SDLC), tracked through JIRA, ensuring compliance with ISO27001 and NHS DTAC standards.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
Cyber Essentials (Plus)
Information security policies and processes
Solventum adheres to a comprehensive information security framework aligned with NHS Digital DTAC, GDPR, HIPAA, ISO27001, and SOC 2 Plus standards. Our policies cover data protection, encryption, vulnerability management, access control, and incident response. All data in transit and at rest is encrypted using TLS 1.2+ and AES-256, with logical tenant separation and robust firewall protections. Regular penetration testing and vulnerability assessments are conducted by CREST-approved third parties, and results are reviewed at board level.
Reporting Structure: Oversight is provided by the Chief Information Security Officer (CISO) and Clinical Safety Officer, supported by compliance and risk management teams. These roles ensure adherence to regulatory requirements and internal standards.
Policy Enforcement: Compliance is maintained through mandatory staff training, secure development lifecycle practices, and automated monitoring tools. Change control processes documented in our SDLC require approvals via JIRA and include rollback plans. Incident management follows a severity-based escalation model, with 24/7 monitoring and rapid response protocols. Governance includes periodic reviews, internal audits, and customer-facing assurance reports under NDA.
This structured approach ensures robust security, transparency, and continuous improvement throughout the contract lifecycle.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Solventum uses a structured configuration and change management process aligned with ISO27001 and NHS Digital DTAC standards. All service components are tracked throughout their lifecycle using a centralized configuration management database (CMDB) integrated with JIRA for change control. Each change request includes detailed documentation, approval workflows, and rollback plans. Changes undergo formal impact assessments, including security risk analysis, to evaluate potential vulnerabilities before implementation. Penetration testing and regression checks validate security posture post-change. Governance is enforced through mandatory reviews by the Information Security Officer and periodic audits, ensuring compliance and traceability across all environments.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Solventum’s vulnerability management process is proactive and aligned with ISO27001, NHS DTAC, and SOC 2 Plus standards. Potential threats are assessed through continuous monitoring, automated vulnerability scans, and regular penetration testing by CREST-approved third parties. Threat intelligence is sourced from NHS Cyber Alerts, NIST, vendor advisories, and security bulletins. When vulnerabilities are identified, patches are prioritized by severity and deployed rapidly—critical issues within 14 days, often sooner for high-risk items. All changes follow documented SDLC protocols, including security impact analysis and rollback plans, ensuring resilience and compliance throughout the lifecycle.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Solventum employs robust protective monitoring processes to safeguard its services. Potential compromises are identified through continuous monitoring, automated intrusion detection systems (IDS/IPS), and vulnerability scans across all environments. Alerts are generated for anomalies such as unauthorized access attempts or unusual data flows. When a potential compromise is detected, incidents are escalated immediately to the Information Security Officer and handled under our severity-based response model: Critical incidents receive a response within 30 minutes and resolution within 4 hours. Investigations include root-cause analysis, containment, and remediation, followed by customer notifications and audit reporting to ensure transparency and compliance.
Incident management type
Supplier-defined controls
Incident management approach
Solventum follows a structured incident management process aligned with NHS DTAC and ISO27001 standards. We maintain pre-defined workflows for common events such as outages and security incidents, with severity-based escalation (Critical: response within 30 minutes; resolution within 4 hours). Users report incidents via a Monday-Friday 9-5 toll-free support line, or email. After resolution, we provide detailed incident reports outlining root cause, corrective actions, and preventive measures, delivered through the portal or email and logged for audit purposes. Governance includes periodic reviews and continuous improvement to ensure transparency and compliance.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
There's no free trial available for the base Medicode Encoder Product, however there is for the optional additional modules.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
2.5%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
10%
Between £1,000,001 and £2,500,000
12%
Between £2,500,001 and £5,000,000
15%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
BSI
ISO/IEC 27001 accreditation date
Wednesday 7 August 2024
What the ISO/IEC 27001 doesn’t cover
Solventum HIS (Health information Systems) is fully covered in the UK by ISO27001.
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
BSI
ISO 9001 accreditation date
Monday 13 January 2025
What the ISO 9001 doesn’t cover
All functions in scope.
Quality management systems (QMS)
Yes
CSA STAR certification
Yes
CSA STAR accreditation date
Tuesday 25 November 2025
CSA STAR certification level
Level 2: CSA STAR Attestation
What the CSA STAR doesn’t cover
All parts covered.
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
17a8c65c-2c59-478a-900e-a94910b58818
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
662b0be8-be3b-468f-b4d1-f2b121b15245
Other security certifications
Yes
Any other security certifications
  • NHS DSPT (Standards met) - ODS Code: V3KCI
  • NHS DTAC & DCB0129 accredited
  • ICO Registration (Number: ZA926711)

Social value

Section B - Commitment for Future: Delivery
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at mcole3@solventum.com. Tell them what format you need. It will help if you say what assistive technology you use.