Solventum Medicode Cloud
Solventum™ Medicode Cloud is a secure, Cloud hosted clinical coding platform designed to improve accuracy, speed, and compliance. It offers intelligent analytics, real-time prompts, and audit tools to optimize workflows, ensure accurate reimbursement, and support service planning, forecasting, and population health management—all with minimal IT burden and high reliability.
Features
- Cloud-based SaaS architecture ensures scalability, security, and UK compliance.
- Live interface passing patient episode details to and from PAS/EPR
- Multi-search functionality for clinical terms and codes
- Coding workflows featuring prompting and simple navigation
- HRG production and assistance
- Template Coding - predefined code sequence deployment
- Medical History Assurance - comorbidity recording
- Data Quality Analytics - with user prompting and recording
- Integrity Plus - clinical coding audit
Benefits
- Centralise software updates for coding updates and iterative functional improvements
- Seamless access for clinical coding and HRG grouping and tariffs
- Efficient and accurate clinical code allocation, to speed coding departments
- Increase coder throughput and accuracy via intuitive prompting
- Produce accurate HRG's ensuring accurate and maximised financial compensation
- Deploy multiple codes within adjustable templates for speed and accuracy
- Capturing comorbidities otherwise missed ensuring true reflection of case mix
- Reduces error and promotes clinical documentation improvement via actionable data
- Seamless audit of coding, error key assignment and report generation
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 2 6 6 1 2 9 5 4 3 2 8 7 3 2
Contact
Solventum UK
Megan Cole
Telephone: +44 (0) 7385397266
Email: mcole3@solventum.com
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes
- What software services is the service an extension to
- Medicode Cloud will interface with an EPR to send episode information to and from the patient record. We work with all major EPR providers
- Cloud deployment model
- Public cloud
- Service constraints
- Updates to clinical coding information such as classification updates, coding standard updates, HRG updates, and tariff updates are reliant on timely release from the NHS. All updates to such areas need to be incorporated into the software and thoroughly tested before being made available to clinical coding departments.
- System requirements
-
- Windows 11 operating system for desktop workflows.
- Modern browser support
- HL7 and FHIR interfaces for EHR integration and scheduling feeds.
- Single Sign-On (SSO) or Active Directory authentication capability.
- TLS 1.2 or higher encryption for all data transmissions.
User support
- Email or online ticketing support
- Yes
- Support response times
-
Solventum provides Mon-Fri 9-5 support
Severity 1 – Critical Impact - Initial response 30 mins. Resolution Response - 4 hours.
Severity 2 – High Impact
Production impaired or time-sensitive issue affecting productivity.
Response: Within 30 minutes
Resolution: Typically same day during business hours
Severity 3 – Moderate Impact
Important but non-critical issues.
Response: Standard business hours (Mon–Fri, 9am–5pm)
Initial response time - 2 hours.
Resolution response time - 4 working days.
Severity 4 - Minor - Initial response time - 8 hours.
Resolution response time - 6 working days.
Severity 5 - Low/Enhancement.
General request Initial Response - 24 hours. - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes
- Support levels
-
Solventum provides tiered support aligned to issue severity, ensuring rapid response and resolution:
Severity 1 – Critical Impact - Initial response 30 mins. Resolution Response - 4 hours.
System down or immediate work stoppage threatening production.
Severity 2 – High Impact
Production impaired or time-sensitive issue affecting productivity.
Response: Within 30 minutes
Resolution: Typically same day during business hours
Severity 3 – Moderate Impact
Important but non-critical issues.
Response: Standard business hours (Mon–Fri, 9am–5pm)
Initial response time - 2 hours.
Resolution response time - 4 working days.
Severity 4 - Minor (Single user impact) - Initial response time - 8 hours.
Resolution response time - 6 working days.
Severity 5 - Low/Enhancement.
General request Initial Response - 24 hours.
Support for Medicode Cloud is offered Monday-Friday 9-5. - Support available to third parties
- No
Onboarding and offboarding
- Getting started
-
Solventum will provide a comprehensive onboarding program to help users start using Medicode Cloud quickly and confidently. We offer onsite training during implementation and go-live phases, including floor-walking and/or open Microsoft Teams sessions to give new users the support they may need and to gather user feedback. For flexibility, we also provide online training through a “Train the Trainer” model, enabling Trust trainers to cascade knowledge internally.
To complement live sessions, Solventum delivers interactive eLearning modules, short video tutorials, and web-based user guides covering setup, workflow navigation, and best practices. These resources allow clinical coding teams to learn at their own pace and revisit materials as needed.
Beyond initial training, Solventum assigns a dedicated Key Account Manager and subject matter expert contact information for the life of the contract. This account manager and subject matter expert team monitors adoption, provides optimization recommendations, and acts as an escalation point for support. Combined with proactive adoption services, this approach ensures a smooth transition, rapid uptake, and sustained success for all users. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
At the end of the contract, Solventum ensures a secure and compliant process for data extraction. All customer data is stored within Solventum’s cloud infrastructure during the contract term. When the agreement concludes, users can request a full export of their data in standard, interoperable formats such as HL7 CDA, FHIR objects, or PDF, ensuring compatibility with downstream systems and EHRs.
The extraction process is managed through Solventum’s professional services team, working closely with the Trust’s IT and Information Governance teams to meet local compliance requirements. Data is transferred via secure, encrypted channels (TLS 1.2 or higher) and can be delivered through secure file transfer protocols or physical encrypted media if required.
Solventum guarantees that all retained data is purged from its systems following confirmation of successful extraction, in line with GDPR and NHS DSPT standards.
By providing structured, standards-based outputs and a fully managed extraction workflow, Solventum ensures continuity, security, and transparency when transitioning away from the service - End-of-contract process
-
When the contract ends, Solventum follows a structured offboarding process to ensure compliance and continuity. All customer data remains securely stored in Solventum’s cloud until extraction is complete. The Trust can request a full data export in standard formats such as HL7 CDA, FHIR objects, or PDF for interoperability with EHR systems. After confirmation of successful transfer, Solventum performs secure data deletion and issues a formal certificate of destruction to meet GDPR and NHS DSPT requirements.
What’s Included in the Price
Core Software Licenses: Medicode Cloud and any additional purchased modules
Cloud Hosting & Security: infrastructure, encryption, compliance
Implementation Services: Project management, configuration, and initial workflow setup
Training: Train-the-Trainer sessions, eLearning, and onboarding documentation
Support: 9-5 helpdesk, adoption monitoring throughout the contract
Additional Costs
Professional Services: Custom integrations
Extended Training: Beyond standard onboarding or additional onsite sessions
Future Enhancements: New features outside contracted scope or major upgrades - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
Solventum ensures onboarding and offboarding documentation for Medicode Cloud is fully accessible and user-friendly across multiple formats. All materials are provided digitally via a secure, web-based portal, allowing users to download comprehensive guides in PDF format for offline use. These include step-by-step setup instructions, workflow diagrams, and troubleshooting guides.
Interactive eLearning modules and short video tutorials complement written guides, catering to different learning styles and ensuring flexibility for busy clinical coding teams.
Role-based access ensures the right content reaches the right audience: managers receive Medicode Management guidance and workflow tips, while coders and auditors can access training relevant to their roles and functions they will use within the software.
Combined with live training and ongoing adoption support, this approach ensures onboarding and offboarding documentation is always available, easy to navigate, and tailored to user needs.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- Yes
- Compatible operating systems
- Windows
- Designed for use on mobile devices
- No
- Service interface
- No
- User support accessibility
- None or don’t know
- API
- No
- Customisation available
- Yes
- Description of customisation
- There are several areas in which the software can be customised. There are generalised system settings enabling customer sites to adjust workflows to best suit their needs e.g. specific code pair prompts or disabling the save function if the episode is generating a UZ HRG. There is also the concept of roles, where a site can determine the access level of each of it's users e.g. ability to run reports or ability to use the system as an auditor. User profiles can also be amended to toggle on/off access to specific functions such as being able to deploy templates or use the repeat coding functionality. All of the above is managed by Medicode Manager profiles at the user site, either within settings pages within the application itself or via our foundation services tool with it's own separate login. Aside from this, Solventum will be able to control access to certain functions related to modules associated with additional cost, such as the Medical History Assurance or Data Quality Analytics modules.
Scaling
- Independence of resources
- Solventum guarantees consistent performance through its cloud-based, multi-tenant architecture hosted data centres. The platform is designed for elastic scalability, meaning resources automatically adjust to demand without impacting individual users. Each customer operates within a logically isolated tenant, ensuring workloads are segregated and performance remains stable even during peak usage. Advanced load balancing and auto-scaling mechanisms distribute processing efficiently across servers, while proactive monitoring by Solventum’s operations team prevents bottlenecks. This approach ensures coding teams experience real-time responsiveness, regardless of concurrent usage by other organizations.
Analytics
- Service usage metrics
- Yes
- Metrics types
- The solution offers reporting capabilities allowing management staff to review worker throughput, both in episodes and coding depth, amongst others.
- Reporting types
-
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- In-house
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Data Erasure
Data importing and exporting
- Data export approach
- Users can export their data via our reporting tool in csv format
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
Solventum guarantees high availability through its cloud-based encoder platform, designed for resilience and scalability. Medicode Cloud and it's associated modules are delivered via a fully managed SaaS model hosted in Solventum Cloud data centres, ensuring compliance with NHS Digital, GDPR, and ISO27001 standards. The platform is architected for 24/7/365 operation, supporting coding teams across multiple specialties without downtime. Automated updates, multi-tenant architecture, and proactive monitoring safeguard performance and minimize disruption.
Service Level Agreements (SLAs): Solventum commits to 99.9% uptime, excluding scheduled maintenance. Severity-based response times are embedded in our support model:
Critical Impact: Response within 30 minutes; resolution within 4 hours.
High Impact: Response within 1 hour; resolution within 8 hours.
Support is available through a 9-5 Monday-Friday toll-free line, and dedicated Adoption Services team for the life of the contract. - Approach to resilience
-
Medicode Cloud is engineered for resilience, ensuring uninterrupted performance and secure clinical documentation workflows. The solution is delivered as a fully managed SaaS platform hosted in the Solventum Cloud EEA region (Germany), leveraging a multi-tenant architecture with automated failover and elastic scalability to handle peak workloads without degradation. This cloud-native design provides high availability and disaster recovery capabilities, supported by redundant infrastructure and proactive monitoring.
Data security underpins resilience: all data in transit and at rest is encrypted using TLS 1.2+ and AES-256, with logical tenant separation and robust firewall protections. Compliance with NHS Digital DTAC, ISO27001, and GDPR standards ensures operational integrity. In the event of connectivity loss.
Continuous monitoring and automated updates maintain system health and deliver enhancements without downtime. Solventum hosting adds geographic redundancy and disaster recovery protocols, minimizing risk of service disruption. Combined with Solventum's Mon-Friday 9-5 support and severity-based SLAs, these measures guarantee a resilient, secure, and scalable service that clinicians can rely on for real-time ambient documentation across diverse care settings. - Outage reporting
-
Medicode Cloud provides proactive outage reporting through multiple channels to ensure transparency and rapid communication. The service is hosted in the Cloud and is monitored continuously for performance and availability. When an outage or service degradation occurs, Solventum initiates alerts via email notifications to designated client contacts, detailing the nature of the issue, impact, and estimated resolution time. These alerts follow severity-based SLAs, ensuring critical issues receive immediate attention.
All notifications and updates are logged for audit purposes, and clients can opt for scheduled reports summarizing uptime and incident history.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Username or password
- Access restrictions in management interfaces and support channels
- Solventum enforces strict access controls across management interfaces and support channels. Access is restricted using role-based access control (RBAC), ensuring only authorized personnel can perform administrative tasks. Authentication is managed through Single Sign-On (SSO) or Active Directory integration, with multi-factor authentication (MFA) applied where required. Verified client contacts are the only users permitted to raise tickets or view case details via the secure support portal. All actions are logged for audit purposes, and permissions undergo regular reviews. Administrative changes follow documented approval workflows within our secure development lifecycle (SDLC), tracked through JIRA, ensuring compliance with ISO27001 and NHS DTAC standards.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- Cyber Essentials (Plus)
- Information security policies and processes
-
Solventum adheres to a comprehensive information security framework aligned with NHS Digital DTAC, GDPR, HIPAA, ISO27001, and SOC 2 Plus standards. Our policies cover data protection, encryption, vulnerability management, access control, and incident response. All data in transit and at rest is encrypted using TLS 1.2+ and AES-256, with logical tenant separation and robust firewall protections. Regular penetration testing and vulnerability assessments are conducted by CREST-approved third parties, and results are reviewed at board level.
Reporting Structure: Oversight is provided by the Chief Information Security Officer (CISO) and Clinical Safety Officer, supported by compliance and risk management teams. These roles ensure adherence to regulatory requirements and internal standards.
Policy Enforcement: Compliance is maintained through mandatory staff training, secure development lifecycle practices, and automated monitoring tools. Change control processes documented in our SDLC require approvals via JIRA and include rollback plans. Incident management follows a severity-based escalation model, with 24/7 monitoring and rapid response protocols. Governance includes periodic reviews, internal audits, and customer-facing assurance reports under NDA.
This structured approach ensures robust security, transparency, and continuous improvement throughout the contract lifecycle. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Solventum uses a structured configuration and change management process aligned with ISO27001 and NHS Digital DTAC standards. All service components are tracked throughout their lifecycle using a centralized configuration management database (CMDB) integrated with JIRA for change control. Each change request includes detailed documentation, approval workflows, and rollback plans. Changes undergo formal impact assessments, including security risk analysis, to evaluate potential vulnerabilities before implementation. Penetration testing and regression checks validate security posture post-change. Governance is enforced through mandatory reviews by the Information Security Officer and periodic audits, ensuring compliance and traceability across all environments.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Solventum’s vulnerability management process is proactive and aligned with ISO27001, NHS DTAC, and SOC 2 Plus standards. Potential threats are assessed through continuous monitoring, automated vulnerability scans, and regular penetration testing by CREST-approved third parties. Threat intelligence is sourced from NHS Cyber Alerts, NIST, vendor advisories, and security bulletins. When vulnerabilities are identified, patches are prioritized by severity and deployed rapidly—critical issues within 14 days, often sooner for high-risk items. All changes follow documented SDLC protocols, including security impact analysis and rollback plans, ensuring resilience and compliance throughout the lifecycle.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Solventum employs robust protective monitoring processes to safeguard its services. Potential compromises are identified through continuous monitoring, automated intrusion detection systems (IDS/IPS), and vulnerability scans across all environments. Alerts are generated for anomalies such as unauthorized access attempts or unusual data flows. When a potential compromise is detected, incidents are escalated immediately to the Information Security Officer and handled under our severity-based response model: Critical incidents receive a response within 30 minutes and resolution within 4 hours. Investigations include root-cause analysis, containment, and remediation, followed by customer notifications and audit reporting to ensure transparency and compliance.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Solventum follows a structured incident management process aligned with NHS DTAC and ISO27001 standards. We maintain pre-defined workflows for common events such as outages and security incidents, with severity-based escalation (Critical: response within 30 minutes; resolution within 4 hours). Users report incidents via a Monday-Friday 9-5 toll-free support line, or email. After resolution, we provide detailed incident reports outlining root cause, corrective actions, and preventive measures, delivered through the portal or email and logged for audit purposes. Governance includes periodic reviews and continuous improvement to ensure transparency and compliance.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- There's no free trial available for the base Medicode Encoder Product, however there is for the optional additional modules.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 2.5%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 10%
- Between £1,000,001 and £2,500,000
- 12%
- Between £2,500,001 and £5,000,000
- 15%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- BSI
- ISO/IEC 27001 accreditation date
- Wednesday 7 August 2024
- What the ISO/IEC 27001 doesn’t cover
- Solventum HIS (Health information Systems) is fully covered in the UK by ISO27001.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- BSI
- ISO 9001 accreditation date
- Monday 13 January 2025
- What the ISO 9001 doesn’t cover
- All functions in scope.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- Yes
- CSA STAR accreditation date
- Tuesday 25 November 2025
- CSA STAR certification level
- Level 2: CSA STAR Attestation
- What the CSA STAR doesn’t cover
- All parts covered.
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 17a8c65c-2c59-478a-900e-a94910b58818
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 662b0be8-be3b-468f-b4d1-f2b121b15245
- Other security certifications
- Yes
- Any other security certifications
-
- NHS DSPT (Standards met) - ODS Code: V3KCI
- NHS DTAC & DCB0129 accredited
- ICO Registration (Number: ZA926711)
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-