Medanets solution
Medanets revolutionises healthcare with superior mobile solutions. Developed together with healthcare professionals, the app enables safe and efficient nursing workflows, supports decision-making and leaves more time for care. The Medanets app integrates with EHR systems and complements their features.
Features
- Viewing and recording patient information at the bedside
- Medication management: view and record administration
- Clinical risk assessments (EWS, Sepsis etc.) at the bedside
- Tasks, worklists and checklists and Decision prompts
- Seamless connection of patient monitoring devices via the app
- Summary views, such as dashboard, graphs and patient card
- Electronic patient identification and secure user authentication
- Offline mode for uninterrupted use
- AdminUi, reporting and configuration tool
- Clinical photos and clinical messaging
Benefits
- Elimination of double documentation and smoother daily routines
- Instant data sync with the EHR and built-in decision support
- Structured bedside documentation and direct access to up-to-date data
- Guided, standardised healthcare workflows with EHR-mobile integration
- CE-marked medical device, class I (MDD) / class IIa (MDR)
- Measurable cost savings through time efficiency and avoided adverse events
- Erroneous documentation can be reduced by about 70 %
- Improves quality of care by supporting quicker interventions.
- User-friendly design, intuitive and fast to learn
- Proven adoption: used 100+ hospitals and care units accross Europe
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 2 6 9 1 8 3 8 5 2 0 9 4 4 4
Contact
Medanets Oy
Juha-Matti Ranta
Telephone: +358 44 566 4999
Email: hello@medanets.com
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes
- What software services is the service an extension to
- Medanets solution complements Electronic Patient Record (EPR) Systems by mobile app. It retrieves and writes patient data directly to the EPR, ensuring near real-time synchronization of observations, medication records, and clinical assessments. Can be integrated to multiple EPRs.
- Cloud deployment model
-
- Public cloud
- Private cloud
- Service constraints
-
Medanets solution supports e.g. Millennium EPR and is possible to integrate to other EPRs with open integration principles.
Medanets application updates requires planned maintenance schedules minimum once a year.
Medanets validates mobile devices which are to be used for the application. - System requirements
-
- Linux servers (Ubuntu, RedHatLinux or Oracle Enterprise Linux or Kubernetes)
- Access to generic Linux repositories and Medanets own application registry
- IPSEC or VPN connection for Medanets engineers to hosted environment
- Server certificates for encrypted connection
- Automated backup, monitoring and alerts of hosted environment
User support
- Email or online ticketing support
- Yes
- Support response times
- Quickly and according to SLA
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Business hours support included in the price, 24/7 support available with separate price.
Technical account manager provided as a rule.
24/7 support:
Phone support 24/7 every day. Email during normal business hours 9 to 5 (UK time) Monday to Friday (excluding bank holidays).
Phone Response immediate or within 30 minutes. Email response with in a full business day.
Normal business hours support:
Phone and email during normal business hours 9 to 5 (UK time) Monday to Friday (excluding bank holidays).
Response within a full business day.
Technical support tiers:
Expecting client to have first tier support and Medanets provides second tier support. - Support available to third parties
- No
Onboarding and offboarding
- Getting started
- Users are provided with online user manuals, Training the Trainers on use of the service, Go-live onsite training and support during the use of service.
- Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- Not applicable as user data is already stored in customer's data repository.
- End-of-contract process
- A separate exit plan will be created and agreed together with the buyer.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Provided via email to the organization as there are differences how organizations use the Medanets application.
Using the service
- Web browser interface
- No
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
Service (end user application) on mobile.
Administration on desktop AdminUi tool. - Service interface
- No
- User support accessibility
- None or don’t know
- API
- No
- Customisation available
- Yes
- Description of customisation
-
Terminology, care processes, code sets, etc. can be customised.
Only named buyer administrators can customise the service.
Customisation can be done through AdminUI tool.
Customisation of features under EU Medical Device Regulation is done only by Medanets support team.
Scaling
- Independence of resources
- Tenant isolation in solution architecture ensures resources are always available
Analytics
- Service usage metrics
- Yes
- Metrics types
- Solution usage, API usage, database analytics, runtime environment resources monitoring.
- Reporting types
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
- Not applicable. Data is only stored temporarily in the Medanets service and is automatically deleted periodically. All data is stored in third party electronic patient record system.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
Service Availability:
The availability of the solution is calculated according to the customer’s support service. If the customer has support only during office hours, the availability of the solution is also calculated based on office-hour time. If the customer has purchased 24/7 support, the availability is calculated on a 24/7 basis as well.
Target Uptime:
Medanets shall maintain 99.5% monthly availability, excluding scheduled maintenance windows, hosting related availability issues and force majeure events.
Offline Mode Guarantee: In the event of network disruption, the application shall remain fully functional in offline mode, with automatic synchronization upon connectivity restoration.
Scheduled Maintenance: Maintenance windows will be communicated at least 72 hours in advance.
Emergency maintenance will be notified immediately.
Support Commitments:
Standard Support Hours:
Monday–Friday, 09:00–17:00 (local time).
Critical Incident Support (Defect Class 1): 24/7 hotline availability for severe issues impacting patient safety or system operability.
Initial response within 30 minutes of ticket submission.
Resolution or workaround within 4 hours for critical defects.
Optional Extended Support: 24/7 coverage for all severity levels available under premium SLA. Dedicated account manager and quarterly performance reviews. - Approach to resilience
- This information is available on request.
- Outage reporting
- Email alerts
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- Medanets restricts access to its management interfaces through customer‑owned identity systems (Entra ID, AD) and role‑based access controls, ensuring that only authorised administrators can configure or view system settings. Access to Medanets servers and logs is limited to named customer personnel and named Medanets technicians. Support channels are similarly access‑restricted: only authorised customer representatives may contact the Medanets Helpdesk, and remote support is possible only over a customer‑controlled VPN. Diagnostic tools and logs are accessible exclusively to named technical staff, ensuring secure and auditable support operations.
- Access restriction testing frequency
- Less than once a year
- Management access authentication
- Multi-Factor Authentication (MFA)
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
-
Medanets’ security governance approach relies on:
A formal ISO 27001‑aligned ISMS with organization‑wide scope.
Comprehensive policies (security policy, supplier security, communication programme, secure coding).
Clear roles and responsibilities and oversight groups.
Strong technical security governance, including authentication, encryption, device security, and logging.
Continuous risk management, monitoring, and improvement processes.
Integration of quality system controls and regulatory requirements, especially relevant for medical‑device‑related processes.
This governance structure ensures that Medanets’ security activities are systematic, auditable, compliant, and aligned with international best practices. - Information security policies and processes
-
Medanets Oy has established, implemented, maintained, and is continuously improving an information security management system aimed at preserving the confidentiality, integrity, and availability of information. The management system is implemented by applying a risk management process. The information security management system follows the ISO 27001 standard and is intended to be certified in
the coming years.
Medanets' management has written an information security policy from which the company's information security objectives are derived.
The information security policy is described in the document ‘ISMS-DOC-05-2 Information Security Policy’, and the objectives derived from the policy can be found in the document ‘ISMS-DOC-06-1 InfoSec Objectives and Plan’.
Medanets has ensured that roles, responsibilities, and authorities are clearly defined to prevent many information security incidents from happening and to react effectively and appropriately if they do. All personnel have been trained on the information security policy. In addition, personnel receive regular training in accordance with their duties. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- The configuration and change management process is part of the Medanets Design and Development process which has been defined under certified Medanets ISO 13485 quality management system. In addition the software development process complies with the IEC 62304:2006 standard for medical device software, which defines a set of processes for managing the lifecycle of medical device software. These include the software development process, the configuration management process, the software bug management process, the risk management process (in conjunction with ISO 14971), deployment and the maintenance process.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Medanets manages vulnerabilities through secure‑by‑design development (OWASP/NIST), automated vulnerability detection in CI/CD pipelines, structured ISO 14971 & IEC 81001‑5‑1 risk‑based controls, and formal security problem‑resolution processes covering identification, analysis, mitigation, and verification of vulnerabilities. This ensures vulnerabilities are prevented early, detected continuously, and remediated systematically with documented governance.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Medanets’ protective monitoring approach combines secure technical logging, restricted log access, continuous monitoring of integrations and system health, MDM‑enforced device controls, structured cybersecurity lifecycle monitoring under IEC 81001‑5‑1, proactive post‑market surveillance, and active monitoring of global vulnerability alerts. This ensures real‑time oversight, early detection of abnormal activity, and rapid response to potential security threats.
- Incident management type
- Supplier-defined controls
- Incident management approach
-
Medanets has created a procedure that provides an overview of incident response, defines roles and responsibilities, communication protocols, decision-making processes, and post-incident activities to manage information security incidents effectively.
Medanets users report incidents via the Medanets Helpdesk by email or telephone. Medanets documents and investigates incidents using its ISO 27001‑aligned Incident Response Procedure and produces structured incident reports (including root cause analysis, chronology, impact, and corrective actions). Customer‑specific reports are shared directly with affected customers, and regulatory reports are submitted to authorities when required for medical‑device‑related incidents. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- Demo version only by request.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 15%
- Between £500,001 and £1,000,000
- 20%
- Between £1,000,001 and £2,500,000
- 30%
- Between £2,500,001 and £5,000,000
- 35%
- Over £5,000,001
- 40%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- Yes
- Any other security certifications
- ISO 13485 Medical devices — Quality management systems certificate
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
-