QA360 Mediref Specialist Service Referrals
QA360 Mediref Specialist Service Referrals is a secure, cloud-based referral management solution supporting the capture, tracking and coordination of specialist service referrals. It provides configurable referral pathways, workflows, document management and reporting to improve visibility, governance and efficiency across referral processes.
Features
- Referral management: End-to-end referral tracking and status management
- Configurable referral pathways: Supports multiple specialist service workflows
- Referral forms: Structured capture of referral information
- Document management: Secure storage of referral documentation
- Role-based access control: Secure access by user role
- Audit and traceability: Full history of referral activity
- Reporting and analytics: Referral volumes, performance and trends
- Service directories: Configurable specialist service listings
- Task management: Supports referral follow-ups and actions
- Modular configuration: Adaptable to different referral models
Benefits
- Improved referral visibility: Clear status tracking and oversight
- Faster processing: Reduces delays in referral handling
- Consistent workflows: Supports standardised referral processes
- Improved governance: Clear audit trails and accountability
- Reduced administration: Streamlines referral management tasks
- Flexible configuration: Adapts to local service models
- Secure information handling: Protects sensitive referral data
- Better reporting: Supports service planning and monitoring
- Scalable solution: Grows with service demand
- Improved coordination: Enhances collaboration across services
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 3 9 7 5 4 3 6 4 6 9 9 5 3 4
Contact
QAPLUS LIMITED
Sion Davis
Telephone: 01633876142
Email: info@qaplus.co.uk
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Education
- Adult Social Care
- Children's Social Care
- Other
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Service constraints
- QA360 Mediref Specialist Service Referrals is delivered as a secure, cloud-based service and is optimised for use with modern web browsers. The service follows a regular release cycle, with updates and enhancements applied at planned intervals and interim patches deployed where required. Release notes are provided in advance via the helpdesk to support continuity, performance, and security.
- System requirements
- None as this is a cloud based solution
User support
- Email or online ticketing support
- Yes
- Support response times
- QAPlus provides responsive helpdesk support, with all queries acknowledged and investigation initiated within four working hours during standard helpdesk hours (9:00am to 5:30pm, Monday to Friday, excluding public and statutory holidays), in accordance with our Service Level Agreement.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Unlimited Helpdesk Support is available for trained users of the solutions, for how to use queries. This is included within the investment for the licence. Helpdesk calls are triaged depending on agreed urgency and severity to H1 requiring conclusion within 4 hours, H2 within a week and H3 within a month.
Each client is allocated a Client Service Manager who will meet quarterly as a minimum standard. Should it be more frequent meet ups are required this will be charged as per the pricing document. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
QA360 provides a structured and fully managed onboarding process for Mediref Specialist Service Referrals. An experienced project manager works collaboratively with customer stakeholders to develop an agreed implementation plan, covering configuration, data setup, user access, and readiness activities.
Onboarding activities focus on configuring referral pathways, service descriptions, user roles, and reporting to align with agreed referral processes. Training and knowledge transfer are provided as required to support confident use of the service from day one.
Offboarding is managed in a controlled and transparent manner, supporting secure data export and service exit in line with contractual and data protection requirements. This ensures continuity and clarity at the end of the service lifecycle. - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- QA360 assures collaboration to extract and export your data into a usable format. Additional costs, based on data size and scope, will be calculated and communicated upfront, ensuring transparency and informed decision-making regarding any incurred expenses.
- End-of-contract process
- QA360 acknowledges that the end-of-contract process is tailored to each client, considering factors like retention periods and data format preferences. While typically not chargeable, any additional work may incur fees, which will be assessed once all requirements are known. Please refer to the terms and conditions for detailed information regarding end-of-contract procedures and associated charges.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
Onboarding and offboarding documentation is provided in PDF format and is written in clear, plain English to support ease of understanding for a wide range of users. The documentation is structured with logical headings, consistent formatting, and step-by-step guidance to aid navigation and comprehension.
Where required, documentation can be shared electronically to enable the use of assistive technologies such as screen readers, zoom tools, and text reflow features supported by standard PDF readers. Customers may also request alternative versions or additional support during onboarding and offboarding to ensure information is accessible to their users.
In addition to written documentation, onboarding and offboarding activities are supported by direct engagement from the QA Plus team, allowing users to ask questions and receive clarification where needed. This approach helps ensure that all users can effectively access and understand the information provided, regardless of individual accessibility needs.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Chrome
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Selected referral capture and review features are optimised for mobile use, while full configuration, reporting and administration are accessed via desktop browsers.
- Service interface
- No
- User support accessibility
- None or don’t know
- API
- Yes
- What users can and can't do using the API
- There not any current open source APIs. New APIs can be developed on a case-by-case basis, tailored to specific requirements, and provided as a chargeable service.
- API documentation
- No
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
-
QA360 Mediref Specialist Service Referrals is supported by the same configurable framework and professional services model used across QA360 solutions. The service can be configured during implementation and refined over time to reflect organisational processes and operational requirements.
During onboarding, QA360 works collaboratively with customers to configure referral pathways, service descriptions, referral forms, roles, permissions, and reporting structures. This ensures the service supports local referral processes while maintaining consistent governance, auditability, and oversight.
Configuration is delivered through system settings and templates rather than bespoke code changes, helping to maintain platform stability, security, and ongoing supportability. Changes can be requested through an agreed change process and may be delivered as part of standard configuration activity or as chargeable professional services, depending on scope.
Optional professional services are available to support pathway changes, service updates, training, and optimisation over time. Full details of available services and pricing are provided in the QA360 pricing documentation.
Scaling
- Independence of resources
- QA360 Mediref is delivered using dedicated virtual environments per customer, ensuring one organisation’s usage does not impact another. The service supports scalable deployment and increased referral volumes, with resource utilisation monitored continuously to maintain performance and availability.
Analytics
- Service usage metrics
- Yes
- Metrics types
- QA360 provides monthly and quarterly service metrics aligned to agreed success measures. These reports support service review and help customers understand how the solution is performing against agreed objectives.
- Reporting types
-
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Staff screening not performed
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- In-house
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
-
QA360 provides a range of standard reports to meet most user needs, with additional reports available upon request (which may incur charges). Users can export data from all list pages using export-to-Excel functionality, and SQL-based reports can be exported in Excel, CSV, or PDF formats.
In addition, at the end of the contract or upon request, QA Plus supports the secure export of customer data in commonly used electronic formats to support data portability and transition to alternative systems, in line with agreed exit arrangements. - Data export formats
-
- CSV
- ODF
- Data import formats
-
- CSV
- ODF
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- QA360 is designed for high availability and provides 99% uptime during business hours, excluding pre-planned and emergency maintenance. Planned maintenance is communicated in advance and scheduled outside business hours wherever possible to minimise disruption.
- Approach to resilience
-
QA360 is designed with resilience and availability as core principles. The service is hosted on resilient cloud infrastructure and uses load balancing and redundancy to minimise single points of failure and maintain service availability in the event of component failure.
The platform is deployed across multiple backend components and supports automatic scaling to manage demand and maintain performance. All releases are subject to controlled deployment processes and thorough testing prior to production to ensure stability and reliability.
Data is hosted in UK-based datacentres that meet recognised industry standards for resilience and physical security. Regular backups are performed and stored securely to support data recovery and service restoration if required.
Further details of the infrastructure design and datacentre arrangements are available on request. - Outage reporting
-
System outage will be reported to the technical director at QA360.
This will then be communicated to clients via the QA360 support portal.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is restricted to authorised personnel only. User authentication is required using unique usernames and passwords, with 2-factor authentication applied to administrative and support access where appropriate. Access is role-based and limited to the minimum required to perform assigned duties. Administrative and support access is monitored and reviewed regularly, and access is removed promptly when no longer required.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
-
Cyber Essentials Plus
IG Toolkit - Information security policies and processes
- The information security policies for QA360 are available on request.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- QA Plus operates defined configuration and change management processes to support secure and stable service delivery. Service components are tracked throughout their lifecycle using controlled versioning and configuration records from development through to live operation. All changes are subject to formal change control and assessed for risk and potential security impact prior to approval. Changes are tested in non-production environments before deployment, and access to make changes is restricted to authorised personnel only, with all changes logged for audit purposes.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- QA Plus operates a defined vulnerability management process to identify, assess, and remediate potential security threats. Potential vulnerabilities are assessed based on risk, impact, and exploitability, with priority given to issues affecting data security or service availability. Security patches and updates are deployed in a timely manner following testing, with critical patches applied as a priority. Information about potential threats is obtained from cloud platform providers, software vendors, security advisories, and ongoing operational monitoring, supporting proactive management of vulnerabilities.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
QA Plus operates defined protective monitoring processes to identify and respond to potential security incidents. System activity and service performance are continuously monitored to detect unusual behaviour or indicators of compromise. Alerts are investigated promptly by authorised personnel, and appropriate containment and remediation actions are taken where required.
Incidents are handled in line with internal incident management procedures, with priority given to issues affecting data security or service availability. Response times are based on the severity of the incident, with critical issues investigated immediately during support hours and escalated as necessary. - Incident management type
- Supplier-defined controls
- Incident management approach
- QA Plus operates defined incident management processes for handling common incident types, including service availability and security-related events. Users report incidents via the QA Plus helpdesk during standard support hours, where incidents are logged, prioritised, and managed to resolution. Customers are kept informed as appropriate, and incident reports can be provided following resolution, particularly where incidents impact service availability or data security.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 20%
- Between £250,000 and £500,000
- 40%
- Between £500,001 and £1,000,000
- 50%
- Between £1,000,001 and £2,500,000
- 60%
- Between £2,500,001 and £5,000,000
- 65%
- Over £5,000,001
- 65%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Citation
- ISO 9001 accreditation date
- Thursday 18 December 2025
- What the ISO 9001 doesn’t cover
- The ISO 9001 certification covers our quality management system and related business processes. It does not certify specific products, individual customer implementations, or guarantee the performance or availability of the service itself.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- C7e476c2-1312-42ae-9fae-de961c890cdd
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 3c53c59c-521e-472b-be08-f8506111bf7c
- Other security certifications
- Yes
- Any other security certifications
- NHS Data Security and Protection Toolkit
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-