Access Intelligent Care Platform (AICP)
The Access Intelligent Care Platform (AICP) is an AI-enriched operational improvement platform that integrates people, processes, and systems across the health and social care continuum. AICP addresses the critical challenge of communication silos between organisations, improving patient outcomes and operational efficiency.
Features
- AI-powered Co-Pilot provides intelligent patient record summaries
- Rio system integration included as standard baseline capability
- Natural language querying of Rio patient clinical records
- Graphical Timeline View displaying events and interventions chronologically
- Real-time patient demographics, allergies, appointments, and diagnoses
- Modular architecture enabling incremental additional system feed integration
- Automated notifications via platform feed, email, and SMS
- Communications Hub maintaining complete audit trail of discussions
- Role-based permissions ensuring appropriate data privacy controls
- Multi-instance Rio data access supporting cross-regional visibility
Benefits
- Immediate value without requiring complete system integration initially
- 15-20% reduction in clinical and administrative time requirements
- Care professionals quickly understand patient history without searching
- Third-sector staff gain Rio access without full licences
- Patients receive more coordinated, efficient care delivery overall
- Eliminates inefficient phone calls and manual update requirements
- Organisations expand integration capabilities at their own pace
- Partner organisations gain proportionally greater care visibility progressively
- Patients avoid repeatedly providing same information to providers
- More clinical time available for direct patient care
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 7 9 8 1 2 2 3 1 5 2 6 7 2 5
Contact
ACCESS UK LTD
Stacey Graham
Telephone: 01206322575
Email: buyer.enablement@theaccessgroup.com
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
- All end user and citizen facing components of the solution are fully browser based and need nothing installed on the client device other than the browser itself.
- System requirements
-
- End-user facing elements of the solution are accessed via web-browser
- Supported by, Windows 11, Edge (Chromium), Firefox and Chrome
- Supported in Safari on iOS14, iOS15 and iOS16
- Supported in Chrome on Android Tablet devices
User support
- Email or online ticketing support
- Yes
- Support response times
- Access has developed a range of support plans. Our online Knowledge base and Community service plans are available to all our clients. We have made significant investment in our client support tools. The Success portal provides around the clock access to log incidents, browse articles and videos to find solutions. Our Support teams are available M-F 9-5 ( or 8-6 on Standard/Premium) On these plans P1 cases are responded to in 1 hour. Please refer to Access for further details
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), 7 days a week
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- N/A
- Onsite support
- Yes, at extra cost
- Support levels
- Standard Success Plan- offers an enhanced reactive service, including telephone and e-mail support, as well as priority response times and longer support hours. Larger customers will also get access to a primary named support analyst who will deal with the majority of your support questions. Charged at 15% of your subscription fee. Premier Success Plan- provides proactive services, including access to a customer success manager with quarterly and annual review. Charged at 25% of your annual subscription fee.
- Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
- During the initiation stage of the project Access will work with the customer's project team to define a Training Strategy that will plan for the delivery of a range of training courses to relevant Trust staff at the most appropriate time during the implementation project. The Training Strategy will determine the optimum approach for delivering training, including end user training, and supporting materials with the options being traditional classroom based training or interactive eLearning content. In addition, the strategy will also consider available training resources such as trainers and training facilities, the required training environment configuration, and any training pre-requisites.
- Service documentation
- Yes
- Documentation formats
-
- Other
- Other documentation formats
- Microsoft Word
- End-of-contract data extraction
- All data held in the solution belongs to the customer. Data can be extracted via table views from the application into CSV, via Reports or via chargeable services to extract data which is otherwise unavailable to extract via the front end application.
- End-of-contract process
- Data is provided to the customer in the agreed format as described in the response above. The data is deleted securely when the customer has agreed all data has been provided and drives holding the data are securely cleansed. Access can provide an Exit Management Plan to highlight the steps involved in decommissioning the AICP application. Support can be provided to extract data for you on a time and materials basis.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Windows
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- AICP has been signed to work on both desktop and mobile devices.
- Service interface
- No
- User support accessibility
- WCAG 2.2 AA
- API
- Yes
- What users can and can't do using the API
- Access provides and out of the box set of generic APIs that can be used to provide third party systems bi-directional access . Access is part of the TechUK Interoperability charter that ensures these existing APIs are free from development costs and can be used by all our customers.
- API documentation
- Yes
- API documentation formats
- API sandbox or test environment
- No
- Customisation available
- No
Scaling
- Independence of resources
- Proactive monitoring of the platform is provided using Opman / Appman by ManageEngine. Where a server or other component is deemed to be nearing the threshold requiring additional resource the issue is rectified. Customer environments are hosted on either segregated VLANs or dedicated VMs meaning data is held on entirely separate, dedicated servers for each Customer.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Service metrics are provided in the form of call lists which users can filter on calls outstanding either by call reference, created date range, call status, name of reporter (customer reporting the issue), assignee (Access member) and summary. Customers can log in to the online support portal to view this information as and when required at no additional cost. Access can also supply availability statistics to the Customer. Other metrics can be supplied as part of a Service Delivery package which can be provided as an additional service. For example, monthly reporting of SLA performance and KPIs.
- Reporting types
-
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- When configuring reports, users are able to control the output format of the report, allowing reports to be presented for display on screen, or formatted for export as CSV or XML which can be transferred and ingested by other systems if required.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- XML
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- XML
- TXT
- XLS
- DOC
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- AICP availability will be 99.9% within hours of operation as per our standard SLA.
- Approach to resilience
- Each tenant is implemented in a PRIMARY >> WARM-STANDBY model i.e. with a primary service under normal operation & with a failover to another server on different host in a different data centre available for failover if access to some or all of the PRIMARY is lost for any reason. More detailed information is available on request.
- Outage reporting
- Users can subscribe to email alerts giving updates on scheduled maintenance and outages.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Username or password
- Access restrictions in management interfaces and support channels
- We operate role profile based Access Control - based on least privilege access. This applies to all our services.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- All controls included within Annex A of the ISO27001:2013 standard. Statement Of Applicability (SOA) available on request.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- All change management is undertaken in line with ISO27001:2013 using JIRA for audit purposes.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
We provide quarterly internal scans and annual scans by external parties against the infrastructure which feeds into our Cyber Essentials certification.
Our internal hosting policies define that the solution and hosted environment are tested for vulnerabilities regularly with a view to nullify threats, vulnerabilities and exploitation techniques. Penetration tests are conducted by an independent organisation to verify security.
Results of the tests are resolved by making a development change or making configuration changes to the hosted platform. In either case, the fixes are made based on priority according to the nature of the software and hosting methods. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- We have traffic monitoring and content based alerting on changes to the site and/or traffic flows implemented at infrastructure level. We keep daily historical reports from servers which provide the facility to identify when changes occurred. We proactively monitor third party suppliers vulnerability reporting and security fix availability. We patch any vulnerabilities found in a timescale appropriate for their level of severity. Our infrastructure response is within 1 hour in the SLA period 8am-8pm Monday – Friday.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- We operate a robust incident management process in line with ISO27001:2013 Staff are encouraged to report all incidents using a pre-defined process using a form available on our Company Collaborate site Incident reports will be provided following forensics and closure.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
- Health and Social Care Network (HSCN)
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 5%
- Between £250,000 and £500,000
- 6%
- Between £500,001 and £1,000,000
- 12%
- Between £1,000,001 and £2,500,000
- 15%
- Between £2,500,001 and £5,000,000
- 18%
- Over £5,000,001
- 25%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Alcumus ISOQAR
- ISO/IEC 27001 accreditation date
- Saturday 4 January 2014
- What the ISO/IEC 27001 doesn’t cover
- Nothing is excluded from the standard certification.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- BSI
- ISO 9001 accreditation date
- Friday 1 September 2023
- What the ISO 9001 doesn’t cover
- The scope covers the design, integration, maintenance and hosting of managed information systems and software applications, consultancy, user training and support for the Health, Education, Social Care and Local authorities. Excluding all other products that fall outside of this scope.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 88f162a5-ea3c-4f9a-83d5-42769c7d8459
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
- Other security certifications
- Yes
- Any other security certifications
-
- ISO 42001
- ISO 27701
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
-