Merge Imaging Suite
Merge Imaging Suite is a modular, cloud‑native imaging platform that unifies archiving, viewing, workflow orchestration and AI to streamline imaging operations, reduce IT complexity and enhance collaboration. It improves clinical efficiency, centralises data and supports scalable, secure enterprise imaging across hybrid or full‑cloud environments.
Features
- Full PACS client
- Zero-footprint web-based diagnostic viewer
- EPR integration
- True Vendor Neutral Archive (VNA)
- Workflow Orchestrator with AI integration
Benefits
- High throughput diagnostic workstation for Radiologists
- Diagnostic viewer available to all Clinicians
- Single click linking from EPR to relevant imaging studies
- Resilient long-term archiving for DICOM and non-DICOM imaging data
- Lifecycle management, policy based compression/deletion
- Integrates with AI preliminary results to prioritise urgent/actionable studies
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 8 6 5 9 6 9 0 1 0 8 2 2 4 0
Contact
HOSPITAL SERVICES LIMITED
Graham Stewart
Telephone: 01157043000
Email: sales@hsl.ie
About your service
- Service categories
-
Applications
Content workflow and management
Content services
- Enterprise Content Management Applications
- Content Sharing and Collaboration Applications
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
- Merge Imaging Suite requires periodic planned maintenance windows—monthly, quarterly, or annually—which may involve brief downtime across cloud services and on‑premise components. During these windows, diagnostic viewing may temporarily shift to downtime viewers with reduced customisation options such as limited hanging protocols and tool settings. The service also depends on client‑provided on‑premise infrastructure, including physical or virtual servers and adequate bandwidth, and requires correctly configured gateways for failover. Notifications from the Cloud VNA may be limited during gateway failover until the primary node is restored.
- System requirements
-
- Host a small number of VMs on-prem as gateways
- Internet access
User support
- Email or online ticketing support
- Yes
- Support response times
-
P1 incidents (24×7): assigned + acknowledged within 30 minutes for ≥ 98% of tickets logged via Service Desk.
P2 incidents (next business day coverage): assigned + acknowledged within 1 hour for ≥ 98% of tickets.
P3 incidents (next business day coverage): assigned + acknowledged within 1 business day for ≥ 98% of tickets.
P4 incidents (next business day coverage): assigned + acknowledged within 1 business days for ≥ 98% of tickets. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Merge Imaging Suite provides support through a structured SaaS service model that includes cloud‑service operations, monitoring, upgrades, maintenance scheduling, and incident escalation. Customers receive access to Merge’s cloud operations team and established escalation pathways for technical issues, configuration queries, and operational continuity. Support activities cover environment monitoring, maintenance windows, upgrade management, gateway failover assistance, and diagnostic viewer continuity.
Support costs are built into the Imaging Suite subscription, with additional charges where applicable. Standard Professional Services are costed relative to annual recurring revenue, while Optional Professional Services are billed at £1,500 per day. A monthly, non‑refundable Pre‑Production Fee applies during system build and testing before go‑live. Cloud Managed Services (e.g., Tier 2 storage management) are billed monthly.
Customers are supported by Merge’s cloud operations, professional services, and escalation teams as part of the managed SaaS service model. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- A training package will either be onsite or remote. We can train individual Radiologists, or a train-the-trainer approach with PACS administrators.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
At the end of contract term, all imaging data and associated metadata stored within the Merge Imaging Suite remain fully under the customer’s ownership and control. Throughout the service period, customers manage their data within the Merge Vendor Neutral Archive (VNA), which provides administrative tools for exporting, routing, and lifecycle management. These same capabilities enable customers to extract their data at contract end using standard DICOM services, HTTPS‑based transfers, and policy‑driven export workflows, ensuring that images and reports can be securely transferred to any destination system of their choosing.
Crucially, the customer retains access to the environment until the agreed contract termination date. During this period, customers may initiate bulk data export from the VNA, including long‑term archive content and cache. The platform supports flexible routing rules and image retrieval functions, allowing customers to extract data in a structured, standards‑based format compatible with downstream PACS, VNA, or analytics platforms.
Following extraction, any remaining data is deleted in accordance with the customer’s Master Agreement and data‑retention provisions, ensuring secure removal once the customer confirms successful migration. Merge does not restrict or charge penalties for customer‑initiated data extraction beyond any contracted professional services required to assist with large‑scale migrations. - End-of-contract process
-
The customer retains full ownership and control of all data held within the service. Prior to termination, the customer continues to have access to the Merge Imaging Suite environment, allowing them to extract all required data—typically DICOM images, associated metadata, reports, audit records, and configuration files. Data can be exported using standard industry protocols (e.g., DICOM retrieve, HTTPS‑based export, routing rules) and through the administrative tools available within the Vendor Neutral Archive (VNA) or other components of Imaging Suite.
Once the customer confirms successful extraction or migration, the service enters a decommissioning phase. At this point, the supplier securely removes remaining data from cloud or on‑premises components in accordance with the Master Agreement’s data‑retention and data‑destruction clauses. A confirmation of deletion can be provided if required.
Included in the contract price
- Continued access to the platform until contract termination
- Ability to self‑export data using built‑in administrative tools
- Standard data‑deletion activities following customer confirmation
- Access to system logs and audit data
Additional cost items
- Professional services for large‑scale or complex data migrations
- Custom data formatting, transformation, or validation
- Extended access beyond the contract end date
- Any third‑party tooling or infrastructure needed for migration - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- While accessibility principles—such as appropriate contrast, legible typography, keyboard navigation and UI clarity—are referenced in design documentation, including mention of WCAG, Merge Imaging Suite documentation is not certified or stated as compliant with WCAG 2.2 (A/AA/AAA) or EN 301 549.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- Yes
- Compatible operating systems
-
- Linux or Unix
- Windows
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Merge Universal Viewer is not certified as diagnostic quality on smartphone screens, only full size displays.
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- Web portal for customer-configurable settings.
- Accessibility standards
- None or don’t know
- Description of accessibility
- N/a
- Accessibility testing
- N/a
- API
- No
- Customisation available
- Yes
- Description of customisation
-
Merge provides mandatory training courses for administrators, enabling self-service customisation of many functions. Sometimes Professional Services are required, which can be quoted ad-hoc.
End-user training is also available and highly recommended, whether on-site face to face, remote, or simply online reading. PACS and Merge Universal Viewer allow a great deal of customisation to preserve user preferences between sessions, such as bespoke Hanging Protocol support.
Scaling
- Independence of resources
-
Merge Imaging Suite operates a Kubernetes environment with customer-dedicated Containers, ensuring independence from other customers, whether in terms of upgrades or planned maintenance. As a large pool of compute resource is available to these multiple customers - and additional compute resources can be provisioned by Azure in minutes, any fluctuation in demand can be satisfied without downtime.
Merge Cloud Ops monitors and manages capacity, pre-emptively adding worker nodes based on demand.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Customer portal shows usage in terms of study volumes. Merge VNA provides a number of relevant pre-defined and customisable reports as well as user-customisable Kibana based reporting. Customers can contact our helpdesk for assistance in creating custom reports.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- Merge by Merative
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Degaussing
Data importing and exporting
- Data export approach
-
The Merge VNA makes data available via DICOM query/retrieve at any time.
At end of contract, if desired, Merge can execute a Transfer Of Ownership of a customer's Azure Blob bucket such that they have direct access to the studies stored in their native format. - Data export formats
- Other
- Other data export formats
-
- DICOM
- Blob bucket access
- Data import formats
-
- CSV
- Other
- Other data import formats
- DICOM migration project
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
- Each customer's containers are also separated at a network level.
Availability and resilience
- Guaranteed availability
- An uptime SLA of 99.9% availability is standard. Higher uptime can be engineered and priced if required.
- Approach to resilience
-
Imaging Suite runs in Microsoft Azure using a Kubernetes platform spread between three data centres, thus providing both component-level and infrastructure-level resilience for compute. Storage is in Azure Blob under which all studies are stored in three data centres in the Region.
If a customer has higher resilience requirements, Merge is able to deploy between two independent Azure Regions at increased cost, thereby mitigating against region-wide disasters. - Outage reporting
- Outages are communicated via email alerts.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is tightly controlled using role‑based access control (RBAC) to enforce least‑privilege and separation of duties. Privileged accounts use encrypted access methods and de‑identified logins, with no direct database or file‑system access granted to end users. Identity and access governance follows NIST‑aligned policies, including formal authorisation, periodic reviews, and full audit trails. Network segmentation restricts management traffic, while system‑to‑system access is controlled through validated identifiers. Support access uses secure, authenticated channels such as SecureLink or approved customer remote‑access platforms, ensuring all interactions remain controlled, logged, and limited to authorised personnel.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- Merge Imaging Suite is SOC 2 Type II certified and leverage ISO 27001 compliant infrastructure via Microsoft Azure.
- Information security policies and processes
-
Merge follows a comprehensive set of information security policies and processes designed to safeguard confidentiality, integrity, and availability across all systems and services. The foundation is the organisation’s ITS-POL-001 IT Corporate Security Policy, which defines global security requirements, roles, sanctions, and controls governing physical and logical access, least‑privilege authorisation, separation of duties, and secure management of information assets.
This is complemented by the ISO-POL-001 Merative Information Security and Privacy Manual, which underpins Merative’s ISO/IEC 27001 and 27701‑aligned Information Security Management System (ISMS) and Privacy Information Management System (PIMS). It establishes formal governance, risk assessment methodology, continuous improvement cycles, and responsibilities across IT, Legal, Privacy, and Compliance.
Merge also maintains detailed operational processes, including incident response, vulnerability management, asset protection, secure disposal, and exception handling, as demonstrated in risk assessment and security questionnaires. The organisation adheres to the NIST Cybersecurity Framework and implements controls consistent with NIST SP 800‑53, reinforced by regular policy reviews and security testing (including SAST, DAST, and third‑party penetration testing).
Additional measures are documented in the Technical and Organisational Measures (TOMs), which details incident handling, secure sanitisation, endpoint protection, and breach‑notification obligations.
Together, these policies ensure a mature, audited, and standards‑aligned security framework across all Merge solutions. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- QA-5268 defines the Standard Operating Procedure for Internal Product Change Control within the Development organisation. It establishes the required governance, documentation, and approval workflow for modifying product components, ensuring all changes follow Merative’s Quality Management System. The SOP outlines roles, responsibilities, evidence requirements, and traceability expectations throughout the change lifecycle. It ensures changes are assessed for impact, reviewed for compliance, verified through appropriate testing, and recorded for auditability. Its purpose is to maintain product integrity, support regulatory alignment, minimise risk, and ensure consistency across development processes. The document is in Released status with a revision level of 6.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
ITS‑SOP‑012 defines Merative’s Product Security Vulnerability Management process, outlining how software vulnerabilities—such as OWASP Top 10, SANS Top 25, and NIST‑identified weaknesses—are proactively identified, assessed, and addressed. It incorporates real‑time threat intelligence from CVE, CISA, HC3, and H‑ISAC to strengthen detection and response.
ITS‑SOP‑011 details System and Network Vulnerability Assessment procedures, including automated internal and external scanning, Qualys‑based monitoring, severity classification, mapping of vulnerabilities to affected assets, and verification of remediation. The Vulnerability Management Team coordinates notification, tracking, and validation to ensure consistent, auditable remediation across environments. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Merative maintains a comprehensive, NIST‑aligned incident response program designed to protect client systems and data. Our 24/7 Security Operations Center continuously monitors for potential threats and rapidly investigates alerts. When an issue is suspected, we follow a structured lifecycle—detection, analysis, containment, eradication, and recovery—coordinated by a multidisciplinary Cybersecurity Incident Response Team involving Security, Privacy, Legal, and technical experts. If an incident affects a client, we notify them without undue delay, provide regular status updates, and work collaboratively until full resolution. Our process ensures swift, transparent handling of incidents while minimising impact and strengthening long‑term security.
- Incident management type
- Supplier-defined controls
- Incident management approach
-
Merge follows a structured, NIST‑aligned incident‑management process covering detection, analysis, containment, eradication, recovery, and post‑incident review. A 24/7 Security Operations Centre monitors systems and triages alerts, escalating any suspected incident to the Cybersecurity Incident Response Team. Incidents are investigated promptly, with impact assessed, forensic analysis performed, and affected clients identified. Containment and remediation actions are executed to restore secure operations. Legal, Privacy, and Compliance functions determine notification obligations, ensuring clients are informed without undue delay when required. All incidents are documented, lessons learned are reviewed, and policies are updated to strengthen future security posture.
See ITS‑SOP‑007 Cybersecurity Incident Response Plan. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 1%
- Between £500,001 and £1,000,000
- 1%
- Between £1,000,001 and £2,500,000
- 1%
- Between £2,500,001 and £5,000,000
- 1%
- Over £5,000,001
- 1%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- BMTrada
- ISO/IEC 27001 accreditation date
- Tuesday 29 July 2025
- What the ISO/IEC 27001 doesn’t cover
- Full Scope Covered
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- NQA
- ISO 9001 accreditation date
- Friday 11 November 1994
- What the ISO 9001 doesn’t cover
- Full Scope Covered
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Ed2e888b-2e5b-483b-9bc2-7456c9351fb5
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 561e4d9e-c849-4a96-b973-6ea95a37959c
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Ensuring new workers are informed of their right to join a trade union
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
- How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
- How the supplier will work with NGOs, trade unions or other businesses to address modern slavery risk
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
-