Virtual Health Platform
Virtual Health Platform is Telstra Health’s virtual care solution designed to support the transformation traditional care delivery into a digital, automated, and streamlined process that can be easily adopted by healthcare services right across the continuum of care.
Features
- Triage dashboard: Triaged view of patient cohort for prioritisation
- Observations: Comprehensive hospital grade observation
- Care pathways: Patient journey management as-a-pathway
- Device agnostic: iOS, Android, web and 3rd party biometric compatibility
- Standards: FHIR open data model and clinical data repository (CDR).
- Patient communication: Azure Communication Services (ACS) based clinician-patient communication
- Accessibility: WCAG2.1 AA Level compliant solution
Benefits
- Improved patient safety through real time access to patient data
- Reduction in unplanned and avoidable readmission
- High compliance rate amongst patients >90%*
- Enhanced patient experience and empowerment
- Decreased length of stay
- Faster response to clinical deterioration
- Increased ability to confidently manage large cohort of patients
Pricing
£25.12 to £30.62 a user a month
Service documents
Request an accessible format
Framework
G-Cloud 14
Service ID
8 4 3 2 5 0 2 1 2 0 9 6 5 6 0
Contact
DR FOSTER LIMITED
Sales Team
Telephone: 0800 288 9808
Email: sales@drfoster.com
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Telstra Health Helix Primary Care EMR System
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
- None
- System requirements
- None.
User support
- Email or online ticketing support
- Email or online ticketing
- Support response times
-
The Support Team prioritises incidents and requests based on their business impact and urgency. Impact refers to the severity of the issue and its potential disruption to business operations. The urgency reflects the timeframe for a resolution to minimise negative consequences. This prioritisation applies to all issues and requests submitted through the customer portal, email, and phone.
The following outlines response and resolution times based on issue severity.
- P1(Critical): 100% in 30 Minutes*
- P2 (High): 98% within 1 Hour*
- P3 (Med) 92% within 4 business days
- P4 (Low) 90% within 6 days
*If full support purchased - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), 7 days a week
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Level 1 - Issue which relates to or is caused by the Software which causes the Service as a whole to be completely down/not operational, for which there is no reasonable work-around. Characteristics:
- Virtual Health Portal is offline/inaccessible
- Virtual Health Portal FHIR (API) Server is offline/inaccessible
- Virtual Health Platform Video Conferencing is offline/inaccessible
Level 2 - Severity Level 2 means an Issue which has, or potentially has, a major impact on Authorised Users. Characteristics:
- Causes a loss of access to, or degraded functionality.
- Inability to access a page.
- Any issue preventing the transfer or linking of data
Level 3 - Severity Level 3 means an Issue which has, or potentially has, a medium impact on Authorised Users. Characteristics:
- Limited functionality of environmental element(s) with no imminent impact on the functionality of the Software; and/or
- Degraded functionality with no significant business impact but work around available.
Level 4 - Severity 4 means an Issue which has, or potentially has, a minimal impact on Authorised Users. Characteristics:
- Degraded minor functionality; and/or
- A minor feature or functionality is not available.
- General query/application support - Support available to third parties
- No
Onboarding and offboarding
- Getting started
-
VHP prioritises a smooth onboarding experience for both patients and clinicians by providing:
- Straightforward Interface: inlcuding a clear and easy-to-navigate interface suitable for users of all technical abilities. Designed to minimise confusion, it allows for intuitive exploration and quick access to key functionalities.
- Inclusive Design: Adherence to Web Content Accessibility Guidelines (WCAG) 2.1 AA, guaranteeing accessibility for a diverse range of users, including those with disabilities.
- Comprehensive Support Materials: Provision of in-depth user guides and training materials tailored to each user type (patients, clinicians, administrators). These resources explain core functionalities and best practices.
- Training Options: We offer a Train-the-Trainer program to equip your team with the knowledge to confidently train others on VHP. Additionally, tailored training sessions can be arranged to address your specific needs.
- Mobile-Friendly Onboarding: MyHealthAccess, the VHP patient app provides clear and guided experiences to set up their accounts, access care plans, and manage their health information.
- Designed with Clinicians for Clinicians: Telstra Health incorporates clinical SME within the entire product lifecycle as well as incorporating feedback from our clinical customers. This means the workflow of our solution is aligned to how clinicians manage patients for the most effective care offering. - Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
-
- Microsoft Word
- Diagrams
- Microsoft PowerPoint Presentations
- End-of-contract data extraction
- Once a contract has been completed and on request of the customer, the data would be extracted on behalf of the customer within a reasonable timeframe and cost. This would be on request i.e. via a service desk request.
- End-of-contract process
- At the end of a contract, all clinical records and patient data can be extracted from the solution for migration to a new solution or data retention as required; noting that clinical records and patient data are wholly owned by our clients. End of contract data extraction and migration support are not included in the software licensing and support contract. These services can be provided by Telstra Health on agreement under a separate work order as required. Services provided can include, but need not be limited to, review and agreement on scope of data, data and file formats, data conversion (cleansing and mapping), migration staging environment provision, extract, transfer, load (ETL) support, testing and data quality review and support. The work order can be scoped and agreed with you with consideration of days effort and Telstra Health professional services rates valid at the time of contract ending.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
Clinical staff can access the VHP Application through a web-based browser. Mobile app (MyHealthAccess) and desktop browser are offered for the Patient Portal. Both are WCAG 2.1 AA compliant.
Both platforms offer core functionalities like viewing care plans, scheduling video consultations, and communicating with clinicians through chat. Data collection through supported Bluetooth devices or manual entry. Mobile App provides additional features:
- Push notifications: Receive alerts and reminders for appointments and tasks.
- Camera access: Easily upload photos or documents for efficient communication with clinical staff.
- Touch-optimized interface: Designed for intuitive navigation with your fingers on a smaller screen. - Service interface
- Yes
- User support accessibility
- WCAG 2.1 AA or EN 301 549
- Description of service interface
- As a SaaS solution, a range of service and maintenance activities are managed by Telstra Health for example upgrades, patching, systems performance monitoring and tuning. Telstra Health support and maintenance specialists do not have access to client-side data. Client-side Systems Administrator users do not need to access or manage software code. Systems Administrator views are designed in alignment with the WCAG principles that guide the overall design of the solution. These views provide intuitive (point and click and keyboard entry) web browser interfaces for administrative tasks such as user provisioning, security settings, workflow rules, auditing and reporting.
- Accessibility standards
- WCAG 2.1 AAA
- Accessibility testing
- All end user interfaces, including for Patients, Clinicians and System Administrators, are designed and developed to adhere to the WCAG2.1 AA Level accreditation for accessibility standards. This includes meeting assistive technologies compatibility such as screen readers, audio descriptors and text enlargement. In addition, the solution is enabled to support multiple languages and regional formats. The solution has demonstrated uptake across diverse Patient cohorts within Culturally and Linguistically Diverse (CALD) areas of Australia enabled by an intuitive blend of text and non-text content (text alternatives), time-based media and layout adaptability.
- API
- Yes
- What users can and can't do using the API
-
The service interface and API are built on REST architecture, utilizing OAuth authentication and token-based authorization to ensure secure access. Each method and API endpoint is protected by user roles and permissions, with short-lived tokens that need to be regenerated periodically. This provides a robust and standardized way of managing user authentication and authorization, with fine-grained control over access to resources and actions. The combination of REST, OAuth, RBAC, and permission-based access control provides a secure foundation for the service interface and API, ensuring that access is granted only to authorized users and their actions are strictly controlled.
We have documentation for an Integration layer for Customers to manage resources within VHP.
We have UAT environments for testing purposes - API documentation
- Yes
- API documentation formats
- Other
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
VHP offers a comprehensive suite of tools designed to streamline care management and personalise the patient experience. Clinicians and health care professionals can create and configure individualised care pathways, guiding patients through their specific treatment journeys. These pathways can be tailored with specific medication protocols, treatment schedules, and other interventions, ensuring each patient receives the most appropriate care plan. VHP also simplifies documentation by allowing for the easy recording of patient observations, treatment outcomes, and overall management strategies.
Beyond streamlined processes, VHP fosters better patient engagement by empowering administrators and providers to design customisable questionnaires, forms, and pathway templates. This functionality ensures patients receive information directly relevant to their unique demographics, needs, conditions, and treatment plans.
VHP is a highly customisable solution given it’s a FHIR native application, allowing for seamless integration which caters for customisation on how integrations may be developed. In addition, the solution has a variety of rules or conditions used for the triage of patients, providing patient credentials and leveraging the care pathways as well as the management of observations through various rule settings to set calling criteria.
Scaling
- Independence of resources
- The Virtual Health Portal (VHP) leverages Azure's high availability by utilising Platform as a Service (PaaS) and deploying on Kubernetes Services across two geographically distinct regions within the UK. This redundancy ensures continuous operation even if one region experiences an outage. The secondary region acts as an active load balancer and failover zone, automatically directing traffic in case of any primary region disruption. This "Active-Active" configuration guarantees high availability, keeping the VHP accessible at all times. VHP is backed by infrastructure with an availability/uptime SLA of 99.99%.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
VHP empowers users to produce on-demand reports alongside dynamic operational dashboards powered by Microsoft PowerBI. The interactive dashboard facilitates in-depth data exploration, allowing clinicians to dissect information for trend analysis quickly. By leveraging PowerBI functionality, Extraction of reports is achieved via industry-standard formats such as Excel and CSV ensuring compatibility and flexibility in sharing data.
Dashboard includes:
Overall current patient load stats
Patient Adherence
Alerts and Acknowledgements
VHP Calls
Altered Calling Criteria Review Breach
Reports includes:
Patient Statuses
Archived Patients
Current suspended Patients
All Pathways
All Alerts
All Alert Acknowledgement and Finalisations
All VHP Calls
All Altered Calling Critera - Reporting types
- API access
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Up to Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Supplier-defined controls
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- In-house
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Data sanitisation type
-
- Explicit overwriting of storage before reallocation
- Deleted data can’t be directly accessed
- Equipment disposal approach
- A third-party destruction service
Data importing and exporting
- Data export approach
- Users may export data through our dashboard and reporting module. This would be a data extract from Microsoft PowerBI in CSV format, alternatively we may be able to export via an API, however a fee may apply for this service.
- Data export formats
- CSV
- Data import formats
- Other
- Other data import formats
- Data import via FHIR APIs or HL7 data feed
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
-
Data encryption at rest is achieved using Transparent Data Encryption (TDE) to encrypt the SQL Server.
Since the communication between multiples services and between client and the server is always over TLS the data in transit is default encrypted as a result, the data packets in transit cannot be tampered with or read even if they are intercepted
Availability and resilience
- Guaranteed availability
- We provide a guaranteed service delivery and system response time for each user. The SLA details the hours of cover as well as the target response and resolution times for each Incident Severity. Reports can be generated at any time for any given time period. We confirm that the application can be hosted within an environment that provides full disaster recovery services.
- Approach to resilience
- Multiple Servers will be configured as a cluster of VMs across these hosts and, should one of these servers fail or be taken out of service for maintenance work, then the remaining servers in the VM cluster will take up the additional workload. With the rapid recovery features in VMware your preferred method for resilience may be to dynamically provision new servers as and when a failure occurs. Your local preferences will dictate your approach to resilience and availability but be assured that the solution can be configured to meet your needs. A number of options enable you to build resilience into your applications. We offer Private Cloud Compute from two geographically distinct sites, both located in the UK and separated by over 100km for excellent geo-diversity.
- Outage reporting
- All outages will be reported via the Service Status page and the notifications service within the Cloud Portal. Outages are identified as Planned maintenance, Emergency maintenance, and platform issues. In addition, the designated Technical Account Manager will proactively contact customers as appropriate.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- 2-factor authentication
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- We include strong password policies and restrict access to particular individuals on the support/admin team. On PROD access further bolstered through IP whitelisting and the implementation of two-factor authentication.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- 2-factor authentication
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- British Assessment Bureau
- ISO/IEC 27001 accreditation date
- 09/09/2015
- What the ISO/IEC 27001 doesn’t cover
- Nothing.
- ISO 28000:2007 certification
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber essentials plus
- Yes
- Other security certifications
- No
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- NHS Digital Data Security and Protection Toolkit (DSPT)
- Information security policies and processes
-
Telstra Health UK’s Information Security Management System (ISMS) includes an Information Security Policy Manual (ISPM) which includes policies for IS relevant to the service, and associated processes. IS and DP is by design and default, so individual team processes refer back to the core ISPM as well as providing more detailed procedures based on best practice. As well as the Information Security Policy the ISPM includes, among others, the IT Acceptable Use Policy, Data Protection Policy, Security Incident Event Reporting Policy, Information Governance Training Policy, Information Asset Classification Policy, Supplier Security Policy, Information Security Continuity Policy, and the Change Control Policy.
Policies are approved via the Information Security Management Forum (ISMF) with representation from across the organisation including the SIRO, Head of Governance and Risk, and the DPO. The ISMF reports up to the Senior Leadership Team. All staff commit via contract to following policies, and are provided with copies at induction, and regular reminders and updates provided by email and training sessions. Compliance with policies is also ensured through internal and external ISO27001 audits, and the work of the organisation’s SecOps group and ISMF. Failure to follow policy and processes may result in penalties under the Disciplinary Policy.
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
System changes, including enhancements and defects, will be managed via Change Management Process implemented within Governance Framework administered by the Programme Director.
As part of programme governance framework, we create a Joint Design Authority will be led by the Programme Director. The Joint Design Authority includes representatives from across the programme and membership will be finalised during mobilisation. This group take responsibility for identifying, reviewing and prioritising requests for change to services and solutions. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Potential new threats, vulnerabilities or exploitation techniques which could affect customer service are assessed and corrective action is taken. The severity of threats and vulnerabilities is considered within the context of the service and this information is used to prioritise the implementation of mitigations. Our change management process ensures known vulnerabilities are tracked until mitigations have been deployed.
We monitor threats by using scanning tools that scan our network estate such as AppCheck and Crowd Strike, Qualys for internal penetration testing. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- We take prompt and appropriate action to address incidents. Incidents are categorised by laid down priorities which each have response times for remedial action. Following best practice from National Cyber Security Centre, our service has enhanced protective monitoring, including checks on time sources, cross-boundary traffic, suspicious boundary activities, network connections and backup status etc.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Incident management processes are in place for the service and are actively deployed in response to security incidents. Pre-defined processes are in place for responding to common types of incident and attack. A defined process and contact route exists for reporting of security incidents by consumers and external entities. Security incidents of relevance to you will be reported in acceptable timescales and formats
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Social Value
- Social Value
-
Social Value
- Fighting climate change
- Tackling economic inequality
- Equal opportunity
- Wellbeing
Fighting climate change
As Australia’s leading telecommunications and technology company, Telstra has a role to play in helping our customers and society adapt to technological change and the opportunities it brings. We want everyone to thrive in a digital world and our Environment Strategy is key to achieving this. Telstra’s Environment Strategy focuses on using technology to address environmental challenges while also helping our suppliers, customers and the communities we serve to do the same. Telstra’s previous Environment Strategy (2014) provided a foundation for responsibly managing our environment risks and opportunities. The updated strategy takes this to the next level. It goes beyond simply managing our own environmental footprint and encourages innovation in digital products and services that create environmental solutions to monitor, protect and improve the environment. Telstra’s Environment Strategy is comprised of five strategic priorities:
- Managing Carbon Emissions – Reducing carbon emissions intensity by 50% by 2020.
- Climate Change Resilience – Ensuring climate change risks are embedded in our Networks for the Future program.
- Low-carbon Economic Growth – Enabling a low carbon economy by helping reduce our customers’ carbon emissions.
- Resource Efficiency – Reusing or recycling 60 tonnes of old mobile phones and increasing Telstra’s waste recycling rate to 42% by 2020.
- Environment Management – Achieving best practice environmental management.
Accountability for the delivery of our Environment Strategy is shared across Telstra. Progress against the Strategy is overseen by the Chief Sustainability Officer and relevant project sponsors, and is reported to the Board twice a year.Tackling economic inequality
It is well known that ethnic minorities were most disproportionately impacted by Covid. Through our work with the NHS, health inequalities are core to our mission and day-to-day delivery of product and services. However, we want to enact positive change – to this end we are engaging with our suppliers and working with originations such has MSDUK https://www.msduk.org.uk/about-us - the UK’s leading supplier diversity advocacy organisation - to engage minority owned businesses on our supply chain. We are committed to increasing the diversity of our supply chain with a target to increase the number of suppliers who are minority owned by one supplier per annum.Equal opportunity
A cause close to the team’s heart enabling those with neurodiversity to realise their full potential. To enact this, we have initiated a programme of sending selected members of the team on a practitioner course run by the National Centre for Autism and Mental Health in order to educate the company on presentations of autism, ADHD and mental health conditions associated with these including anxiety, depression, eating disorders, and OCD.Wellbeing
Telstra Health UK places a paramount emphasis on supporting mental health and overall wellbeing within our workforce, recognising the pivotal role it plays in fostering positive and productive workplace. To actualize this commitment, we have implemented a comprehensive approach:
- We have a weekly protected calendar slot for all staff to dedicate and prioritise their health and wellbeing. This structured time incorporates a range of wellbeing initiatives, carefully curated each week, including monthly sessions dedicated to mental and physical health education, providing our team with valuable knowledge and tools to enhance their overall wellbeing.
- In recognising the importance of immediate and empathetic support, we have trained Mental Health First Aiders embedded within our business. These individuals are equipped to provide assistance and guidance to colleagues facing mental health challenges, reinforcing a culture of care and understanding.
- Complementing this, our EAP stands as a cornerstone of our support system. Through this program, telephone/face to face counselling sessions is offered, providing confidential and professional support to our employees and their families.
Pricing
- Price
- £25.12 to £30.62 a user a month
- Discount for educational organisations
- No
- Free trial available
- No