Management and Supervision, decision-making Support for Community Mental Health Teams
The Management and Supervision Tool (MaST) is a powerful caseload management solution for community mental health services which uses predictive analysis to identify those people who are most likely, or least likely to require crisis services. MaST supports improved caseload management, decision making and resource allocation across the caseload.
Features
- Web based solution for mental health services
- Near time reporting with clear analysis of caseload performance
- Hosted within HSCN: Health and Social Care network
- Agnostic with regards to Electronic Patient records (EPR Systems)
- Role based access control (RBAC) for Care Coordinators, Doctors, Managers
- Configurable to trust services to enable controlled access to data
- Integration with single sign on through openID
- Configurable business rules to map to clinical service needs
- Ability to sort and filter large cohorts of service users
- Ability to include structured data captured within Trust systems
Benefits
- Generates insights from data triangulation to support mental health reporting
- Predictive Analytics to risk categorise caseloads linked to crisis
- Caseload visualisation to support large complex caseloads
- Caseload balancing, allowing safer allocation and mental health support
- Supporting care co-ordinators with workload management and caseload overview
- Manager oversight view for supporting supervision using operational dashboards
- Enables clear governance and standards adherence for quality improvement
- Supports with discharge planning from community mental health services
- Supports flow by increasing speed for mental health assessments
- Support with clinical practice adoption and change management
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 0 7 3 7 9 7 3 9 7 0 1 2 3 8
Contact
HOLMUSK EUROPE LIMITED
Nick Hebden
Telephone: 07552 278852
Email: nick.hebden@holmusk.co.uk
About your service
- Service categories
-
Application Development and Deployment
Analytics and business intelligence
- Business Intelligence
- Advanced and predictive analytics
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- MaST processes data from Electronic Patient records and then triangulates and displays in an easy to read format.
- Cloud deployment model
- Private cloud
- Service constraints
-
Routine support is offered weekdays 9-5pm.
Maintenance windows will be completed out of hours where possible.
New functionality or agreed change request will be released Monday - Thursday.
If an updated data feed is not received and data becomes more than 72 hours out of date then a holding page will be placed on MaST dashboard saying the service is unavailable until a refreshed data feed is imported.
Application accessed through a compatible browser.
Transfer of data via an SQL Backup file sent to the Holmusk sFTP server (default method) or via a suitable alternative such as Azure Data Lake. - System requirements
-
- Ability to set up and connect to sFTP
- Connection to HCSN
- Ability to run Azure entra ID
- Ability to send SQL Backup from a data warehouse
- Trust use of a compatible browser
User support
- Email or online ticketing support
- Yes
- Support response times
-
During the set up and launch phase (Year 1), Holmusk will provide first line help desk support for MaST software and analytics during standard working hours (9am to 5pm weekdays,
excluding public holidays). Response times will be within 1 working day with resolution agreed depending on the classification of the query.
On transition to Business as Usual (Year 2),
Holmusk will provide second line helpdesk support during standard working hours (9am to 5pm weekdays, excluding public holidays).
Response times will be within 1 working day with resolution agreed depending on the classification of the query. - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes
- Support levels
-
MaST is a web based solution supported by a team of data analysts, technologists and clinical experts to support implementation.
Holmusk provide 1 Level of support which is included in the set up and license fee.
Users of the product will initially receive 1st line support from Holmusk via the Holmusk helpdesk during set up.
Once the service is launched and established (usually at 12 months), Holmusk will provide 2nd line support.
Holmusk also proactively supports Trusts as part of the standard pricing model to ensure a smooth and successful adoption, with attendance at weekly operational meetings, service mapping and engagement sessions, onsite visits and membership of the monthly strategic oversight meetings throughout set up. Holmusk continue to provide support to Trusts in subsequent years as agreed with the Trust as part of the transfer to business as usual.
A Holmusk Senior Manager, Data Analyst and Clinician are allocated to form the account team responsible for successful implementation and ensure MaST continues to meet expectations in line with national guidance.
At the request of customer we are able to visit on site and provide remote training sessions or self guided learning (included within the set up and license fee). - Support available to third parties
- No
Onboarding and offboarding
- Getting started
- The overarching objective is for clinical, administrative, and managerial staff to have access to insightful information through a consistent and seamless platform. An on-boarding document will be supplied to each NHS Trust during project initiation detailing specific technical specifications and the support from the Holmusk team to ensure MaST is embedded into and enhances normal ways of working.
- Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
-
MaST is a read only solution which uses data provided by the Trust from existing data sources. Therefore Holmusk does not hold any patient or staff data that the Trust does not already have.
In the event that the customer chooses to terminate the contract any data supplied to MaST will already be held by the Trust in the source systems and database.
The Trust may request the transfer of newly generated data such as audit logs, algorithm performance reports, usage reports. If a Trust required a copy then the copy would be provided in an agreed method, typically SQL or CSV via sFTP. Remaining data will be destroyed in agreement with the Trust.
All decommissioning activities above are included in the license agreement. - End-of-contract process
-
On termination of the contract Holmusk will work with the buyer to ensure there is a smooth transition to an alternative service or removal of the service from end users where there is no alternative. This will include:
Notification from the Trust of intent to end the contract.
Planning meeting to agree communications plan, management of data, decommissioning of service.
The organisation would communicate the plan to terminate to end users.
The transfer of data (examples include audit logs, algorithm performance reports, usage reports).
The decommissioning of the buyers site including (removing access to the sFTP, removal of web application sites, removal of databases, removal of back ups).
A report from Holmusk confirming decommissioning activities have been undertaken.
Confirmation from the buyer that the end of contract process has been completed.
All decommissioning activities above are included in the license agreement. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
On request of onboarding and offboarding documentation PDFs will be the primary format in which these will be provided. When exporting to PDF the following methods will be used
- PDF will contain proper tags for headings, lists, tables, and images to enable screen readers to interpret the document correctly.
- Document will be saved as an accessible PDF by selecting the "Tagged PDF" option in the save dialog.
- We will follow WCAG 2.1 AA standards, ensuring clear structure, sufficient contrast, and proper reading order.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Chrome
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- No
- User support accessibility
- None or don’t know
- API
- No
- Customisation available
- Yes
- Description of customisation
- Aspects of interface and business rules can be customised to reflect local service delivery. Users themselves can not customise. MaST team would be responsible for customisation work.
Scaling
- Independence of resources
- Holmusk use load balancing for our users which are directed across two web servers and these web servers talk to two independent database servers. Traffic is evenly spread between the two servers. Web servers and database servers are high end servers with fast multi threaded CPUs and sufficient memory to allow our processing and caching requirements for many users and currently comfortably supports up well in excess of the normal daily traffic. Holmusk regularly monitor this and reconfigure hardware if it is necessary to take on additional load.
Analytics
- Service usage metrics
- Yes
- Metrics types
- 1. Weekly usage 2. Quarterly outcome monitoring
- Reporting types
- Regular reports
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Staff screening not performed
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Physical access control, complying with another standard
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Data Erasure
Data importing and exporting
- Data export approach
- MaST is a read only solution which uses data provided by the Trust from existing data sources. In the event that the customer chooses to terminate the contract or export data from MaST for use into other systems, export will typically be SQL via or CSV via sFTP. This will be agreed as part of the Data Processing discussion and DPIA approval process
- Data export formats
- Other
- Other data export formats
- SQL via sFTP
- Data import formats
-
- CSV
- Other
- Other data import formats
- SQL Server backup
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
MaST will be accessible 99% of the time.
MaST will be updated no more than 12 hours after receipt of data file
(except where this is not possible due to issues at the NHS Trust
preventing the daily feed from being created or sent to the secure
FTP servers).
Holmusk has a Disaster Recovery Policy which aims to ensure
availability of MaST and by restoring systems and data within 24hrs
of a critical disaster. - Approach to resilience
- Load balancing and if one server disappears then all traffic directed to other server ensuring we have as maximum uptime.
- Outage reporting
- Holmusk are alerted to any disruption in service by our Hosting provider as well as internal systems monitoring usage. Trusts will be communicated with directly to inform them of any outage and kept informed until resolution.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Access restrictions in management interfaces and support channels
- Role based access.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- Adhere to ISO 27001 2022 which includes comprehensive audit/training and awareness / policy and documentation.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Laid out in MHRA configuration management documentation. Tracked through risk register as part of ISO 27001 2022 change management process and contract with suppliers.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
The company takes a proactive approach to vulnerability management.
Strategic threat intelligence: exchange of high-level information about the changing threat landscape (e.g. types of attackers or types of attacks); Tactical threat intelligence: information about attacker methodologies, tools and technologies involved; Operational threat intelligence: details about specific attacks, including technical indicators.
Information collected through device management alerts for hardware, O365 Defender alerts for systems and networks, updates from National Cyber Security Centre and CareCert. Vulnerability assessed by technical lead - Patches are applied at the first opportunity - (if considered high level risk implemented within 24hrs). - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
The company monitors compromises through employee vigilance, Information collected through device management for hardware, O365 Defender for systems and networks.
This compromises is assessed by our technical lead and SRO and when required the Critical Security Incident Response Team convened. - Incident management type
- Supplier-defined controls
- Incident management approach
-
Incidents are reported from customers via the Helpdesk. The business has processes and policies in place to log and review any incidents or near misses daily. Standard Operating Process's are in place to handle common events. All incident are reviewed by the SIRO and appropriate action taken. If the incident is considered high the CSIRT (Critical Incident Response Team) would form to agree course of action and channels of communication.
Customers receive regular updates about ongoing incidents via email.
Customers receive detailed report after incidents if affected via email.
Notification to authorities actioned as required. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
- Health and Social Care Network (HSCN)
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Approachable Certification Ltd
- ISO/IEC 27001 accreditation date
- Tuesday 23 September 2025
- What the ISO/IEC 27001 doesn’t cover
- Controls associated with with physical premises as fully remote team (A7.1 Physical Security Perimeters, A7.2 Physical Entry, A7.3 Securing Offices, Rooms, Facilities, 7.4 Physical Security Monitoring, 7.6 Working in Secure Areas, 7.11 Supporting Utilities, 7.12 Cabling Security).
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 7b87f844-081d-4478-be6e-4d67315f32c1
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- Yes
- Any other security certifications
- Data Security and Protection Toolkit Compliance
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-