Skip to main content

Help us improve the Digital Marketplace - send your feedback

HOLMUSK EUROPE LIMITED

Management and Supervision, decision-making Support for Community Mental Health Teams

The Management and Supervision Tool (MaST) is a powerful caseload management solution for community mental health services which uses predictive analysis to identify those people who are most likely, or least likely to require crisis services. MaST supports improved caseload management, decision making and resource allocation across the caseload.

Features

  • Web based solution for mental health services
  • Near time reporting with clear analysis of caseload performance
  • Hosted within HSCN: Health and Social Care network
  • Agnostic with regards to Electronic Patient records (EPR Systems)
  • Role based access control (RBAC) for Care Coordinators, Doctors, Managers
  • Configurable to trust services to enable controlled access to data
  • Integration with single sign on through openID
  • Configurable business rules to map to clinical service needs
  • Ability to sort and filter large cohorts of service users
  • Ability to include structured data captured within Trust systems

Benefits

  • Generates insights from data triangulation to support mental health reporting
  • Predictive Analytics to risk categorise caseloads linked to crisis
  • Caseload visualisation to support large complex caseloads
  • Caseload balancing, allowing safer allocation and mental health support
  • Supporting care co-ordinators with workload management and caseload overview
  • Manager oversight view for supporting supervision using operational dashboards
  • Enables clear governance and standards adherence for quality improvement
  • Supports with discharge planning from community mental health services
  • Supports flow by increasing speed for mental health assessments
  • Support with clinical practice adoption and change management

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at nick.hebden@holmusk.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

3 0 7 3 7 9 7 3 9 7 0 1 2 3 8

Contact

HOLMUSK EUROPE LIMITED Nick Hebden
Telephone: 07552 278852
Email: nick.hebden@holmusk.co.uk

About your service

Service categories

Application Development and Deployment

Analytics and business intelligence

  • Business Intelligence
  • Advanced and predictive analytics
Multi cloud support
No

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
MaST processes data from Electronic Patient records and then triangulates and displays in an easy to read format.
Cloud deployment model
Private cloud
Service constraints
Routine support is offered weekdays 9-5pm.
Maintenance windows will be completed out of hours where possible.
New functionality or agreed change request will be released Monday - Thursday.
If an updated data feed is not received and data becomes more than 72 hours out of date then a holding page will be placed on MaST dashboard saying the service is unavailable until a refreshed data feed is imported.
Application accessed through a compatible browser.
Transfer of data via an SQL Backup file sent to the Holmusk sFTP server (default method) or via a suitable alternative such as Azure Data Lake.
System requirements
  • Ability to set up and connect to sFTP
  • Connection to HCSN
  • Ability to run Azure entra ID
  • Ability to send SQL Backup from a data warehouse
  • Trust use of a compatible browser

User support

Email or online ticketing support
Yes
Support response times
During the set up and launch phase (Year 1), Holmusk will provide first line help desk support for MaST software and analytics during standard working hours (9am to 5pm weekdays,
excluding public holidays). Response times will be within 1 working day with resolution agreed depending on the classification of the query.

On transition to Business as Usual (Year 2),
Holmusk will provide second line helpdesk support during standard working hours (9am to 5pm weekdays, excluding public holidays).
Response times will be within 1 working day with resolution agreed depending on the classification of the query.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes
Support levels
MaST is a web based solution supported by a team of data analysts, technologists and clinical experts to support implementation.
Holmusk provide 1 Level of support which is included in the set up and license fee.
Users of the product will initially receive 1st line support from Holmusk via the Holmusk helpdesk during set up.
Once the service is launched and established (usually at 12 months), Holmusk will provide 2nd line support.
Holmusk also proactively supports Trusts as part of the standard pricing model to ensure a smooth and successful adoption, with attendance at weekly operational meetings, service mapping and engagement sessions, onsite visits and membership of the monthly strategic oversight meetings throughout set up. Holmusk continue to provide support to Trusts in subsequent years as agreed with the Trust as part of the transfer to business as usual.
A Holmusk Senior Manager, Data Analyst and Clinician are allocated to form the account team responsible for successful implementation and ensure MaST continues to meet expectations in line with national guidance.
At the request of customer we are able to visit on site and provide remote training sessions or self guided learning (included within the set up and license fee).
Support available to third parties
No

Onboarding and offboarding

Getting started
The overarching objective is for clinical, administrative, and managerial staff to have access to insightful information through a consistent and seamless platform. An on-boarding document will be supplied to each NHS Trust during project initiation detailing specific technical specifications and the support from the Holmusk team to ensure MaST is embedded into and enhances normal ways of working.
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
MaST is a read only solution which uses data provided by the Trust from existing data sources. Therefore Holmusk does not hold any patient or staff data that the Trust does not already have.
In the event that the customer chooses to terminate the contract any data supplied to MaST will already be held by the Trust in the source systems and database.
The Trust may request the transfer of newly generated data such as audit logs, algorithm performance reports, usage reports. If a Trust required a copy then the copy would be provided in an agreed method, typically SQL or CSV via sFTP. Remaining data will be destroyed in agreement with the Trust.

All decommissioning activities above are included in the license agreement.
End-of-contract process
On termination of the contract Holmusk will work with the buyer to ensure there is a smooth transition to an alternative service or removal of the service from end users where there is no alternative. This will include:
Notification from the Trust of intent to end the contract.
Planning meeting to agree communications plan, management of data, decommissioning of service.
The organisation would communicate the plan to terminate to end users.
The transfer of data (examples include audit logs, algorithm performance reports, usage reports).
The decommissioning of the buyers site including (removing access to the sFTP, removal of web application sites, removal of databases, removal of back ups).
A report from Holmusk confirming decommissioning activities have been undertaken.
Confirmation from the buyer that the end of contract process has been completed.

All decommissioning activities above are included in the license agreement.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
On request of onboarding and offboarding documentation PDFs will be the primary format in which these will be provided. When exporting to PDF the following methods will be used
- PDF will contain proper tags for headings, lists, tables, and images to enable screen readers to interpret the document correctly.
- Document will be saved as an accessible PDF by selecting the "Tagged PDF" option in the save dialog.
- We will follow WCAG 2.1 AA standards, ensuring clear structure, sufficient contrast, and proper reading order.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Chrome
Application to install
No
Designed for use on mobile devices
No
Service interface
No
User support accessibility
None or don’t know
API
No
Customisation available
Yes
Description of customisation
Aspects of interface and business rules can be customised to reflect local service delivery. Users themselves can not customise. MaST team would be responsible for customisation work.

Scaling

Independence of resources
Holmusk use load balancing for our users which are directed across two web servers and these web servers talk to two independent database servers. Traffic is evenly spread between the two servers. Web servers and database servers are high end servers with fast multi threaded CPUs and sufficient memory to allow our processing and caching requirements for many users and currently comfortably supports up well in excess of the normal daily traffic. Holmusk regularly monitor this and reconfigure hardware if it is necessary to take on additional load.

Analytics

Service usage metrics
Yes
Metrics types
1. Weekly usage 2. Quarterly outcome monitoring
Reporting types
Regular reports
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Staff screening not performed
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
Physical access control, complying with another standard
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
Data Erasure

Data importing and exporting

Data export approach
MaST is a read only solution which uses data provided by the Trust from existing data sources. In the event that the customer chooses to terminate the contract or export data from MaST for use into other systems, export will typically be SQL via or CSV via sFTP. This will be agreed as part of the Data Processing discussion and DPIA approval process
Data export formats
Other
Other data export formats
SQL via sFTP
Data import formats
  • CSV
  • Other
Other data import formats
SQL Server backup

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
MaST will be accessible 99% of the time.
MaST will be updated no more than 12 hours after receipt of data file
(except where this is not possible due to issues at the NHS Trust
preventing the daily feed from being created or sent to the secure
FTP servers).
Holmusk has a Disaster Recovery Policy which aims to ensure
availability of MaST and by restoring systems and data within 24hrs
of a critical disaster.
Approach to resilience
Load balancing and if one server disappears then all traffic directed to other server ensuring we have as maximum uptime.
Outage reporting
Holmusk are alerted to any disruption in service by our Hosting provider as well as internal systems monitoring usage. Trusts will be communicated with directly to inform them of any outage and kept informed until resolution.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
Access restrictions in management interfaces and support channels
Role based access.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Dedicated link (for example VPN)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Adhere to ISO 27001 2022 which includes comprehensive audit/training and awareness / policy and documentation.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Laid out in MHRA configuration management documentation. Tracked through risk register as part of ISO 27001 2022 change management process and contract with suppliers.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
The company takes a proactive approach to vulnerability management.
Strategic threat intelligence: exchange of high-level information about the changing threat landscape (e.g. types of attackers or types of attacks); Tactical threat intelligence: information about attacker methodologies, tools and technologies involved; Operational threat intelligence: details about specific attacks, including technical indicators.
Information collected through device management alerts for hardware, O365 Defender alerts for systems and networks, updates from National Cyber Security Centre and CareCert. Vulnerability assessed by technical lead - Patches are applied at the first opportunity - (if considered high level risk implemented within 24hrs).
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
The company monitors compromises through employee vigilance, Information collected through device management for hardware, O365 Defender for systems and networks.
This compromises is assessed by our technical lead and SRO and when required the Critical Security Incident Response Team convened.
Incident management type
Supplier-defined controls
Incident management approach
Incidents are reported from customers via the Helpdesk. The business has processes and policies in place to log and review any incidents or near misses daily. Standard Operating Process's are in place to handle common events. All incident are reviewed by the SIRO and appropriate action taken. If the incident is considered high the CSIRT (Critical Incident Response Team) would form to agree course of action and channels of communication.
Customers receive regular updates about ongoing incidents via email.
Customers receive detailed report after incidents if affected via email.
Notification to authorities actioned as required.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
Yes
Connected networks
Health and Social Care Network (HSCN)

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Approachable Certification Ltd
ISO/IEC 27001 accreditation date
Tuesday 23 September 2025
What the ISO/IEC 27001 doesn’t cover
Controls associated with with physical premises as fully remote team (A7.1 Physical Security Perimeters, A7.2 Physical Entry, A7.3 Securing Offices, Rooms, Facilities, 7.4 Physical Security Monitoring, 7.6 Working in Secure Areas, 7.11 Supporting Utilities, 7.12 Cabling Security).
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
7b87f844-081d-4478-be6e-4d67315f32c1
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
Yes
Any other security certifications
Data Security and Protection Toolkit Compliance

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Volunteering opportunities for staff
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
    • Actions to invest in the physical and mental health and wellbeing of the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at nick.hebden@holmusk.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.