Skip to main content

Help us improve the Digital Marketplace - send your feedback

PROXXIMOS LIMITED

Proxximos Safer Care

Proxximos combats the harmful and costly spread of communicable disease in hospitals through our next generation digital infection control solution. Healthcare settings are then safer for patients & staff whilst saving time and money. Our solution also supports wayfinding, digital twinning & asset tracking.

Features

  • Precise infection control contact tracing data
  • Precise pathogen transmission tracing data
  • Staff location data
  • Patient location data
  • Real-time, precise location of assets
  • Real-time alerts if patients or staff leave a defined area
  • Real-time alerts if assets leave a defined area
  • Location triggers into EPR
  • Live infection & pathogen risk displayed to staff
  • Location triggers into multiple digital platforms

Benefits

  • More rapid implementation of Infection Control measures saves money
  • Automating current manual contract tracing workloads saves time
  • Improve staff utilization & efficiencies (surgery, portering etc)
  • Reduce time searching for critical medical devices improving patient safety
  • Early warning of a wandering patient improving patient safety
  • Reduce expensive medical devices that are lost or stolen
  • EPR Workflow Automation reducing clerical inputs saving money
  • Improve patient flow & optimise complex care pathways

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at martin.pipe@proxximos.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

6 8 8 8 0 0 4 4 9 2 4 8 9 7 2

Contact

PROXXIMOS LIMITED Mr Martin Pipe
Telephone: 07976701491
Email: martin.pipe@proxximos.com

About your service

Service categories

Application Development and Deployment

Analytics and business intelligence

  • Advanced and predictive analytics
  • Location and geospatial data management and analytics
Multi cloud support
No

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Electronic Health Records, Asset Management Systems, Patient Flow Systems, Laboratory Information Management Systems
Cloud deployment model
Hybrid cloud
Service constraints
The Proxximos system works by providing staff, patients & assets with a wearable tag. The staff wearable will be on a lanyard with their NHS pass. The patient wearable can be worn on the wrist attached to their patient ID band. Hubs located every ward, can then see and range the wearables. This data is then used to measure the precise location of the wearables every 10 seconds. The Proxximos system needs to access the hospital WIFI network in order to get the location data out to the cloud. Wearables also need to have batteries changed every 2 years.
System requirements
  • Access to a WIFI network with Internet access
  • Access to a Real Time Location Solution (or Proxximos provided)
  • Continuous mains power for the hubs / anchors
  • Devices with web browsers and Internet access for the webapp

User support

Email or online ticketing support
Yes
Support response times
Response within 30 minutes from 9am to 5pm (UK time), Monday to Friday excluding Bank Holidays
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 A
Phone support
Yes
Phone support availability
9 to 5 (UK time), 7 days a week
Web chat support
Yes
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
WCAG 2.2 A
Web chat accessibility testing
None so far. We commit to have tested this with users of assistive technology as required
Onsite support
Yes, at extra cost
Support levels
We have a full support package included within our subscription service for all customers and then have 4 different priority levels of calls/incidents within the package:
P1’s cover critical support calls with a target response time of 30 minutes and target resolution time of 30 minutes
P2’s cover high priority support calls with a target response time of 60 minutes and target resolution time of 1 business day
P3’s cover moderate priority support calls with a target response time of 4 business hours and target resolution time of 2 business days
P4’s cover low priority support calls with a target response time of 6 business hours and target resolution time of 5 business days
We provide a named customer success manager (as part of our service) to ensure our system is used effectively and working as it should.
Support available to third parties
Yes
AI chatbot
No

Onboarding and offboarding

Getting started
Proxximos will provide full support for the successful onboarding to all our customers. We provide onsite training for management and super users of the systems. We also provide 1 onsite go live training session for all staff (this is delivered onsite and can be streamed using a TEAM's call and recorded for those unable to attend). Our go live session will include how users can access the system, navigate & use the webapp features, see alerts, log activity, change and edit settings (where permission levels allow) and log support calls. We will also advise how reports can be generated and the systems tested. We will provide post launch monitoring to ensure the systems continues to be used and embedded.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
The core data in the Proxximos system relates to real-time location of people or assets. Trusts are the data controller for this data and Proxximos can provide the data to the Trust if required at the end of the contract. Noting that this is a large and historic data set it is unlikely customers may request this.
End-of-contract process
At the end of the contract Proxximos will agree with the customer how best to off-board the service. This will include returning and/or deletion of customer data that Proxximos may hold following adherence to GDPR guidelines. We will agree a date from which access to the webapp will be discontinued. The price of the service includes the closure of access to the WebApp and Proxximos collecting all the wearable devices and hubs.
Documentation accessibility standard
WCAG 2.2 A

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
There are no functionality differences between the mobile & desktop service but the screen is resized and layout optimized for the screen size of the specific mobile device being used
Service interface
Yes
User support accessibility
WCAG 2.2 A
Description of service interface
We provide a WebApp for users and we can also provide open API's (Application Programming Interfaces) access for other service providers presentation layers (interfaces)
Accessibility standards
WCAG 2.2 A
Accessibility testing
None so far. We commit to have tested this with users of assistive technology as needed
API
Yes
What users can and can't do using the API
The Proxximos systems comes with a Web interface. Proxximos can make our API’s available to other service providers or users as required. Users with Administrator-level access can create new administration/API users through an API call. API calls exist for various functions including creating/deleting users, adding/removing wearables, logging infection data, retrieving exposure data, and other functionality. The initial Administrator user must be created by Proxximos.
API documentation
Yes
API documentation formats
Open API (also known as Swagger)
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Proxximos is designed to be highly configured for the individual NHS Trust requirement. Where multiple Trust’s require new features or customisations Proxximos would evolve the service offering accordingly.

Scaling

Independence of resources
Our service is based in scalable Microsoft Azure services and these scale as demand changes thus mitigating any such impact. Our tracking devices need WIFI to send data to Azure but the data is low volume and not anticipated to impact other WIFI services

Analytics

Service usage metrics
Yes
Metrics types
Usage data for users. System health metrics (e.g. devices registered but not seen etc)
Reporting types
  • Real-time dashboards
  • Regular reports
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Staff screening not performed
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
In-house
Protecting data at rest
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Regular service users can export data as reports in PDF format. Proxximos can provide API access or customized data exports to more specialist users.
Data export formats
  • CSV
  • Other
Other data export formats
PDF
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Our commitment to availability surpasses industry standards, ensuring 99.95% uptime for our services. This excludes scheduled (out of hours) downtime. Backed by robust Service Level Agreements (SLAs), we guarantee this level of availability to our users. In the rare event that we fall short of our promised uptime, our SLAs detail clear refund processes to compensate affected users. This includes prorated refunds based on the duration and severity of the outage, demonstrating our accountability and dedication to customer satisfaction. Our meticulous monitoring and proactive mitigation strategies minimize the risk of downtime, reinforcing our promise of uninterrupted service delivery. With our stringent SLAs and relentless focus on reliability, users can trust in our platform's stability to support their mission-critical operations without compromise.
Approach to resilience
Our service is crafted to ensure resilience, employing industry-standard techniques to fortify against potential disruptions. High Availability (HA) is a cornerstone, achieved through redundant components distributed across multiple Availability Zones (AZs). We leverage Microsoft Azure Auto Scaling to dynamically adjust resources in response to demand fluctuations, ensuring consistent performance even during peak loads. Load balancing further enhances reliability by distributing traffic evenly across instances.
Data durability is paramount, supported by Microsoft Azures approach to Locally Redundant Storage (LRS), Zone‑Redundant‑Storage (ZRS) & Geo‑Zone‑Redundant‑Storage (GZRS)
Outage reporting
Notifications are given for any planned outages via email, and any unexpected outages are notified via email upon discovery.

Identity and authentication

User authentication needed
Yes
User authentication
Multi-Factor Authentication (MFA)
Access restrictions in management interfaces and support channels
User-level fine-grained access controls provide administrative permissions only to authorised users. Support/feedback mechanisms are available to all users, but data protection rules are enforced so that sensitive information is not available outside of administrative channels/users.
Access restriction testing frequency
At least every 6 months
Management access authentication
Multi-Factor Authentication (MFA)

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
Other
Other security governance standards
Cyber Essentials Plus
Information security policies and processes
Regular audits and assessments validate compliance with established policies, supplemented by ongoing employee training to reinforce security protocols. We employ robust technologies, including intrusion detection systems and encryption mechanisms, to fortify our defenses against potential breaches. Incident response protocols enable swift and coordinated action in the event of security incidents, minimising impact and facilitating rapid recovery.
Furthermore, our governance framework includes regular review and updates to policies and procedures, ensuring alignment with evolving regulatory requirements and emerging threats. By integrating security into every aspect of our operations and fostering a culture of continuous improvement, we uphold the highest standards of information security to protect our assets and those of our customers.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Our configuration and change management processes leverage Agile methodologies and GitHub workflows. Each component is tracked via version control, allowing for traceability throughout its lifecycle. Changes undergo thorough code review, with security impact assessments integrated into our automated testing pipelines including third-party vulnerability scanning. Continuous monitoring ensures rapid detection and response to any deviations, maintaining the integrity and security of our services.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Software patches are applied based on security advisories reported on: The US National Vulnerability database, Npm Security advisories database, FriendsOfPHP database, Go Vulncheck database, Python Packaging Advisory database, Ruby Advisory database, RustSec advisory database.

Security risk is scored using the Common Vulnerability Scoring System (CVSS). Critical and High patches are applied within 24 hours with Medium and Low patches applied within 48 hours. OS vulnerability analysis is based on data from the US National Vulnerability database and scored using the CVSS. Azure Update Manager’s Automatic VM Guest Patching automatically downloads and installs all Critical and Security OS updates
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
We proactively identify potential compromises through continuous monitoring and anomaly detection. Upon detection, we swiftly initiate our incident response protocol, isolating affected systems and launching forensic analysis. Our rapid response aims to contain and mitigate the impact, with critical incidents addressed within minutes and comprehensive resolution within hours.
Incident management type
Supplier-defined controls
Incident management approach
While not formally on SSAE-18 standards, we broadly comply with pre-defined processes for common events, ensuring consistency and efficiency. Users report incidents via designated channels including web-app based feedback and telephone, facilitating prompt response and resolution. Incident reports are provided through secure channels, detailing the event, its impact, and mitigation measures, in alignment with SSAE-18 guidelines.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
1%
Between £500,001 and £1,000,000
2%
Between £1,000,001 and £2,500,000
2.5%
Between £2,500,001 and £5,000,000
2.5%
Over £5,000,001
5%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
7aa8d083-735d-4b05-be63-00ba4eed24d3
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
Bd0b05c1-4405-46f1-845c-c9e0596ce89e
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
    • Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
    • Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
    • Plans for positive actions with community groups.
    • Measures to engage users and communities and build relationships to increase community integration build trust and influence how the contract is delivered
    • Plans to respond flexibly and adapt approaches to community engagement and initiatives
    • Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at martin.pipe@proxximos.com. Tell them what format you need. It will help if you say what assistive technology you use.