MyBotGP Primary Care Automation
Our MyBotGP NHS Cloud product range improves Primary Care productivity by automating critical workflows. 1. Pathology Management (EMIS & SystmOneTPP). 2. Docman letter Management (EMIS and SystmOneTPP) and 3. Repeat prescriptions. Our automated product range (MyBotGP) frees clinical and admin time, reduces costs and supports outstanding patient care.
Features
- Automation of Pathology Filing, Document management & Repeat Prescription
- NHS Cloud delivered as a service SAAS
- Practice and PCN rules
- Remote Log in
- Can bespoke rules at practice (your rules, your way)
- Works autonimously 365 days a year
- Accommodate differing lab reports and hospital letters
Benefits
- Enforces additional checks on Pathology & Letters
- Supports setting baseline of checks
- Free clinical time & lowers cost
- Quicker processing of pathology tests, letters and repeat requests
- Improve patient care as you can automate additional checks
- Can sms patients
- Reduces errors
- Free staff to focus on other value-added areas
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 1 6 0 0 3 5 1 8 7 6 3 5 8 3
Contact
JIFJAFF LIMITED
James Aitman
Telephone: 07956 182256
Email: enquiries@jifjaff.co.uk
About your service
- Service categories
-
Application Development and Deployment
Application platforms
- Robotic process automation
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
- No
- System requirements
-
- 1 x Laptop, PC or Virtual Machine
- 1 x Windows login for MyBotGP laptop
- 1 x EMIS/System One/Accurx Credentials
- Internet Connection
User support
- Email or online ticketing support
- Yes
- Support response times
- Within 4 hours
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- No
- Support levels
-
Severity 1 - MyBotGP is not working/unresponsive within 4 hours - JifJaff will work with the client to address the issue & will rank this as a priority one for our help desk.
Severity 2 - Automation workflow product, whereby it is functioning in a reduced capacity. Response within 6 hours - JifJaff will work with the client to address the issue & will rank this as a priority one for our help desk.
Severity 3 - Medium-to-low impact error that involves partial or non-critical loss of functionality. Response within 1 Working Days - JifJaff will work with the client to address the issue & will rank this as a priority one for our help desk. - Support available to third parties
- No
Onboarding and offboarding
- Getting started
- Once onboarded, there is a weekly webinar to run through the set up, access to online training and user documentation
- Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- No client data is held
- End-of-contract process
- User account is deleted and NHS cloud space is reprovisioned - no patient or client data is held.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
- Chrome
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- No
- User support accessibility
- WCAG 2.2 AA
- API
- No
- Customisation available
- No
Scaling
- Independence of resources
- Scalable solution as all services are delivered from NHS cloud and so capacity is not an issue re performance.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Dashboard within the platform covering off all usage metrics
- Reporting types
-
- Real-time dashboards
- Regular reports
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- NCSC approved service provider
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- There is a downloadable feature in the platform whereby all blood test filing rules and metrics can be downloaded and uploaded
- Data export formats
- Other
- Data import formats
- Other
- Other data import formats
- Excel
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- 99.9% availibility
- Approach to resilience
- All automations are delieverd from NHS cloud - https://www.hblict.nhs.uk/
- Outage reporting
- Yes
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
-
All administrative access is controlled through role-based access control (RBAC), ensuring users have only the minimum privileges necessary for their duties.
Access requires strong authentication, including multi-factor authentication (MFA) for all administrative accounts.
Management interfaces are only accessible via secure network connections (HTTPS/TLS 1.2+) and are not exposed to the public internet without appropriate security controls.
Administrative actions are logged and monitored for audit purposes, with regular reviews of access logs and permissions.
Access reviews are conducted quarterly to ensure compliance with internal policies and NHS DSPT (Data Security and Protection Toolkit) standards. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- We follow ISO standards
- Information security policies and processes
- Please request our information security document
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Change Management Framework:
Process Design and Re-engineering
Implementation
Project Management and Communication
Change Management
Change Readiness Assessment
Leadership
Alignment & Buy-in
Stakeholder Engagement
Communication Planning & Execution
Change Request Process
Change board Approval
Meeting occurrences depends on the number and
frequency of change requests.
• Change requests are assessed and prioritized by CAB.
• CAB assesses the Change Request`s impact on the
automation schedule, priories planning, business
process, RPA design.
• Business Owner/ Operations will need to follow
through the solution adopted by CAB.
• CAB Membership: PMs, IT, Sol Arch, Support, BA, with
participation of process owners or SME. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
JifJaff processes to scan for vulnerabilities in information systems and hosted applications at least annually and when new vulnerabilities potentially affecting the information systems / applications are reported.
• JifJaff process to control privileged access to vulnerability scanning tools and vulnerability reports.
• JifJaff to analyse vulnerability scan reports and results from security control assessments.
• JifJaff remediate identified vulnerabilities in accordance with JifJaff assessment of risk.
• Penetration Testing - JifJaff conducts penetration testing exercises on an annual basis, either by use of internal resources or employing an independent third-party penetration team. - Protective monitoring type
- Undisclosed
- Protective monitoring approach
-
JifJaff has a process and tools to maintain detailed records of information security incidents that occur in external (e.g., boundary systems) and internal information systems.
• JifJaff implement a policy to require personnel to report suspected information security incidents to the incident response team and/or JifJaff leadership. - Incident management type
- Undisclosed
- Incident management approach
-
• JifJaff develop, document, and publish an incident response policy that addresses scope, roles, and responsibilities, internal coordination efforts, and compliance.
• JifJaff establish formal, documented procedures to facilitate the implementation of the incident response policy and associated incident response controls.
• JifJaff reviews and update the incident response policy and procedures on an annual basis.
INCIDENT RESPONSE PLAN -
JifJaff implement an incident response plan to establish a roadmap for implementing incident response capabilities
Establish a roadmap for implementing incident response capabilities;
Establish metrics to help ensure incident response capabilities remain effective - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 1%
- Between £250,000 and £500,000
- 1%
- Between £500,001 and £1,000,000
- 1.25%
- Between £1,000,001 and £2,500,000
- 1.5%
- Between £2,500,001 and £5,000,000
- 1.75%
- Over £5,000,001
- 2%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 5c102b85-667c-4c56-9f5a-3fe3ddcaee8b
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 89655760-21cd-4079-8eeb-ea648b56c3e1
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-