NHS Risk Stratification Demand and Capacity Planning Tools
NHS Demand & Capacity Planning Tools (Eclipse) allows GP Practices & ICBs to transform patient activity through centralised management of all patients within their ICB. The service reduces waiting times, prioritises patients and engages with patients to maximise efficiency and patient safety.
Features
- Creation of your Eclipse Dynamic Database
- Live risk stratification of all patients
- Systematic identification of priority patient optimisation opportunities
- Systematic patient reviews and prioritisation.
- Role based access enabling genuine integrated working
- Ensures that patients most in need of service receive it
- Built in risk stratification and prioritisation capability
- Web based content and reporting configurability.
- Build in outcomes validation and continual improvement
- Built in patient engagement capability
Benefits
- Integration within a fully secure and compliant infrastructure
- Flexible and Intuitive web-based access
- Risk stratification of vulnerable patient groups
- Population level analysis, prioritisation, implementation, validation
- Built in Intelligent patient engagement tools.
- Longitudinal tracking of pathways adherence and implementation.
- Enabling focus on holistic outcomes of patients.
- Translating insights to patient level implementations
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 3 4 7 1 6 9 8 4 3 0 3 6 3 7
Contact
PRESCRIBING SERVICES LTD
Jake Finney
Telephone: 01553 615555
Email: support@prescribingservices.org
About your service
- Service categories
-
Application Development and Deployment
Analytics and business intelligence
- Business Intelligence
- Advanced and predictive analytics
- Location and geospatial data management and analytics
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Service constraints
- The service is available only over the web. Access is restricted to authorised users. Routine maintenance and upgrades are minimised and aligned to central NHS assurance accreditation. Sensitive codes set by NHS England are excluded. The local requirements maybe constrained by local IG and security policies
- System requirements
-
- Current Web Browser
- Active Data Processing Contract in place
- HSCN connectivity
User support
- Email or online ticketing support
- Yes
- Support response times
- Training is given on commencement of live service. Email/ticket queries will be responded to during usual business hours, we aim to respond within the hour of receiving a query. We have out of office support for any emergencies, as detailed in our user guide.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), 7 days a week
- Web chat support
- No
- Onsite support
- Yes
- Support levels
- The Eclipse Service Management Function and support structures have completed central NHSE Assurance. Upon service commencement full user training is offered in the form of in person or remote and user guides are provided. Each region has a dedicated account manager who can be contacted for any general queries during usual business hours, they have access to our technical team and IT support. In addition our phone line operates during usual business hours alongside our email inboxes. Onsite training can be offered depending on customer need. All costs are included within our service price
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- All training, implementation and on-going support activity within Eclipse has completed central NHSE Assurance. Training is implemented in line with client and end user preferences and learning need analysis. Training is delivered in person, or remotely, one to one or in groups. User manuals and support materials are available within the service platform and utilised within training events. Service demo's are provided and training impact is validated with end users.
- Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- The Eclipse Platform utilises dynamic data flow derived from the Clinical Systems and as such data extraction when the contract ends is not required.
- End-of-contract process
- Upon contract closure and at the customer’s request, all data associated with the customer organisation is deleted. This is included in the price of the contract.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- N/A
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Web based Clinical Support Platform
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- Testing ensures digital accessibility for people with disabilities. We are continually improving the user experience for everyone, and applying the relevant accessibility standards
- API
- No
- Customisation available
- Yes
- Description of customisation
- Our service platform is designed to be modular and is continuously updated to meet user requirements. Approved end users can configure data presentation and preferences.
Scaling
- Independence of resources
-
Eclipse is delivered using a multi-tenant SaaS architecture with logical separation between customers. Platform capacity, availability, and performance are monitored 24/7 and hosted on virtualised infrastructure to support scalability and high availability.
An N+1 resilience approach, frequent backups, database mirroring, and use of multiple servers across separate geographic locations ensure that demand from one customer does not impact others. All Eclipse services have completed NHS England service functionality assurance. Capacity is proactively managed using monitoring, alerting, and scaling controls, with workload management in place to prevent excessive demand from a single tenant affecting overall service performance.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Our service tracks service usage metrics including key performance indicators as defined locally and priority project indicators for equality, safety and admissions avoidance. In addition to qualitative insights, all activity is tracked for audit and quality purposes.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Reports can be exported into Excel / CSV / PDF Formats.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Other
- Other protection between networks
- The environment is protected behind firewall security, and data is accessible by authorised personnel only
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Other
- Other protection within supplier network
- The environment is protected behind firewall security, and data is accessible by authorised personnel only.
Availability and resilience
- Guaranteed availability
- In compliance with our NHS central assurance and terms we use reasonable endeavours to maintain a service minimum availability percentage of 99.99% through service provision (excluding scheduled downtime) in any calendar month.
- Approach to resilience
- Systems are hosted on virtualised infrastructure to ensure scalability, high availability and reduce single point of failures. All infrastructure implements an N+1 policy to ensure rapid resolution of infrastructure downtime. Frequent backups, database mirroring and multiple servers in separate geo-locations ensure robust resiliency. Data processed by our accredited data centre is hosted within industry standard data platform that conforms to industry best practices (ISO27001 & G-Cloud IL3) and standards for security as defined in the relevant contract terms and conditions.
- Outage reporting
- As per our accreditation as a NHS centrally assured clinical support provider our service platform is continually monitored for any interruptions or outages. This is implemented within our Data and Service Management team function. In the event of any issues all end users and stake holders are updated via email alerts.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Limited access network (for example PSN)
- Username or password
- Access restrictions in management interfaces and support channels
- Services apply Role Based Access Control (RBAC), to manage which functions a user has access to and which views they are able to see. This leverages local administration rights and approvers.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Limited access network (for example PSN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- Aligned to our British Assessment Bureau certification ISO 27001:2022 we have established Information Security Management systems (ISMS) that ensure our overall approach to information security and the processes we follow, encompassing the information security policy. Regular ISMS review meetings review and refine the functioning of the ISMS, and progress against actions arising from internal audit and external ISO assurance visits. There is a formal annual review of the ISMS to further ensure its continuing suitability and correct implementation. Annual internal audit is used to ensure policies are being followed and identify any remedial actions required. To support the effective delivery of information security, we train all staff on induction, and as part of annual Information Governance refresher training. This approach delivers against our Information Security policy.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- In line with our central NHS assurance we implement a standard ITIL deployment methodology for all Design, Development and Change Management practices for software and platform releases. We use a standard methodology to log, track and manage change requests. All Releases and changes are version controlled through our Change Management process. All system changes complete UAT and Release requirements.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Our vulnerability management approach consists of a combination of internal vulnerability scanners, system monitoring and industry sources. We apply patches within 14 days of their release, unless regarded as urgent which are implemented upon release . We also utilise the NHS CARE-cert and nationally recognised industry vulnerability publications. We also undertake regular penetration testing against OWASP top 10.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Utilising real time firewall based Intrusion Detection / Prevention Systems (IDS / IPS) to actively monitor and prevent intrusions. Alerts are issued on any suspicious activity and investigated immediately by the technical security team.
- Incident management type
- Supplier-defined controls
- Incident management approach
- In line with both our central NHS assurance obligations and established industry standards all reported incidents are received and managed by our Data Security and Governance Team. The team implements a standard approach raising an event report, completing a clinical risk assessment, root cause analysis, and resolution report. All events are managed through our established escalation process and defined with NHS England. All documentation is shared with key stake holders and subject to senior team review.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
-
- Public Services Network (PSN)
- Health and Social Care Network (HSCN)
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- Implementation of the Eclipse Platform for NHS Integrated Care Systems allowing activation of the module for all patients across an ICB through centralised SystmOne (strategic reporting) or EMIS IM1 integration. The free trial will be available for 6 months and is only available to new ICBs for one pathway.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- British Assessment Bureau
- ISO/IEC 27001 accreditation date
- Monday 19 February 2024
- What the ISO/IEC 27001 doesn’t cover
- The ISO/IEC 27001 certification covers the information security management system supporting the Eclipse platform and associated prescribing analytics services. It does not extend to customer-owned infrastructure, third-party systems operated independently of Prescribing Services Ltd, or local customer environments beyond PSL’s control.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Citation ISO Certification Limited
- ISO 9001 accreditation date
- Wednesday 12 July 2023
- What the ISO 9001 doesn’t cover
- The ISO 9001 certification covers Prescribing Services Ltd’s quality management system for the design, delivery and support of its prescribing analytics and Medicines Optimisation services. It does not cover customer-owned processes, third-party systems operated independently of Prescribing Services Ltd, or activities carried out entirely outside the defined scope of the certified quality management system.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- C4646f46-6a7f-4b1f-b46d-4649bb79afa4
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 75fa54ea-e5b5-45c7-b0f0-1d6a35b0712c
- Other security certifications
- Yes
- Any other security certifications
-
- NHS DSP Toolkit (DSPT) - Standards exceeded
- NHS Digital Assured
- DTAC
- ICO. Data Protection Register
- NHSE Section 251 Status
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-