Skip to main content

Help us improve the Digital Marketplace - send your feedback

S.T.C.S. LTD

Lung Cancer Screening Manager

Bespoke software product to support delivery and administration of the NHS England Lung Cancer Screening programme pathway.

Includes functionality to invite patients, book appointments, calculate patient risk score, record SRM Outcome, track follow up scans, collate monthly reporting dataset and record cancer diagnosis.

Features

  • Flexible workflow management tool covering full LCS pathway
  • NHS Protocol compliant
  • Automatic Letter/Referral Generation for Incidental Findings
  • On Demand NHS Dataset via Reporting Dashboard
  • Public/Private Cloud or on Premise Hosting with Role Based Access
  • Built-in calculation of PLCO / LLP Risk Score
  • Links to third party systems (Print/SMS/GP Correspondence)
  • Exception Reports to monitor system misuse and data inaccuracies
  • Automatic generation of referral to Stop Smoking Services
  • Module to track diagnosis of Lung and other cancers

Benefits

  • Reducing risk associated with disparate systems / spreadsheets
  • Bulk allocate appointments using auto-book functionality
  • Patient focused - facilities face-to-face or virtual appointments
  • Reduce admin with automatically generated clinic lists for Nurses
  • Reduce downtime via a reserve list for last minute cancellations
  • Reduce DNA numbers through automatic generation of SMS reminders
  • Eliminates manual calculation of risk scores
  • Save time with automatic correspondence generation (letters/referrals)
  • Automatically prioritises scan for review at SRM
  • Automatic identification of patients who require reinviting to programme

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at digm@stcs.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

1 7 3 0 4 0 8 4 8 8 0 6 4 8 7

Contact

S.T.C.S. LTD Stephen Connolly
Telephone: 0191 490 3232
Email: digm@stcs.co.uk

About your service

Service categories

Applications

Production and operations

Service industry and public sector operations

  • Healthcare
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
  • Public cloud
  • Private cloud
  • Community cloud
  • Hybrid cloud
Service constraints
None
System requirements
  • Email Server
  • SQL Server
  • IIS / App Service
  • Storage (Blob / Local)

User support

Email or online ticketing support
Yes
Support response times
Standard support times are 8-6 Mon to Fri (excluding bank holidays)
P1 initial response time = 2 hours
P2 initial response time = 2 hours
P3 initial response time = 4 hours
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
STCS has defined three levels of priority.
P1 - System is not operational or is operational but with critical functionality not available or not working correctly and there is no workaround to the problem.
P2 - System is operational and critical functionality is unavailable or not working correctly but there is a workaround to the problem.
P3 - System is operational and there are faults but the critical functionality is working correctly.

Monthly charge differs depending on which licence model is purchased and the amount of customisation that is made to the basic core product. Support costs will be discussed as part of the procurement process but costs for 2026 start from £3,000 per month.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
As part of the installation period we step through user's processes and identify any changes to the system. We then customise all elements of the system then walk the users through user acceptance testing and training. This is usually done onsite. We also provide documentation such as user guides, key information documents and document libraries which can be used to onboard additional staff.
Service documentation
Yes
Documentation formats
  • PDF
  • Other
Other documentation formats
  • Word
  • Excel
End-of-contract data extraction
Customers host their own data and retain control over this, therefore data extraction is not required at the end of the contract.
End-of-contract process
If the client chooses to move to a new supplier for system support, any handover of knowledge would be charged at an agreed rate.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Designed to work on mobile devices but it is not envisaged that a mobile device will be realistic due to the intended use of the system.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
Web-based application which was based on GDS.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
We used WAVE to ensure users with assistive technology were catered for.
API
Yes
What users can and can't do using the API
The current API is a role based solution which currently only the front end has access to, but if requirements are made we can open up and grant secure access to the API for data sharing.
API documentation
Yes
API documentation formats
Open API (also known as Swagger)
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Basic customisation is included as part of the initial installation. This includes:
- patient data
- Patient and GP correspondence methods
- SMS functionality / wording
- letter / referral wording content

Additional customisation can be considered but charges will likely be incurred.

Scaling

Independence of resources
Not applicable, each programme has their own version of the system so other users won't affect their service.

Analytics

Service usage metrics
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
Less than once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
Other
Other data at rest protection approach
This is the responsibility of the customer when selecting their cloud solution, however we are always happy to advise on requirements to ensure data is fully protected.
Data sanitisation process
Yes
Equipment disposal approach
In-house destruction process
Data sanitisation type
Deleted data can’t be directly accessed / Cryptographic Erasure

Data importing and exporting

Data export approach
Standard reports can be extracted via csv from the front end of the system. Any other data / all core data can be exported directly from the database which remains under the control of the customer.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
Other
Other protection between networks
Data is held solely on the customer network on in their cloud and accessed directly on their platform (via a VPN service) for support purposes.
Data protection within supplier network
Other
Other protection within supplier network
Data is held solely on the customer network on in their cloud and accessed directly on their platform (via a VPN service) for support purposes.

Availability and resilience

Guaranteed availability
Availability depends on the hosting solution selected by the customer, i.e. cloud provider or internal network. The system is designed to have 100% availability and only requires downtime for releases.
Approach to resilience
We do not host any data. We are happy to advise on setup and when clients are selecting platform / hosts.
Outage reporting
Email alerts would be sent to designated mailbox

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Dedicated link (for example VPN)
  • Username or password
Access restrictions in management interfaces and support channels
We use Role Based Access solution to control access.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Dedicated link (for example VPN)
  • Username or password
  • Other
Description of management access authentication
Role Based Access

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
Other
Other security governance standards
NHS DSP Toolkit
Information security policies and processes
We have an STCS Information Security policy which all staff are required to comply with and we also have an Information Security policy for each system we support, including LCS Manager.
Our nominated Information Security Officer conducts onboarding and yearly review with all staff.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Software changes are assessed to DCB0129 standard which is assessed by our CSO provider Safehand.
Vulnerability management type
Undisclosed
Vulnerability management approach
Our risk management strategy covers human, network and asset vunerabilities and details the tools used to monitor activity, detect threats and protect systems and data. We are signed up to security alert services and these are actioned by our Infrastructure Manager. Scans and patching are carried out on a weekly basis in additional to any ad-hoc urgent updates.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Weekly scans of our own network plus we expect cloud providers and hosts to carry out their own independent monitoring and notify us of any compromises requiring our investigation and action. We advise all clients to ensure that their cloud provider / internal network configuration utilises the highest level of monitoring and protection.
Incident management type
Supplier-defined controls
Incident management approach
Processes are defined and communicated to customers. Users report incidents and concerns via either our dedicated email inbox or phone line. Incidents are documented and reported via email to nominated customer contact. Incident log is reviewed monthly by Clinical Safety Officer and Sponsor to see if any updates to the Hazard log or changes to the system are required.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
9eceb2c4-50d5-40ad-94ca-9661aec19699
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
702418c9-ae78-4e74-8d7c-c79ec70d152d
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at digm@stcs.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.