Lung Cancer Screening Manager
Bespoke software product to support delivery and administration of the NHS England Lung Cancer Screening programme pathway.
Includes functionality to invite patients, book appointments, calculate patient risk score, record SRM Outcome, track follow up scans, collate monthly reporting dataset and record cancer diagnosis.
Features
- Flexible workflow management tool covering full LCS pathway
- NHS Protocol compliant
- Automatic Letter/Referral Generation for Incidental Findings
- On Demand NHS Dataset via Reporting Dashboard
- Public/Private Cloud or on Premise Hosting with Role Based Access
- Built-in calculation of PLCO / LLP Risk Score
- Links to third party systems (Print/SMS/GP Correspondence)
- Exception Reports to monitor system misuse and data inaccuracies
- Automatic generation of referral to Stop Smoking Services
- Module to track diagnosis of Lung and other cancers
Benefits
- Reducing risk associated with disparate systems / spreadsheets
- Bulk allocate appointments using auto-book functionality
- Patient focused - facilities face-to-face or virtual appointments
- Reduce admin with automatically generated clinic lists for Nurses
- Reduce downtime via a reserve list for last minute cancellations
- Reduce DNA numbers through automatic generation of SMS reminders
- Eliminates manual calculation of risk scores
- Save time with automatic correspondence generation (letters/referrals)
- Automatically prioritises scan for review at SRM
- Automatic identification of patients who require reinviting to programme
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 7 3 0 4 0 8 4 8 8 0 6 4 8 7
Contact
S.T.C.S. LTD
Stephen Connolly
Telephone: 0191 490 3232
Email: digm@stcs.co.uk
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Community cloud
- Hybrid cloud
- Service constraints
- None
- System requirements
-
- Email Server
- SQL Server
- IIS / App Service
- Storage (Blob / Local)
User support
- Email or online ticketing support
- Yes
- Support response times
-
Standard support times are 8-6 Mon to Fri (excluding bank holidays)
P1 initial response time = 2 hours
P2 initial response time = 2 hours
P3 initial response time = 4 hours - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
STCS has defined three levels of priority.
P1 - System is not operational or is operational but with critical functionality not available or not working correctly and there is no workaround to the problem.
P2 - System is operational and critical functionality is unavailable or not working correctly but there is a workaround to the problem.
P3 - System is operational and there are faults but the critical functionality is working correctly.
Monthly charge differs depending on which licence model is purchased and the amount of customisation that is made to the basic core product. Support costs will be discussed as part of the procurement process but costs for 2026 start from £3,000 per month. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- As part of the installation period we step through user's processes and identify any changes to the system. We then customise all elements of the system then walk the users through user acceptance testing and training. This is usually done onsite. We also provide documentation such as user guides, key information documents and document libraries which can be used to onboard additional staff.
- Service documentation
- Yes
- Documentation formats
-
- Other
- Other documentation formats
-
- Word
- Excel
- End-of-contract data extraction
- Customers host their own data and retain control over this, therefore data extraction is not required at the end of the contract.
- End-of-contract process
- If the client chooses to move to a new supplier for system support, any handover of knowledge would be charged at an agreed rate.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Designed to work on mobile devices but it is not envisaged that a mobile device will be realistic due to the intended use of the system.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Web-based application which was based on GDS.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- We used WAVE to ensure users with assistive technology were catered for.
- API
- Yes
- What users can and can't do using the API
- The current API is a role based solution which currently only the front end has access to, but if requirements are made we can open up and grant secure access to the API for data sharing.
- API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Basic customisation is included as part of the initial installation. This includes:
- patient data
- Patient and GP correspondence methods
- SMS functionality / wording
- letter / referral wording content
Additional customisation can be considered but charges will likely be incurred.
Scaling
- Independence of resources
- Not applicable, each programme has their own version of the system so other users won't affect their service.
Analytics
- Service usage metrics
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- Less than once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
- Other
- Other data at rest protection approach
- This is the responsibility of the customer when selecting their cloud solution, however we are always happy to advise on requirements to ensure data is fully protected.
- Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- Standard reports can be extracted via csv from the front end of the system. Any other data / all core data can be exported directly from the database which remains under the control of the customer.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- Other
- Other protection between networks
- Data is held solely on the customer network on in their cloud and accessed directly on their platform (via a VPN service) for support purposes.
- Data protection within supplier network
- Other
- Other protection within supplier network
- Data is held solely on the customer network on in their cloud and accessed directly on their platform (via a VPN service) for support purposes.
Availability and resilience
- Guaranteed availability
- Availability depends on the hosting solution selected by the customer, i.e. cloud provider or internal network. The system is designed to have 100% availability and only requires downtime for releases.
- Approach to resilience
- We do not host any data. We are happy to advise on setup and when clients are selecting platform / hosts.
- Outage reporting
- Email alerts would be sent to designated mailbox
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Dedicated link (for example VPN)
- Username or password
- Access restrictions in management interfaces and support channels
- We use Role Based Access solution to control access.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Dedicated link (for example VPN)
- Username or password
- Other
- Description of management access authentication
- Role Based Access
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
- NHS DSP Toolkit
- Information security policies and processes
-
We have an STCS Information Security policy which all staff are required to comply with and we also have an Information Security policy for each system we support, including LCS Manager.
Our nominated Information Security Officer conducts onboarding and yearly review with all staff. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Software changes are assessed to DCB0129 standard which is assessed by our CSO provider Safehand.
- Vulnerability management type
- Undisclosed
- Vulnerability management approach
- Our risk management strategy covers human, network and asset vunerabilities and details the tools used to monitor activity, detect threats and protect systems and data. We are signed up to security alert services and these are actioned by our Infrastructure Manager. Scans and patching are carried out on a weekly basis in additional to any ad-hoc urgent updates.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Weekly scans of our own network plus we expect cloud providers and hosts to carry out their own independent monitoring and notify us of any compromises requiring our investigation and action. We advise all clients to ensure that their cloud provider / internal network configuration utilises the highest level of monitoring and protection.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Processes are defined and communicated to customers. Users report incidents and concerns via either our dedicated email inbox or phone line. Incidents are documented and reported via email to nominated customer contact. Incident log is reviewed monthly by Clinical Safety Officer and Sponsor to see if any updates to the Hazard log or changes to the system are required.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 9eceb2c4-50d5-40ad-94ca-9661aec19699
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 702418c9-ae78-4e74-8d7c-c79ec70d152d
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
-