Howz
The service provides in-depth analytics and actionable insight to care practitioners supporting people with advancing or complex care needs. Howz establishes a pattern of life from sensor activity and enables timely interventions, promotes independence, and provides an accurate foundation for health and social care decision making.
Features
- Processing data from home monitoring devices
- Real-time reporting of data
- Analysis of data to identify trends and anomalies
- Use of AI and Machine Learning to generate reports
- Use of Changepoint analytics to detect change in routine
- Family app to support remote monitoring
- API integration to UMO (ARC platform)
- Open API to support range of hardware and integration
Benefits
- Identify daily routine of the household to reduce unnecessary care
- Detect behavioural change in routine to enable early intervention
- Data visualisation to support decision making improves staff efficiency
- Easily generate reports reduces cost of adult social care delivery
- Reassurance to families viewing data on the app
- Use of AI report enables optimisation of care packages
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 2 2 4 7 4 9 4 1 8 8 6 7 3 4
Contact
Howz
Kate Fairhurst
Telephone: 07971611486
Email: info@howz.com
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Adult Social Care
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
- Specifically designed for one or two people living in the home, not suitable for multiple occupancy homes. Requires local team to view and respond to the alerts and reports generated.
- System requirements
- There are no specific requirements
User support
- Email or online ticketing support
- Yes
- Support response times
- Within 1 working day, no response at weekends or public holidays
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- EN 301 549
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Account management
Training for staff
Data reviews with data science team
Technical support - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Online training, user documentation, project initiation support
- Service documentation
- Yes
- Documentation formats
-
- HTML
- ODF
- End-of-contract data extraction
- At the end of the contract, users are able to extract their data either by requesting a secure data export from Howz or by accessing site-level downloads directly via the web portal. All data transfers are carried out using approved secure methods.
- End-of-contract process
- Upon contract completion, Howz supports the archiving of all sites and ensures that all data processing activities are fully ceased. The transfer of all data in line with the contract is completed which may include data destruction.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Our onboarding and offboarding documentation is easily accessible via our secure web portal and is also provided as part of the project initiation package to ensure all stakeholders have clear and timely access. We offer the documentation in a range of formats to support the use of accessibility software. Collaboration with the customer for project initiation enables a pro-active approach to dissemination of the necessary documents.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- The service is delivered through a secure web portal that provides a single interface for the installation and management of monitoring kits, processing of incoming data, user training, and day-to-day site and referral management. The platform enables users to visualise data through dashboards and reports, download datasets and reports as required, and manage access and permissions. The interface is designed to be intuitive and role-based, supporting efficient operational use, oversight, and decision-making across all participating sites.
- Accessibility standards
- None or don’t know
- Description of accessibility
- Users can download charts as image files for further analysis or inclusion in external documents. All reports include written descriptions of the data visualisations and can be downloaded for review using accessibility support devices. The web portal supports keyboard navigation to ensure accessibility for users who do not use a mouse.
- Accessibility testing
- The Howz web portal has been trialled in live use across multiple health and social care services, including structured user interviews to review the interface and identify potential accessibility issues. Feedback from users, including those who use assistive technologies, has been used to inform ongoing improvements to the platform. Accessibility testing and user review is an embedded part of our standard development and service delivery process, with continued engagement from users who rely on assistive technology. Automated and manual testing is supported through the use of Accessibility Insights for Web and the WAVE Evaluation Tool to assess compliance against WCAG 2.1 AA standards and support work to achieve the standard.
- API
- Yes
- What users can and can't do using the API
- We have published API available on a website for testing. The API's are used to send and receive data only, users cannot make changes or set up the service through the API. There is a reasonable use policy for the API. New sensors require Howz to create integration channel for web portal - not users.
- API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- No
Scaling
- Independence of resources
- Load is continually monitored via cloudwatch and status cake alerts/dashboards. We retain the ability to scale up any resource when necessary.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Uptime, app access. Also can provide use level of platform by user.
- Reporting types
-
- Real-time dashboards
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Staff screening not performed
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- Less than once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
- Physical access control, complying with CSA CCM v4.0
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Explicit overwriting of storage before reallocation / Secure Erase
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- Download from webportal or via API
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- Can be down for 24 hours - extra cost for 24/7 availability (multiple server)
- Approach to resilience
- Our service is hosted on AWS servers which meet the highest standards for data centre provision. The infrastructure has been created with support from AWS security experts to ensure separation and protection. Automated backups happen daily, business continuity tests carried out on a regular basis. All development work carried out on staging environment. Risk assessment of any releases - where high risk releases identified the release plan includes a test of the recovery plan.
- Outage reporting
- Email alerts of any outages
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- Access is reviewed on a regular basis. Admin profiles are separated from day to day work profiles. Roles are identified an allocated on a needs basis. Within the platform roles are used to restrict access to functionality.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
-
We use an established secure development approach, including secure-by-design/default principles, code review and testing practices, and active management of third-party components and dependencies.Our build and release processes are controlled to reduce the risk of unauthorised access and to maintain integrity, including change control.
We maintain operational security processes for secure deployment and ongoing maintenance, including vulnerability detection and prioritisation, and timely security fixes/patch communications.
We also have incident management processes and customer communications to share relevant security information such as support/maintenance commitments, and notable incidents where appropriate. - Information security policies and processes
-
A full suite of governance policies cover our processes. These follow the NHS DSP Toolkit recommendations and include Incident reporting policy, Access policy, asset register. Annual audits are carried out to review compliance, and there is annual training for staff. All incidents and investigations reviewed by senior team and action plans generated where required.
The Chief Clinical Officer leads on compliance with regular policy reviews and updates. The MD has overall responsibility and is the primary report for any incident supported by the CCO and the Technical Officer. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Tracked via GitHub, code review and testing prior to release.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- NCSC alerts. Deploy patches within 24 hours if urgent. Weekly reviews and updates as standard
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Continual error tracking in place and weekly reviews of any potential compromises via customer reports, NSCS reports, or staff testing. The potential compromise is reviewed by the technical team including a risk assessment at which point an action plan is agreed with priority - high risk are within 24 hours, moderate risk within 3 working days, low risk within 7 working days.
- Incident management type
- Supplier-defined controls
- Incident management approach
- The Incident reporting policy defines the processes and is based on NHS requirements. Users can report incidents via email ticketing system or call the office directly. On identification of an incident - An Incident report is completed using the organisation template on the same working day as the incident. Incident logged. MD or Technical lead review and oversee investigation and resolution including post incident review with customers if appropriate. Reports are emailed to the customer. Store reports within GitHub system.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- Limited time period.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 7%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 15%
- Over £5,000,001
- 20%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 7e5bb237-e3a8-44b7-bf09-8e3512c2f26a
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- B6ad5b13-0961-4915-8c82-33bea6618a23
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-