Theta Sleep
Tech-enabled sleep medicine service
Features
- Cloud-based platform supporting end-to-end sleep medicine pathways.
- Digital onboarding, education and structured sleep history capture.
- Inclusive access pathways, including telephone support if lower digital literacy.
- Integrated home sleep study logistics, scoring and reporting.
- Remote clinical consultations for results review and treatment decisions.
- Treatment initiation workflows including prescription and fulfilment coordination.
- Clinician tools supporting triage, decision-making and clinical documentation.
- Secure messaging and document sharing with patients and referrers.
- Configurable components supporting partial or full pathway deployment.
- Web-based delivery with no local installation or on-site infrastructure.
Benefits
- Faster access to diagnosis and treatment for sleep disorders.
- Reduced healthcare inequalities through at-home care
- Improved patient experience via digital access, education and remote consultations.
- Reduced carbon footprint through fewer hospital visits and travel.
- Increased service capacity through efficient, scalable digital pathways.
- Reduced reliance on hospital estate for sleep medicine pathways.
- Care delivered at significant reduction to NHS tariffs.
- Care delivered in line with NHS, NICE and BSS guidance.
- Reduced administrative burden through streamlined data capture and documentation.
- Safe care delivery supported by robust clinical governance and security.
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 2 2 8 2 6 4 1 9 3 5 9 8 9 5
Contact
THETA SLEEP LTD
Tom Chambers
Telephone: 020 8178 9938
Email: tom.chambers@thetasleep.com
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
-
The service is delivered as a browser-based SaaS application and does not require buyers to install or maintain any specific hardware or software. The service is accessible using modern, standards-compliant web browsers.
Planned maintenance is carried out occasionally and, where possible, outside of UK business hours. Buyers will be notified in advance of any planned maintenance that may affect service availability. - System requirements
- Modern, standard-compliant web browser
User support
- Email or online ticketing support
- Yes
- Support response times
- 24hrs
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- No
- Support levels
-
The service is provided with a single standard support level.
Support is provided remotely during UK business hours via email and/or online support channels.
There are currently no separate or premium support tiers, and no additional costs for different support levels.
The service does not include a dedicated technical account manager or named cloud support engineer. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Users begin using the service after receiving an invitation email with a secure link. By clicking the link, they are taken to the web application where they can set up their account and log in. The service is designed to be intuitive and easy to navigate without the need for formal documentation or classroom training.
In-application support is provided through contextual help elements: a persistent “Help” button on all screens opens guidance relevant to the current page, and information (“i”) icons provide additional context where appropriate.
We also offer responsive support channels (email and phone) to assist users with any questions during onboarding.
Non-digital pathways are available for our service for those who cannot access the internet or have lower digital literacy. A member of the support team is able to gather information usually collected on the application via the telephone to ensure all users receive the same quality of care. - Service documentation
- No
- End-of-contract data extraction
-
Users are routinely provided with their health data during delivery of the service, including clinical letters and sleep study reports generated as part of the clinical pathway.
At contract end, we will support buyers to extract user data in structured formats suitable for migration or archival, in line with agreed timelines and data protection requirements. This includes clinical records and associated pathway data held within the service.
Following contract end, access arrangements will be agreed with the buyer. Where appropriate, users may be given time-limited access to view their data. Users may also request copies of their personal data via a subject access request in line with our GDPR policies and public-facing privacy notice.
Data retention and deletion are managed in line with NHS data retention requirements and agreed contractual terms. Upon confirmed account closure, data is securely retained and then deleted in accordance with these policies. - End-of-contract process
-
At the end of the contract, a clinically safe exit process is actioned to ensure continuity of care. At termination, no new patients are onboarded to the service. Patients already in the diagnostic pathway are supported to complete diagnosis, with Theta Sleep providing clinical letters and reports to the patient, their GP and the buyer organisation. These patients are referred back to local NHS services via their GP for onward management.
Patients already receiving treatment through Theta Sleep are transitioned back to local NHS services via their GP, supported by a complete record of their diagnosis and treatment history. Where appropriate, patients within an initial treatment period may complete planned follow-up appointments before being safely handed back with full clinical documentation. Exit arrangements, timelines and communications are agreed with the buyer to ensure patient safety, continuity of care, and compliance with clinical governance and data protection requirements.
Appropriate and clinically safe exit arrangements, including standard service wind-down, patient handover and data transfer, are included within the contract price. Accelerated exits, extended clinical follow-up beyond agreed pathways, or custom data extracts outside standard formats are not supported and would require separate agreement.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
The mobile and desktop versions of the service provide the same functionality and access to the same content.
The user interface is responsive and adapts to different screen sizes, but there are no functional differences between mobile and desktop use. - Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The service interface is a webapp provided via a secure, browser-based user interface that enables users to access all service functionality through standard web browsers on desktops and mobile devices. The interface is designed for intuitive navigation and responsive display across screen sizes. It supports common modern browsers and presents functionality through menus, forms, dashboards, and interactive views. The service does not require any client installation.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
We design and test our service to meet WCAG 2.2 AA accessibility requirements and consider accessibility throughout design, development and release. Interface testing includes a combination of automated accessibility testing, manual testing, and user-centred review against WCAG success criteria. We test keyboard-only navigation, focus order, colour contrast, text resizing, form validation and error messaging to ensure compatibility with common assistive technologies.
Manual testing includes use of screen readers and browser accessibility tools to validate that content is perceivable, operable and understandable. Accessibility issues identified during testing are logged, prioritised and remediated as part of our normal development and change management processes. Where appropriate, accessibility feedback from users is incorporated into ongoing improvements. We regularly review accessibility guidance and update our approach to ensure continued alignment with WCAG 2.2 AA and evolving best practice. - API
- Yes
- What users can and can't do using the API
-
Our service provides a secure, standards-based API that enables authorised integrated systems (such as the clinical systems used by GP practices and hospitals within an NHS trust) to automate key referral and results workflows. Using the API, buyer systems can submit patient referrals into our platform from their own clinical systems, triggering the creation of a referral record in our SaaS application. When clinical assessment and diagnosis are complete, the API supports sending structured outcome data and clinic letters back to the referring system for incorporation into the patient’s record.
Users cannot use the API to perform actions outside of the defined clinical workflows (for example, administrative user management or management of platform configuration), and we enforce strict authentication, authorisation and audit controls on all API access. Integration work is scoped with each buyer to ensure secure access, appropriate data mappings and adherence to clinical governance requirements. Documentation and support are provided to help buyer developers implement and test against the API in their environments. - API documentation
- Yes
- API documentation formats
-
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- No
Scaling
- Independence of resources
- Our service is hosted on Google Cloud using managed, autoscaling infrastructure. We leverage serverless platforms (such as Cloud Run and Cloud SQL) which automatically scale resources in response to demand, helping ensure consistent performance regardless of load growth. Traffic is routed through protective layers such as Cloud Armor and Cloudflare to mitigate DDoS and abusive traffic. This architecture and use of cloud autoscaling and isolation mechanisms help prevent high usage from one customer affecting the experience of others.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
We provide service and pathway metrics to support monitoring and service improvement. Operational metrics include platform availability and uptime, response times, system performance indicators, and numbers of active users.
Where the service supports clinical sleep pathways, we also provide clinically relevant KPIs aligned to NHS reporting. These include time from referral to diagnosis (DM01), time from referral to treatment (RTT), patient satisfaction measured using the Friends and Family Test, and treatment adherence metrics where applicable. Metrics are shared with buyers through agreed reporting arrangements in line with governance and data protection requirements. - Reporting types
-
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
-
Users are routinely provided with their health data as part of the service. This includes structured clinical letters and sleep study reports generated during the clinical pathway, which are shared with patients, GPs and referring organisations.
Users and buyers can request export of structured data held within the service in standard formats (e.g. CSV files). Data exports are provided in line with data protection requirements and agreed timelines.
Where users require copies of their personal data outside routine service delivery, this can also be requested in accordance with our GDPR policies and public-facing privacy notice. - Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
We guarantee 99.9% availability for the Theta Sleep platform, measured on a monthly basis, excluding planned maintenance agreed in advance with buyers. Availability covers access to core platform functionality delivered via our cloud-hosted service.
This availability commitment is defined within our service level agreement. Platform availability is monitored continuously, and performance against agreed service levels is reported to buyers as part of routine service management.
If availability falls below the guaranteed level, buyers are eligible for service credits in line with the service level agreement. Service credits are applied to future invoices and are calculated based on the extent and duration of the availability shortfall. - Approach to resilience
- Our service is designed for resilience using Google Cloud’s highly available and fault-tolerant infrastructure. Application components run on Cloud Run, which supports autoscaling and zonal redundancy within the region to absorb load spikes and isolate failures. Data storage is provided by Cloud SQL, configured for high availability with automatic synchronous replication to a standby instance in another zone within the same region, enabling seamless failover if the primary zone becomes unavailable. Managed load balancing and autoscaling ensure traffic distribution and continuity under varying demand. Regular backups and managed storage contribute to data durability. External protective layers (e.g., Cloud Armor and Cloudflare) mitigate network-level disruptions. Monitoring and alerting enable prompt detection and response. These design patterns help ensure continuity of service even in the event of component or zonal failures, aligning with recognised resilience objectives.
- Outage reporting
- We monitor service health internally and operate incident management processes to detect outages as soon as they occur. In the event of a service interruption, we notify affected customer contacts via email alerts with timely updates on the issue and resolution progress. Outages and incident statuses are also communicated through our support channels and available on request to contracted buyers. If required, we can work with buyers to establish additional notification mechanisms or integrations (e.g., webhook or API-based alerts) as part of their onboarding. Our approach ensures customers are informed promptly and transparently when disruptions occur.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is restricted using strong identity and access controls. Administrative access is protected by authenticated user accounts with role-based permissions, ensuring only authorised personnel can perform configuration or operational tasks. We enforce multi-factor authentication (MFA). Support channels such as the ticketing system are accessible only to verified internal support users, with least-privilege roles assigned. Our controls are reviewed regularly to ensure appropriate separation of duties and minimise the risk of unauthorised access.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- Between 6 months and 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
- Our security governance complies with key NHS standards including NHS Digital Technology Assessment Criteria (DTAC) and the NHS Data Security and Protection Toolkit (DSPT) which includes compliance with UK Cyber Essentials. Our email systems are compliant with NHS DCB1596 (The secure email standard for sharing health data).
- Information security policies and processes
-
We operate a documented information security governance framework covering Information Security, Access Control and Acceptable Use, Data Protection and Privacy, Data Protection by Design and Default, Secure Development and Change Management, Incident Response, and Business Continuity and Disaster Recovery. Policies are owned by senior leadership, reviewed at least annually or following material change, and stored centrally with controlled access.
Security controls include role-based access, data classification and minimisation, secure coding practices, audit logging, vulnerability scanning, and regular internal reviews. Third-party suppliers and hosting partners are subject to security due diligence and contractual controls.
Our approach is supported by recognised NHS assurance frameworks including Cyber Essentials, the NHS Data Security and Protection Toolkit (DSPT), and DTAC compliance. Staff receive onboarding and ongoing information security training. Policy adherence is monitored through audits, access reviews and incident tracking, with findings used to drive continuous improvement. We conduct regular monthly meetings to review compliance with clinical and information governance. System access is reviewed quarterly in line with DSPT, Cyber Essentials, and DCB 1596 requirements. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- We manage configuration and changes using version-controlled repositories in GitHub for both application code and infrastructure-as-code, with all changes tagged using semantic versioning. Every commit, merge and tagged release is visible and recorded, and we log release activity in team communication channels for full traceability. Our CI pipeline runs automated tests on every change, and all branches undergo manual testing in a dedicated environment before deployment. Changes are reviewed, approved and tracked to ensure quality. This structured approach ensures that components are tracked throughout their lifecycle and that potential security impacts of changes are assessed and mitigated prior to release.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- We maintain a structured vulnerability management process that identifies, assesses and remediates security issues across our service. Dependencies and code libraries are monitored via GitHub Dependabot, which generates pull requests for known vulnerabilities. Our CI pipeline includes automated container vulnerability scanning to detect potential issues early in development. Identified vulnerabilities are assessed by severity and prioritised for remediation based on impact. Changes are tracked and deployed in accordance with our release process, with security patches applied promptly after review and testing. Threat information is informed by public sources and security community alerts, helping us stay aware of emerging risks.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- We collect and analyse key system logs and metrics to identify potential compromise or abnormal activity. Automated alerts (e.g., error‐rate thresholds) are configured to notify the team via Slack for prompt attention. We also monitor application and access logs for indicators such as unusual access patterns or repeated failures. When a potential issue is identified, we investigate promptly, contain any confirmed incident, and apply corrective actions. Response times are prioritised by severity, with critical events addressed as soon as possible and others within normal business hours. Lessons from incidents feed into monitoring and response improvements.
- Incident management type
- Supplier-defined controls
- Incident management approach
- We follow a documented incident management process for the detection, logging, assessment and resolution of service and security incidents. Pre-defined procedures cover common event types, including categorisation, escalation and remediation steps. Users report incidents via our support channels, and all incidents are logged and tracked in our compliance and risk platform (Assuric) for visibility and audit. Incident details and timelines are available to buyers on request or as agreed in onboarding discussions. Post-incident reviews feed into continual improvement of our processes and controls.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 10%
- Between £1,000,001 and £2,500,000
- 15%
- Between £2,500,001 and £5,000,000
- 30%
- Over £5,000,001
- 35%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 0c84d07e-191c-4b2e-90bf-5535d31b06c3
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- Yes
- Any other security certifications
-
- NHS Data Security and Protection Toolkit (DSPT)
- NHS Digital Technology Assessment Criteria (DTAC)
- NHS DCB0129 (Clinical Risk Management for Suppliers)
- NHSDCB0160 (Clinical Risk Management for Organisations)
- NHD DCB1596 (Secure Email Standard)
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
- Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
- Measures to engage users and communities and build relationships to increase community integration build trust and influence how the contract is delivered
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-