Skip to main content

Help us improve the Digital Marketplace - send your feedback

THETA SLEEP LTD

Theta Sleep

Tech-enabled sleep medicine service

Features

  • Cloud-based platform supporting end-to-end sleep medicine pathways.
  • Digital onboarding, education and structured sleep history capture.
  • Inclusive access pathways, including telephone support if lower digital literacy.
  • Integrated home sleep study logistics, scoring and reporting.
  • Remote clinical consultations for results review and treatment decisions.
  • Treatment initiation workflows including prescription and fulfilment coordination.
  • Clinician tools supporting triage, decision-making and clinical documentation.
  • Secure messaging and document sharing with patients and referrers.
  • Configurable components supporting partial or full pathway deployment.
  • Web-based delivery with no local installation or on-site infrastructure.

Benefits

  • Faster access to diagnosis and treatment for sleep disorders.
  • Reduced healthcare inequalities through at-home care
  • Improved patient experience via digital access, education and remote consultations.
  • Reduced carbon footprint through fewer hospital visits and travel.
  • Increased service capacity through efficient, scalable digital pathways.
  • Reduced reliance on hospital estate for sleep medicine pathways.
  • Care delivered at significant reduction to NHS tariffs.
  • Care delivered in line with NHS, NICE and BSS guidance.
  • Reduced administrative burden through streamlined data capture and documentation.
  • Safe care delivery supported by robust clinical governance and security.

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at tom.chambers@thetasleep.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

2 2 2 8 2 6 4 1 9 3 5 9 8 9 5

Contact

THETA SLEEP LTD Tom Chambers
Telephone: ‪020 8178 9938‬
Email: tom.chambers@thetasleep.com

About your service

Service categories

Applications

Production and operations

Service industry and public sector operations

  • Healthcare
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
The service is delivered as a browser-based SaaS application and does not require buyers to install or maintain any specific hardware or software. The service is accessible using modern, standards-compliant web browsers.

Planned maintenance is carried out occasionally and, where possible, outside of UK business hours. Buyers will be notified in advance of any planned maintenance that may affect service availability.
System requirements
Modern, standard-compliant web browser

User support

Email or online ticketing support
Yes
Support response times
24hrs
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
No
Support levels
The service is provided with a single standard support level.

Support is provided remotely during UK business hours via email and/or online support channels.

There are currently no separate or premium support tiers, and no additional costs for different support levels.

The service does not include a dedicated technical account manager or named cloud support engineer.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Users begin using the service after receiving an invitation email with a secure link. By clicking the link, they are taken to the web application where they can set up their account and log in. The service is designed to be intuitive and easy to navigate without the need for formal documentation or classroom training.

In-application support is provided through contextual help elements: a persistent “Help” button on all screens opens guidance relevant to the current page, and information (“i”) icons provide additional context where appropriate.

We also offer responsive support channels (email and phone) to assist users with any questions during onboarding.

Non-digital pathways are available for our service for those who cannot access the internet or have lower digital literacy. A member of the support team is able to gather information usually collected on the application via the telephone to ensure all users receive the same quality of care.
Service documentation
No
End-of-contract data extraction
Users are routinely provided with their health data during delivery of the service, including clinical letters and sleep study reports generated as part of the clinical pathway.

At contract end, we will support buyers to extract user data in structured formats suitable for migration or archival, in line with agreed timelines and data protection requirements. This includes clinical records and associated pathway data held within the service.

Following contract end, access arrangements will be agreed with the buyer. Where appropriate, users may be given time-limited access to view their data. Users may also request copies of their personal data via a subject access request in line with our GDPR policies and public-facing privacy notice.

Data retention and deletion are managed in line with NHS data retention requirements and agreed contractual terms. Upon confirmed account closure, data is securely retained and then deleted in accordance with these policies.
End-of-contract process
At the end of the contract, a clinically safe exit process is actioned to ensure continuity of care. At termination, no new patients are onboarded to the service. Patients already in the diagnostic pathway are supported to complete diagnosis, with Theta Sleep providing clinical letters and reports to the patient, their GP and the buyer organisation. These patients are referred back to local NHS services via their GP for onward management.

Patients already receiving treatment through Theta Sleep are transitioned back to local NHS services via their GP, supported by a complete record of their diagnosis and treatment history. Where appropriate, patients within an initial treatment period may complete planned follow-up appointments before being safely handed back with full clinical documentation. Exit arrangements, timelines and communications are agreed with the buyer to ensure patient safety, continuity of care, and compliance with clinical governance and data protection requirements.

Appropriate and clinically safe exit arrangements, including standard service wind-down, patient handover and data transfer, are included within the contract price. Accelerated exits, extended clinical follow-up beyond agreed pathways, or custom data extracts outside standard formats are not supported and would require separate agreement.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The mobile and desktop versions of the service provide the same functionality and access to the same content.

The user interface is responsive and adapts to different screen sizes, but there are no functional differences between mobile and desktop use.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
The service interface is a webapp provided via a secure, browser-based user interface that enables users to access all service functionality through standard web browsers on desktops and mobile devices. The interface is designed for intuitive navigation and responsive display across screen sizes. It supports common modern browsers and presents functionality through menus, forms, dashboards, and interactive views. The service does not require any client installation.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
We design and test our service to meet WCAG 2.2 AA accessibility requirements and consider accessibility throughout design, development and release. Interface testing includes a combination of automated accessibility testing, manual testing, and user-centred review against WCAG success criteria. We test keyboard-only navigation, focus order, colour contrast, text resizing, form validation and error messaging to ensure compatibility with common assistive technologies.

Manual testing includes use of screen readers and browser accessibility tools to validate that content is perceivable, operable and understandable. Accessibility issues identified during testing are logged, prioritised and remediated as part of our normal development and change management processes. Where appropriate, accessibility feedback from users is incorporated into ongoing improvements. We regularly review accessibility guidance and update our approach to ensure continued alignment with WCAG 2.2 AA and evolving best practice.
API
Yes
What users can and can't do using the API
Our service provides a secure, standards-based API that enables authorised integrated systems (such as the clinical systems used by GP practices and hospitals within an NHS trust) to automate key referral and results workflows. Using the API, buyer systems can submit patient referrals into our platform from their own clinical systems, triggering the creation of a referral record in our SaaS application. When clinical assessment and diagnosis are complete, the API supports sending structured outcome data and clinic letters back to the referring system for incorporation into the patient’s record.

Users cannot use the API to perform actions outside of the defined clinical workflows (for example, administrative user management or management of platform configuration), and we enforce strict authentication, authorisation and audit controls on all API access. Integration work is scoped with each buyer to ensure secure access, appropriate data mappings and adherence to clinical governance requirements. Documentation and support are provided to help buyer developers implement and test against the API in their environments.
API documentation
Yes
API documentation formats
  • HTML
  • PDF
API sandbox or test environment
Yes
Customisation available
No

Scaling

Independence of resources
Our service is hosted on Google Cloud using managed, autoscaling infrastructure. We leverage serverless platforms (such as Cloud Run and Cloud SQL) which automatically scale resources in response to demand, helping ensure consistent performance regardless of load growth. Traffic is routed through protective layers such as Cloud Armor and Cloudflare to mitigate DDoS and abusive traffic. This architecture and use of cloud autoscaling and isolation mechanisms help prevent high usage from one customer affecting the experience of others.

Analytics

Service usage metrics
Yes
Metrics types
We provide service and pathway metrics to support monitoring and service improvement. Operational metrics include platform availability and uptime, response times, system performance indicators, and numbers of active users.

Where the service supports clinical sleep pathways, we also provide clinically relevant KPIs aligned to NHS reporting. These include time from referral to diagnosis (DM01), time from referral to treatment (RTT), patient satisfaction measured using the Friends and Family Test, and treatment adherence metrics where applicable. Metrics are shared with buyers through agreed reporting arrangements in line with governance and data protection requirements.
Reporting types
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CHECK service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
Deleted data can’t be directly accessed / Cryptographic Erasure

Data importing and exporting

Data export approach
Users are routinely provided with their health data as part of the service. This includes structured clinical letters and sleep study reports generated during the clinical pathway, which are shared with patients, GPs and referring organisations.

Users and buyers can request export of structured data held within the service in standard formats (e.g. CSV files). Data exports are provided in line with data protection requirements and agreed timelines.

Where users require copies of their personal data outside routine service delivery, this can also be requested in accordance with our GDPR policies and public-facing privacy notice.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
We guarantee 99.9% availability for the Theta Sleep platform, measured on a monthly basis, excluding planned maintenance agreed in advance with buyers. Availability covers access to core platform functionality delivered via our cloud-hosted service.

This availability commitment is defined within our service level agreement. Platform availability is monitored continuously, and performance against agreed service levels is reported to buyers as part of routine service management.

If availability falls below the guaranteed level, buyers are eligible for service credits in line with the service level agreement. Service credits are applied to future invoices and are calculated based on the extent and duration of the availability shortfall.
Approach to resilience
Our service is designed for resilience using Google Cloud’s highly available and fault-tolerant infrastructure. Application components run on Cloud Run, which supports autoscaling and zonal redundancy within the region to absorb load spikes and isolate failures. Data storage is provided by Cloud SQL, configured for high availability with automatic synchronous replication to a standby instance in another zone within the same region, enabling seamless failover if the primary zone becomes unavailable. Managed load balancing and autoscaling ensure traffic distribution and continuity under varying demand. Regular backups and managed storage contribute to data durability. External protective layers (e.g., Cloud Armor and Cloudflare) mitigate network-level disruptions. Monitoring and alerting enable prompt detection and response. These design patterns help ensure continuity of service even in the event of component or zonal failures, aligning with recognised resilience objectives.
Outage reporting
We monitor service health internally and operate incident management processes to detect outages as soon as they occur. In the event of a service interruption, we notify affected customer contacts via email alerts with timely updates on the issue and resolution progress. Outages and incident statuses are also communicated through our support channels and available on request to contracted buyers. If required, we can work with buyers to establish additional notification mechanisms or integrations (e.g., webhook or API-based alerts) as part of their onboarding. Our approach ensures customers are informed promptly and transparently when disruptions occur.

Identity and authentication

User authentication needed
Yes
User authentication
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is restricted using strong identity and access controls. Administrative access is protected by authenticated user accounts with role-based permissions, ensuring only authorised personnel can perform configuration or operational tasks. We enforce multi-factor authentication (MFA). Support channels such as the ticketing system are accessible only to verified internal support users, with least-privilege roles assigned. Our controls are reviewed regularly to ensure appropriate separation of duties and minimise the risk of unauthorised access.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
Between 6 months and 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
Other
Other security governance standards
Our security governance complies with key NHS standards including NHS Digital Technology Assessment Criteria (DTAC) and the NHS Data Security and Protection Toolkit (DSPT) which includes compliance with UK Cyber Essentials. Our email systems are compliant with NHS DCB1596 (The secure email standard for sharing health data).
Information security policies and processes
We operate a documented information security governance framework covering Information Security, Access Control and Acceptable Use, Data Protection and Privacy, Data Protection by Design and Default, Secure Development and Change Management, Incident Response, and Business Continuity and Disaster Recovery. Policies are owned by senior leadership, reviewed at least annually or following material change, and stored centrally with controlled access.

Security controls include role-based access, data classification and minimisation, secure coding practices, audit logging, vulnerability scanning, and regular internal reviews. Third-party suppliers and hosting partners are subject to security due diligence and contractual controls.

Our approach is supported by recognised NHS assurance frameworks including Cyber Essentials, the NHS Data Security and Protection Toolkit (DSPT), and DTAC compliance. Staff receive onboarding and ongoing information security training. Policy adherence is monitored through audits, access reviews and incident tracking, with findings used to drive continuous improvement. We conduct regular monthly meetings to review compliance with clinical and information governance. System access is reviewed quarterly in line with DSPT, Cyber Essentials, and DCB 1596 requirements.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
We manage configuration and changes using version-controlled repositories in GitHub for both application code and infrastructure-as-code, with all changes tagged using semantic versioning. Every commit, merge and tagged release is visible and recorded, and we log release activity in team communication channels for full traceability. Our CI pipeline runs automated tests on every change, and all branches undergo manual testing in a dedicated environment before deployment. Changes are reviewed, approved and tracked to ensure quality. This structured approach ensures that components are tracked throughout their lifecycle and that potential security impacts of changes are assessed and mitigated prior to release.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
We maintain a structured vulnerability management process that identifies, assesses and remediates security issues across our service. Dependencies and code libraries are monitored via GitHub Dependabot, which generates pull requests for known vulnerabilities. Our CI pipeline includes automated container vulnerability scanning to detect potential issues early in development. Identified vulnerabilities are assessed by severity and prioritised for remediation based on impact. Changes are tracked and deployed in accordance with our release process, with security patches applied promptly after review and testing. Threat information is informed by public sources and security community alerts, helping us stay aware of emerging risks.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
We collect and analyse key system logs and metrics to identify potential compromise or abnormal activity. Automated alerts (e.g., error‐rate thresholds) are configured to notify the team via Slack for prompt attention. We also monitor application and access logs for indicators such as unusual access patterns or repeated failures. When a potential issue is identified, we investigate promptly, contain any confirmed incident, and apply corrective actions. Response times are prioritised by severity, with critical events addressed as soon as possible and others within normal business hours. Lessons from incidents feed into monitoring and response improvements.
Incident management type
Supplier-defined controls
Incident management approach
We follow a documented incident management process for the detection, logging, assessment and resolution of service and security incidents. Pre-defined procedures cover common event types, including categorisation, escalation and remediation steps. Users report incidents via our support channels, and all incidents are logged and tracked in our compliance and risk platform (Assuric) for visibility and audit. Incident details and timelines are available to buyers on request or as agreed in onboarding discussions. Post-incident reviews feed into continual improvement of our processes and controls.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
10%
Between £1,000,001 and £2,500,000
15%
Between £2,500,001 and £5,000,000
30%
Over £5,000,001
35%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
0c84d07e-191c-4b2e-90bf-5535d31b06c3
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
Yes
Any other security certifications
  • NHS Data Security and Protection Toolkit (DSPT)
  • NHS Digital Technology Assessment Criteria (DTAC)
  • NHS DCB0129 (Clinical Risk Management for Suppliers)
  • NHSDCB0160 (Clinical Risk Management for Organisations)
  • NHD DCB1596 (Secure Email Standard)

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
    • Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
    • Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
    • Measures to engage users and communities and build relationships to increase community integration build trust and influence how the contract is delivered
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
    • Actions to invest in the physical and mental health and wellbeing of the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at tom.chambers@thetasleep.com. Tell them what format you need. It will help if you say what assistive technology you use.