Hear Me Now
Hear Me Now provides a digital person-held record (digital passport) of health and care information for people with a learning disability and cognitive impairments. Data is held on the person's device (Android, iOS) and enables them to share remotely information about themselves with friends, family, health and care staff.
Features
- Multimedia information
- Remote sharing
- About Me information
- Digital passport
- Online Easy Read Questionnaires
- My Week planner
- Individualised, personalised content
- Document store
- Online information dissemination
- Diary
Benefits
- 30% reduction in engagement episodes
- Annual savings of over £70,000
- Increased independence and control
- Better articulation of needs and wishes
- Improved self-management of long-term conditions
- Better information sharing between health and care agencies
- Greater transparency of health and care provision
- Evidence generation for regulators
- Oversight for commissioners
- Reassurance for families
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 3 5 8 3 5 6 4 6 7 0 6 2 7 0
Contact
MALDABA LIMITED
Mark Clements
Telephone: 07989 973 791
Email: tender@maldaba.co.uk
About your service
- Service categories
-
Applications
Content workflow and management
- Capture
- Document
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
- No constraints. App users (supported people/patients) require a phone or tablet (iOS, Android) purchased in the last 6 years. We routinely plan maintenance, however this is done out of hours with minimal downtime (if any at all). Remote access (for staff) is via a web browser, on any modern major browser. No other hardware constraints.
- System requirements
-
- Android (for app users) 5.0
- IOS (for app users) 10.0
- Any major modern web browser (Chrome, Safari, Edge, IE, Firefox)
User support
- Email or online ticketing support
- Yes
- Support response times
- Standard support is provided within 24hrs during normal business days (Mon-Fri excluding national holidays).
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes
- Support levels
-
Our support and customer services team will work with you to resolve any queries or issues as quickly as possible. We remain in contact with you (normally via email) and update you on progress.
Customers may request bespoke enhancements which we will always consider and may charge for. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- We provide onboarding documentation, training, engagements sessions and virtual support throughout onboarding. We provide a series of user guides and manuals to help users refer to after training to get using Hear Me Now. We offer regular (fortnightly and monthly) sessions to keep in touch with users and help them get used to using Hear Me Now daily.
- Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- Users request to Maldaba and we will provide data extracts as required, in system-agnostic formats.
- End-of-contract process
- Following the end of contract, app users continue to have access to their information in read-only mode. Customers can choose to extend app licences and pay for continuing support ad-hoc.
- Documentation accessibility standard
- EN 301 549
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The app is designed for use by vulnerable people and is co-created with people with learning disabilities. The web interface (the remote interface) is designed with and for the individual's support network (family, health and care staff). The two versions therefore have very different features, and different user interfaces and user experiences for these reasons.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The web application is written in PHP. The Android and iOS apps are each written natively, for their respective environments.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- We use NVDA to replicate a screen reader. We use https://webaim.org/resources/contrtastchecker for contrast checking.
- API
- Yes
- What users can and can't do using the API
- We work with customers who require API interoperability on a case-by-case basis. Our API is fully documented.
- API documentation
- Yes
- API documentation formats
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Admin-level customers can configure their organisation settings (such as managing users, managing sharing of information).
Bespoke customisations are possible and may be charged.
Scaling
- Independence of resources
- We actively monitor server resources to ensure sufficient resources are available for all our customers. Our servers are cloud-based and can quickly/easily be scaled as required.
Analytics
- Service usage metrics
- Yes
- Metrics types
- We provide aggregated app usage and web user analytics (usage, nature of use). Where an app user has shared data with a web user, some individual app user behaviour is also available. App users choose whether to consent to analytics or not. Data is only available with app user consent.
- Reporting types
-
- Real-time dashboards
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
- Physical access control, complying with another standard
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Request to Maldaba, who will export data on request.
- Data export formats
- CSV
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- MP3
- MP4
- JPG
- PNG
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- 99.5% service availability.
- Approach to resilience
- The data centre is compliant to ISO/IEC 27001 standards.
- Outage reporting
- Email alerts
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- The service uses Role-Based Access Controls (R-BAC). Customer admin users are supported to create appropriate permissions for users based on their roles. Support channels are restricted to these admin users, who in turn support their organisation colleagues.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- Between 6 months and 12 months
- How long system logs are stored for
- Between 6 months and 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
- The server hosts and data centres are each certified to ISO/IEC 27001 standard. Maldaba is Cyber Essentials Plus certified, and holds the NHS Data Security and protection Toolkit certification (Standards Exceeded). Maldaba is registered with the ICO.
- Information security policies and processes
- Maldaba has a Data Protection Policy, is CE+ and NHS DSPT (standards exceeded) certified.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- All system updates are logged, timestamped, and version-controlled, for easy rollback/regression testing where needed. Database backups are regularly taken and held for a period of months for major changes. Data backups are taken nightly to protect the data. Code is managed using source control.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Server and network security is maintained by our server hosts who operate to ISO/IEC 27001 standards. The data centre is separately ISO/IEC 27001 standard-certified.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Server and network security is maintained by our server hosts who operate to ISO/IEC 27001 standards. The data centre is separately ISO/IEC 27001 standard-certified.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Server and network security is maintained by our server hosts who operate to ISO/IEC 27001 standards. The data centre is separately ISO/IEC 27001 standard-certified. Users request support via email, we record all activities in our ticketing system and Sharepoint, and respond via email. Behaviour practices are documented on our internal Wiki for staff to access.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- Android (only) app users may use Hear Me Now for 30 days free trial.
- Link to free trial
- https://www.hearmenowapp.com/
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 00f44119-aedb-40be-9622-736e8bceb3cf
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- Ef371ff3-bb98-4988-a43f-547598ab6844
- Other security certifications
- Yes
- Any other security certifications
-
- DSPT Standards Exceeded
- Server hosts are ISO/IEC 27001 certified.
- Data centres are ISO/IEC 27001 certified.
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Working conditions which promote an inclusive working environment and promote retention and progression
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-