Smart Messaging Tailored for Healthcare from BT
Smart Messaging Tailored for Healthcare is a web-based, cloud-hosted platform for mobile messaging. Send, receive and automates real-time SMS and RCS conversations with your patients. Send Friends and Family Surveys (FFT), reduce do not attend rates and engage with your patients.
Features
- SMS service overseeing SMS mobile interactions and SMS campaigns
- Multi-channel communication (RCS)
- Two way messaging: using shortcodes, keywords or virtual mobile numbers
- Web portal & SMTP email 2 SMS API
- One way SMS Messaging and International SMS. Opt-out capability
- Clinical integrations including: EMIS, AccurX, Allocate, Netcall, Patchs, Footfall
- Multiple API Integration Options including HTTP, SMTP, REST, SMPP
- Real-time reporting, cost centre breakdown & decision automation
- UK data centre security and ISO27001 certified
- Direct UK message routing
Benefits
- Fast and effective mobile communication with your patients
- Mass messaging: contact your customers on their preferred communication channel
- User friendly platform: allowing two-way interactions
- Integrate Smart Messaging with your own CRM and software tools
- Sub users and sub accounts support multi-department organisations
- Supports alpha tags, short codes, Virtual Mobile Numbers and keywords
- Use cases include: appointment reminders, emergency communications, surveys, patient feedback
- Patient surveys: NHS Friends and Family Test (FFT) solution
- Cases including appointment reminders, emergency communications, surveys, patient feedback
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 2 6 8 4 3 4 2 1 1 1 5 8 2 6
Contact
BRITISH TELECOMMUNICATIONS LIMITED
Frameworks Team
Telephone: 0800 328 8077
Email: ccsframeworks@bt.com
About your service
- Service categories
-
Applications
Customer relationship management
- Marketing campaign management
- Digital commerce
- Customer service
Advertising
- Advertising Placement
- Advertising Measurement
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Third-party integrations are possible via APIs
- Cloud deployment model
- Public cloud
- Service constraints
-
Multi-tenant SaaS architecture.
Support for international messaging has some country-specific limitations.
The delivery of messages via our services is dependent on third party carriers and may be impacted by technical and network coverage issues that are outside our control (e.g. due to a handset being out of range or switched off). International SMS - country specific routing/pricing/regulation. RCS Agents require validation approval from UK Mobile networks. - System requirements
- Internet Connection
User support
- Email or online ticketing support
- Yes
- Support response times
- All requests acknowledged with ticket reference. Targeted response time of 30 minutes (within business hours).
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
UK Service Desk Availability Mon - Fri 0800 - 1800.
Telephone Calls (General Support) Within 30 seconds within Support Hours.
Telephone Calls (24/7 Hotline) Within 30 seconds.
On Call Duty Manager Availability (P1 & P2 only) 24x7x365 within 1 hour All electronic communication requests - average time to respond Within 30 minutes.
All metrics are targets only. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Welcome email with getting started guide, virtual training sessions and demos available.
- Service documentation
- Yes
- Documentation formats
- Other
- Other documentation formats
-
- Microsoft Word
- Microsoft Powerpoint
- End-of-contract data extraction
- Export report.
- End-of-contract process
- The service will continue to roll on a monthly basis at the end of the minimum term agreement.
- Documentation accessibility standard
- EN 301 549
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Not applicable
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- Web Portal
- Accessibility standards
- None or don’t know
- Description of accessibility
- The Smart Messaging portal provides users with access, via any web browser with internet access, to a rich set of features that enable bulk messaging and interactive inbound responses.
- Accessibility testing
- Our platform has been tested and passed for accessibility compliance.
- API
- Yes
- What users can and can't do using the API
- Multiple low/no-code APIs available, including HTTPS, SMPP, SMTP, SFTP/FTPS, Connect API (RESTful, both real-time and batch mode).
- API documentation
- Yes
- API documentation formats
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
-
Sender Names (alpha tags)
Virtual mobile numbers
Dedicated short codes
Shared Keyword short codes
Free to end user short codes
API's
RCS Agents
Scaling
- Independence of resources
- For capacity planning, we monitor the load on the platform, including peak rates/volumes, and ensure that we have sufficient capacity to meet our customers’ growing requirements.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Send & receive reports.
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- Soprano Design PTY LTD
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- Less than once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Other
- Other data at rest protection approach
- All users must have unique UserID’s regular password changes (at a minimum every 90 days)accounts must be locked following no more than 5 unsuccessful login attempts unused accounts must be automatically disabled after a period of 60 days and deleted after a further 30 days password strength – (minimum 8 characters, 1 capital, 1 numeric, 1 special character) access to information systems must be restricted according to the role of the individual -regular access reviews must be undertaken; Regular audits of user access; and -more stringent access controls for administrator access must be implemented.
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Export reports via the administration console.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- Target 99.9% availability (not guaranteed)
- Approach to resilience
- High Availability Disaster Recovery (HADR) architecture with geographic redundancy Provides data replication protecting against partial and complete failures.
- Outage reporting
- Outages (and maintenance) are communicated to customers via email .
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- User access levels (Management (BT) profiles, Customer Admin, Customer standard user). Within our servers, our enterprise customers' data is logically separated, so that each customer can only access their data. This is controlled by customer accounts and user access controls i.e. via username and password. Each of the usernames is associated with a particular customer account, and when the user logs in they will only have access to the data associated with that account.
- Access restriction testing frequency
- Less than once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- Between 1 month and 6 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- Between 1 month and 6 months
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- BT's Security Policies and processes are modelled against ISO27001.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- We have formal change management systems in place, with a pre-defined maintenance schedule for updates to the platform. Scheduled maintenance is usually associated with new releases or upgrades, fixes to correct defects, and essential system maintenance.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- We proactively perform security reviews and engage an independent third party to help test and validate security hardening against industry standards. All web facing systems and services are subject to penetration testing, regular vulnerability scans and following major changes. The application goes through a regular release cycle, typically every 6 weeks, to implement new features, fix bugs and patch vulnerability. Upon identifying a vulnerability issue, the team performs a review to determine if the platform is impacted. If impact is identified then a change process is followed to prepare, test, validate and apply a patch to fix the issue.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Protective monitoring is achieved through continuous logging, automated alerting, and real-time analysis of security events across network, application, and infrastructure layers. Tools like AWS GuardDuty, SIEM, IDS/IPS, and anomaly detection systems are used. All critical events are logged, reviewed, and retained for at least two years. Alerts are generated for suspicious activity, and incidents are managed by a dedicated response team. Monitoring is aligned with SOC2 and ISO 27001 standards, ensuring rapid detection and response to threats.
- Incident management type
- Supplier-defined controls
- Incident management approach
-
Hotline assistance for emergency support. This is available 24 hours a day, 7 days a week, 365 days a year to report and manage Critical and Major incidents and manage unplanned outages and faults.
Email technical enquiry service - provides answers and first line technical guidance to email queries and to support all non-critical support requests such as password resets, general platform queries, service provision or modification etc.
Phone technical support service - provides first line technical support to telephone queries during UK support hours. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- LQRA Limited
- ISO/IEC 27001 accreditation date
- Friday 16 January 2026
- What the ISO/IEC 27001 doesn’t cover
- This covers our published service offers
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- LRQA Limited
- ISO 9001 accreditation date
- Tuesday 19 August 2025
- What the ISO 9001 doesn’t cover
- This covers our published service offers
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 30d49a42-7676-4f9e-ba34-05a211d0dd04
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 31cf450d-d8be-4c72-9251-45f5a9a4025a
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-