Skip to main content

Help us improve the Digital Marketplace - send your feedback

BRITISH TELECOMMUNICATIONS LIMITED

Smart Messaging Tailored for Healthcare from BT

Smart Messaging Tailored for Healthcare is a web-based, cloud-hosted platform for mobile messaging. Send, receive and automates real-time SMS and RCS conversations with your patients. Send Friends and Family Surveys (FFT), reduce do not attend rates and engage with your patients.

Features

  • SMS service overseeing SMS mobile interactions and SMS campaigns
  • Multi-channel communication (RCS)
  • Two way messaging: using shortcodes, keywords or virtual mobile numbers
  • Web portal & SMTP email 2 SMS API
  • One way SMS Messaging and International SMS. Opt-out capability
  • Clinical integrations including: EMIS, AccurX, Allocate, Netcall, Patchs, Footfall
  • Multiple API Integration Options including HTTP, SMTP, REST, SMPP
  • Real-time reporting, cost centre breakdown & decision automation
  • UK data centre security and ISO27001 certified
  • Direct UK message routing

Benefits

  • Fast and effective mobile communication with your patients
  • Mass messaging: contact your customers on their preferred communication channel
  • User friendly platform: allowing two-way interactions
  • Integrate Smart Messaging with your own CRM and software tools
  • Sub users and sub accounts support multi-department organisations
  • Supports alpha tags, short codes, Virtual Mobile Numbers and keywords
  • Use cases include: appointment reminders, emergency communications, surveys, patient feedback
  • Patient surveys: NHS Friends and Family Test (FFT) solution
  • Cases including appointment reminders, emergency communications, surveys, patient feedback

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at ccsframeworks@bt.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

3 2 6 8 4 3 4 2 1 1 1 5 8 2 6

Contact

BRITISH TELECOMMUNICATIONS LIMITED Frameworks Team
Telephone: 0800 328 8077
Email: ccsframeworks@bt.com

About your service

Service categories

Applications

Customer relationship management

  • Marketing campaign management
  • Digital commerce
  • Customer service

Advertising

  • Advertising Placement
  • Advertising Measurement
Multi cloud support
No

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Third-party integrations are possible via APIs
Cloud deployment model
Public cloud
Service constraints
Multi-tenant SaaS architecture.
Support for international messaging has some country-specific limitations.
The delivery of messages via our services is dependent on third party carriers and may be impacted by technical and network coverage issues that are outside our control (e.g. due to a handset being out of range or switched off). International SMS - country specific routing/pricing/regulation. RCS Agents require validation approval from UK Mobile networks.
System requirements
Internet Connection

User support

Email or online ticketing support
Yes
Support response times
All requests acknowledged with ticket reference. Targeted response time of 30 minutes (within business hours).
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
UK Service Desk Availability Mon - Fri 0800 - 1800.
Telephone Calls (General Support) Within 30 seconds within Support Hours.
Telephone Calls (24/7 Hotline) Within 30 seconds.
On Call Duty Manager Availability (P1 & P2 only) 24x7x365 within 1 hour All electronic communication requests - average time to respond Within 30 minutes.

All metrics are targets only.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Welcome email with getting started guide, virtual training sessions and demos available.
Service documentation
Yes
Documentation formats
Other
Other documentation formats
  • Microsoft Word
  • Microsoft Powerpoint
End-of-contract data extraction
Export report.
End-of-contract process
The service will continue to roll on a monthly basis at the end of the minimum term agreement.
Documentation accessibility standard
EN 301 549

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Other
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Not applicable
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
Web Portal
Accessibility standards
None or don’t know
Description of accessibility
The Smart Messaging portal provides users with access, via any web browser with internet access, to a rich set of features that enable bulk messaging and interactive inbound responses.
Accessibility testing
Our platform has been tested and passed for accessibility compliance.
API
Yes
What users can and can't do using the API
Multiple low/no-code APIs available, including HTTPS, SMPP, SMTP, SFTP/FTPS, Connect API (RESTful, both real-time and batch mode).
API documentation
Yes
API documentation formats
PDF
API sandbox or test environment
No
Customisation available
Yes
Description of customisation
Sender Names (alpha tags)
Virtual mobile numbers
Dedicated short codes
Shared Keyword short codes
Free to end user short codes
API's
RCS Agents

Scaling

Independence of resources
For capacity planning, we monitor the load on the platform, including peak rates/volumes, and ensure that we have sufficient capacity to meet our customers’ growing requirements.

Analytics

Service usage metrics
Yes
Metrics types
Send & receive reports.
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Reseller providing extra features and support
Organisation whose services are being resold
Soprano Design PTY LTD

Staff security

Staff security clearance
Other security clearance
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
  • Other locations
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
Less than once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
Other
Other data at rest protection approach
All users must have unique UserID’s regular password changes (at a minimum every 90 days)accounts must be locked following no more than 5 unsuccessful login attempts unused accounts must be automatically disabled after a period of 60 days and deleted after a further 30 days password strength – (minimum 8 characters, 1 capital, 1 numeric, 1 special character) access to information systems must be restricted according to the role of the individual -regular access reviews must be undertaken; Regular audits of user access; and -more stringent access controls for administrator access must be implemented.
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Export reports via the administration console.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
Data protection within supplier network
IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
Target 99.9% availability (not guaranteed)
Approach to resilience
High Availability Disaster Recovery (HADR) architecture with geographic redundancy Provides data replication protecting against partial and complete failures.
Outage reporting
Outages (and maintenance) are communicated to customers via email .

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
Access restrictions in management interfaces and support channels
User access levels (Management (BT) profiles, Customer Admin, Customer standard user). Within our servers, our enterprise customers' data is logically separated, so that each customer can only access their data. This is controlled by customer accounts and user access controls i.e. via username and password. Each of the usernames is associated with a particular customer account, and when the user logs in they will only have access to the data associated with that account.
Access restriction testing frequency
Less than once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
Between 1 month and 6 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
Between 1 month and 6 months
How long system logs are stored for
Between 1 month and 6 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
BT's Security Policies and processes are modelled against ISO27001.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
We have formal change management systems in place, with a pre-defined maintenance schedule for updates to the platform. Scheduled maintenance is usually associated with new releases or upgrades, fixes to correct defects, and essential system maintenance.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
We proactively perform security reviews and engage an independent third party to help test and validate security hardening against industry standards. All web facing systems and services are subject to penetration testing, regular vulnerability scans and following major changes. The application goes through a regular release cycle, typically every 6 weeks, to implement new features, fix bugs and patch vulnerability. Upon identifying a vulnerability issue, the team performs a review to determine if the platform is impacted. If impact is identified then a change process is followed to prepare, test, validate and apply a patch to fix the issue.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Protective monitoring is achieved through continuous logging, automated alerting, and real-time analysis of security events across network, application, and infrastructure layers. Tools like AWS GuardDuty, SIEM, IDS/IPS, and anomaly detection systems are used. All critical events are logged, reviewed, and retained for at least two years. Alerts are generated for suspicious activity, and incidents are managed by a dedicated response team. Monitoring is aligned with SOC2 and ISO 27001 standards, ensuring rapid detection and response to threats.
Incident management type
Supplier-defined controls
Incident management approach
Hotline assistance for emergency support. This is available 24 hours a day, 7 days a week, 365 days a year to report and manage Critical and Major incidents and manage unplanned outages and faults.
Email technical enquiry service - provides answers and first line technical guidance to email queries and to support all non-critical support requests such as password resets, general platform queries, service provision or modification etc.
Phone technical support service - provides first line technical support to telephone queries during UK support hours.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
LQRA Limited
ISO/IEC 27001 accreditation date
Friday 16 January 2026
What the ISO/IEC 27001 doesn’t cover
This covers our published service offers
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
LRQA Limited
ISO 9001 accreditation date
Tuesday 19 August 2025
What the ISO 9001 doesn’t cover
This covers our published service offers
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
30d49a42-7676-4f9e-ba34-05a211d0dd04
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
31cf450d-d8be-4c72-9251-45f5a9a4025a
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Volunteering opportunities for staff
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at ccsframeworks@bt.com. Tell them what format you need. It will help if you say what assistive technology you use.