Skip to main content

Help us improve the Digital Marketplace - send your feedback

GRAPHNET HEALTH LIMITED

Graphnet Population Health

Graphnet Population Health is an analytics platform designed to support health economies delivering population health programs. The solution enables data driven transformation to undertake evidence-based patient care improvements. A suite of use cases can be used to drive initiatives. Data can be incorporated from any available source as required.

Features

  • Population health longitudinal record using data from across an ICB
  • Scalable Microsoft Fabric based population health analytics Data Lakehouse platform
  • Johns Hopkins ACG system risk stratification and population segmentation
  • Casefinding patients for interventions
  • Intervention cohort tracking, management and benefits outcomes analysis
  • Clinical system integration of analytic outputs
  • Extensive population health use cases, co-designed with integrated health economies
  • Segregated data marts available; identifiable, anonymised, pseudonymised and customer owned
  • Near real-time data feeds (up to 15 mins)
  • Allows local data flows to be crosslinked into patient records

Benefits

  • Analyse the health and care of a community or population
  • Advanced case finding capabilities for interventions using linked datasets
  • Monitors impact of care intervention programmes
  • Identify and understand data quality issues
  • Identify and support care delivery best practice using casemix approaches
  • Toolset for local analysts to proactively build targeted analytics
  • Understand the drivers and risks which lead to outcomes.
  • Identify trends in activity, diseases and patient behaviour
  • Supports pro-active care though identification and monitoring of patient cohorts

Pricing

  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at salesandbids@graphnethealth.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

3 6 9 3 0 6 8 2 6 2 1 5 1 5 5

Contact

GRAPHNET HEALTH LIMITED Lisa Haslam
Telephone: 03330771988
Email: salesandbids@graphnethealth.com

About your service

Service categories

Applications

Production and operations

Service industry and public sector operations

  • Healthcare
  • Police
Multi cloud support
No

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Can be optionally integrated with the Graphnet Shared Care Record to aid with data ingestion or implemented stand alone.
Cloud deployment model
Public cloud
Service constraints
GDPR objection and nationally Opted out patients and all their corresponding information, are excluded from data marts where legally required. Sensitive codes defined by NHS England are excluded. The local deployment model maybe constrained by local IG and security policies regarding presentation of secure information.
System requirements
  • Micrososft Edge
  • Google Chrome
  • Firefox
  • Access to the web server via http/https

User support

Email or online ticketing support
Yes
Support response times
Support is available on commencement of live service and we offer a variety of support packages. Each support package includes full details of call priority rankings and the corresponding response times agreed with the customer.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Options to suit customer's need. Typically 9 - 5.30pm, 24/7 or other daily times possible subject to agreed SLA and commercials. Costings depend on the number of product and user licences required. Support engineers are supplied as part of the Service Desk provision as specified under the Service Level T&Cs for each customer.
Support available to third parties
No

Onboarding and offboarding

Getting started
Our Population Health platform significantly increases the availability of patient data in a single repository which allows for far more detailed data analysis.

Ultimately Graphnet want our customers to be self sufficient in creating and maintaining their own dashboards. To support this outcome each Graphnet customer is assigned a Population Health Consultant. One of the roles of the Consultant is to ensure the customers analysts are familiar with the platform, the data dictionary and have access to the Microsoft Business Intelligence application. The platform also includes a set of “core” dashboards which can be deployed FOC. Including a set of dashboards is both to familiarise customers as to the art of the achievable and ensure an element of speed to value.

A key component of the Population Health platform is the “Enhanced Case Finder” functionality which enables end users such as Practice Managers, GPs and Provider Clinicians to analyse the data pertinent to their organisation and/or specialty. Through the provision of customer specific training materials and enabling “Train the Trainer” programs of work Graphnet ensure these users are familiar with the solution as well.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
In each agreement Graphnet provides a Project Initiation Document (PID), a component of which is an agreed exit plan detailing how data would be provided back to the customer should the contract end. The documentation always includes details of Graphnet’s obligations to transfer data and will detail an agreed format.

The Graphnet Population Health platform sources data both from “feeds” from the provider organisations as well as 3rd party data sources. Both data sources would be in scope for extract.

Users can then extract their data at the end of the contract through a process facilitated by Graphnet. This involves accessing a designated data extraction tool. Users can select the data they wish to export, specifying the format and destination for the extracted data. Graphnet also commit to provide additional support to ensure a smooth transition and compliance with data protection regulations. Clear communication and documentation will be provided to support users throughout the extraction process adhering to industry best practices and regulatory requirements.
End-of-contract process
6 to 12 months prior to the contract expiry, Graphnet will work with the customers senior leadership, finance and contract management teams to discuss what options are available. Options to discuss would include.

Non-Renewal: Clearly we hope that all contracts are renewed, but in some rare cases contracts do expire. In such cases where appropriate provisions are made such that any information entered into the Shared Record is returned in a format agreed with the customer and that here is a managed transition to a new system.

Renewal: Contract is renewed. Contracted components and/or participant organisations may alter.

Should the contract actually no longer be required Graphnet will offer the provision of other reasonable termination assistance at the Authority’s request at the Supplier’s standard rates (e.g. to assist with data migration to the replacement contractor’s system). In addition, if necessary, a “read only licence” for historic data is offered.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
Yes
Compatible operating systems
Windows
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The Graphnet Population Health platform provides analytical dashboards via a devices browser. So long as a device is utilising a supported browser, then there is no difference between mobile and desktop services.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
The service is delivered via a web browser for accessing the Population Health use cases using single sign on. Dashboards and reports can also be embedded within clinical systems such as the Graphnet Shared Care Record and other EPRs.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
Our solution has been designed taking into account the W3C Web Content Accessibility Guidelines. We undergo testing during the design process to support colour blindness, high contrast settings and use of iconography as well as colour in key areas of the application. Additionally, we are prepared to work with customers that have specific needs on a case by case basis. Our Agile design and development approach is collaborative so we continue to develop accessible, meaningful and intuitive system.
API
Yes
What users can and can't do using the API
A limited subset of Population Health calculated data is made available for third party clinical applications to consume. This includes risk stratification and cohort mapping engine outputs at a patient level. Microsoft Fabric has a suite of APIs which enable access to both data and visualisations for embedding into Clinical systems.
API documentation
Yes
API documentation formats
Open API (also known as Swagger)
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Customer's information analysts can securely access the underlying data marts and data structures directly using analytics tools such as Azure Data Studio, Microsoft Business Intelligence, SQL Management Studio, Python and other tools. The platform also includes Population Explorer / Enhanced Case Finder functionality identifying population cohorts and undertaking risk stratification at local and ICB level with contemporaneous data. This enables the analysts to create any custom analytics utilising the wealth of data on the platform. The adopted approach gives users ultimate control. Platform use cases are created in Power BI can also be customised and published by end users.

Scaling

Independence of resources
We use Platform-as-a-Service capabilities within Microsoft Azure Cloud to ensure our high scalability and availability requirements are met. Our application tiers utilise auto-scaling based on system demand, as well as clustering at the data layers with appropriately scaled resources (including headroom and automatic data expansion). In addition, we have in-depth monitoring capabilities allowing us to observe capacity and be proactively alerted when thresholds are met before end-user performance is adversely affected. This is a key consideration in our design approach which influences the hardware platform, software design and associated processes covering Support and Maintenance, Business Continuity and Disaster Recovery.

Analytics

Service usage metrics
Yes
Metrics types
The metrics provides relate to;
- Number of user logins over time
- Reports accessed
- Queries run
- Data load management / timeliness
Reporting types
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Reseller providing extra features and support
Organisation whose services are being resold
Johns Hopkins ACG system

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CHECK service provider
Protecting data at rest
Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Our population health platform provides access to Microsoft tooling to enable the export of any data within the system in any industry standard format. These extracts can be ad-hoc or scheduled. Bespoke extracts can also be setup using Microsoft Azure functionality into any supported system.
Data export formats
  • CSV
  • Other
Other data export formats
  • Industry-standard formats supported by Microsoft analytics tools
  • Power BI
  • Azure Data Studio
  • Azure Data Factory
  • SQL Management Studio
  • Python
  • DataBricks
Data import formats
  • CSV
  • Other
Other data import formats
  • Any industry standard format
  • MS Office
  • CSV
  • JSON
  • XML
  • HL7 messaging
  • APIs

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • Other
Other protection between networks
Graphnet deploys the industry leading Cloudflare application security service across all customer systems which provides enhanced protection of customer data against increasingly sophisticated Internet based threat actors. It acts as a gateway from the Internet to the application interface and examines all traffic passing through it protecting against the following threats: distributed denial of service attacks, rogue bots, cross site scripting, zero-day vulnerability attacks and Web Application Firewall functionality based on the ‘OWASP Top 10’. If required, IP “allow lists” can be also applied to the interface to manage where connections can originate from.
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
Graphnet's guaranteed availability is 99.9% excluding agreed maintenance windows out of hours.

Graphnet recognise that each solution provided are all critical solutions for the provision of safe and effective care. To that end Graphnet have multiple systems and procedures to ensure the solution(s) are available.

When deployment issues are logged they are immediately triaged to determine the extent to which the availability has been affected. The levels of severity and the associated resolution time are detailed below.

P1 (Critical) Entire system unavailable/unusable. Resolution: within four hours
P2 (High) Significant loss of the service but the impacted business function is not halted. Resolution: within eight Hours.
P3 (Medium) Significant loss of the service but the impacted business function is not halted. Resolution: Resolved within one hundred and twenty Hours.
P4 (Low) defined as Intermittent or partial faults resulting in loss of non-critical functionality where the software is still useable or there is a suitable alternative. Resolution: within twenty days

The recovery time objective (RTO) is four hours and the recovery point objective (RPO) is 0.5 hours from the initial incident.
Approach to resilience
Graphnet's Population Health solution is hosted in Microsoft Azure which provides a robust, secure and highly available hosting service. Microsoft Azure meets a broad set of international and industry-specific compliance standards, such as ISO 27001, HIPAA, FedRAMP, SOC 1 and SOC 2, as well as country-specific standards.

Graphnet maintain numerous Operational standards which are designed to further ensure the provision of a resilient service. These include:

Business Continuity Process: Mitigation against, fire, bombing, flooding and area wide outage etc.
Quality & Security Processes: Ensure quality solutions are deployed safely and securely.
Risk Assessment Processes: Continually reviewing recognised risks and mitigation processes.
Access Controls: Ensure only approved staff have access to customer environments.
Penetration Testing: To mitigate against malicious attacks.

In some cases the Graphnet solution may need to be made unavailable to provide updates to the

In the rare case of a system outage, Graphnet will declare a “Priority 1” incident whereby support services are as a norm extended to 24/7 with a target resolution of 4 hours.
Outage reporting
All outages are recorded as part of the incident management process and should a problem be detected then the service desk will inform the customer as required.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
All Graphnet Shared Care Record applications support in-built Role Based Access Control (RBAC) functionality which manages which functions a user has access to and which views of data they are able to see. The system includes 25 pre-configured roles, which align with the National Registration Authority Smart Card access roles and are grouped into 5 granular levels of system functionality. Graphnet Shared Care Record has a well-established concept of Patient Groups, which supports the ability to control which users, roles and groups of users have access to which groups of patients. System Administrators can also further refine permissions, as required.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
We comply with NHS standards and best practice guidelines. Standards/accreditations include; •ISO27001:2022 •ISO9001:2015 •Data Security and Protection Toolkit •Cyber Essentials Plus
Graphnet's ICO Registration is Z1045461. Other SCCIs/ISNs applicable to shared care record solutions, including DCB 0129 and DSCN14-2009.
Information security policies and processes
We have ISO 27001 and Cyber Essentials Plus certification, supported by policies ensuring compliance with Information Governance and Information Security requirements. These include: •Access Control •Quality and Security Policy •Clean Screen and Clear Desk •Control of Records •Secure Software and Solution Development •Key Management and Encryption •Data Transfer (Encryption) •Secure Disposal •Acceptable Use •Network Control •Password Management •Cyber Incident Response Plan •Business Continuity Plan. Additional guidance and policies provide assurance for our Data Processor obligations and internal responsibilities. We have a Governance Board which our CFO and SIRO, Information Governance Manager (Data Protection Officer), Information Security Manager, ISO Compliance Manager, sit on. Through these key roles we ensure policies are reviewed and amended in light of any issues arising, audit reviews and process changes etc. Policies are available to all staff via our employee hub which requires staff to read all required policies. We incorporate Crown Commercial Service’s Generic Standard GDPR clauses in all our contracts where we process personal data; we process in compliance with Article 32. Where services use the “cloud” this processing adheres to the fourteen National Cyber Security Centre cloud service security principles as applicable to UK OFFICIAL and the cloud host complies with ISO27018.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
To ensure the security and reliability of Graphnet's solutions, Graphnet follow a 5 phase configuration and change management process.
•Development and QA and internal only proof of concept (POC) activities
•Customer facing POC work.
•Build of all pre-production systems that may go on to hold customer or
Graphnet data (deployment phase work)
•BAU customer systems provided by Graphnet including all UAT,
Sandpit, Training, Testing, Production or Live systems.
•All systems managed out or curtailed (including part of customer and
data egress) where there is a requirement for secure planning for data
clearance and reuse for other purposes or secure disposal.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Graphnet monitors NHS CSOC Cyber Alerts, US-CERT and other industry sources for intelligence regarding threats, vulnerabilities and exploits.
Vulnerability assessments of the application and its components are performed within Azure and any findings are investigated and appropriate remedial actions taken.
Vulnerabilities are managed through a cycle of regular patching for the IaaS elements within 14 days of the patches being made available. The Microsoft Azure platform handles the patching of the hardware infrastructure and PaaS components. Any out of band, critical or high severity patches or fixes will be applied according to the suppliers’ guidelines.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
The application undergoes continuous monitoring by a third-party Security Operation Centre (SOC) using Microsoft's Sentinel, Defender for Cloud, and Azure policies. Anomalies trigger alerts, including suspicious/malicious activities. Audit logs for Azure, web app, and SQL server activities are retained for one year, while application logs are kept indefinitely. The SOC responds to alerts within agreed SLAs, escalating critical issues to Graphnet staff. Operational support receives email alerts for audit findings, investigating them promptly. Proactive monitoring addresses environmental triggers like low disk space and high CPU usage. Anti-malware software ensures vigilance against malicious software or activities.
Incident management type
Supplier-defined controls
Incident management approach
Incidents are formally managed through Graphnet's Support Desk, using an ITIL focused call logging application to record, track and manage issues through all stages of the incident lifecycle. The Service Desk is also briefed on the service responses agreed through the customer contracts and use the incident logging application to monitor incidents’ service level response times. Problems are identified through incident reviews and managed through diagnosis, resolution and planned changes. These reviews of issues attempt to identify trends/recurrent issues; when identified, these undergo a root cause analysis and recommendations are made for changes to the product based on the analysis.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
Yes
Connected networks
Health and Social Care Network (HSCN)

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
Where practical, we accommodate requests. For instance, if a customer seeks a system showcasing real-life data from GP and Acute systems, it incurs substantial third-party costs. However, a test version with dummy data may suffice, which we can provide without such expense.
Link to free trial
We do not have a generic link as each customer's requirements are slightly different. We make test systems available on request with them configured as per the customer's requirements.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
BSI Assurance UK Limited
ISO/IEC 27001 accreditation date
Monday 15 July 2024
What the ISO/IEC 27001 doesn’t cover
Our 27001 covers the full business operation without exclusions. Graphnet holds Certification number IS 614375 and operates Information Management Systems which comply with the requirements of ISO/IEC 27001:2022 for: All automated information systems under the direct control of Graphnet Health Ltd. All employees and agents of Graphnet Health Limited. All employees and agents of other organisations who directly or indirectly make use of or support the use of information systems under the direct control of Graphnet Health Limited.
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
BSI Assurance UK Limited
ISO 9001 accreditation date
Monday 11 March 2024
What the ISO 9001 doesn’t cover
Our 9001 covers the full business operation without exclusions. Graphnet holds Certification number FS 614373 and operates a Quality Management System which complies with the requirements of ISO/IEC 9001:2015 with no exceptions.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
51f753d9-3a05-43aa-90d0-054a83d271a4
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
9a259fc6-6ab9-413e-aa1d-c1968dbc6f89
Other security certifications
Yes
Any other security certifications
  • Data Security and Protection Toolkit (NHS Digital ODS code 8GX89)
  • Data Protection Act 1998 (DPA)
  • Level 3 compliance with NHS IGSoC

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Volunteering opportunities for staff

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at salesandbids@graphnethealth.com. Tell them what format you need. It will help if you say what assistive technology you use.