Graphnet Population Health
Graphnet Population Health is an analytics platform designed to support health economies delivering population health programs. The solution enables data driven transformation to undertake evidence-based patient care improvements. A suite of use cases can be used to drive initiatives. Data can be incorporated from any available source as required.
Features
- Population health longitudinal record using data from across an ICB
- Scalable Microsoft Fabric based population health analytics Data Lakehouse platform
- Johns Hopkins ACG system risk stratification and population segmentation
- Casefinding patients for interventions
- Intervention cohort tracking, management and benefits outcomes analysis
- Clinical system integration of analytic outputs
- Extensive population health use cases, co-designed with integrated health economies
- Segregated data marts available; identifiable, anonymised, pseudonymised and customer owned
- Near real-time data feeds (up to 15 mins)
- Allows local data flows to be crosslinked into patient records
Benefits
- Analyse the health and care of a community or population
- Advanced case finding capabilities for interventions using linked datasets
- Monitors impact of care intervention programmes
- Identify and understand data quality issues
- Identify and support care delivery best practice using casemix approaches
- Toolset for local analysts to proactively build targeted analytics
- Understand the drivers and risks which lead to outcomes.
- Identify trends in activity, diseases and patient behaviour
- Supports pro-active care though identification and monitoring of patient cohorts
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 6 9 3 0 6 8 2 6 2 1 5 1 5 5
Contact
GRAPHNET HEALTH LIMITED
Lisa Haslam
Telephone: 03330771988
Email: salesandbids@graphnethealth.com
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Police
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Can be optionally integrated with the Graphnet Shared Care Record to aid with data ingestion or implemented stand alone.
- Cloud deployment model
- Public cloud
- Service constraints
- GDPR objection and nationally Opted out patients and all their corresponding information, are excluded from data marts where legally required. Sensitive codes defined by NHS England are excluded. The local deployment model maybe constrained by local IG and security policies regarding presentation of secure information.
- System requirements
-
- Micrososft Edge
- Google Chrome
- Firefox
- Access to the web server via http/https
User support
- Email or online ticketing support
- Yes
- Support response times
- Support is available on commencement of live service and we offer a variety of support packages. Each support package includes full details of call priority rankings and the corresponding response times agreed with the customer.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- Options to suit customer's need. Typically 9 - 5.30pm, 24/7 or other daily times possible subject to agreed SLA and commercials. Costings depend on the number of product and user licences required. Support engineers are supplied as part of the Service Desk provision as specified under the Service Level T&Cs for each customer.
- Support available to third parties
- No
Onboarding and offboarding
- Getting started
-
Our Population Health platform significantly increases the availability of patient data in a single repository which allows for far more detailed data analysis.
Ultimately Graphnet want our customers to be self sufficient in creating and maintaining their own dashboards. To support this outcome each Graphnet customer is assigned a Population Health Consultant. One of the roles of the Consultant is to ensure the customers analysts are familiar with the platform, the data dictionary and have access to the Microsoft Business Intelligence application. The platform also includes a set of “core” dashboards which can be deployed FOC. Including a set of dashboards is both to familiarise customers as to the art of the achievable and ensure an element of speed to value.
A key component of the Population Health platform is the “Enhanced Case Finder” functionality which enables end users such as Practice Managers, GPs and Provider Clinicians to analyse the data pertinent to their organisation and/or specialty. Through the provision of customer specific training materials and enabling “Train the Trainer” programs of work Graphnet ensure these users are familiar with the solution as well. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
In each agreement Graphnet provides a Project Initiation Document (PID), a component of which is an agreed exit plan detailing how data would be provided back to the customer should the contract end. The documentation always includes details of Graphnet’s obligations to transfer data and will detail an agreed format.
The Graphnet Population Health platform sources data both from “feeds” from the provider organisations as well as 3rd party data sources. Both data sources would be in scope for extract.
Users can then extract their data at the end of the contract through a process facilitated by Graphnet. This involves accessing a designated data extraction tool. Users can select the data they wish to export, specifying the format and destination for the extracted data. Graphnet also commit to provide additional support to ensure a smooth transition and compliance with data protection regulations. Clear communication and documentation will be provided to support users throughout the extraction process adhering to industry best practices and regulatory requirements. - End-of-contract process
-
6 to 12 months prior to the contract expiry, Graphnet will work with the customers senior leadership, finance and contract management teams to discuss what options are available. Options to discuss would include.
Non-Renewal: Clearly we hope that all contracts are renewed, but in some rare cases contracts do expire. In such cases where appropriate provisions are made such that any information entered into the Shared Record is returned in a format agreed with the customer and that here is a managed transition to a new system.
Renewal: Contract is renewed. Contracted components and/or participant organisations may alter.
Should the contract actually no longer be required Graphnet will offer the provision of other reasonable termination assistance at the Authority’s request at the Supplier’s standard rates (e.g. to assist with data migration to the replacement contractor’s system). In addition, if necessary, a “read only licence” for historic data is offered. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- Yes
- Compatible operating systems
- Windows
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The Graphnet Population Health platform provides analytical dashboards via a devices browser. So long as a device is utilising a supported browser, then there is no difference between mobile and desktop services.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The service is delivered via a web browser for accessing the Population Health use cases using single sign on. Dashboards and reports can also be embedded within clinical systems such as the Graphnet Shared Care Record and other EPRs.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- Our solution has been designed taking into account the W3C Web Content Accessibility Guidelines. We undergo testing during the design process to support colour blindness, high contrast settings and use of iconography as well as colour in key areas of the application. Additionally, we are prepared to work with customers that have specific needs on a case by case basis. Our Agile design and development approach is collaborative so we continue to develop accessible, meaningful and intuitive system.
- API
- Yes
- What users can and can't do using the API
- A limited subset of Population Health calculated data is made available for third party clinical applications to consume. This includes risk stratification and cohort mapping engine outputs at a patient level. Microsoft Fabric has a suite of APIs which enable access to both data and visualisations for embedding into Clinical systems.
- API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Customer's information analysts can securely access the underlying data marts and data structures directly using analytics tools such as Azure Data Studio, Microsoft Business Intelligence, SQL Management Studio, Python and other tools. The platform also includes Population Explorer / Enhanced Case Finder functionality identifying population cohorts and undertaking risk stratification at local and ICB level with contemporaneous data. This enables the analysts to create any custom analytics utilising the wealth of data on the platform. The adopted approach gives users ultimate control. Platform use cases are created in Power BI can also be customised and published by end users.
Scaling
- Independence of resources
- We use Platform-as-a-Service capabilities within Microsoft Azure Cloud to ensure our high scalability and availability requirements are met. Our application tiers utilise auto-scaling based on system demand, as well as clustering at the data layers with appropriately scaled resources (including headroom and automatic data expansion). In addition, we have in-depth monitoring capabilities allowing us to observe capacity and be proactively alerted when thresholds are met before end-user performance is adversely affected. This is a key consideration in our design approach which influences the hardware platform, software design and associated processes covering Support and Maintenance, Business Continuity and Disaster Recovery.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
The metrics provides relate to;
- Number of user logins over time
- Reports accessed
- Queries run
- Data load management / timeliness - Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- Johns Hopkins ACG system
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Our population health platform provides access to Microsoft tooling to enable the export of any data within the system in any industry standard format. These extracts can be ad-hoc or scheduled. Bespoke extracts can also be setup using Microsoft Azure functionality into any supported system.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- Industry-standard formats supported by Microsoft analytics tools
- Power BI
- Azure Data Studio
- Azure Data Factory
- SQL Management Studio
- Python
- DataBricks
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- Any industry standard format
- MS Office
- CSV
- JSON
- XML
- HL7 messaging
- APIs
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- Other
- Other protection between networks
- Graphnet deploys the industry leading Cloudflare application security service across all customer systems which provides enhanced protection of customer data against increasingly sophisticated Internet based threat actors. It acts as a gateway from the Internet to the application interface and examines all traffic passing through it protecting against the following threats: distributed denial of service attacks, rogue bots, cross site scripting, zero-day vulnerability attacks and Web Application Firewall functionality based on the ‘OWASP Top 10’. If required, IP “allow lists” can be also applied to the interface to manage where connections can originate from.
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
Graphnet's guaranteed availability is 99.9% excluding agreed maintenance windows out of hours.
Graphnet recognise that each solution provided are all critical solutions for the provision of safe and effective care. To that end Graphnet have multiple systems and procedures to ensure the solution(s) are available.
When deployment issues are logged they are immediately triaged to determine the extent to which the availability has been affected. The levels of severity and the associated resolution time are detailed below.
P1 (Critical) Entire system unavailable/unusable. Resolution: within four hours
P2 (High) Significant loss of the service but the impacted business function is not halted. Resolution: within eight Hours.
P3 (Medium) Significant loss of the service but the impacted business function is not halted. Resolution: Resolved within one hundred and twenty Hours.
P4 (Low) defined as Intermittent or partial faults resulting in loss of non-critical functionality where the software is still useable or there is a suitable alternative. Resolution: within twenty days
The recovery time objective (RTO) is four hours and the recovery point objective (RPO) is 0.5 hours from the initial incident. - Approach to resilience
-
Graphnet's Population Health solution is hosted in Microsoft Azure which provides a robust, secure and highly available hosting service. Microsoft Azure meets a broad set of international and industry-specific compliance standards, such as ISO 27001, HIPAA, FedRAMP, SOC 1 and SOC 2, as well as country-specific standards.
Graphnet maintain numerous Operational standards which are designed to further ensure the provision of a resilient service. These include:
Business Continuity Process: Mitigation against, fire, bombing, flooding and area wide outage etc.
Quality & Security Processes: Ensure quality solutions are deployed safely and securely.
Risk Assessment Processes: Continually reviewing recognised risks and mitigation processes.
Access Controls: Ensure only approved staff have access to customer environments.
Penetration Testing: To mitigate against malicious attacks.
In some cases the Graphnet solution may need to be made unavailable to provide updates to the
In the rare case of a system outage, Graphnet will declare a “Priority 1” incident whereby support services are as a norm extended to 24/7 with a target resolution of 4 hours. - Outage reporting
- All outages are recorded as part of the incident management process and should a problem be detected then the service desk will inform the customer as required.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- All Graphnet Shared Care Record applications support in-built Role Based Access Control (RBAC) functionality which manages which functions a user has access to and which views of data they are able to see. The system includes 25 pre-configured roles, which align with the National Registration Authority Smart Card access roles and are grouped into 5 granular levels of system functionality. Graphnet Shared Care Record has a well-established concept of Patient Groups, which supports the ability to control which users, roles and groups of users have access to which groups of patients. System Administrators can also further refine permissions, as required.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
-
We comply with NHS standards and best practice guidelines. Standards/accreditations include; •ISO27001:2022 •ISO9001:2015 •Data Security and Protection Toolkit •Cyber Essentials Plus
Graphnet's ICO Registration is Z1045461. Other SCCIs/ISNs applicable to shared care record solutions, including DCB 0129 and DSCN14-2009. - Information security policies and processes
- We have ISO 27001 and Cyber Essentials Plus certification, supported by policies ensuring compliance with Information Governance and Information Security requirements. These include: •Access Control •Quality and Security Policy •Clean Screen and Clear Desk •Control of Records •Secure Software and Solution Development •Key Management and Encryption •Data Transfer (Encryption) •Secure Disposal •Acceptable Use •Network Control •Password Management •Cyber Incident Response Plan •Business Continuity Plan. Additional guidance and policies provide assurance for our Data Processor obligations and internal responsibilities. We have a Governance Board which our CFO and SIRO, Information Governance Manager (Data Protection Officer), Information Security Manager, ISO Compliance Manager, sit on. Through these key roles we ensure policies are reviewed and amended in light of any issues arising, audit reviews and process changes etc. Policies are available to all staff via our employee hub which requires staff to read all required policies. We incorporate Crown Commercial Service’s Generic Standard GDPR clauses in all our contracts where we process personal data; we process in compliance with Article 32. Where services use the “cloud” this processing adheres to the fourteen National Cyber Security Centre cloud service security principles as applicable to UK OFFICIAL and the cloud host complies with ISO27018.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
To ensure the security and reliability of Graphnet's solutions, Graphnet follow a 5 phase configuration and change management process.
•Development and QA and internal only proof of concept (POC) activities
•Customer facing POC work.
•Build of all pre-production systems that may go on to hold customer or
Graphnet data (deployment phase work)
•BAU customer systems provided by Graphnet including all UAT,
Sandpit, Training, Testing, Production or Live systems.
•All systems managed out or curtailed (including part of customer and
data egress) where there is a requirement for secure planning for data
clearance and reuse for other purposes or secure disposal. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Graphnet monitors NHS CSOC Cyber Alerts, US-CERT and other industry sources for intelligence regarding threats, vulnerabilities and exploits.
Vulnerability assessments of the application and its components are performed within Azure and any findings are investigated and appropriate remedial actions taken.
Vulnerabilities are managed through a cycle of regular patching for the IaaS elements within 14 days of the patches being made available. The Microsoft Azure platform handles the patching of the hardware infrastructure and PaaS components. Any out of band, critical or high severity patches or fixes will be applied according to the suppliers’ guidelines. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- The application undergoes continuous monitoring by a third-party Security Operation Centre (SOC) using Microsoft's Sentinel, Defender for Cloud, and Azure policies. Anomalies trigger alerts, including suspicious/malicious activities. Audit logs for Azure, web app, and SQL server activities are retained for one year, while application logs are kept indefinitely. The SOC responds to alerts within agreed SLAs, escalating critical issues to Graphnet staff. Operational support receives email alerts for audit findings, investigating them promptly. Proactive monitoring addresses environmental triggers like low disk space and high CPU usage. Anti-malware software ensures vigilance against malicious software or activities.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Incidents are formally managed through Graphnet's Support Desk, using an ITIL focused call logging application to record, track and manage issues through all stages of the incident lifecycle. The Service Desk is also briefed on the service responses agreed through the customer contracts and use the incident logging application to monitor incidents’ service level response times. Problems are identified through incident reviews and managed through diagnosis, resolution and planned changes. These reviews of issues attempt to identify trends/recurrent issues; when identified, these undergo a root cause analysis and recommendations are made for changes to the product based on the analysis.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
- Health and Social Care Network (HSCN)
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- Where practical, we accommodate requests. For instance, if a customer seeks a system showcasing real-life data from GP and Acute systems, it incurs substantial third-party costs. However, a test version with dummy data may suffice, which we can provide without such expense.
- Link to free trial
- We do not have a generic link as each customer's requirements are slightly different. We make test systems available on request with them configured as per the customer's requirements.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- BSI Assurance UK Limited
- ISO/IEC 27001 accreditation date
- Monday 15 July 2024
- What the ISO/IEC 27001 doesn’t cover
- Our 27001 covers the full business operation without exclusions. Graphnet holds Certification number IS 614375 and operates Information Management Systems which comply with the requirements of ISO/IEC 27001:2022 for: All automated information systems under the direct control of Graphnet Health Ltd. All employees and agents of Graphnet Health Limited. All employees and agents of other organisations who directly or indirectly make use of or support the use of information systems under the direct control of Graphnet Health Limited.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- BSI Assurance UK Limited
- ISO 9001 accreditation date
- Monday 11 March 2024
- What the ISO 9001 doesn’t cover
- Our 9001 covers the full business operation without exclusions. Graphnet holds Certification number FS 614373 and operates a Quality Management System which complies with the requirements of ISO/IEC 9001:2015 with no exceptions.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 51f753d9-3a05-43aa-90d0-054a83d271a4
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 9a259fc6-6ab9-413e-aa1d-c1968dbc6f89
- Other security certifications
- Yes
- Any other security certifications
-
- Data Security and Protection Toolkit (NHS Digital ODS code 8GX89)
- Data Protection Act 1998 (DPA)
- Level 3 compliance with NHS IGSoC
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Volunteering opportunities for staff
-