Skip to main content

Help us improve the Digital Marketplace - send your feedback

SURGERY HERO LIMITED

Surgery Hero Health Coaching

Surgery Hero helps people prepare for and recover from their surgery. We do this by giving our members a tailored programme that’s designed to tackle their specific modifiable risk factors as well as a human health coach to support them throughout.

Features

  • Patient Optimisation
  • Remote access
  • Health Data Centre
  • Digital Prehabilitation
  • Learn Content
  • Remote monitoring
  • Self Management
  • Health coaching
  • Security built in by design
  • Digital Rehabilitation

Benefits

  • Increased PAM scores - Patient Activation Measure
  • Continuous monitoring
  • Reduced length of stay following surgery
  • Reduced readmissions following surgery
  • Reduced cancellations for surgery
  • Earlier return to work of patients following surgery
  • Learn content to power self management
  • Empowered patients who can self manage
  • Improved surgical outcomes
  • Reduced costs related to surgery

Pricing

£150 to £220 a unit

  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at luke@surgeryhero.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 14

Service ID

3 8 4 9 2 3 4 7 4 2 6 2 1 1 7

Contact

SURGERY HERO LIMITED Luke Eastwood
Telephone: 07596496242
Email: luke@surgeryhero.com

Service scope

Software add-on or extension
No
Cloud deployment model
Private cloud
Service constraints
NA
System requirements
Recent versions of ios and android

User support

Email or online ticketing support
Email or online ticketing
Support response times
Within 24 hours
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
Web chat
Web chat support availability
9 to 5 (UK time), 7 days a week
Web chat support accessibility standard
WCAG 2.1 AA or EN 301 549
Web chat accessibility testing
WCAG 2.1 level AA compliance & DTAC compliant
Onsite support
Onsite support
Support levels
Extensive support and training at point of purchase, onboarding and thereafter as required
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Training materials and demos provided online before onsite training and onboarding is conducted in person.
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
Option to do so by contacting Surgery Hero staff
End-of-contract process
Hosting services
Health coaching
Support and Reporting

All included in contract price - a detailed service level agreement can be provided for services.

Using the service

Web browser interface
No
Application to install
Yes
Compatible operating systems
  • Android
  • IOS
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Available on all recent ios and android devices
Service interface
No
User support accessibility
WCAG 2.1 AA or EN 301 549
API
No
Customisation available
Yes
Description of customisation
Some elements are customisable, learn content, reporting schedule and logos and branding.

Customisation will be conducted via Surgery Hero staff during onboarding and training with the payor.

Scaling

Independence of resources
AWS cloud provider enables easy scaling with increased demand without affecting level of services provided

Analytics

Service usage metrics
Yes
Metrics types
Quarterly business reviews and reports can be emailed / shared at agreed time intervals
Reporting types
  • Regular reports
  • Reports on request

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Up to Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 3.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CHECK service provider
Protecting data at rest
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
  • Other
Other data at rest protection approach
Data is encrypted in transit and at rest. Stringent access controls to AWS backend and ability to access patient health data. Internally pseudoanonymisation techniques are used. Surgery Hero has been certified to ISO27001 (Info Sec) and meets the standards of NHS DSTP, DTAC & and is cyber essentials certified.
Data sanitisation process
Yes
Data sanitisation type
  • Explicit overwriting of storage before reallocation
  • Deleted data can’t be directly accessed
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v.30, CAS (Sanitisation) or ISO/IEC 27001

Data importing and exporting

Data export approach
Contacting dedicated Surgery Hero support staff
Data export formats
CSV
Data import formats
Other
Other data import formats
Can be entered manually in data centre of the app

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Surgery Hero is certified to ISO27001 for information security - Availability risks must be mitigated to an acceptable risk level. Several controls have been implemented to mitigate this risk including but not limited to continuous back up services provided via AWS
Approach to resilience
Data collected on the platform is hosted by Amazon Web Services (AWS) in a manner that is ISO 27001 (International Standard for Information Security Management) compliant.

Communications are encrypted and authenticated using TLS1.2 (protocol), ECDHE_RSA with P-256 (key exchange), and AES-128-GCM (cipher) using 2048 bit keys. Public Surgery Hero sites, such as those potentially accessed from hospital systems that may be running old versions of Windows that do not support TLS 1.2, accept TLS 1 and TLS 1.1.

All data is encrypted regardless of its classification and access control can be defined to the field level if required. DynamoDB encryption at rest provides enhanced security by encrypting all data at rest using encryption keys stored in AWS Key Management Service (AWS KMS). This functionality helps reduce the operational burden and complexity involved in protecting sensitive data.

Surgery Hero has been eternally audited and certified to ISO27001 (InfoSec) and ensures the availability, integrity and confidentiality of all information Assets.
Outage reporting
Email alerts

Identity and authentication

User authentication needed
Yes
User authentication
  • 2-factor authentication
  • Public key authentication (including by TLS client certificate)
  • Username or password
Access restrictions in management interfaces and support channels
System access and the associated security is controlled by taking full advantage of the AWS Identity and Access Management solution. Multi Factor Authentication is used by all users with access to the infrastructure. Only trained users have access to health data that is not anonymised. This is typically only for the purpose of responding to subject access requests.
Access restriction testing frequency
At least once a year
Management access authentication
  • 2-factor authentication
  • Public key authentication (including by TLS client certificate)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
You control when users can access audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
BQAI
ISO/IEC 27001 accreditation date
25/03/2024
What the ISO/IEC 27001 doesn’t cover
NA
ISO 28000:2007 certification
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Cyber essentials plus
No
Other security certifications
Yes
Any other security certifications
ISO 13485

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
NHS DST, Cyber Essentials, DTAC, ISO 13485
Information security policies and processes
The Information Security Management System is compliant and certified to ISO27001. All annex A controls are in scope. MRB meetings always have Infosec as a topic for discussion where adherence with policies and procedures and possible improvements is reviewed.

Operational security

Configuration and change management standard
Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
Configuration and change management approach
There is a dedicated change management procedure that must be followed by staff. This procedure is reviewed at least annually.
Vulnerability management type
Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
Vulnerability management approach
Vulnerability management approach meets the standards of ISO 27001 and cyber essentials (Surgery Hero has been accredited with both these certifications).
Protective monitoring type
Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
Protective monitoring approach
Dedicated incident reporting procedures and responding to incident procedures that have be built in line with ISO27001 accredication.
Incident management type
Conforms to a recognised standard, for example, CSA CCM v3.0 or ISO/IEC 27035:2011 or SSAE-16 / ISAE 3402
Incident management approach
Dedicated ISMS procedures to handle reporting and responding to incidents (externally certified to ISO27001).

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v3.0)

Public sector networks

Connection to public sector networks
No

Social Value

Social Value

Social Value

  • Fighting climate change
  • Covid-19 recovery
  • Wellbeing

Fighting climate change

Facilitating remote care and prehabilition outside the hospital setting. Improved surgical outcomes (reduced LoS in hospital post surgery, complication and readmission rates) also aid this endeavour.

Covid-19 recovery

Facilitating remote care and prehabilition outside the hospital setting. Improved surgical outcomes (reduced LoS in hospital post surgery, complication and readmission rates) also aid this endeavour.

Wellbeing

Facilitating remote care and prehabilition outside the hospital setting. Improved surgical outcomes (reduced LoS in hospital post surgery, complication and readmission rates) also aid this endeavour.

Pricing

Price
£150 to £220 a unit
Discount for educational organisations
No
Free trial available
Yes
Description of free trial
Time limited trial may be possible upon success criteria being agreed

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at luke@surgeryhero.com. Tell them what format you need. It will help if you say what assistive technology you use.