Surgery Hero Health Coaching
Surgery Hero helps people prepare for and recover from their surgery. We do this by giving our members a tailored programme that’s designed to tackle their specific modifiable risk factors as well as a human health coach to support them throughout.
Features
- Patient Optimisation
- Remote access
- Health Data Centre
- Digital Prehabilitation
- Learn Content
- Remote monitoring
- Self Management
- Health coaching
- Security built in by design
- Digital Rehabilitation
Benefits
- Increased PAM scores - Patient Activation Measure
- Continuous monitoring
- Reduced length of stay following surgery
- Reduced readmissions following surgery
- Reduced cancellations for surgery
- Earlier return to work of patients following surgery
- Learn content to power self management
- Empowered patients who can self manage
- Improved surgical outcomes
- Reduced costs related to surgery
Pricing
£150 to £220 a unit
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 14
Service ID
3 8 4 9 2 3 4 7 4 2 6 2 1 1 7
Contact
SURGERY HERO LIMITED
Luke Eastwood
Telephone: 07596496242
Email: luke@surgeryhero.com
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
- NA
- System requirements
- Recent versions of ios and android
User support
- Email or online ticketing support
- Email or online ticketing
- Support response times
- Within 24 hours
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Web chat
- Web chat support availability
- 9 to 5 (UK time), 7 days a week
- Web chat support accessibility standard
- WCAG 2.1 AA or EN 301 549
- Web chat accessibility testing
- WCAG 2.1 level AA compliance & DTAC compliant
- Onsite support
- Onsite support
- Support levels
- Extensive support and training at point of purchase, onboarding and thereafter as required
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Training materials and demos provided online before onsite training and onboarding is conducted in person.
- Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- Option to do so by contacting Surgery Hero staff
- End-of-contract process
-
Hosting services
Health coaching
Support and Reporting
All included in contract price - a detailed service level agreement can be provided for services.
Using the service
- Web browser interface
- No
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Available on all recent ios and android devices
- Service interface
- No
- User support accessibility
- WCAG 2.1 AA or EN 301 549
- API
- No
- Customisation available
- Yes
- Description of customisation
-
Some elements are customisable, learn content, reporting schedule and logos and branding.
Customisation will be conducted via Surgery Hero staff during onboarding and training with the payor.
Scaling
- Independence of resources
- AWS cloud provider enables easy scaling with increased demand without affecting level of services provided
Analytics
- Service usage metrics
- Yes
- Metrics types
- Quarterly business reviews and reports can be emailed / shared at agreed time intervals
- Reporting types
-
- Regular reports
- Reports on request
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Up to Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 3.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Other
- Other data at rest protection approach
- Data is encrypted in transit and at rest. Stringent access controls to AWS backend and ability to access patient health data. Internally pseudoanonymisation techniques are used. Surgery Hero has been certified to ISO27001 (Info Sec) and meets the standards of NHS DSTP, DTAC & and is cyber essentials certified.
- Data sanitisation process
- Yes
- Data sanitisation type
-
- Explicit overwriting of storage before reallocation
- Deleted data can’t be directly accessed
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v.30, CAS (Sanitisation) or ISO/IEC 27001
Data importing and exporting
- Data export approach
- Contacting dedicated Surgery Hero support staff
- Data export formats
- CSV
- Data import formats
- Other
- Other data import formats
- Can be entered manually in data centre of the app
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- Surgery Hero is certified to ISO27001 for information security - Availability risks must be mitigated to an acceptable risk level. Several controls have been implemented to mitigate this risk including but not limited to continuous back up services provided via AWS
- Approach to resilience
-
Data collected on the platform is hosted by Amazon Web Services (AWS) in a manner that is ISO 27001 (International Standard for Information Security Management) compliant.
Communications are encrypted and authenticated using TLS1.2 (protocol), ECDHE_RSA with P-256 (key exchange), and AES-128-GCM (cipher) using 2048 bit keys. Public Surgery Hero sites, such as those potentially accessed from hospital systems that may be running old versions of Windows that do not support TLS 1.2, accept TLS 1 and TLS 1.1.
All data is encrypted regardless of its classification and access control can be defined to the field level if required. DynamoDB encryption at rest provides enhanced security by encrypting all data at rest using encryption keys stored in AWS Key Management Service (AWS KMS). This functionality helps reduce the operational burden and complexity involved in protecting sensitive data.
Surgery Hero has been eternally audited and certified to ISO27001 (InfoSec) and ensures the availability, integrity and confidentiality of all information Assets. - Outage reporting
- Email alerts
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- 2-factor authentication
- Public key authentication (including by TLS client certificate)
- Username or password
- Access restrictions in management interfaces and support channels
- System access and the associated security is controlled by taking full advantage of the AWS Identity and Access Management solution. Multi Factor Authentication is used by all users with access to the infrastructure. Only trained users have access to health data that is not anonymised. This is typically only for the purpose of responding to subject access requests.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- 2-factor authentication
- Public key authentication (including by TLS client certificate)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- You control when users can access audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- BQAI
- ISO/IEC 27001 accreditation date
- 25/03/2024
- What the ISO/IEC 27001 doesn’t cover
- NA
- ISO 28000:2007 certification
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber essentials plus
- No
- Other security certifications
- Yes
- Any other security certifications
- ISO 13485
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- NHS DST, Cyber Essentials, DTAC, ISO 13485
- Information security policies and processes
- The Information Security Management System is compliant and certified to ISO27001. All annex A controls are in scope. MRB meetings always have Infosec as a topic for discussion where adherence with policies and procedures and possible improvements is reviewed.
Operational security
- Configuration and change management standard
- Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
- Configuration and change management approach
- There is a dedicated change management procedure that must be followed by staff. This procedure is reviewed at least annually.
- Vulnerability management type
- Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
- Vulnerability management approach
- Vulnerability management approach meets the standards of ISO 27001 and cyber essentials (Surgery Hero has been accredited with both these certifications).
- Protective monitoring type
- Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
- Protective monitoring approach
- Dedicated incident reporting procedures and responding to incident procedures that have be built in line with ISO27001 accredication.
- Incident management type
- Conforms to a recognised standard, for example, CSA CCM v3.0 or ISO/IEC 27035:2011 or SSAE-16 / ISAE 3402
- Incident management approach
- Dedicated ISMS procedures to handle reporting and responding to incidents (externally certified to ISO27001).
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v3.0)
Public sector networks
- Connection to public sector networks
- No
Social Value
- Social Value
-
Social Value
- Fighting climate change
- Covid-19 recovery
- Wellbeing
Fighting climate change
Facilitating remote care and prehabilition outside the hospital setting. Improved surgical outcomes (reduced LoS in hospital post surgery, complication and readmission rates) also aid this endeavour.Covid-19 recovery
Facilitating remote care and prehabilition outside the hospital setting. Improved surgical outcomes (reduced LoS in hospital post surgery, complication and readmission rates) also aid this endeavour.Wellbeing
Facilitating remote care and prehabilition outside the hospital setting. Improved surgical outcomes (reduced LoS in hospital post surgery, complication and readmission rates) also aid this endeavour.
Pricing
- Price
- £150 to £220 a unit
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- Time limited trial may be possible upon success criteria being agreed