Bullet Health
Bullet Health is an innovative, comprehensive client data collection and management system; built to help public health and social care teams manage their client interventions. A range of modules allow extensive data collection and monitoring to help support health improvement and inform service performance.
Features
- Cloud based client management system
- Manage client health intervention data
- Simple, intuitive data entry via web interface
- AI powered note summarising from scanned notes or voice
- Versatile, granular, role based permissions to manage access
- Full notification system (incl appointment reminders)
- Central client record with health interventions linked
- Comprehensive reporting suite to offer realtime and trend insights
- Secure management of public health and social care delivery
- Customisable modules built around your delivery and data collection
Benefits
- Access on any device with internet and browser
- API allows integration with public facing referral mechanisms
- Build client data capture needs around intevention
- Realtime reporting to inform provision
- Quick data entry saves time for advisors
- Built in intelligence and AI functions to streamline processes
- Appointment booking system and eVoucher generation
- Customisable reporting and export functions
- Full auditing function
- Client facing referral forms
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 8 7 9 2 1 4 0 1 8 8 8 9 0 3
Contact
CC2I LIMITED
Guy Giles
Telephone: 07973 909663
Email: info@cc2i.org.uk
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Adult Social Care
- Children's Social Care
- Other
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- There are no real constraints. Any third party service issues we are unable to control.
- System requirements
-
- Modern Web Browser
- Access to the Internet
User support
- Email or online ticketing support
- Yes
- Support response times
- We will classify all error/bug requests as one of urgent, high, normal and low. We will respond to any support ticket (question) within 1 working day. If an issue is reported at the weekend we will respond on the next working day after that weekend.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- No
- Support levels
- Our tool is covered by our standard SLA which means buyers have access to our support ticketing system to report issues or ask questions. Tickets are assessed for severity and response times allocated. Where further information is needed, a member of our support team will correspond with the buyer through our support system to ascertain the additional information required. Our core, reactive support service is included in our license cost. At additional cost, we offer a more proactive support arrangement. Here a dedicated account manager would monitor the usage and interactions with Bullet Health and how you use it. We'd provide regular feedback on areas of the tool that could be better used. In addition we'll provide commentary around your dashboard usage stats, should you need it. We'll also include quarterly workshop sessions to discuss ways we could enhance how the tool supports your users.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Our service will start with a piece of consultancy where we'd spend time with the organisation and help them shape the interventions and data we will model in our tool. For each module (health intervention) we'll work with the organisation to understand the data we will take and key organisation specific workflows that need consideration. We will also look at any systems that are required to interact with. From this consultancy, we'll shape our proposed solution for use. A period of testing and tweaking will ensure the tool is ready for use. Should any marketing support be needed, we can offer this through our sister agency or help advise internal communications teams. Any data migration from existing tools will be looked at and import scripts created ready for launch. Training will be provided for buyer's team around how to use the tool and get the most from it. Online screencasts and guides will be available at all times to cover key journeys on the system. End user engagement is key to maximise adoption of the new tool.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- Bullet Health holds a wealth of client data relating to the health interventions they have engaged with the organisation for. This health data is all linked to a client and we'd offer a full database export as well as module specific data exports in CSV format. The actual data retained is subject to the retention policies set by the buyer. Any data around usage reporting can be requested and provided in PDF format by us. We'd assist with the data export process at end of contract and provide any data schema diagrams as requested.
- End-of-contract process
- At end of contract, the Bullet Health service would be disabled for the organisation in question. Users would not be able to access the interface through their browser and any linked or integrated services would no longer function (in terms of the integration). There is no extra cost involved end of contract, the service provision would simply end, with any data requested, extracted and provided along with final usage reporting.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Tablet/Mobile service will allow users to complete key tasks likely to be used on the move, so focused for use on that device. Other longer form functions where larger screen useful, would be available but advised better completed on large screen.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Bullet Health can be accessed via a web browser (any modern browser) so available on any internet enabled device through such a browser.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- We adopt browser technology and ensure code is written in a way to enable use of device-enabled assistive technology. This ensures the user has the knowledge and existing learnt behaviours to utilise our platform.
- API
- Yes
- What users can and can't do using the API
- Our API allows buyers to interact with certain data streams. For instance referrals into Bullet Health can be passed in via the API (securely). There are also API points to allow certain reporting data to be accessed.
- API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Bullet Health comes shipped with a range of "public health and social care" intervention modules. Within existing modules and via new modules, users can work with us to customise data taken within a referral and intervention. Customisation will only be carried out by super admins and in partnership with the supplier (us). Customised data entry requirements will also impact reporting output. Consultancy is offered by our team to ensure the appropriate customisation is delivered.
Scaling
- Independence of resources
- Our solution is hosted on AWS and built to scale with demand.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Buyers are able to access the service and monitor the client data held at any time. Trend and demographic reporting is also available to allow health planning to be carried out based on real data. Core reporting functions are offered out of the box but additional reports are built around buyer need to ensure operational metrics are offered as well as higher level trend analytics.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- Bullet AI Ltd
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Data Erasure
Data importing and exporting
- Data export approach
-
Buyers would manage their data retention periods (per health intervention).
Data can be exported and downloaded at logical points within the interface. - Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- Our service guarantees a 99.9% uptime availability, as outlined in our Service Level Agreement (SLA). This SLA ensures that our services remain highly available and reliable, minimising disruptions and maximising efficiency for users. In the event that we fail to meet this guaranteed level of availability, users are eligible for service credits as compensation. The process for claiming these credits is straightforward: users must submit a claim within 30 days of the reported downtime. Each claim is reviewed against our system logs to confirm the downtime duration. Credits are calculated as a percentage of the monthly service fee based on the severity and duration of the outage. For instance, if the availability falls below 99.9% but remains above 99%, a credit of 5% of the monthly fee is provided. Below 99%, the credit increases to 10%.
- Approach to resilience
- Our service is designed with resilience as a core principle to ensure continuous availability and robust protection of assets, in alignment with the government’s 2nd cloud security principle. Our resilience strategy includes redundant data centres located in geographically diverse regions. Each data centre operates on independent power grids and network connections to mitigate regional disruptions. The infrastructure utilises active-active replication to synchronise data across sites in real-time, ensuring no single point of failure. Additionally, our systems are designed to automatically failover to backup facilities without service interruption in the event of a primary data centre failure. Regular disaster recovery drills are conducted to ensure rapid response capabilities and system integrity under various failure scenarios. For security-sensitive details about specific data centre setups and resilience measures, this information is available upon request to ensure confidentiality and integrity of the infrastructure. This approach guarantees that our services remain operational and secure, even under adverse conditions, providing peace of mind and continuity for all users.
- Outage reporting
- Our service implements a comprehensive outage reporting system to ensure transparency and timely communication during disruptions. We provide several mechanisms for reporting outages: Public Dashboard: Our users have access to a real-time, public dashboard that displays the current status of all services, including any ongoing outages or issues. This dashboard is updated continuously to reflect the most recent changes and conditions. Email Alerts: Users can subscribe to receive email alerts for any service disruptions. These alerts provide immediate notification when an outage is detected and include regular updates until resolution. After the issue is resolved, a final summary email is sent detailing the outage duration, impact, and any steps taken to prevent future occurrences. These reporting tools are designed to provide comprehensive and up-to-date information, allowing users to plan accordingly and minimise impact on their operations.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Other
- Other user authentication
- Integration with Buyer SSO (SAML/oAUTH) if needed.
- Access restrictions in management interfaces and support channels
- We enforce strict access controls on our management interfaces and support channels. This includes implementing two-factor authentication (2FA) for all login attempts. 2FA adds an extra layer of security by requiring a second verification factor, like a time-based code from a mobile app or SMS, in addition to a username and password. This significantly reduces the risk of unauthorised access even if login credentials are compromised, ensuring only authorised personnel can access sensitive information and make critical changes.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Other
- Description of management access authentication
- Integration with buyer SSO (SAML/oAUTH)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- As an SME in the UK, we prioritise security with clear policies and processes. We focus on: Policies: We have developed an Information Security Policy outlining data protection, access controls, and incident response. We reference NCSC guidance [NCSC secure development] for secure development practices. Processes: We implement risk assessments to identify vulnerabilities and mitigation strategies. We regularly update software and conduct penetration testing. Reporting: We assign a senior manager to oversee information security. All staff should report security incidents through a designated channel. Enforcement: We regularly review policy adherence through audits and training. Disciplinary procedures address security breaches. This structured approach, with clear ownership and reporting, demonstrates our commitment to information security. We are Cyber Essentials Plus certified.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Our approach integrates version control for robust tracking and security assessments across component life cycles. Each component is logged in a Configuration Management Database (CMDB) detailing versions, deployment, and interdependencies. Changes are managed through version control, supporting detailed documentation, branching for isolated testing, and precise audit trails. Each update undergoes a rigorous security impact assessment before approval and implementation. Post-deployment, we monitor for stability and security compliance, ensuring continuous integrity of the service. This systematic use of version control enhances control and transparency in our change management process.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Our vulnerability management approach ensures continuous protection and rapid response across all services. We assess threats using industry-standard tools and intelligence from leading cybersecurity agencies and vendors. Each potential threat is evaluated for its impact and urgency, guiding our prioritisation for patch deployment. Patches are systematically tested and deployed within hours for critical vulnerabilities, ensuring minimal disruption. Information on emerging threats is sourced from trusted security advisories and databases, allowing us to stay ahead of potential risks. This proactive strategy ensures robust defence and maintains the integrity and security of our services.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Our protective monitoring approach leverages advanced detection systems to identify potential compromises swiftly. Using a combination of real-time analytics and threat intelligence, we detect anomalies and signs of unauthorised access or activities. Upon identifying a potential compromise, our incident response team is alerted immediately. We initiate a standardised response protocol that includes containment, eradication, and recovery steps, typically responding to incidents within minutes. Our rapid response ensures minimal impact and quick restoration of services, while post-incident analysis helps strengthen future defences. This vigilant approach ensures continuous security monitoring and swift action on potential threats.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Our incident management approach utilises predefined protocols for efficiency. Users can report incidents via a support portal, email, or phone. Each report is promptly categorised and addressed based on severity. Updates are communicated through the portal and emails, ensuring transparency. Post-incident, a detailed report is issued, reviewing the cause and resolution steps. This structured process ensures rapid and effective management of incidents.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- We have a demo version allowing potential buyers to use Bullet Health with some standard health intervention modules set up. This should be used for testing/evaluation purposes only and not with real client data. We'll offer a walk around of this demo area initially.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 03aaef52-f62f-4a67-87bf-e7c7bfd7def7
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- Eb30c1fb-5517-4260-bd6a-13072b4ed90a
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
-