Healthcare App
Fully customisable healthcare app delivers better patient engagement and staff experience. Available via app stores with a powerful admin CMS, it enables secure real-time communication, resources, reminders and self-care guidance. Reduce admin, improve collaboration, boost morale and empower patients and staff with intuitive tools that strengthen care at every stage.
Features
- Fully mobile app available on both major app stores
- Intuitive CMS with unlimited training and ongoing support
- Unlimited real-time alerts from anywhere within the app
- Optional registration enables private, personalised user communication
- Flexible calendar with manual entry or third-party integrations
- News updates added manually or synced via feeds
- Build secure forms with compiled or emailed results
- Upload PDFs, images and links for rich content
- Tailored content delivery based on user registration needs
- Dedicated support team offering refresher training and content editing
Benefits
- Streamlines communication for staff, patients, and carers efficiently
- Reduces administrative workload for reception and clinical teams
- Improves patient access to accurate information and resources
- Enables educational teams to guide students effectively
- Send alerts instantly to all app users simultaneously
- Target alerts privately to subgroups or individual users
- Unlimited admins can manage content seamlessly
- Track and audit content creation easily and securely
- Fully compatible with device accessibility tools
- Enhances collaboration and engagement across all healthcare teams
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 5 2 9 7 6 6 3 8 0 2 4 8 8 4
Contact
SCHAPPIT LTD
Carl Nancollas
Telephone: 07740673857
Email: carl.nancollas@siliconpractice.co.uk
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Education
- Adult Social Care
- Children's Social Care
- Other
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- Our platform is hosted on AWS Cloud, leveraging its robust, scalable, and secure infrastructure to ensure optimal performance and reliability. We follow a zero planned downtime process, meaning all updates and enhancements are implemented with minimal service interruption. We ensure changes are compatible with existing functionality while continuously improving and introducing new features, enabling our users to enjoy uninterrupted access at all times.
- System requirements
-
- Browser required, Google Chrome, Microsoft Edge, Mozilla Firefox, Opera, Safari
- Internet Connection - Minimum connection speed 2Mbps
User support
- Email or online ticketing support
- Yes
- Support response times
- We provide customer support Monday to Friday, 08:00–17:00, excluding Bank Holidays. All support requests receive an initial response within one working day. Simple app edits are typically completed within one working day. Where a request requires additional time, we will confirm timescales within one working day. Each customer is assigned a dedicated Silicon Practice Account Manager, available via email and telephone for non-change-related support, within agreed escalation routes and service expectations.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Silicon Practice provides user support built around accessibility, responsiveness, and a user-centred approach, ensuring every user can access guidance when needed. Support also serves as a key channel for feedback, helping us continually improve our platform.
We provide support Monday to Friday, 08:00–17:00 (excluding Bank Holidays), with first responses to email requests typically within one working day. Simple updates or queries are resolved quickly, while more complex requests receive an estimated resolution timeframe within one working day.
Each customer is assigned a dedicated Silicon Practice Account Manager, contactable via email or telephone. Our team follows defined incident management procedures, triaging and assigning priority levels based on impact and type of issue. Severity levels are aligned with NHS England Incident Management and Severity guidelines.
All support, including guidance, troubleshooting, and escalation, is included at no additional charge. For critical outages, the team provides immediate prioritisation and escalation to minimise disruption, ensuring users have reliable access and confidence in the platform at all times. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Silicon Practice delivers a structured, flexible onboarding process tailored to the needs of each organisation.
A typical implementation timeframe takes between 4–6 weeks, depending on the level of customisation required.
Our team uses Zoho Projects to track each stage of deployment, ensuring transparency and clear milestones throughout the process.
We begin by arranging a consultation to establish what customisation is required. We will then build you a version to review and approve. Next step is to arrange online video training sessions for all staff.
For customers requiring rapid deployment and a clear idea of what they would like, an app can be created and rolled out within a few days.
Additional training can be arranged at any point during the contract to support new staff or evolving organisational needs. This approach ensures a seamless, efficient rollout, empowering staff to launch their app effectively from day one. - Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
- YouTube Training/Support Videos
- End-of-contract data extraction
- Silicon Practice will, at the choice of the Data Controller, delete or return all the Personal Data to the Data Controller after the end of the provision of Services relating to Processing, and delete existing copies unless retention of the Personal Data is required by UK law.
- End-of-contract process
-
Contracts with Silicon Practice run for the period specified in each Order Form or Call-Off Contract, including any optional extension periods. Termination rights and notice requirements are also set out within the relevant Order Form or Call-Off Contract. Where contract extensions are permitted, we request customers provide at least 4 weeks’ notice before the end of the current term.
If a contract is not extended, Silicon Practice follows a structured exit and offboarding plan, facilitated by a dedicated Customer Success Manager in collaboration with nominated customer stakeholders. The plan outlines key actions for all parties, a communication strategy, notice period activities, service switch-off, post-exit procedures, and the secure transfer of information to any new provider.
All data is managed safely throughout the offboarding process to ensure compliance and continuity. At the conclusion of the contract, user accounts are disabled, and no further messages can be sent through the platform, ensuring secure closure of the service while maintaining the integrity and privacy of data. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- User guides are provided in MS Word, PowerPoint or PDF. An online resources centre, accessible via a web browser, contains links to download materials in the above formats or contains links to videos.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- MacOS
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The app is a fully mobile app and is searchable on both Google Play and App Store. In addition you are able to download it from the App store on a Mac computer. The CMS which controls the content for the app is web based and compatible with all computer and browser types.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Our healthcare solution consists of a fully mobile app and an intuitive Content Management System (CMS), designed to work seamlessly together. The app provides secure, real-time messaging, alerts, calendars, educational resources, self-care guidance, and tailored content for patients and staff, all accessible on iOS and Android devices. The CMS empowers administrators to manage content, configure categories, upload PDFs, images, and links, build secure forms, and track or audit all activity. Multiple admins can update the system simultaneously, ensuring timely, accurate information. Together, the app and CMS create a unified, easy-to-use platform for communication, engagement, and operational efficiency.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- The app has been widely tested on different device's native accessibility tools using an emulator.
- API
- Yes
- What users can and can't do using the API
-
We can provide a basic API to export any content to a website. If content is designated for a group or an individual only, then this will be automatically excluded from any outward feed.
Equally its very easy to import calendar or news content using .css or .rss URLs into the app, preventing the need for any duplication of work. - API documentation
- No
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
-
Our healthcare app offers unparalleled customisation, allowing your organisation to create a solution that truly reflects your brand and meets your unique needs. Using your logo, colours, and branding, we can design an app that aligns perfectly with your style guide, giving it a fully bespoke look and feel. Beyond appearance, the app can be configured with any category types, names, and icons to suit the way your teams work and how patients access information.
The initial onboarding consultation is a vital part of this process, allowing us to understand your requirements and advise on the best way to structure categories, content, and navigation. This ensures the app is intuitive for staff, patients, and carers while maintaining consistent branding and communication standards across all touchpoints.
Customisation extends to functionality as well. Alerts can be sent to all users or targeted subgroups, content can be managed by multiple admins, and forms, news, and resources can be tailored to specific needs. Whether improving patient engagement, reducing admin, supporting training, or enhancing staff collaboration, our app is flexible, scalable, and designed to empower healthcare teams while providing a seamless, branded experience for every user.
Scaling
- Independence of resources
- We have monitoring services in place to assess the demand on our services and can scale-up capacity quickly in periods of intense usage.
Analytics
- Service usage metrics
- Yes
- Metrics types
- We provide real-time dashboards that allow healthcare teams to monitor app usage and downloads, along with detailed breakdowns of article views and growth trends. The dashboards present key information clearly, including active user metrics and category/article level view counts displayed both numerically and visually. All of this data can be exported as a CSV at a click of a button.
- Reporting types
- Real-time dashboards
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- If an organisation requests a Documented Data Extract, we will provide a .CSV file with every piece of Data submitted to that orgainsation.
- Data export formats
- Other
- Other data export formats
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- PNG
- IMG
- JPEG
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- We use Amazon Web Services (AWS) infrastructure within the UK regions and availability zones, providing a resilient, cloud-based environment designed for high availability and fault tolerance. Data is replicated in real time across multiple AWS Availability Zones, ensuring continuity and rapid failover in the event of an outage. All data is encrypted to NHS encryption standards (AES-256). The AWS environment and associated services are ISO 27001 certified. The service is available 24/7/365 with a minimum 99.9% uptime commitment.
- Approach to resilience
-
Our service is built on Amazon Web Services (AWS) infrastructure within UK regions and Availability Zones, delivering a resilient, cloud-based environment engineered for high availability and fault tolerance. Patient-identifiable data is encrypted to NHS standards (AES-256) and replicated in real time across multiple AWS Availability Zones, ensuring continuity and rapid failover in the unlikely event of an outage. The entire environment is ISO 27001 certified, giving our clients confidence in the security and compliance of our platform.
We provide 24/7/365 availability with a minimum 99.9% uptime commitment, supported by continuous monitoring systems that alert our team to any system faults or server failures, allowing prompt resolution.
Our software is continuously updated to meet evolving legislation and regulatory requirements. Updates are first identified by our Principal Developer in collaboration with the Compliance Manager, then gaps are assessed and an action plan is produced. These are incorporated into the development plan and linked directly to the software release process. This is overseen by our Clinical Safety Officer.
This combination of resilient architecture, robust monitoring, rigorous compliance, and proactive software management ensures our service remains secure, reliable, and consistently available to support healthcare providers. - Outage reporting
-
When any issue arises that may impact system availability, our Helpdesk and Account Management Team act swiftly to keep all users informed. We proactively issue updates and guidance through multiple channels. This ensures that users are immediately aware of the situation, understand any potential impact, and receive timely instructions on next steps or workarounds.
In the unlikely event of a system outage, our Helpdesk is fully prepared to provide direct technical assistance. Users can contact the team via phone, email, or online support channels to receive guidance, troubleshooting support, and updates on restoration timelines. All communications are coordinated to ensure clarity, transparency, and consistency, minimising uncertainty and maintaining user confidence.
Our approach combines proactive notification, multi-channel communication, and responsive technical support to ensure that any disruption is managed efficiently and with minimal impact. By prioritising timely information and accessible assistance, we uphold our commitment to service continuity and user satisfaction.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to the management interface is controlled through role-based permissions. Staff can be assigned as Publishers to add content to the app, or Administrators to manage user accounts and registration data within the CMS. Support is available through a dedicated email address.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Silicon Practice operates within a robust information security and governance framework aligned to recognised national standards and regulatory guidance. Our policies and controls are informed by ISO 27001, NHS England requirements and Cyber Essentials, including CE+. This ensures that information security, privacy, and governance are embedded across all areas of the organisation.
Information security oversight is led through a dedicated governance function that adopts a structured, risk-based approach to protecting our systems, services, and data. A documented security strategy is maintained and reviewed on an ongoing basis to ensure it remains appropriate as regulatory guidance, organisational needs, and the threat landscape evolve.
Key policies include vulnerability management, supported by regular penetration testing; secure development practices that enforce privacy and security by design; and Data Protection Impact Assessments for all new products, system changes, and data-sharing activities. These policies and assessments are reviewed at least annually.
The Silicon Practice platform is hosted within Amazon Web Services (AWS) infrastructure. All data is encrypted both in transit and at rest in accordance with NHS encryption standards.
All employees undertake mandatory information security and data protection training on joining the organisation, with regular refresher training delivered thereafter, ensuring continued awareness, compliance, and accountability. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- All development work goes through a pull request testing process: developers submit completed feature code for review, which is added to the relevant release branch upon passing peer code review. All releases and final builds are tested to ensure they maintain compliant and do not introduce further or critical bugs. We carry out regular penetration testing of all products to assess for any potential security impacts.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Threats to Silicon Practice services are assessed based on the risk they pose to our business, customers, or patient data, including UK GDPR, information security, and clinical safety considerations. Any threats to data confidentiality, integrity, or availability are treated as high priority. Patches are deployed via scheduled releases to our servers, typically in the evening to minimise downtime. Updates are applied across all hosted FootFall websites and dashboards simultaneously. Release schedules are planned in advance, though urgent patches can be deployed the same day. Threat intelligence is sourced from cybersecurity advisory services and official notices.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
We run multiple forms of malware scanning in our environments. New files being uploaded by users are scanned and are either made available if safe or quarantined if not. We also have a WAF. We also monitor and log all access to production databases and websites.
Once reported, we aim to remediate any security incidents as soon as possible. - Incident management type
- Supplier-defined controls
- Incident management approach
-
Service requests, feedback and complaints are raised via our support email or phone number, both of which are provided to practices upon onboarding. Any incidents may be reported through these channels and then are logged through our helpdesk.
We then ensure our Service Level Agreements (SLAs) are upheld and resolve any incident as soon as we can with full resource behind it. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- We offer a 30 day free no obligation trial for a container based app.
- Link to free trial
- https://outlook.office365.com/book/SolutionDemonstration@siliconpractice.co.uk/?ismsaljsauthenabled=true
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 3%
- Between £250,000 and £500,000
- 8%
- Between £500,001 and £1,000,000
- 15%
- Between £1,000,001 and £2,500,000
- 20%
- Between £2,500,001 and £5,000,000
- 22%
- Over £5,000,001
- 25%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Alcumus
- ISO/IEC 27001 accreditation date
- Friday 21 June 2024
- What the ISO/IEC 27001 doesn’t cover
- All parts of the service are covered
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 654c1d7c-5ff3-4431-8f07-d909c87c9875
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- F46f4f82-4586-411d-9b18-263c82719091
- Other security certifications
- Yes
- Any other security certifications
-
- NHS DSPT assurance - Standards Exceeded (ODS code 8KC12)
- Fully compliant with DCB0129
- ICO Registration (ZA074234)
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Plans to engage the contract workforce in deciding the most important workplace issues to address
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
-