Hero Health
A comprehensive booking, triage, and patient engagement solution that integrates with EMIS Web and SystmOne and as a standalone, non-integrated solution. NHS primary care providers use Hero for online consultation & triage, and to communicate with their patients by SMS or email.
Features
- Two-way messaging
- Message templates
- Attachments
- Individual & Batch messaging
- Custom questionnaires
- Online booking
- Cross-organisational booking
- Care navigation
- Workflow management
- Configurable online consultations
Benefits
- Intuitive triage, appointment booking and messaging
- Full suite of patient engagement tools
- Message entire cohorts of patients or individuals
- Configure digital front door
- Embed pathways in practice website
- Integrated with EMIS and SystmOne
- Best-in-class write to record capability
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 6 0 0 3 0 5 3 3 1 2 9 1 4 4
Contact
Hero Health
Gus Kennedy
Telephone: 07515892785
Email: gus@herohealth.net
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
-
EMIS
TPP SystmOne - Cloud deployment model
- Private cloud
- Service constraints
- No.
- System requirements
-
- Windows (Windows 10 or above recommended)
- High Speed Broadband
- 8GB Ram & 20GB Hard Drive Storage
- Firewall may need to be configured for EMIS and SystmOne
- Correct User permissions for local folders (EMIS)
- Smartcard for services such as EPS
- Ethernet connection (thin clients not recommended)
- HSCN Connection (or a secure VPN)
- .NET 3.5 features installed
- EMIS or SystmOne installed
User support
- Email or online ticketing support
- Yes
- Support response times
-
Within 4 hours;
No support at weekends - User can manage status and priority of support tickets
- No
- Phone support
- No
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 A
- Web chat accessibility testing
- N/A
- Onsite support
- Yes, at extra cost
- Support levels
-
We provide 1st and 2nd line support.
All support is included within the price for our product offering.
We have a customer success manager that supports our high-value contracts as well as support and product contacts that triage issues being raised by customers. - Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
-
Full support during setup and implementation.
Onsite training available by arrangement.
Extensive documentation - articles, video tutorials, support chat. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- Data extraction will be managed by the Hero team on request as appropriate.
- End-of-contract process
-
We mark a Buyer for deletion and they're added to our offboarding list - an internal process then takes place throughout which we communicate with the user, confirm off boarded status and implement data extraction (if required and appropriate).
Additional costs may be incurred if remote or onsite setup/support is specifically requested. We include a 1 day training that is billed but practices can pay for more. - Documentation accessibility standard
- WCAG 2.2 A
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- Yes
- Compatible operating systems
- Windows
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- N/A
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 A
- Description of service interface
- We have an API which allows access to Hero Health fucntionality through the API rather than the UI
- Accessibility standards
- WCAG 2.2 A
- Accessibility testing
- N/A
- API
- Yes
- What users can and can't do using the API
-
Embed Hero's messaging and scheduling functionality within the user product.
Elements: We offer multiple Elements, which are fully pre-built and packaged end-to-end user flows, enabling you to fully embed Hero's existing functionality into your product in no time.
If users prefer to design their own UIs, they can build directly onto Hero APIs. - API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Hero Health has been designed to allow customer customisation for a wide variety of material and features across the platform:
Configurable triage
Pathway creation
Direct and divert patients to specific local services
Interrupt digital journeys to direct to local services
Configure responses by SMS, Email or NHS App
Customisable questionnaires
Set up integration with locally implemented social prescribing, NHS App Prescriptions and other providers
Scaling
- Independence of resources
- We employ a dynamic scaling approach with scalable architecture and resource monitoring.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Flexible usage metrics available on request across all features.
- Reporting types
-
- Real-time dashboards
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
- Data Erasure
Data importing and exporting
- Data export approach
- There are limited reports downloadable from the platform. All other data by request.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
We guarantee 98% availability of service.
If the Service Availability during the contract drops below 98% during three consecutive calendar months, excluding unavailability arising from: (i) the use of third party hardware or software, (ii) a Force Majeure Event (iii) the Licensee’s unauthorised actions or inaction when required, or (iv) due to scheduled downtime, the Licensee will be entitled to a service credit of an amount equal to 5% of the relevant monthly Subscription Fees. - Approach to resilience
- Available on request
- Outage reporting
-
We have a public status page: https://herohealth.instatus.com/
We email users with both regular updates and incident specific information.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- We employ an RBAC approach.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- We secure the Hero platform through a defence-in-depth strategy combining rigorous governance, resilient architecture, and continuous monitoring. We apply strict access controls, MFA, zero-trust principles, and encrypted data flows in transit and at rest. Our development lifecycle embeds secure coding, automated testing, and regular penetration assessments. We maintain NHS DSP Toolkit alignment and follow UK GDPR. Real-time detection, vulnerability scanning, and rapid incident response ensure emerging risks are managed proactively. We have a strong security culture and have embedded consistent, safe handling of sensitive health information across all teams and processes at scale effectively.
- Information security policies and processes
-
We follow comprehensive information security policies and processes to protect the platform, aligned with NHS DSPT, UK GDPR, and ISO27001-standard controls. Our governance structure includes an SRO, a Data Protection Officer, and compliance-focussed staff who oversee day-to-day compliance. All policies—covering access control, encryption, incident management, secure development, and business continuity—are formally approved, version-controlled, and reviewed at least annually.
We ensure policies are followed through mandatory staff training, role-based access controls, and continuous monitoring of systems and user activity. Regular internal audits and risk assessments verify adherence and identify improvement actions. Our secure development lifecycle includes code reviews, change control boards, and automated security testing.
Our incident management process includes clear reporting lines: staff escalate incidents to the Information Security Manager, who leads assessment and response, reporting significant events to senior leadership and, where required, the NHS and the ICO. We maintain detailed audit trails, perform vulnerability scanning, and commission independent penetration testing.
Through structured oversight, clear accountability, and ongoing verification, we ensure our information security practices remain effective, up to date, and fully compliant with healthcare regulatory requirements. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Our configuration management tracks application components through version-controlled secrets files and folders, with regular reviews to ensure accuracy and security compliance throughout each component's lifecycle. All changes flow through CI/CD pipelines, which automatically perform testing, code standards validation, and static vulnerability analysis to identify potential security impacts before deployment. Changes are prioritised based on urgency and risk assessment. We maintain documented baseline configurations and leverage version control to track all modifications. Urgent changes can be expedited when necessary while still passing through automated security checks.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Our vulnerability management process includes continuous monitoring through automated scanning tools and threat intelligence feeds. We conduct regular vulnerability assessments of all systems and applications, prioritising risks based on severity, exploitability, and business impact using CVSS scoring. Critical patches are deployed within 48 hours; high-severity within 7 days; medium/low following monthly maintenance windows. Our process includes annual penetration testing, regular security audits, and immediate threat assessment when zero-day vulnerabilities emerge. All activities are documented with clear escalation procedures for critical vulnerabilities.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Our protective monitoring includes centralised logging and regular review of system alerts, access logs, and security events to identify suspicious activities, failed login attempts, unusual traffic patterns, and potential compromises. We use behavioural analytics, threat intelligence feeds and automated alerting to identify anomalies, unauthorised access attempts and potential compromises. Upon detection, incidents are classified by severity and escalated according to our incident response plan. Response times: Critical incidents within 60 minutes; high-severity within 2 hours; medium within 4 hours. We conduct root cause analysis, implement remediation, and perform post-incident reviews to strengthen defences and prevent recurrence.
- Incident management type
- Supplier-defined controls
- Incident management approach
- We detect and report incidents promptly through staff, user and system reports. We assess each incident's severity and impact, prioritising urgent cases. Our team investigates to understand the root cause, then implements corrective actions to resolve the issue and prevent recurrence. We restore normal service and monitor the effectiveness of our solutions. Once resolved, we document the incident, its outcomes, and any lessons learnt to drive continuous improvement. We ensure incident outcomes and relevant data are shared with stakeholders as appropriate.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
- Health and Social Care Network (HSCN)
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 2%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 7%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 15%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 60288637-7484-4e23-8381-97cc59c4557d
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 45572386-616e-43ce-be94-d33cc7b0d5f8
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
-