Skip to main content

Help us improve the Digital Marketplace - send your feedback

Hero Health

Hero Health

A comprehensive booking, triage, and patient engagement solution that integrates with EMIS Web and SystmOne and as a standalone, non-integrated solution. NHS primary care providers use Hero for online consultation & triage, and to communicate with their patients by SMS or email.

Features

  • Two-way messaging
  • Message templates
  • Attachments
  • Individual & Batch messaging
  • Custom questionnaires
  • Online booking
  • Cross-organisational booking
  • Care navigation
  • Workflow management
  • Configurable online consultations

Benefits

  • Intuitive triage, appointment booking and messaging
  • Full suite of patient engagement tools
  • Message entire cohorts of patients or individuals
  • Configure digital front door
  • Embed pathways in practice website
  • Integrated with EMIS and SystmOne
  • Best-in-class write to record capability

Pricing

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at gus@herohealth.net. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

4 6 0 0 3 0 5 3 3 1 2 9 1 4 4

Contact

Hero Health Gus Kennedy
Telephone: 07515892785
Email: gus@herohealth.net

About your service

Service categories

Applications

Production and operations

Service industry and public sector operations

  • Healthcare
Multi cloud support
No

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
EMIS
TPP SystmOne
Cloud deployment model
Private cloud
Service constraints
No.
System requirements
  • Windows (Windows 10 or above recommended)
  • High Speed Broadband
  • 8GB Ram & 20GB Hard Drive Storage
  • Firewall may need to be configured for EMIS and SystmOne
  • Correct User permissions for local folders (EMIS)
  • Smartcard for services such as EPS
  • Ethernet connection (thin clients not recommended)
  • HSCN Connection (or a secure VPN)
  • .NET 3.5 features installed
  • EMIS or SystmOne installed

User support

Email or online ticketing support
Yes
Support response times
Within 4 hours;
No support at weekends
User can manage status and priority of support tickets
No
Phone support
No
Web chat support
Yes
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
WCAG 2.2 A
Web chat accessibility testing
N/A
Onsite support
Yes, at extra cost
Support levels
We provide 1st and 2nd line support.
All support is included within the price for our product offering.
We have a customer success manager that supports our high-value contracts as well as support and product contacts that triage issues being raised by customers.
Support available to third parties
Yes
AI chatbot
No

Onboarding and offboarding

Getting started
Full support during setup and implementation.
Onsite training available by arrangement.
Extensive documentation - articles, video tutorials, support chat.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
Data extraction will be managed by the Hero team on request as appropriate.
End-of-contract process
We mark a Buyer for deletion and they're added to our offboarding list - an internal process then takes place throughout which we communicate with the user, confirm off boarded status and implement data extraction (if required and appropriate).
Additional costs may be incurred if remote or onsite setup/support is specifically requested. We include a 1 day training that is billed but practices can pay for more.
Documentation accessibility standard
WCAG 2.2 A

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
Yes
Compatible operating systems
Windows
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
N/A
Service interface
Yes
User support accessibility
WCAG 2.2 A
Description of service interface
We have an API which allows access to Hero Health fucntionality through the API rather than the UI
Accessibility standards
WCAG 2.2 A
Accessibility testing
N/A
API
Yes
What users can and can't do using the API
Embed Hero's messaging and scheduling functionality within the user product.
Elements: We offer multiple Elements, which are fully pre-built and packaged end-to-end user flows, enabling you to fully embed Hero's existing functionality into your product in no time.
If users prefer to design their own UIs, they can build directly onto Hero APIs.
API documentation
Yes
API documentation formats
Open API (also known as Swagger)
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Hero Health has been designed to allow customer customisation for a wide variety of material and features across the platform:
Configurable triage
Pathway creation
Direct and divert patients to specific local services
Interrupt digital journeys to direct to local services
Configure responses by SMS, Email or NHS App
Customisable questionnaires
Set up integration with locally implemented social prescribing, NHS App Prescriptions and other providers

Scaling

Independence of resources
We employ a dynamic scaling approach with scalable architecture and resource monitoring.

Analytics

Service usage metrics
Yes
Metrics types
Flexible usage metrics available on request across all features.
Reporting types
  • Real-time dashboards
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with another standard
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
In-house destruction process
Data sanitisation type
Data Erasure

Data importing and exporting

Data export approach
There are limited reports downloadable from the platform. All other data by request.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
We guarantee 98% availability of service.
If the Service Availability during the contract drops below 98% during three consecutive calendar months, excluding unavailability arising from: (i) the use of third party hardware or software, (ii) a Force Majeure Event (iii) the Licensee’s unauthorised actions or inaction when required, or (iv) due to scheduled downtime, the Licensee will be entitled to a service credit of an amount equal to 5% of the relevant monthly Subscription Fees.
Approach to resilience
Available on request
Outage reporting
We have a public status page: https://herohealth.instatus.com/
We email users with both regular updates and incident specific information.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
We employ an RBAC approach.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
We secure the Hero platform through a defence-in-depth strategy combining rigorous governance, resilient architecture, and continuous monitoring. We apply strict access controls, MFA, zero-trust principles, and encrypted data flows in transit and at rest. Our development lifecycle embeds secure coding, automated testing, and regular penetration assessments. We maintain NHS DSP Toolkit alignment and follow UK GDPR. Real-time detection, vulnerability scanning, and rapid incident response ensure emerging risks are managed proactively. We have a strong security culture and have embedded consistent, safe handling of sensitive health information across all teams and processes at scale effectively.
Information security policies and processes
We follow comprehensive information security policies and processes to protect the platform, aligned with NHS DSPT, UK GDPR, and ISO27001-standard controls. Our governance structure includes an SRO, a Data Protection Officer, and compliance-focussed staff who oversee day-to-day compliance. All policies—covering access control, encryption, incident management, secure development, and business continuity—are formally approved, version-controlled, and reviewed at least annually.
We ensure policies are followed through mandatory staff training, role-based access controls, and continuous monitoring of systems and user activity. Regular internal audits and risk assessments verify adherence and identify improvement actions. Our secure development lifecycle includes code reviews, change control boards, and automated security testing.
Our incident management process includes clear reporting lines: staff escalate incidents to the Information Security Manager, who leads assessment and response, reporting significant events to senior leadership and, where required, the NHS and the ICO. We maintain detailed audit trails, perform vulnerability scanning, and commission independent penetration testing.
Through structured oversight, clear accountability, and ongoing verification, we ensure our information security practices remain effective, up to date, and fully compliant with healthcare regulatory requirements.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Our configuration management tracks application components through version-controlled secrets files and folders, with regular reviews to ensure accuracy and security compliance throughout each component's lifecycle. All changes flow through CI/CD pipelines, which automatically perform testing, code standards validation, and static vulnerability analysis to identify potential security impacts before deployment. Changes are prioritised based on urgency and risk assessment. We maintain documented baseline configurations and leverage version control to track all modifications. Urgent changes can be expedited when necessary while still passing through automated security checks.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Our vulnerability management process includes continuous monitoring through automated scanning tools and threat intelligence feeds. We conduct regular vulnerability assessments of all systems and applications, prioritising risks based on severity, exploitability, and business impact using CVSS scoring. Critical patches are deployed within 48 hours; high-severity within 7 days; medium/low following monthly maintenance windows. Our process includes annual penetration testing, regular security audits, and immediate threat assessment when zero-day vulnerabilities emerge. All activities are documented with clear escalation procedures for critical vulnerabilities.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Our protective monitoring includes centralised logging and regular review of system alerts, access logs, and security events to identify suspicious activities, failed login attempts, unusual traffic patterns, and potential compromises. We use behavioural analytics, threat intelligence feeds and automated alerting to identify anomalies, unauthorised access attempts and potential compromises. Upon detection, incidents are classified by severity and escalated according to our incident response plan. Response times: Critical incidents within 60 minutes; high-severity within 2 hours; medium within 4 hours. We conduct root cause analysis, implement remediation, and perform post-incident reviews to strengthen defences and prevent recurrence.
Incident management type
Supplier-defined controls
Incident management approach
We detect and report incidents promptly through staff, user and system reports. We assess each incident's severity and impact, prioritising urgent cases. Our team investigates to understand the root cause, then implements corrective actions to resolve the issue and prevent recurrence. We restore normal service and monitor the effectiveness of our solutions. Once resolved, we document the incident, its outcomes, and any lessons learnt to drive continuous improvement. We ensure incident outcomes and relevant data are shared with stakeholders as appropriate.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
Yes
Connected networks
Health and Social Care Network (HSCN)

Pricing

Discount for educational organisations
Yes
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
2%
Between £500,001 and £1,000,000
5%
Between £1,000,001 and £2,500,000
7%
Between £2,500,001 and £5,000,000
10%
Over £5,000,001
15%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
60288637-7484-4e23-8381-97cc59c4557d
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
45572386-616e-43ce-be94-d33cc7b0d5f8
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at gus@herohealth.net. Tell them what format you need. It will help if you say what assistive technology you use.