MyRenalCare
A delivery solution for Chronic Kidney Disease (renal) that puts the patient in the driving seat and; increases diagnosis, enables rapid up-titration, reduces waiting lists, generates more revenue and reduces costs (patient education, remote monitoring, patient initiated follow up (PIFU), virtual ward)
Features
- Remote monitoring and care
- Inbuilt laboratory results for all UK renal patients
- Patient initiated follow up
- Patient education resources
- Virtual consultations
- Device agnostic dialysis records
- Point of care testing - creatinine
- Data visualisation
- Renal care pathway redesign and implementation support
- Document storage including images
Benefits
- Improve health outcomes for renal patients
- Increase renal outpatient capacity
- Reduce waiting lists
- Reduce renal outpatient costs
- Slow progression to end stage renal failure
- Rapid up-titration and optimisation of medication
- Reduce hospital admissions
- Reduce cardiovascular events
- Better patient experience
- Net zero delivery
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 8 7 1 7 5 9 0 1 4 1 1 0 9 9
Contact
MyRenalCare
Sashi Sangala
Telephone: 07951262420
Email: sashi.sangala@myrenalcare.com
About your service
- Service categories
-
Applications
Content workflow and management
Enterprise portals and digital workspaces
- Multi-Audience Portals
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Patients Know Best
- Cloud deployment model
- Private cloud
- Service constraints
- No service constraints
- System requirements
- None
User support
- Email or online ticketing support
- Yes
- Support response times
- Patients 2 working days, NHS Trusts 1 working day
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), 7 days a week
- Web chat support
- No
- Onsite support
- Yes
- Support levels
-
1. Basic Support:
- This level includes basic assistance such as access to knowledge bases, FAQs, and community forums.
- Cost: Included with the product at no additional charge.
2. Enterprise Support:
- Tailored to large organizations with complex needs.
- Offers weekday support, guaranteed response times, and dedicated account management.
- May include access to a technical account manager or cloud support engineer.
- Cost: Usually negotiated based on the size and requirements of the enterprise, often priced as a percentage of the total contract value or a fixed annual fee. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
MyRenalCare can provide holistic implementation support to maximise value including:
People:
- redefining roles and responsibilities
- job planning
- training (remote or in-person with documentation)
- comms
Processes:
- care pathway redesign
Performance Management:
- KPI definition
- Tracking
Technology & data
- configuration
- integrations
- information governance - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
-
When the contract ends, users of MyRenalCare can easily extract their data through our user-friendly platform. Here's how:
1. Data Export Functionality: MyRenalCare provides a simple and intuitive data export feature within the platform. Users can access this feature to download their data in a format of their choice, such as CSV or JSON.
2. Privacy and Security: We prioritize the privacy and security of our users' data. The data export process is designed to ensure that your information remains protected at all times. We employ encryption and authentication measures to safeguard your data during extraction.
3. Guidance and Support: We understand that extracting data may raise questions or concerns. That's why we offer comprehensive guidance and support throughout the process. Our platform includes detailed instructions on how to use the data export functionality, and our support team is available to assist you if needed.
4.Compliance: MyRenalCare adheres to all relevant data protection regulations, such as GDPR. Our data export process is designed to comply with these regulations, giving you peace of mind knowing that your data is handled in accordance with the highest standards of privacy and security. - End-of-contract process
-
1. Data Management: At the end of the contract, users' data remains securely stored within the MyRenalCare system. Users may have the option to request a data export or transfer to ensure continuity of care if they transition to another healthcare provider or system.
2. Contract Renewal or Termination: The healthcare provider, such as the NHS in the UK, may have the option to renew the contract with MyRenalCare for another term if they find the platform beneficial and wish to continue offering it to their patients. Alternatively, if the contract is not renewed, access to MyRenalCare services may be terminated.
3. Transition Assistance: MyRenalCare may offer transition assistance to support a seamless transition if the contract is not renewed. This could include helping the healthcare provider migrate data to another platform or providing guidance on alternative solutions.
Extraction of data from MyRenalCare is included in the contract cost. Transitioning data from MyRenalCare to another system, especially within the healthcare sector, can involve additional costs. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Xx
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The solution is a webapp, with the same functionality available on mobile and desktop
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
-
Navigation Bar at the top of the page and contains links to different pages of the app.
Content Area where most content of the app is displayed, including text, forms, tables, graphs and videos.
Buttons that users click to perform actions eg submitting a form or triggering specific action.
Forms where users can input data.
Responsive design: the interface adapts to different screen sizes providing a consistent experience across devices (desktop/smartphone/tablet/laptop).
Visual design elements including colors, typography, icons, and other visual cues that help users navigate the app more easily.
Loading Indicators and Error messages - Accessibility standards
- None or don’t know
- Description of accessibility
-
MyRenalCare is committed to ensuring digital accessibility for all people regardless of ability and to make sure all can access our services in a non-discriminatory way, so we can positively impact all our users lives. We aim to make our web-based apps as accessible as possible, compliant with current requirements and supported across all types of devices on a continual basis.
Our ongoing development is guided by best-practice accessibility guidelines such as WCAG and ISO 30071-1.
We recommend users use My Computer, My Way to customise the accessibility features already on their devices to get the most accessible experience - Accessibility testing
-
MyRenalCare has been tested by ORCHA health in 2024, receiving a score of 90% including usability and accessibility.
Other testing we have done includes:
1. Screen Reader Testing
2. Keyboard Navigation Testing
3. Color and Contrast Testing
4. Form and Input Testing - API
- Yes
- What users can and can't do using the API
-
The API is not accessible to users.
External diagnostic medical device providers (eg Hospital Electronic Health Records) can establish API connections using a secure Key provided by us and only on agreement with us. The purpose for these connections at present is to share data automatically (eg lab results or patient reported data), and this can happen bi-directionally.
Users cannot make changes via the API.
As noted, only approved list of API key holders can access APIs. - API documentation
- Yes
- API documentation formats
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Potential for customisation at additional cost, dependent on specific requirements
Scaling
- Independence of resources
-
1. Scalable Infrastructure: We maintain a scalable infrastructure on Cloud that can dynamically adjust resources based on demand.
2. Load Balancing: We use load balancing techniques to distribute incoming traffic evenly across multiple servers or resources.
3. Resource Allocation: We allocate resources based on priority and usage patterns, ensuring that critical functions and high-demand features receive sufficient resources to operate smoothly.
4. Performance Monitoring: We continuously monitor the performance of the platform and individual services to identify any bottlenecks.
5. Capacity Planning: We conduct regular capacity planning exercises to forecast future demand and ensure that sufficient resources are available
Analytics
- Service usage metrics
- Yes
- Metrics types
- MyRenalCare provides service usage metrics to track how the platform is being utilized. These metrics can include data on patient and and clinician engagement, activity levels, usage patterns, and more, helping healthcare providers evaluate the effectiveness of the platform and optimize its usage for better patient outcomes.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
- Physical access control, complying with CSA CCM v4.0
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
-
Users can export their data from MyRenalCare by accessing the data export feature in the platform's settings. They choose the data they want to export, select the format (such as CSV or JSON), initiate the export process, and then download the exported data file once it's ready.
They can also do this by contacting support team - Data export formats
-
- CSV
- Other
- Other data export formats
-
- JSON
- Tabs
- Data import formats
-
- CSV
- Other
- Other data import formats
- JSON
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
We provide a 99.9% uptime guarantee. This means that for any given month, while unlikely, it is possible that MyRenlaCare may experience an average downtime of up to 2678 seconds excluding scheduled maintenance. If an outage exceeds a cumulative of 2678 seconds in a month, we will credit 2% of the your base monthly recurring fee for the affected account, per hour of downtime.
The total credit allowance per month is capped at 100% of that months monthly recurring fee for the affected account.
You must notify us via opening a support ticket indicating that you wish to pursue your rights as guaranteed by this SLA within 10 days of the incident to be eligible for credit.
This guarantee covers MyRenalCares internal infrastructure including application and database servers, routers, switches, the cables connecting them, and connectivity to our backbone providers. This guarantee does not cover email delivery.
MyRenalCare is not required to provide SLA-guaranteed services or credits to customers who are in default of their contractual obligations. - Approach to resilience
- MyRenalCare runs in the cloud with multiple layers of redundancy. There are multiple live back-ups and archives spread across 2 data centres.
- Outage reporting
- We have a live system uptime monitor dashboard that is available to clients
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Public key authentication (including by TLS client certificate)
- Username or password
- Other
- Other user authentication
- End user accounts are confirmed by an administrator user and authentication credentials (eg NHS number) are matched to official NHS records.
- Access restrictions in management interfaces and support channels
-
The management interface is protected by multi factor authentication and managed by the CSO.
Support channels include email, support ticketing, and telephone and is managed by the CSO. - Access restriction testing frequency
- At least once a year
- Management access authentication
- Multi-Factor Authentication (MFA)
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
At MyRenalCare, we adhere to a comprehensive set of information security policies and processes to safeguard our systems, data, and users. Here's an overview:
1.Information Security Policies:We have a suite of information security policies covering areas such as data protection, access control, password management, incident response, and compliance with regulatory requirements (e.g., GDPR, DPA).
2.Reporting Structure:Our reporting structure for information security involves a Chief Information Security Officer (CISO) responsible for overseeing the implementation and enforcement of security policies and processes. This individual reports to executive leadership and is often supported by a dedicated security team.
3.Policy Compliance:We ensure policies are followed through a combination of measures:
-Training and Awareness: to educate employees about security policies, best practices, and their responsibilities.
-Access Controls: and permissions to restrict access to sensitive data and systems only to authorized personnel.
-Monitoring and Auditing: systems, networks, and user activities to detect and respond to security incidents, policy violations, or anomalies.
- Regular Assessments: audits, and reviews to assess compliance with policies, identify gaps or weaknesses, and prioritize remediation efforts.
-Enforcement and Accountability:through disciplinary measures for violations, ensuring accountability at all levels of the organization. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Configuration Management:
We maintain a detailed inventory of all service components, utilizing version control for configuration files and documentation. Automated provisioning tools ensure consistency, and comprehensive documentation aids troubleshooting and team collaboration.
Change Management:
Changes undergo thorough risk assessment, including security impact analysis. Testing in staging environments ensures reliability, and post-deployment monitoring detects anomalies. Our formal change request process involves stakeholder review, auditing, and incident response protocols to maintain service stability and security - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
1.Threat Assessment: We monitor security advisories, vulnerability databases, and threat intelligence feeds to identify potential threats to our services.
2. Vulnerability Scanning: Regular scans identify vulnerabilities in our systems, applications, and dependencies.
3. Risk Prioritization: We assess the severity and impact of vulnerabilities to prioritize patching.
4. Patch Deployment: Critical vulnerabilities are patched promptly after testing in non-production environments.
5. Change Control: Patch deployment follows our formal change management process to minimize disruptions.
6. Monitoring and Response: We continuously monitor for suspicious activity and respond swiftly to security incidents. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
1. Continuous Monitoring: of our systems and networks to detect and respond to security threats in real-time.
2. Log Management: from various sources, including network devices, servers, applications
3. Intrusion Detection and Prevention: (IDPS) to monitor network traffic for signs of malicious activity
4. Endpoint Security: to monitor and protect individual devices from malware, unauthorized access, and other security risks.
5. Security Information and Event Management (SIEM): to aggregate, correlate, and analyze security event data from multiple sources
6. Incident Response: procedures in place to guide our response to security incidents
7. Regular Security Audits and Assessments - Incident management type
- Supplier-defined controls
- Incident management approach
-
1. Pre-defined Processes: We follow established procedures for incident identification, classification, response, and resolution, based on industry best practices ITIL .
2. Incident Reporting: Users can report incidents via email or phone
3. Incident Response: Our team assesses and responds to incidents based on severity, coordinating with internal teams or external experts as needed.
4. Communication: We maintain transparent communication with stakeholders throughout the incident, providing regular updates and incident reports.
5. Post-Incident Analysis: After resolution, we conduct a post-incident analysis to identify root causes, lessons learned, and improvement opportunities. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 6%
- Between £500,001 and £1,000,000
- 8%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 12%
- Over £5,000,001
- 15%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Harrison & Miller Assurance Services
- ISO/IEC 27001 accreditation date
- Saturday 2 March 2024
- What the ISO/IEC 27001 doesn’t cover
- Software development processes. Software is evaluated and certified to ISO 27001 before deployment.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Dd95936b-97d5-4232-8cf0-ac6724c5efb2
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
-