Digital Solution
Digital solution to meet additional health and care requirements. Bridging functionality and technology gaps across the organisations clinical, operational and business systems.
Features
- Easy-to-use workflows for clinician and operational staff
- Enhances the usage of exisiting digital solutions
- Optimisation for current functionalities within off -the-shelf products
- Outputs aligned with client quadruple aim objectives as appropriate
- Configurations to meet local needs
- Includes implementation services as required
- Operational analysis and reporting outputs available
- Supported on client devices
- Service management and warranty included
- Access to advisors for national and client digital strategies
Benefits
- Increased user experience and satisfaction through enhanced functionality
- Improve expected patient, client, organisational outcomes through streamlined workflows
- Alignment to organisational quadruple aim targets as appropriate
- Closure of functionality gaps within larger set of solutions
- C-Suite panel for complex programmes guidance/assurance
- Digital solutions hub includes free NHS & Care solutions
- Flexible skilled scalable teams mobilised within days
- Additional resource whenever needed (sourced by our resourcing division)
- Agile delivery by seasoned consultants at reasonable rates
- Advisors for national and client digital strategies
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 0 1 4 3 6 8 3 0 8 5 8 8 6 3
Contact
ST VINCENT’S CONSULTING LTD
Kyle Dollan
Telephone: 07989415358
Email: frameworks@stvconsulting.uk
About your service
- Service categories
-
Applications
Production and operations
- Other operations
Service industry and public sector operations
- Healthcare
- Education
- Public Order and Safety
- Police
- Defence
- Social Security Administration
- Adult Social Care
- Children's Social Care
- Other
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Integration with other clinic and operational systems to add functionality, features and interoperability
- Cloud deployment model
-
- Public cloud
- Private cloud
- Service constraints
- Where integration with other customer systems is required the constraints on those systems
- System requirements
-
- System requirements vary by solution and functionality
- Client must be able to present and receive valid data
- Anti-virus technology if implemented on virtual machines
User support
- Email or online ticketing support
- Yes
- Support response times
-
On the day for urgent issues, within three working days for non-urgent issues
We provide central support and escalation for all our teams and projects, in addition to a nominated lead for first contact. Additional support costs are limited to additional resources deployed to address the issue and once agreed with the client. Prices are based on our SFIA rate card - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
We provide client support to meet the customers requirements and service levels they wish to consume. We provide a technical account manager to ensure clear communications and a first course of escalation if needed. Our standard service support is included in the annual fee. Additional costs will be determined by what level and availability they require.
We provide central support and escalation for all our teams and projects, in addition to a nominated lead for first contact. Additional support costs are limited to additional resources deployed to address the issue and once agreed with the client. Prices are based on our rate card - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- We follow the St Vincent Implementation methodology for implementations. This includes a Training Needs Analysis and development of use tailored roles based training for users. This can include both virtual and online training. We provide access to digital user documentation and FAQ
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
At the end of the customer contract where we hold client data we provide a digital copy of all the data and an associated data schema in a format agreed with the client and transferred by secure link. We also provide a digital copy of the access and audit report data we hold.
We are able to retain a secure copy of the customer instance until the client is happy for this to be erased. This may incur additional cost - End-of-contract process
- We provide in a format agreed with the client, an extract of all data, the data schema and audit/access logs. If required we can retain a dormant copy of the client instance if required at additional cost.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Chrome
- Other
- Application to install
- Yes
- Compatible operating systems
- Other
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Depending on the solution being deployed it may be available on mobile devices and if so the UI will be tailored to the device
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- This varies depending on the solution(s) being deployed
- Accessibility standards
- None or don’t know
- Description of accessibility
- There are a range of standards applied depending on the solutions. Where applicable they comply with WCAG 2.2 AA and support a range of accessibility requirements.
- Accessibility testing
- None
- API
- Yes
- What users can and can't do using the API
- Depending upon the solutions being deployed API's will be used. Where required users can set up the service and make changes to their local configurations through the API. Users cannot make changes to core system functionality
- API documentation
- Yes
- API documentation formats
-
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Depending upon the solution being deployed our customers have varied ability to customise the solution. Only authorised users who have been trained/certified and have access through MFA can make customisations
Scaling
- Independence of resources
-
Our solutions are deployed as separate instances or in client environments. Where hosted by ourselves these are dynamically managed to auto scale processing and storage as required.
Where deployed in customer environments the availability will be deternmined by the clients environment
Analytics
- Service usage metrics
- Yes
- Metrics types
- The service metrics available are dependant upon the solution deployed and if it is hosted by ourselves or the Customer. This can include access, performance and activity
- Reporting types
-
- Real-time dashboards
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- A number of solution partners detailed in our Service Description.
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- We work with our customers to confirm the data to be exported, its format and structure. This is tested and assured by the customer prior to export. Export is typically by secure link, although we can provide physical transfer
- Data export formats
-
- CSV
- Other
- Other data export formats
- Client specific
- Data import formats
-
- CSV
- Other
- Other data import formats
- Client specific
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- We have SLA agreements for all our deployments, the level of SLA will be determined by the customers availability and performance requirements
- Approach to resilience
- Our platform incorporates multiple redundancy across system components and our 3rd party hosting suppliers provide virtual cloud environments with high levels of resilience, redundancy and business continuity that meet NHS and public sector requirements. We can enhance this further at additional cost if required by the customer.
- Outage reporting
- By email to clients and in-platform messages. We can provide AI links to customer monitoring systems if required. We also advise key client contacts of any outage that impacts service delivery or performance
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Access restrictions in management interfaces and support channels
- We use roles based access controls (RBAC) supported by MFA to restrict access
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- CSA CSM version 4.0
- Other
- Other security governance standards
- DSPT, Cyber Essentials and solution specific requirements. Many of our suppliers have enhanced governance standards and certficications
- Information security policies and processes
- We have robust Information Security process, policies and systems in place. This includes clear intra-company arrangements and data sharing and processing agreements. This includes clear internal and escalation and reporting structures
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- All components and configurations are detailed and tracked through there lifetime. Any changes are subject to rigorous, review and testing, prior to deployment. Any proposed changes are tested to ensure there are no IG or security implications. This includes robust security testing where required and development of appropriate mitigations to address any potential risks.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- .We use Calian's cyber security division and there specialist services and systems to asses potential threats. They provide certified services of this nature to national governments, public and health sector organisations and major international companies including NCSC in the UK. Any patches are deployed quickly using our Agile development and deployment processes. We source information and intelligence from commercial, internal and national cyber security partners
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- We adopt a proactive monitoring approach where we are hosting the solution. We respond to potential compromise in accordance with our established policies and processes which are driven by the risk score that has been assessed. We respond as quickly as practicable, implementing interim solutions if a full solution requires development. Where the solution is hosted by the client in they are responsible for protective monitoring and we support them in identification and response to potential compromises
- Incident management type
- Supplier-defined controls
- Incident management approach
- We have pre-defined processes for common events and incident management processes for other events. users can report by phone or email. We provide incident reports to customers as digital PDF which are updated as changes occur
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
- Health and Social Care Network (HSCN)
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 6c91fbc8-b65b-4c9b-a965-e45be7c7aad6
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
- Other security certifications
- Yes
- Any other security certifications
- NHS - Data Security & Protection Toolkit (DSPT)
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
-