Skip to main content

Help us improve the Digital Marketplace - send your feedback

ST VINCENT’S CONSULTING LTD

Digital Solution

Digital solution to meet additional health and care requirements. Bridging functionality and technology gaps across the organisations clinical, operational and business systems.

Features

  • Easy-to-use workflows for clinician and operational staff
  • Enhances the usage of exisiting digital solutions
  • Optimisation for current functionalities within off -the-shelf products
  • Outputs aligned with client quadruple aim objectives as appropriate
  • Configurations to meet local needs
  • Includes implementation services as required
  • Operational analysis and reporting outputs available
  • Supported on client devices
  • Service management and warranty included
  • Access to advisors for national and client digital strategies

Benefits

  • Increased user experience and satisfaction through enhanced functionality
  • Improve expected patient, client, organisational outcomes through streamlined workflows
  • Alignment to organisational quadruple aim targets as appropriate
  • Closure of functionality gaps within larger set of solutions
  • C-Suite panel for complex programmes guidance/assurance
  • Digital solutions hub includes free NHS & Care solutions
  • Flexible skilled scalable teams mobilised within days
  • Additional resource whenever needed (sourced by our resourcing division)
  • Agile delivery by seasoned consultants at reasonable rates
  • Advisors for national and client digital strategies

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at frameworks@stvconsulting.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

5 0 1 4 3 6 8 3 0 8 5 8 8 6 3

Contact

ST VINCENT’S CONSULTING LTD Kyle Dollan
Telephone: 07989415358
Email: frameworks@stvconsulting.uk

About your service

Service categories

Applications

Production and operations

  • Other operations

Service industry and public sector operations

  • Healthcare
  • Education
  • Public Order and Safety
  • Police
  • Defence
  • Social Security Administration
  • Adult Social Care
  • Children's Social Care
  • Other
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Integration with other clinic and operational systems to add functionality, features and interoperability
Cloud deployment model
  • Public cloud
  • Private cloud
Service constraints
Where integration with other customer systems is required the constraints on those systems
System requirements
  • System requirements vary by solution and functionality
  • Client must be able to present and receive valid data
  • Anti-virus technology if implemented on virtual machines

User support

Email or online ticketing support
Yes
Support response times
On the day for urgent issues, within three working days for non-urgent issues
We provide central support and escalation for all our teams and projects, in addition to a nominated lead for first contact. Additional support costs are limited to additional resources deployed to address the issue and once agreed with the client. Prices are based on our SFIA rate card
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
We provide client support to meet the customers requirements and service levels they wish to consume. We provide a technical account manager to ensure clear communications and a first course of escalation if needed. Our standard service support is included in the annual fee. Additional costs will be determined by what level and availability they require.

We provide central support and escalation for all our teams and projects, in addition to a nominated lead for first contact. Additional support costs are limited to additional resources deployed to address the issue and once agreed with the client. Prices are based on our rate card
Support available to third parties
Yes

Onboarding and offboarding

Getting started
We follow the St Vincent Implementation methodology for implementations. This includes a Training Needs Analysis and development of use tailored roles based training for users. This can include both virtual and online training. We provide access to digital user documentation and FAQ
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
At the end of the customer contract where we hold client data we provide a digital copy of all the data and an associated data schema in a format agreed with the client and transferred by secure link. We also provide a digital copy of the access and audit report data we hold.

We are able to retain a secure copy of the customer instance until the client is happy for this to be erased. This may incur additional cost
End-of-contract process
We provide in a format agreed with the client, an extract of all data, the data schema and audit/access logs. If required we can retain a dormant copy of the client instance if required at additional cost.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Chrome
  • Other
Application to install
Yes
Compatible operating systems
Other
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Depending on the solution being deployed it may be available on mobile devices and if so the UI will be tailored to the device
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
This varies depending on the solution(s) being deployed
Accessibility standards
None or don’t know
Description of accessibility
There are a range of standards applied depending on the solutions. Where applicable they comply with WCAG 2.2 AA and support a range of accessibility requirements.
Accessibility testing
None
API
Yes
What users can and can't do using the API
Depending upon the solutions being deployed API's will be used. Where required users can set up the service and make changes to their local configurations through the API. Users cannot make changes to core system functionality
API documentation
Yes
API documentation formats
  • HTML
  • PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Depending upon the solution being deployed our customers have varied ability to customise the solution. Only authorised users who have been trained/certified and have access through MFA can make customisations

Scaling

Independence of resources
Our solutions are deployed as separate instances or in client environments. Where hosted by ourselves these are dynamically managed to auto scale processing and storage as required.

Where deployed in customer environments the availability will be deternmined by the clients environment

Analytics

Service usage metrics
Yes
Metrics types
The service metrics available are dependant upon the solution deployed and if it is hosted by ourselves or the Customer. This can include access, performance and activity
Reporting types
  • Real-time dashboards
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Reseller providing extra features and support
Organisation whose services are being resold
A number of solution partners detailed in our Service Description.

Staff security

Staff security clearance
Other security clearance
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CHECK service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with another standard
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
We work with our customers to confirm the data to be exported, its format and structure. This is tested and assured by the customer prior to export. Export is typically by secure link, although we can provide physical transfer
Data export formats
  • CSV
  • Other
Other data export formats
Client specific
Data import formats
  • CSV
  • Other
Other data import formats
Client specific

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
We have SLA agreements for all our deployments, the level of SLA will be determined by the customers availability and performance requirements
Approach to resilience
Our platform incorporates multiple redundancy across system components and our 3rd party hosting suppliers provide virtual cloud environments with high levels of resilience, redundancy and business continuity that meet NHS and public sector requirements. We can enhance this further at additional cost if required by the customer.
Outage reporting
By email to clients and in-platform messages. We can provide AI links to customer monitoring systems if required. We also advise key client contacts of any outage that impacts service delivery or performance

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
Access restrictions in management interfaces and support channels
We use roles based access controls (RBAC) supported by MFA to restrict access
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • CSA CSM version 4.0
  • Other
Other security governance standards
DSPT, Cyber Essentials and solution specific requirements. Many of our suppliers have enhanced governance standards and certficications
Information security policies and processes
We have robust Information Security process, policies and systems in place. This includes clear intra-company arrangements and data sharing and processing agreements. This includes clear internal and escalation and reporting structures
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
All components and configurations are detailed and tracked through there lifetime. Any changes are subject to rigorous, review and testing, prior to deployment. Any proposed changes are tested to ensure there are no IG or security implications. This includes robust security testing where required and development of appropriate mitigations to address any potential risks.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
.We use Calian's cyber security division and there specialist services and systems to asses potential threats. They provide certified services of this nature to national governments, public and health sector organisations and major international companies including NCSC in the UK. Any patches are deployed quickly using our Agile development and deployment processes. We source information and intelligence from commercial, internal and national cyber security partners
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
We adopt a proactive monitoring approach where we are hosting the solution. We respond to potential compromise in accordance with our established policies and processes which are driven by the risk score that has been assessed. We respond as quickly as practicable, implementing interim solutions if a full solution requires development. Where the solution is hosted by the client in they are responsible for protective monitoring and we support them in identification and response to potential compromises
Incident management type
Supplier-defined controls
Incident management approach
We have pre-defined processes for common events and incident management processes for other events. users can report by phone or email. We provide incident reports to customers as digital PDF which are updated as changes occur
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
Yes
Connected networks
Health and Social Care Network (HSCN)

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
6c91fbc8-b65b-4c9b-a965-e45be7c7aad6
Cyber essentials plus
No
Cyber Essentials Alternative
You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
Other security certifications
Yes
Any other security certifications
NHS - Data Security & Protection Toolkit (DSPT)

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at frameworks@stvconsulting.uk. Tell them what format you need. It will help if you say what assistive technology you use.