Beam - Self Referral (platform access only)
Beam is an award-winning, clinically proven, digital rehabilitation service delivering exercise, education and lifestyle support for people living with cardio-kidney-metabolic (CKM) conditions. It provides live and on-demand classes and programmes alongside behavioural change features to help people increase physical activity, improve quality of life and reduce healthcare costs.
Features
- Digital rehabilitation programmes designed for people with cardio-kidney-metabolic conditions
- Personalised care plans configurable by condition and patient needs
- Live, remote weekly group classes delivered by specialist physiotherapists
- On-demand library of 400+ exercise, education, diet and lifestyle videos
- Behavioural change features (goal setting, progress tracking, badges)
- Language and accessibility features to support remote and equitable access
- Population-level service usage and outcomes reporting
- Flexible access via two patient pathways: clinical referral or self-referral
- Web-based, cloud-hosted software accessible via standard internet browsers
Benefits
- Evidence-based cost saving of £580 per patient completing the intervention
- Improves equitable access and standardises CKM care delivery
- Aligns with national renal, cardiac, diabetes and obesity standards
- Reduces dialysis demand through increased transplant readiness
- Expands CKM prevention and supports anti-obesity medication pathways
- Improves short-term efficiency and enables long-term cost avoidance
- Strengthens prevention for Core20PLUS5 and underserved populations
- Delivers high patient reach, satisfaction and convenient access
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 0 7 3 8 5 9 1 4 4 5 1 8 6 2
Contact
Kidney Beam
Katie Bell
Telephone: 07861201719
Email: katie.bell@kidneybeam.com
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Education
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
-
- Requires internet access and a modern web-enabled device
- Requires patients to be medically appropriate for remote exercise - System requirements
-
- No specialist software, licences, or plug-ins required
- Service accessed via a modern, standards-compliant web browser
- Requires an internet connection suitable for live video streaming
- Compatible with common operating systems (Windows, macOS, iOS, Android)
- No requirement for buyer-managed infrastructure or virtual machines
- No local installation or elevated user permissions required
User support
- Email or online ticketing support
- Yes
- Support response times
- We typically aim to respond within 1 business day.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- No
- Support levels
-
Standard support is included at no additional cost with the service and offers email-based support during UK business hours (9am–5pm, Monday–Friday, excluding public holidays). The service covers user access issues, configuration queries, and general technical questions with a target response time of within 1 business day.
Technical Account Management - A technical account managers is available to support where required. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Clinicians - Clinics and GP practices signposting our self-referral service to their patients are supported through online training sessions covering the patient signposting and sign-up process. Training is delivered remotely and supported by written guidance to ensure clinicians can confidently refer patients into the service. Physical and digital marketing materials will be provided to clinics on request.
Patients - Patients will be guided to a url where they will be guided through a simple onboarding process. During onboarding, patients are required to review and accept the service’s terms and conditions and privacy policy.
Patients can register and log in using Google, Facebook or an email address and password. Customer service support is available to assist patients during registration via email, phone or video conference by requesting such help by emailing hello@kidneybeam.com.
The service provides clear user guidance within the platform, and additional support is available during UK business hours.
Terms and Conditions: https://www.kidneybeam.com/kidney-beam-tandcs
Privacy Policy: https://www.kidneybeam.com/kidney-beam-privacy - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
-
At contract end, buyers can request a copy of their data held within the service.
Data is provided in a commonly used, machine-readable format (for example CSV or similar) to support portability and reuse. The export includes data relating to the buyer’s users and service activity, subject to data protection requirements.
Data extraction is supported as part of the offboarding process and provided securely within an agreed timeframe. Once data has been successfully transferred and the contract exit process is complete, remaining buyer data is securely deleted in accordance with the service’s data retention and deletion policies.
Support is available to coordinate data export and offboarding activities. - End-of-contract process
-
At the end of the contract, service access for all users associated with the buyer is terminated and the service enters an agreed offboarding period.
During this period, the buyer can request an export of their data held within the service.
Once the data export is complete and confirmed by the buyer, all buyer and user data is securely deleted in line with the service’s data retention and deletion policies. Support is provided to coordinate offboarding activities.
The contract price includes access to the Beam platform, use of all agreed service features and functionality, standard onboarding and user support, standard data export at contract end, secure hosting, maintenance and updates and ongoing service management and support during UK business hours
There are no mandatory additional costs. Optional additional services may be provided if agreed in advance with the Buyer and may incur additional charges, such as health coaching support, bespoke reporting or data extracts outside standard formats, extended support hours beyond standard UK business hours, additional training sessions beyond standard onboarding and extended data retention or bespoke offboarding requirements. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- There are no functional differences between the mobile and desktop service. The service is delivered via a responsive web application, with all pages and features available consistently across both mobile and desktop devices.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The service is accessed through a secure, browser-based user interface delivered via a responsive web application. The interface is designed for patients and authorised administrators and is available on desktop, tablet, and mobile devices without requiring local installation.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
The service interface has been reviewed against common accessibility requirements, including compatibility with screen readers, keyboard-only navigation and browser zoom functionality. Reviews have included use with assistive technologies such as screen readers and built-in accessibility tools on desktop and mobile devices. The service has not undergone formal usability testing with dedicated assistive technology user groups. However, feedback from users has been used to inform ongoing improvements to usability and accessibility.
Accessibility considerations are embedded into the service’s design and development processes and the service is designed with reference to WCAG 2.1 AA principles. - API
- No
- Customisation available
- Yes
- Description of customisation
- Buyers can customise the configuration of onboarding pathways (for example, clinical referral or self-referral), which content or programmes are available to defined user group and communication content (such as messaging and educational materials) can also be tailored where agreed. Core functionality is standardised across all buyers to ensure clinical safety, consistency, and service integrity. No custom code development is required or supported. Users are able to customise their experience by saving content preferences and setting personal goals.
Scaling
- Independence of resources
-
The service is delivered using a scalable, cloud-based architecture designed to manage variable demand and maintain consistent performance.
Platform capacity is continuously monitored and scaled to support changes in user demand. Performance and availability are actively monitored, with alerts in place to identify and address issues proactively.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
- Number of platform registrations through self-referral
- Number of users activating (completing 1st class)
- Programme participation and completion rates
- Demographics of user cohort (ethnicity, gender, locations)
- Service availability - Reporting types
- Regular reports
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
-
Authorised buyer representatives can request an export of their data held within the service, including data relating to their users (subject to data protection requirements), by contacting the Beam support desk on hello@kidneybeam.com.
In addition, end users can request access to the personal data held about them in accordance with the service’s privacy policy and applicable data protection legislation. Such requests are handled through established data subject access request (DSAR) processes and responded to within statutory timeframes. - Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
The service is designed to be highly available and resilient. We provide a service availability target of 99.5% per calendar month, excluding scheduled maintenance. Availability is measured at the application level and covers access to the core service. We have service level agreements (SLAs) for target availability (99.5% per month), measurement (monthly uptime, excluding pre-notified planned maintenance) and monitoring (service availability is continuously monitored). If availability falls below the stated level in any calendar month, the buyer may request a service credit, calculated as a pro-rata refund of the monthly service charge for the affected period.
Service credits are applied to future invoices and represent the buyer’s sole and exclusive remedy for failure to meet availability targets. Planned maintenance is scheduled outside of peak usage where possible and notified in advance. Planned maintenance windows are excluded from availability calculations. - Approach to resilience
-
The service is designed to be resilient at both the application and infrastructure levels to ensure continuity of service.
The platform is hosted on Amazon Web Services (AWS) UK-based data centres, which are designed for high availability and resilience. AWS data centres provide built-in redundancy across power, networking, cooling, and physical infrastructure, with services deployed across multiple availability zones to reduce the risk of single points of failure.
At the application level, the service uses a scalable, cloud-based architecture that supports load balancing and capacity monitoring. Service health and performance are continuously monitored, with alerts in place to identify and respond to issues promptly.
Data is protected through encryption at rest and in transit, regular backups, and defined recovery processes to support service restoration in the event of an incident. Planned maintenance is managed to minimise disruption and is communicated in advance. - Outage reporting
-
Service availability and incidents are actively monitored.
In the event of a service outage or significant degradation 1) Email notifications are sent to named buyer contacts and service users with details of the issue, impact, and progress updates. 2) Updates are provided until the issue is resolved and service is restored.
The service does not currently provide a public status dashboard or an outage reporting API.
Post-incident communications, including a summary of cause and resolution, can be provided to buyers on request.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
-
Access to management interfaces is restricted to authorised staff only and protected by individual user accounts. Administrative access is granted on a least-privilege basis, ensuring users can only access functions required for their role. Access permissions are reviewed periodically and revoked promptly when no longer required.
Management interfaces are accessible only over secure, encrypted connections. Direct access is limited to designated personnel and not exposed to general users.
Support channels are similarly restricted. Support requests are handled by authorised staff through controlled communication channels. Sensitive actions are logged for audit purposes. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- Security governance is embedded within organisational management and overseen by senior leadership. Documented policies and procedures cover information security, data protection, access control, secure development, risk management, and incident response. These are reviewed regularly and updated to reflect changes in risk and guidance. Security risks are identified and managed through ongoing assessment, external penetration testing by an independent provider and in-house security testing. Findings are prioritised and remediated. The organisation follows recognised best practice, including NCSC guidance and the UK Software Security Code of Practice. Hosting is provided on AWS infrastructure under the shared responsibility model.
- Information security policies and processes
-
The organisation follows documented information security policies covering data protection, access control, secure development, risk management, incident response, and supplier management. Policies are approved by senior management and reviewed regularly to ensure they remain effective and aligned with current guidance.
Security governance is overseen by senior leadership, with day-to-day responsibility delegated to designated security and technical leads. Compliance with policies is supported through role-based access controls, staff training, secure development practices and regular security testing.
Security incidents, risks, and audit findings are reported through defined escalation and review processes. Findings are tracked and remediated to ensure continuous improvement and policy adherence. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
The service follows defined configuration and change management processes to ensure changes are controlled, traceable and secure. Service components, including application code, configuration, and infrastructure definitions, are tracked throughout their lifecycle using version control, with changes recorded, auditable and linked to specific releases.
All changes are assessed prior to implementation to identify operational and security impacts, including effects on confidentiality, integrity, availability, dependencies and access controls. Changes are reviewed and approved by designated technical leads. Testing is performed in non-production environments, with post-deployment monitoring and retrospective review for emergency changes. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Vulnerability management is handled through defined supplier-controlled processes. Potential threats to the service are identified through continuous monitoring, external penetration testing by a CREST-accredited provider and in-house security testing. Threat intelligence is gathered from vendor security advisories, NCSC guidance, vulnerability databases (such as CVE listings) and cloud provider notifications. Identified vulnerabilities are risk assessed based on severity, exploitability and potential impact. Security patches and mitigations are prioritised accordingly and deployed promptly, with critical patches applied as soon as practicable.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Protective monitoring is implemented through supplier-defined processes appropriate to the service. Potential compromises are identified through service monitoring, application and access logging, infrastructure alerts and periodic review of security events. Monitoring focuses on identifying unusual activity, authentication anomalies and service disruptions. When a potential compromise is identified, it is assessed and investigated in line with the incident management process. Appropriate containment and remediation actions are taken where required and incidents are logged and reviewed. Response actions are prioritised based on severity and potential impact, with investigation initiated as soon as reasonably practicable following detection.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Incident management is handled through defined, documented processes. Pre-defined procedures are in place for common events such as service outages, security incidents, and access issues. Incidents can be reported by users via email and are logged and assessed on receipt. Incidents are prioritised based on severity and potential impact, with escalation to appropriate technical or security leads as required. Containment and remediation actions are taken in line with the incident type. Buyers are kept informed of significant incidents through email updates and incident reports or summaries can be provided on request following resolution.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Kidney Beam may offer limited free access for evaluation purposes. This includes access to a restricted subset of content or introductory sessions. It does not include full programme access, personalised health coaching, reporting, configuration, or service levels. Free access is time-limited and discretionary.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 671734cc-1188-4deb-b87f-4131b7e0832b
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- E4f88244-190e-43ce-be10-b3e6f75c2fe6
- Other security certifications
- Yes
- Any other security certifications
-
- DTAC
- DSPT
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
-