Skip to main content

Help us improve the Digital Marketplace - send your feedback

Kidney Beam

Beam - Self Referral (platform access only)

Beam is an award-winning, clinically proven, digital rehabilitation service delivering exercise, education and lifestyle support for people living with cardio-kidney-metabolic (CKM) conditions. It provides live and on-demand classes and programmes alongside behavioural change features to help people increase physical activity, improve quality of life and reduce healthcare costs.

Features

  • Digital rehabilitation programmes designed for people with cardio-kidney-metabolic conditions
  • Personalised care plans configurable by condition and patient needs
  • Live, remote weekly group classes delivered by specialist physiotherapists
  • On-demand library of 400+ exercise, education, diet and lifestyle videos
  • Behavioural change features (goal setting, progress tracking, badges)
  • Language and accessibility features to support remote and equitable access
  • Population-level service usage and outcomes reporting
  • Flexible access via two patient pathways: clinical referral or self-referral
  • Web-based, cloud-hosted software accessible via standard internet browsers

Benefits

  • Evidence-based cost saving of £580 per patient completing the intervention
  • Improves equitable access and standardises CKM care delivery
  • Aligns with national renal, cardiac, diabetes and obesity standards
  • Reduces dialysis demand through increased transplant readiness
  • Expands CKM prevention and supports anti-obesity medication pathways
  • Improves short-term efficiency and enables long-term cost avoidance
  • Strengthens prevention for Core20PLUS5 and underserved populations
  • Delivers high patient reach, satisfaction and convenient access

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at katie.bell@kidneybeam.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

5 0 7 3 8 5 9 1 4 4 5 1 8 6 2

Contact

Kidney Beam Katie Bell
Telephone: 07861201719
Email: katie.bell@kidneybeam.com

About your service

Service categories

Applications

Production and operations

Service industry and public sector operations

  • Healthcare
  • Education
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
- Requires internet access and a modern web-enabled device
- Requires patients to be medically appropriate for remote exercise
System requirements
  • No specialist software, licences, or plug-ins required
  • Service accessed via a modern, standards-compliant web browser
  • Requires an internet connection suitable for live video streaming
  • Compatible with common operating systems (Windows, macOS, iOS, Android)
  • No requirement for buyer-managed infrastructure or virtual machines
  • No local installation or elevated user permissions required

User support

Email or online ticketing support
Yes
Support response times
We typically aim to respond within 1 business day.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
No
Support levels
Standard support is included at no additional cost with the service and offers email-based support during UK business hours (9am–5pm, Monday–Friday, excluding public holidays). The service covers user access issues, configuration queries, and general technical questions with a target response time of within 1 business day.

Technical Account Management - A technical account managers is available to support where required.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Clinicians - Clinics and GP practices signposting our self-referral service to their patients are supported through online training sessions covering the patient signposting and sign-up process. Training is delivered remotely and supported by written guidance to ensure clinicians can confidently refer patients into the service. Physical and digital marketing materials will be provided to clinics on request.

Patients - Patients will be guided to a url where they will be guided through a simple onboarding process. During onboarding, patients are required to review and accept the service’s terms and conditions and privacy policy.

Patients can register and log in using Google, Facebook or an email address and password. Customer service support is available to assist patients during registration via email, phone or video conference by requesting such help by emailing hello@kidneybeam.com.

The service provides clear user guidance within the platform, and additional support is available during UK business hours.

Terms and Conditions: https://www.kidneybeam.com/kidney-beam-tandcs

Privacy Policy: https://www.kidneybeam.com/kidney-beam-privacy
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
At contract end, buyers can request a copy of their data held within the service.

Data is provided in a commonly used, machine-readable format (for example CSV or similar) to support portability and reuse. The export includes data relating to the buyer’s users and service activity, subject to data protection requirements.

Data extraction is supported as part of the offboarding process and provided securely within an agreed timeframe. Once data has been successfully transferred and the contract exit process is complete, remaining buyer data is securely deleted in accordance with the service’s data retention and deletion policies.

Support is available to coordinate data export and offboarding activities.
End-of-contract process
At the end of the contract, service access for all users associated with the buyer is terminated and the service enters an agreed offboarding period.

During this period, the buyer can request an export of their data held within the service.
Once the data export is complete and confirmed by the buyer, all buyer and user data is securely deleted in line with the service’s data retention and deletion policies. Support is provided to coordinate offboarding activities.

The contract price includes access to the Beam platform, use of all agreed service features and functionality, standard onboarding and user support, standard data export at contract end, secure hosting, maintenance and updates and ongoing service management and support during UK business hours

There are no mandatory additional costs. Optional additional services may be provided if agreed in advance with the Buyer and may incur additional charges, such as health coaching support, bespoke reporting or data extracts outside standard formats, extended support hours beyond standard UK business hours, additional training sessions beyond standard onboarding and extended data retention or bespoke offboarding requirements.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
There are no functional differences between the mobile and desktop service. The service is delivered via a responsive web application, with all pages and features available consistently across both mobile and desktop devices.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
The service is accessed through a secure, browser-based user interface delivered via a responsive web application. The interface is designed for patients and authorised administrators and is available on desktop, tablet, and mobile devices without requiring local installation.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
The service interface has been reviewed against common accessibility requirements, including compatibility with screen readers, keyboard-only navigation and browser zoom functionality. Reviews have included use with assistive technologies such as screen readers and built-in accessibility tools on desktop and mobile devices. The service has not undergone formal usability testing with dedicated assistive technology user groups. However, feedback from users has been used to inform ongoing improvements to usability and accessibility.

Accessibility considerations are embedded into the service’s design and development processes and the service is designed with reference to WCAG 2.1 AA principles.
API
No
Customisation available
Yes
Description of customisation
Buyers can customise the configuration of onboarding pathways (for example, clinical referral or self-referral), which content or programmes are available to defined user group and communication content (such as messaging and educational materials) can also be tailored where agreed. Core functionality is standardised across all buyers to ensure clinical safety, consistency, and service integrity. No custom code development is required or supported. Users are able to customise their experience by saving content preferences and setting personal goals.

Scaling

Independence of resources
The service is delivered using a scalable, cloud-based architecture designed to manage variable demand and maintain consistent performance.

Platform capacity is continuously monitored and scaled to support changes in user demand. Performance and availability are actively monitored, with alerts in place to identify and address issues proactively.

Analytics

Service usage metrics
Yes
Metrics types
- Number of platform registrations through self-referral
- Number of users activating (completing 1st class)
- Programme participation and completion rates
- Demographics of user cohort (ethnicity, gender, locations)
- Service availability
Reporting types
Regular reports
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
  • Other locations
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure

Data importing and exporting

Data export approach
Authorised buyer representatives can request an export of their data held within the service, including data relating to their users (subject to data protection requirements), by contacting the Beam support desk on hello@kidneybeam.com.

In addition, end users can request access to the personal data held about them in accordance with the service’s privacy policy and applicable data protection legislation. Such requests are handled through established data subject access request (DSAR) processes and responded to within statutory timeframes.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
The service is designed to be highly available and resilient. We provide a service availability target of 99.5% per calendar month, excluding scheduled maintenance. Availability is measured at the application level and covers access to the core service. We have service level agreements (SLAs) for target availability (99.5% per month), measurement (monthly uptime, excluding pre-notified planned maintenance) and monitoring (service availability is continuously monitored). If availability falls below the stated level in any calendar month, the buyer may request a service credit, calculated as a pro-rata refund of the monthly service charge for the affected period.

Service credits are applied to future invoices and represent the buyer’s sole and exclusive remedy for failure to meet availability targets. Planned maintenance is scheduled outside of peak usage where possible and notified in advance. Planned maintenance windows are excluded from availability calculations.
Approach to resilience
The service is designed to be resilient at both the application and infrastructure levels to ensure continuity of service.

The platform is hosted on Amazon Web Services (AWS) UK-based data centres, which are designed for high availability and resilience. AWS data centres provide built-in redundancy across power, networking, cooling, and physical infrastructure, with services deployed across multiple availability zones to reduce the risk of single points of failure.

At the application level, the service uses a scalable, cloud-based architecture that supports load balancing and capacity monitoring. Service health and performance are continuously monitored, with alerts in place to identify and respond to issues promptly.

Data is protected through encryption at rest and in transit, regular backups, and defined recovery processes to support service restoration in the event of an incident. Planned maintenance is managed to minimise disruption and is communicated in advance.
Outage reporting
Service availability and incidents are actively monitored.

In the event of a service outage or significant degradation 1) Email notifications are sent to named buyer contacts and service users with details of the issue, impact, and progress updates. 2) Updates are provided until the issue is resolved and service is restored.

The service does not currently provide a public status dashboard or an outage reporting API.

Post-incident communications, including a summary of cause and resolution, can be provided to buyers on request.

Identity and authentication

User authentication needed
Yes
User authentication
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces is restricted to authorised staff only and protected by individual user accounts. Administrative access is granted on a least-privilege basis, ensuring users can only access functions required for their role. Access permissions are reviewed periodically and revoked promptly when no longer required.

Management interfaces are accessible only over secure, encrypted connections. Direct access is limited to designated personnel and not exposed to general users.

Support channels are similarly restricted. Support requests are handled by authorised staff through controlled communication channels. Sensitive actions are logged for audit purposes.
Access restriction testing frequency
At least once a year
Management access authentication
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
Security governance is embedded within organisational management and overseen by senior leadership. Documented policies and procedures cover information security, data protection, access control, secure development, risk management, and incident response. These are reviewed regularly and updated to reflect changes in risk and guidance. Security risks are identified and managed through ongoing assessment, external penetration testing by an independent provider and in-house security testing. Findings are prioritised and remediated. The organisation follows recognised best practice, including NCSC guidance and the UK Software Security Code of Practice. Hosting is provided on AWS infrastructure under the shared responsibility model.
Information security policies and processes
The organisation follows documented information security policies covering data protection, access control, secure development, risk management, incident response, and supplier management. Policies are approved by senior management and reviewed regularly to ensure they remain effective and aligned with current guidance.

Security governance is overseen by senior leadership, with day-to-day responsibility delegated to designated security and technical leads. Compliance with policies is supported through role-based access controls, staff training, secure development practices and regular security testing.

Security incidents, risks, and audit findings are reported through defined escalation and review processes. Findings are tracked and remediated to ensure continuous improvement and policy adherence.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
The service follows defined configuration and change management processes to ensure changes are controlled, traceable and secure. Service components, including application code, configuration, and infrastructure definitions, are tracked throughout their lifecycle using version control, with changes recorded, auditable and linked to specific releases.

All changes are assessed prior to implementation to identify operational and security impacts, including effects on confidentiality, integrity, availability, dependencies and access controls. Changes are reviewed and approved by designated technical leads. Testing is performed in non-production environments, with post-deployment monitoring and retrospective review for emergency changes.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Vulnerability management is handled through defined supplier-controlled processes. Potential threats to the service are identified through continuous monitoring, external penetration testing by a CREST-accredited provider and in-house security testing. Threat intelligence is gathered from vendor security advisories, NCSC guidance, vulnerability databases (such as CVE listings) and cloud provider notifications. Identified vulnerabilities are risk assessed based on severity, exploitability and potential impact. Security patches and mitigations are prioritised accordingly and deployed promptly, with critical patches applied as soon as practicable.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Protective monitoring is implemented through supplier-defined processes appropriate to the service. Potential compromises are identified through service monitoring, application and access logging, infrastructure alerts and periodic review of security events. Monitoring focuses on identifying unusual activity, authentication anomalies and service disruptions. When a potential compromise is identified, it is assessed and investigated in line with the incident management process. Appropriate containment and remediation actions are taken where required and incidents are logged and reviewed. Response actions are prioritised based on severity and potential impact, with investigation initiated as soon as reasonably practicable following detection.
Incident management type
Supplier-defined controls
Incident management approach
Incident management is handled through defined, documented processes. Pre-defined procedures are in place for common events such as service outages, security incidents, and access issues. Incidents can be reported by users via email and are logged and assessed on receipt. Incidents are prioritised based on severity and potential impact, with escalation to appropriate technical or security leads as required. Containment and remediation actions are taken in line with the incident type. Buyers are kept informed of significant incidents through email updates and incident reports or summaries can be provided on request following resolution.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
Kidney Beam may offer limited free access for evaluation purposes. This includes access to a restricted subset of content or introductory sessions. It does not include full programme access, personalised health coaching, reporting, configuration, or service levels. Free access is time-limited and discretionary.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
671734cc-1188-4deb-b87f-4131b7e0832b
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
E4f88244-190e-43ce-be10-b3e6f75c2fe6
Other security certifications
Yes
Any other security certifications
  • DTAC
  • DSPT

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
    • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at katie.bell@kidneybeam.com. Tell them what format you need. It will help if you say what assistive technology you use.