OneTouch Health
OneTouch Health provides an all-in-one digital care management platform for social and home-care providers. It unifies client records, scheduling and rostering, digital care plans, medication workflows, HR documents, payroll, invoicing and compliance tools, helping organisations coordinate personalised care efficiently in real time. Includes bolt-on recruitment and e-learning platforms.
Features
- Single cloud platform bundling care, workforce, finance and compliance
- Digital care planning with real-time mobile care recording
- Workforce scheduling, rostering and time & attendance management
- Mobile apps for carers, clients and families
- Integrated staff onboarding and compliance management
- Configurable workflows, forms and approval processes
- Secure document management and audit trails
- Real-time dashboards and statutory reporting
- UK-hosted cloud infrastructure with disaster recovery
- Open APIs for integration with third-party systems
Benefits
- Reduces administrative burden and operational costs
- Improves quality, safety and consistency of care delivery
- Optimises workforce deployment and shift coverage
- Supports faster onboarding and safer staffing
- Strengthens compliance and inspection readiness
- Provides a single source of accurate operational data
- Improves management oversight and decision-making
- Enhances staff experience and retention
- Increases transparency for families and stakeholders
- Scales easily across services and care models
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 1 6 5 5 7 7 4 9 1 8 1 8 3 0
Contact
ONETOUCHTELECARE LIMITED
John Van Den Maagdenberg
Telephone: 0161 509 2309
Email: sales@onetouchhealth.net
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Education
- Adult Social Care
- Children's Social Care
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
-
• Systems are monitored 24/7, to ensure response to critical incidents. Lower-level ticket support is available Monday–Friday, 8:30–17:30 via our Zendesk
• The platform exposes a RESTful API. API access requires an active customer account, issued credentials, and authorised source IPs or domains. Production integrations must use token-based authentication. Supported payload format is JSON, with HL7 FHIR support under evaluation.
• Integrations with proprietary systems may require additional discussion.
• Family portal access is online, read-only, and prohibits data download for GDPR compliance. - System requirements
-
- Devices should have minimum 2GB RAM for optimal performance
- IOS v12.0 or later, Android v8.0 or later
- Current antivirus software and operating system patches encouraged
- MS Office needed to open/ download attachments or export data
User support
- Email or online ticketing support
- Yes
- Support response times
-
Our average first response time is under 20 minutes.
Our SLAs are:
•Priority 1 (Critical): e.g. Platform inaccessible: Response time 0–1 hour (24/7).
•Priority 2 (High): e.g. Non-access to client/carer info: Response time: ≤1 hour (business hours).
•Priority 3 (Medium): User navigation issue: Response time: ≤4 hours.
•Priority 4 (Low): Cosmetic/configuration change: Response time: ≤1working day.
We respond to Priority 2, 3 and 4 tickets received over the weekend the next working day - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- No
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
We offer onsite support primarily during the implementation and go-live phases, as required by the client.
Onsite support can include training sessions, hands-on configuration, process consultation and additional direct assistance during key transition periods.
Support levels range from standard remote support (included in the base service) to enhanced onsite support.
We typically schedule onsite support for:
•Implementation project management and system rollout
•Staff training (face-to-face)
•Go-live hyper-support periods for rapid response and troubleshooting
Standard remote support, account management, technical onboarding, and implementation consultancy are included in the service price.
Onsite support (beyond scheduled training or go-live activities) may incur additional costs, which are quoted based on the client’s requirements, travel, accommodation, and duration of work (£1500 per day).
A dedicated Account Manager to each client acts as their key point of contact for consultancy and ongoing support for operational and technical issues.
During implementation, a Project Lead works closely with the client, which can include onsite visits.
The support team includes highly-skilled clinical, medical and technical staff who may also deliver onsite support when required (e.g., setup, troubleshooting, or escalation).
We manage cloud support services and infrastructure centrally, and clients have access to UK- and Ireland-based support staff. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Our comprehensive and multi-modal onboarding package includes:
TRAINING
•In-person sessions tailored to different organisational roles within the. Guiding users through the practical use of the system, ensuring competence before go-live.
o Session One: System Introduction
o Session Two: Account Configuration, Carer and Client Compliance
o Session Three: Scheduling
o Session Four: Finance
o Session Five: Finance Pay Cycle and Invoice Cycle Review
o Session Six: Clinical Care, eCare Plans, eForms and eLetters
o Session Seven: Carer App
•Live virtual interactive sessions covering core modules and workflows, with users asking questions in real time.
•Recorded sessions for ongoing access for new staff or as refreshers.
•Online Help Centre with hundreds of articles, manuals, step-by-step guides, FAQs, and how-to videos
•Train-the-Trainer programme to equip local champions to cascade knowledge.
ONGOING POST-IMPLEMENTATION SUPPORT
•Continued access to our Zendesk support team for ongoing assistance, troubleshooting and queries.
•Test environment for users to practise using training materials in a risk-free setting.
•Before signing off the training plan we review all system features, recording comments and plans for any features not yet deployed. This ensures all organisational training needs are addressed. - Service documentation
- Yes
- Documentation formats
-
- HTML
- ODF
- End-of-contract data extraction
-
When a contract ends, client can extract their data in the following way:
1. Comprehensive Data Export: We provide the client with .zip files containing all their data from the platform. This includes data from all live, test, backup and archive instances.
2. Accessible File Formats: We supply the exported data in user-friendly formats like CSV (for structured data) and include any additional asset uploads (e.g., PDFs, PNGs, etc.). This facilitates easy access, review and migration to other systems.
3. Data Sovereignty & Control: The client retains full ownership of their data. We do not archive, retain or maintain copies beyond the offboarding date as set in the Service Level Agreement (SLA).
4. Verified Data Deletion: Upon client instruction, we delete or transfer all remaining data using NIST SP 800-88-compliant erasure methods. We provide a verified destruction log, ensuring compliance and transparency.
5. End-of-Contract Procedures: The SLA clearly defines the agreed offboarding time frame and data deletion assurances. We exclude backups are from future cycles and purged them to ensure no recoverable copies remain.
6. Downloadable and Auditable: The client can download all datasets and uploads, and we provide audit logs to confirm complete transfer/destruction. - End-of-contract process
-
We follow a structured process to ensure secure data handling, transparency and client support.
-Data Export & Transfer: We provides the client with a full export of their data in a structured and commonly used format (such as CSV or Excel) for import into a new system or safe archive.
-Data Retention & Erasure: Once data export is confirmed, data held on our systems is securely deleted in line with GDPR and contractual requirements, following NIST SP 800-88-compliant methods.
-Audit Logging: of all actions performed during the export and deletion process, including who initiated, accessed or processed export or erasure.
-Collaboration & Support: Our team works collaboratively with the client’s outgoing or incoming system suppliers to facilitate a smooth transition.
-Certificate of Data Destruction: Provided following completion, confirming compliance with all legal and contractual requirements.
INCLUDED IN THE CONTRACT PRICE
-Standard Data Export: The client’s full data set in Excel, CSV or PDF format.
-Collaboration and Transition Support: Reasonable technical advice and cooperation with outgoing/incoming teams for data migration and system decommissioning.
-Standard Data Deletion & Reporting: audit logging and providing a Certificate of Data Deletion.
ADDITIONAL COSTS
-Complex or Custom Data Migration Support
-Extended Access or Data Retention - Documentation accessibility standard
- WCAG 2.2 A
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Chrome
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- MacOS
- Windows
- ChromeOS
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
Our platform offers both mobile and desktop services, each tailored to the needs of different user roles.
DESKTOP: Best for managers, coordinators and admins handling overview, reporting, company-wide or multi-site management, configuration and audit activities.
•Optimised for large screens, supporting in-depth administrative and management tasks.
•Features advanced controls and oversight of the entire platform
•Full administrative rights
•Advanced permissions management
APP: Designed for carers and field-based staff who need mobility, quick task access, and immediate update of care records.
•Streamlined, user-friendly interface suitable for quick data entry and real-time updates.
•Focused on care delivery
•Fewer administrative features
•Supported offline mode - Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The OneTouch interface is a modern, browser-based platform that works on any device without installations. A clear, intuitive dashboard provides quick access to scheduling, care planning, reporting, communication tools, and administrative functions, with real-time notifications for urgent updates. The design is fully responsive, and carers benefit from an optimised mobile app with offline capability. Navigation is role-based and configurable, ensuring each user sees only relevant modules. All records—service users, staff, visits, plans, and messages—are centralised for seamless navigation. Built-in messaging, alerts, accessible settings, and full audit logging support secure, collaborative, and efficient service delivery.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- We have conducted interface testing with users of assistive technology. All updates and new features undergo accessibility testing before deployment to ensure compliance with evolving standards. The platform specifically supports a wide range of assistive technologies, including screen readers (JAWS, NVDA, and VoiceOver), keyboard-only navigation, browser-level zoom, high-contrast display modes and more. This consistent testing ensures the interface remains compatible and accessible for users relying on assistive technology.
- API
- Yes
- What users can and can't do using the API
-
SET UP: The OneTouch Open API allows authorised customers to integrate external systems and perform CRUD (Create, Read, Update, Delete) operations on selected record types. It is RESTful, supports JSON, XML and HL7 FHIR formats, and uses OAuth 2.0/OpenID Connect for secure token-based access. To set up the service, customers must hold an active OneTouch Health account, request API enablement, and receive credentials used to generate an API key. Production API keys are restricted to approved source IPs or domains, while setup and testing environments allow broader access.
MAKING CHANGES Through the API, users can create or update staff profiles, service-user records, schedules, visit logs and other approved data objects, enabling automated workflows and real-time data exchange with systems such as payroll, HR or compliance tools. Permissions set by administrators govern which data scopes and operations an integration may access.
LIMITATIONS: Users cannot perform unrestricted setup, create new modules, bypass role permissions or access data outside their assigned scope. Integration with proprietary or non-standard systems may require custom work and is not guaranteed. API usage must follow published specifications, and unsupported operations are not permitted. - API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Customers can customise OneTouch extensively to match their operational and organisational needs. Most configuration is completed through the built-in administrative interface, enabling authorised non-technical users to adjust settings without development work. During onboarding, the OneTouch team helps define best-practice configurations, and customers can continue to revise settings at any time as requirements evolve.
Users can customise digital care plans, forms and assessments by editing templates, fields and workflows. We can tailor roles and permissions to define access for staff, managers, carers and family users. Scheduling options, such as rota periods, shift types, availability templates and service rules, are fully configurable. OneTouch can personalise dashboards, homepage widgets, quick links, alerts and notifications at organisational or user level. Customers can create bespoke reports by selecting data sets, filters and layouts. Document libraries, signature settings, service-provision rules and integration preferences (e.g., payroll, HR or finance systems) can also be customised.
Top-level administrators or designated managers with the appropriate permissions can carry out customisation. Our implementation and support teams assist with advanced requests such as bespoke workflows or integrations. Everyday users can customise personal dashboards and reports within the limits of their role-based access.
Scaling
- Independence of resources
-
Our measures include:
• A platform designed to maintain 99.95% availability, ensuring high reliability and consistent performance.
• System architecture including automated alerts and enforced escalation protocols that monitor for any performance deviations or network issues, allowing for rapid response.
• Infrastructure investments to boost resilience and reliability, minimising risk of service degradation due to high demand.
• 24/7 system monitoring, ensuring immediate responses and escalation of any significant deviations in service.
Flagging scheduled maintenance in advance designing patches to avoid impacting service delivery.
These proactive measures mean OneTouch can handle varying levels of demand without affecting individual user experiences.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
We provide a variety of service metrics through standard reports and user-friendly dashboards. These include:
• Key performance indicators relating to care delivery
• Customer experience data
• Performance monitoring metrics
• Analytics to support adjustments in service delivery to help achieve targets
• Data supporting compliance, efficiency and quality of care monitoring
• Metrics that track variations in performance and support continuous improvements
We have designed the dashboards to present this information in a visually engaging and accessible format, making it easy for users to monitor performance, identify trends and support decision-making. - Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
- Physical access control, complying with CSA CCM v4.0
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
-
Users of the OneTouch platform can export their data directly from the system in several formats: Excel, CSV, or PDF. Users can complete exports by selecting the export button available on all report screens.
Additionally, users have the ability to configure the report screens to display or hide specific columns before exporting. All data exports maintain clean and consistent field structures, making it easy to manipulate or merge with other datasets.
The export process is fully traceable, as the system logs who accessed or generated a report, what filters or datasets were applied, and when exports were created. - Data export formats
-
- CSV
- Other
- Other data export formats
-
- Excel
- Data import formats
-
- CSV
- Other
- Other data import formats
- Excel
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- Other
- Other protection between networks
-
Industry-standard encryption and secure communication controls protect data exchanged between the buyer's network and OneTouch. TLS 1.2+ encryption ensures security of data in transit over public/ private networks.
Strong authentication and authorisation mechanisms restrict access:
•Token-based access (OAuth 2.0), enforcing permissions at API and service level.
•Firewalls
•IP allow-listing
•Security groups
These limit exposure to approved sources only. We isolate and control traffic between internal services, reducing risk of lateral movement.
Continuous monitoring, logging and alerting detect anomalous activity/ potential threats. We review and improve security controls/ configurations based on observed data, platform usage patterns and evolving best practices. - Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
-
Our cloud infrastructure is hosted on Amazon Web Services (AWS), which provides multiple layers of internal defence. This includes:
-Virtual Private Clouds (VPCs): Isolating and segmenting network traffic within secure cloud boundaries.
-Network Firewalls and Security Groups: Controlling and restricting inter-service and internal communications.
-VPNs: Used for secure administrative access and potentially for specific secure links within the network.
A Web Application Firewall (WAF) protects the application from application-layer security threats internally and at the edge of the network.
Availability and resilience
- Guaranteed availability
-
We commit to a minimum availability (uptime) of 99.95%. This target applies to the core platform’s operational readiness, excluding planned and notified maintenance, emergency outages required for data security, or force majeure.
OneTouch and our cloud hosting provider monitor the system 24/7. The system automatically triggers alerts and enforces escalation procedures whenever it detects a deviation from the agreed SLA. We typically schedule maintenance and upgrades for overnight or weekends and notify clients in advance to avoid disruption to operational availability during regular hours.
If OneTouch fails to meet the agreed availability SLA, the authority (client) is entitled to up to one month’s service credit for serious breaches as compensation. The precise amount may depend on the duration and severity/frequency of the SLA breach.
In the event of consistent and serious breaches, our SLA allows either party (including the client/authority) the option to cancel the contract. - Approach to resilience
-
OneTouch delivers high resilience through a cloud-based architecture hosted across multiple, geographically separated UK AWS data centres. The platform runs on dual hosting across independent availability zones, so if one location becomes unavailable, another site immediately continues service. The system continuously replicates data using master-to-master mirroring, maintaining live copies across sites and enabling automatic failover without interrupting users. Both the application and database layers operate with full redundancy, eliminating single points of failure.
Our systems perform multiple automated backups each day and store them securely in separate AWS regions. Disaster recovery replicas protect against data loss, while our recovery targets remain tight—an RTO under four hours and an RPO under 15 minutes. Our team monitors the service 24/7, using real-time logging and automated alerts to detect and respond to issues quickly. We routinely review and test business continuity and disaster recovery plans, including quarterly full restore tests.
We strengthen resilience further through ISO 27001 certification, NHS DSP Toolkit compliance, strong encryption and strict access controls. AWS Tier 3+ data centres provide additional protection by ensuring independent power, network redundancy and continuous environmental monitoring. Together, these measures ensure the platform remains robust, secure and highly available. - Outage reporting
-
OneTouch reports outages and critical incidents using direct notification channels:
1. Direct Notification to Clients
Email Alerts: When an outage or critical system incident occurs, OneTouch notifies affected clients and key stakeholders directly via email. This ensures we inform those responsible for service continuity as soon as an issue arises.
Escalation Procedures: The 24/7 monitoring system automatically triggers alerts to our support and cloud management teams. If a client’s service is affected, the escalation process ensures we contact responsible personnel without delay.
2. Follow-up Communication
We send regular updates, incident post-mortems, and restoration notifications to clients as the situation is resolved.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
-
OneTouch restricts access in management interfaces and support channels through a comprehensive, role-based, and auditable access control system, combined with strong authentication and oversight procedures:
Role-Based Access: granular, by position template, least privilege enforced
Secure Authentication: unique credentials, strong password, MFA
Shared Credentials: Not permitted (except with explicit management approval and never for PII)
Access Provisioning: Verified identity, management approval, access removed upon role/contract end
Support Channel Access: Tiered, restricted to authorised staff with traceability
Audit & Monitoring: All activities logged, client defined retention period, regular review - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
-
Cyber Essentials Plus
NHS Data Security and Protection Toolkit - Information security policies and processes
-
Our IT Security Policy covers confidentiality, integrity and availability. Policies and procedures address all aspects of information security. Our policies permit access only as explicitly authorised, using role-based access controls.
We use programmatic access, with separation of customer data a core architectural principle. All requirements in the IT Security Policy are mandatory for every staff member, with managers responsible for ensuring enforcement.
Our Integrated Management System supports compliance with ISO27001, ISO9001 and Cyber Essentials Plus, with routine recertification and audits.
We document and monitor risks and compliance requirements, logging incidents in a Corrective System, which alerts Senior Management for investigation and action.
Annual internal and external audits underpin our Information Security Management System. Ongoing employee training and awareness refreshers support compliance. Regular reviews and testing ensure policies remain effective.
We educate staff to assess information sensitivity and protect data physically or electronically, enforcing encryption in transit and at rest.
Our CTO is the designated board-level owner for information security, with security and risk reporting reviewed by the Board. We escalate policy breaches, significant risks or incidents to Senior Management and ultimately to Board level for oversight and action. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- We apply strict configuration and change-management controls to maintain reliability, security, and full traceability. We track all service components, code, configurations, integrations and infrastructure, as configuration items throughout their lifecycle. Our teams document, version-control and log every modification, linking each change to its system dependencies. We assess all proposed changes for security impact, reviewing risks to data access, infrastructure and compliance. We develop and test changes in controlled environments, then deploy them only after they pass security review, testing and authorised approval. By enforcing these processes, we ensure every update is safe, auditable and aligned with security and operational requirements.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
We manage vulnerabilities through continuous assessment, rapid patching, and trusted threat-intelligence sources. We run monthly automated scans across all servers and systems and immediately review any new risks identified through vendor alerts, security notifications, or threat-intelligence feeds.
We assess each vulnerability using CVSS scoring and determine exploitability based on existing controls. We deploy patches for critical vulnerabilities within 48 hours, applying compensating controls if no patch is available.
We address lower-severity issues during scheduled patch windows and verify weekly. We rely on vendor advisories, NCSC alerts, industry threat-feeds, and annual CREST-accredited penetration testing to maintain up-to-date awareness of emerging threats - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
We monitor the platform 24/7 using a SOC, SIEM tooling, automated alerts, and comprehensive audit logs to identify potential compromises. Real-time thresholds trigger immediate alerts when abnormal activity occurs, supported by daily scans and ongoing threat-intelligence monitoring. When the system flags a potential compromise, the on-call security team receives an instant escalation and begins triage to confirm impact and determine required action.
We follow defined incident-management procedures, isolating affected systems, removing threats and applying remediation steps.
We respond to critical incidents within one hour and high-priority issues within eight hours, ensuring rapid investigation and containment. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
OneTouch follows pre-defined, ISO-aligned processes for common incidents such as data breaches, service disruptions and security threats.
Our Corrective System logs every incident and drives structured workflows from detection through resolution and post-incident review. Users report incidents through Zendesk, the online support portal, their Account Manager, or by phone for urgent issues. Staff can record immediate actions using built-in “Post-it” functionality. Once logged, an assigned incident owner investigates, manages remediation and communicates updates. We notify clients without undue delay—typically within 24 hours—and provide full incident reports, including root-cause findings and corrective actions, through our Integrated Management System. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
-
- Health and Social Care Network (HSCN)
- Other
- Other public sector networks
- MESH network
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 15%
- Between £250,000 and £500,000
- 16%
- Between £500,001 and £1,000,000
- 17%
- Between £1,000,001 and £2,500,000
- 18%
- Between £2,500,001 and £5,000,000
- 19%
- Over £5,000,001
- 20%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Business Quality Assurance International Ltd
- ISO/IEC 27001 accreditation date
- Wednesday 1 June 2022
- What the ISO/IEC 27001 doesn’t cover
-
Outsourced Development
oA.8.30 - deemed not applicable as OneTouch Health does not outsource any development activities. - ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Business Quality Assurance International Ltd
- ISO 9001 accreditation date
- Wednesday 1 June 2022
- What the ISO 9001 doesn’t cover
-
Resources
o7.1.5 Monitoring and measuring resources as OneTouch Health operates as a SaaS product, there is no equipment therefore this section is not applicable.
o7.1.6 Organisational knowledge - it was considered that this clause was adequately addressed in our Business Continuity and Disaster Recovery policies and deemed not to be applicable for this audit purpose. - Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Ae6e7268-3b74-4604-9e42-671dc46060ca
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- Bb165730-46dd-4076-8f16-567861bcb901
- Other security certifications
- Yes
- Any other security certifications
- NHS Data Security and Protection Toolkit
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How the supplier will work with NGOs, trade unions or other businesses to address modern slavery risk
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
- Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
- Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Other measures to provide equality of opportunity for disabled people and those with health conditions into employment, including becoming a Disability Confident employer and inclusion of supported businesses in the contract supply chain
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-