Skip to main content

Help us improve the Digital Marketplace - send your feedback

Joy

Joy - Social Prescribing Software

Joy is a preventative healthcare and WorkWell platform that integrates with NHS medical records to identify patients needing support, connect them to local services, and measure outcomes. Used across 2,000 GP surgeries, it reduces demand for healthcare services and improves population health through AI, analytics, and behavioural science.

Features

  • EMIS and TPP SystmOne integration for in-workflow preventative actions
  • Sits on-top/launches-with of any NHS/Social-Care system (e.g.EPIC/ Rio/Cerner/Mosaic/LiquidLogic)
  • AI-powered directory of services
  • JoyNotes ambient capture, clinical notes, coding, and preventative prompts
  • AI Link Worker via messaging, guided service discovery and follow-through
  • Real-time risk stratification surfacing cohorts for proactive interventions (CORE20PLUS5 cohorts)
  • EHR-informed matching, personalise services by needs and eligibility
  • Insights dashboards: attendance, outcomes, before-after, demand reduction analytics
  • Configurable WorkWell and employment support referral pathways
  • WorkWell digital pathways integrated with community and preventative services

Benefits

  • 2.1x increase in proactive/preventative care referrals
  • 39% reduction in GP-appointment demand
  • 26% reduction in A&E demand
  • 60% of-patients attend services referred to; 20x-higher than verbal/SMS-signposting
  • Improve equity with targeted outreach based on stratified-risk cohorts
  • Scale personalised care without growth in link worker capacity
  • Prove value for money with before/after ROI outcomes/demand metrics
  • Improve commissioning decisions with live insight into service performance
  • Supports WorkWell delivery across health, employment and community partners
  • WorkWell digital preventative outcomes across employment and community pathways

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at support@thejoyapp.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

5 2 8 0 1 3 8 2 8 2 0 0 8 6 9

Contact

Joy Patrick Harding
Telephone: 07724467145
Email: support@thejoyapp.com

About your service

Service categories

Applications

Production and operations

Service industry and public sector operations

  • Healthcare
  • Adult Social Care
  • Children's Social Care
Multi cloud support
No

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Optum EMIS Web, TPP SystmOne
Cloud deployment model
Public cloud
Service constraints
Any routine downtime required for system maintenance is scheduled outside normal office hours.

A maximum 8 hour per month window is provisionally allocated for system maintenance, if required.

In any month when the maintenance window is to be used, customers are notified at least seven working days in advance.
System requirements
  • Modern web browser
  • Internet connection
  • Windows 11
  • 150MB hard drive space
  • 100MB working RAM
  • .NET 4.6.1 or greater

User support

Email or online ticketing support
Yes
Support response times
Within 2 hrs during normal working hours on weekdays only
User can manage status and priority of support tickets
No
Phone support
No
Web chat support
Yes
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
WCAG 2.2 AAA
Web chat accessibility testing
Our web chat support is delivered using Intercom, which is designed to meet WCAG 2.2 AA accessibility standards.
Onsite support
Yes, at extra cost
Support levels
Joy is provided as a fully managed SaaS with standard support included as part of the service subscription.

Standard support includes access to web chat and email support during UK business hours (9am to 5pm, Monday to Friday). This covers onboarding queries, user support, configuration guidance, incident reporting, and general technical assistance. There is no additional cost for standard support.

All customers receive access to our support team, who work closely with product and engineering to resolve issues and prioritise fixes. Issues are triaged based on severity, with service-impacting issues prioritised.

For larger deployments, integrated care systems, or complex programmes, enhanced support options can be agreed. These may include a named technical contact, more frequent check-ins, structured rollout support, and tailored reporting. Any enhanced support is agreed with the buyer and priced separately where required in line with our rate card on G-Cloud.

Joy does not require buyers to manage infrastructure. Cloud operations, maintenance, updates, and monitoring are handled by Joy as part of the service.
Support available to third parties
No
AI chatbot
Yes

Onboarding and offboarding

Getting started
Joy is implemented as part of a broader preventative healthcare ecosystem rather than a standalone tool.

We support organisations through a structured onboarding process that typically includes service discovery, marketplace configuration, integration setup, and user enablement. This work is delivered remotely, working closely with clinical, operational, information governance and IT stakeholders.

Initial setup includes confirming data protection and information governance requirements, completing relevant documentation such as DPIAs where required, and agreeing safe and appropriate use of the service. We support buyers through this process and provide the necessary technical and compliance information.

Configuration then focuses on defining use cases, agreeing priority service categories, setting up the marketplace, and enabling integrations with existing systems. Desktop components such as JoyConnect are deployed with support from local or central IT teams.

Training is provided through remote sessions tailored to different user groups, supported by written guidance and in-product prompts. Ongoing support is available via web chat and email during UK business hours, with phased rollout support available for larger programmes.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
Users can extract their data using the built-in bulk export functionality within Joy.

If users require data in a specific format or scope, Joy can provide a custom data extract. Custom extracts are delivered in line with user requirements and are priced separately in accordance with the G-Cloud rate card.
End-of-contract process
Access to Joy is removed in line with the agreed end date.

Standard contract pricing includes continued access until the contract end and the ability for users to export their data using the built-in bulk export functionality.

If a buyer requires data in a specific format or scope beyond the standard export, Joy can provide a custom data extract. This is optional and charged separately in line with the G-Cloud rate card.

After the contract ends and any agreed data extraction is complete, customer data is securely retained or deleted in accordance with Joy’s data retention and information governance policies, typically after 8 years of inactivity or earlier upon customer request.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
Yes
Compatible operating systems
Windows
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Joy is delivered primarily as a desktop-first service for clinicians and administrators.

The marketplace and patient-facing components are responsive and can be accessed on mobile devices via a web browser.

On mobile devices, the interface adapts to smaller screens and supports core tasks such as browsing services, guided self-referral, and viewing communications.

More complex configuration, reporting, and clinical workflows are optimised for desktop use to support speed, accuracy, and integration with clinical systems.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
Joy is a web-based service with interfaces for clinicians, administrators, service providers and patients. Clinicians and staff access Joy through secure web and desktop interfaces, while patients use responsive web pages for self-referral and communications
Accessibility standards
WCAG 2.2 AAA
Accessibility testing
Accessibility has been considered in the design of the service with patients.

The interface supports keyboard navigation and screen readers.

Feedback from users is used to identify and address accessibility issues.
API
No
Customisation available
No

Scaling

Independence of resources
Joy is delivered as a multi-tenant SaaS hosted on scalable cloud infrastructure. System resources automatically scale to meet demand, ensuring consistent performance as usage increases.

Data is logically separated between customers, and access controls ensure each organisation only accesses its own data. Monitoring and alerting are in place to identify and respond to performance issues.

Analytics

Service usage metrics
Yes
Metrics types
Joy provides service usage metrics including referral volumes, referral reasons, services used, attendance rates, and outcomes. Metrics also include user activity, service performance, and before and after analysis showing impact on demand, such as GP appointment reduction.
Reporting types
  • Real-time dashboards
  • Regular reports
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with another standard
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure

Data importing and exporting

Data export approach
Users can export their data using the built-in bulk export functionality within the Joy software.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Availability: 99.9%

In any calendar month in which we have unscheduled down time that causes the service level to drop below agreed performance level, the basic monthly charge is reduced by 5% for each full percentage below the agreed level, up to a maximum credit in that month of 100%.
Approach to resilience
Available on request

Joy is delivered as a cloud-hosted SaaS on resilient third-party infrastructure within the United Kingdom. The service is designed to maintain availability during peaks in demand through active monitoring and managed scaling.

Resilience is supported through redundancy across core platform components, regular backups, and documented recovery processes. Planned maintenance is scheduled outside normal office hours and communicated in advance.

Details of our datacentre resilience setup, backup and recovery, and disaster recovery arrangements are available to buyers on request.
Outage reporting
Email alerts

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces is restricted to authorised staff using least privilege and role-based access controls. Administrative access requires strong authentication and is logged and monitored. Privileged actions are audited.

Customer support access is controlled through named accounts and permission-based workflows. Support staff can only access customer data where necessary to resolve an issue, and access is time-limited where possible. Sensitive actions, such as configuration changes or data exports, require additional approval and are recorded.

We do not share credentials, and access is removed promptly when roles change.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Dedicated link (for example VPN)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
Between 6 months and 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Joy follows an information security management system aligned to ISO 27001 and Cyber Essentials Plus.

Information security is owned at senior leadership level, with clear accountability for security risks, incidents and compliance. Policies cover access control, encryption, secure development, vulnerability management, supplier management, incident response, business continuity, and data retention and disposal.

We enforce least privilege access, role-based permissions, and multi-factor authentication where appropriate. Changes are controlled through documented processes, with audit trails for administrative actions. Security events and incidents are logged, triaged and managed through an incident response process, with notification to customers where required.

We ensure policies are followed through staff training, documented procedures, regular reviews, and independent assurance activities, including penetration testing.

Compliance is monitored through routine checks and management review, and actions are tracked to completion.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Joy uses documented configuration and change management processes aligned to ISO 27001. Service components and configurations are tracked through their lifecycle using version control, ticketing and audited release records.

Changes are proposed, reviewed and approved before deployment. Each change is assessed for security impact, including access, data handling, dependencies and potential vulnerabilities. Changes are tested in non-production environments and released using controlled deployments with monitoring and rollback plans. Emergency changes follow an expedited process and are reviewed after release.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Joy follows a vulnerability management process aligned to ISO 27001. We assess threats through risk-based triage of vulnerabilities affecting our codebase, dependencies and cloud services.

We monitor for new issues using vendor advisories, security bulletins, dependency scanning, penetration test findings, and threat intelligence sources such as NCSC guidance. Vulnerabilities are prioritised by severity and potential impact on confidentiality, integrity and availability.

Critical security patches are deployed as soon as practicable, typically within days. Other patches are scheduled through normal release cycles, with testing and controlled deployment. Mitigations and compensating controls are applied where patching is not immediate.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Joy uses protective monitoring aligned to ISO 27001. We monitor system and security logs, access activity, and service health to identify suspicious behaviour, abnormal usage patterns, and potential compromises.

Alerts are triaged by severity. Where compromise is suspected, we follow an incident response process including containment, investigation, remediation, and post-incident review. Access can be restricted and affected components isolated as required.

We respond to high severity security incidents as soon as practicable, typically the same day, with ongoing updates provided to customers where appropriate. Lower severity alerts are investigated and resolved through normal operational processes.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
“Joy follows documented incident management processes aligned to ISO 27001. We have predefined runbooks for common events such as service degradation, security alerts and integration issues.

Users can report incidents through web chat or email. Incidents are logged, triaged by severity, and managed through containment, investigation, resolution and post-incident review.

For significant incidents, we provide status updates during resolution and share an incident report afterwards. Reports summarise impact, timelines, root cause, corrective actions and any required customer actions.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
Yes
Connected networks
Health and Social Care Network (HSCN)

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Y Citation ISO Certification Limited
ISO/IEC 27001 accreditation date
Saturday 6 January 2024
What the ISO/IEC 27001 doesn’t cover
Our ISO/IEC 27001-certified ISMS covers the people, processes, and technology used to design, build, host, operate, and support the Joy service.

Items outside the certification boundary are limited to buyer-managed environments, for example end-user devices, local networks, and third-party clinical systems.

Where Joy interfaces with third-party services or platforms, these suppliers are managed through vendor assurance, contractual controls, and our information governance processes, but they are not themselves covered by our ISO certificate.
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
43dc8d04-da63-4ae8-b872-0f5e7f66af7f
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
5a6ab350-aee7-4782-b355-e13c6722e3cb
Other security certifications
Yes
Any other security certifications
NHS DSPT: https://www.dsptoolkit.nhs.uk/OrganisationSearch/8KN75

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
    • Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Creation of outreach activities to create a pipeline of employees for the future contract delivery
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Actions to invest in the physical and mental health and wellbeing of the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at support@thejoyapp.com. Tell them what format you need. It will help if you say what assistive technology you use.