Xyla (CYP Therapies)
Xyla provides tailored, technology-based, one-to-one assessment and therapy for children and young people inline with the i-Thirve model focusing on 'getting help' or 'getting more help'. Our patients can access therapy 7 days a week (8am-10pm)
Features
- Remote, Technology-Based Therapy Solutions for patients
- Extended opening hours of 8am-10pm, 7 days a week
- Quick access to assessment and treatment
- Real time reporting of notes and clinical contacts
- Quick set up and service implementation
- Pool of over 2,500 active therapists
- Broad choice of evidence-based therapies available
- Scale up and down with agility
Benefits
- Patients can book appointments 7 days p/w around their availability
- Enhanced patient experience which removes need/cost for interpreters
- Recording routine outcome measures
- Provides clients with patient visibility and transparency of treatment
- Provide immediate support in line with local challenges
- Patients can take control of their care improving engagement
- Ability to scale quickly to support waitlist initiatives
- Removing geographical boundaries ensures we match therapists to patients needs
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
6 0 1 8 2 4 9 6 5 8 9 3 4 1 6
Contact
Xyla
Robert Taylor
Telephone: 0207 713 2757
Email: bid.team@xyladigitaltherapies.com
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Other
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
-
We have clear support processes in place for clinical, administration, and technical queries. Operational hours are outlined and confirmed in service level agreements before a contract commences.
Scheduled maintenance may occur from technology partner, Mayden (iaptus). These Suppliers provide advanced notification of scheduled maintenance where appropriate, which often takes place outside of operational hours.
Therapy sessions are delivered through Mayden (iaptus) using the video platform Jitsi. - System requirements
-
- PC / VM Server
- Email client
- Telephone
User support
- Email or online ticketing support
- Yes
- Support response times
- We resolve low-level issues within 24 working hours, medium-level issues in 48 working hours and technical issues within 14 working days.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
We supply in and out of hours support with specific support processes in place for clinical, administration and technical queries.
Clinical: Clinical support is available. During operational hours (8am – 10pm, Monday – Sunday), our clinical team are available for case management, clinical supervision and any risk management queries. We are also supported by a company wide clinical governance structure.
Administration: Available during operational hours.
Technical: Available through internal infrastructure during operational hours, and through technology partners.
All support is included in the pricing.
There are clear points of contacts throughout engagement for any levels of support required. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Our Therapists provide accessible mental health services to patients referred to our service through a range of remote and digital methods.
We use systems already in use at NHS Trusts, and therefore minimal induction to our service is required for Trust staff.
Our therapists complete a rigorous selection process; they are specially recruited and asked to conduct a detailed online interview to determine competence. All our therapists are registered with the appropriate professional bodies.
All therapists are provided with one-to-one training on iaptus. This training is augmented with the use of a shared intranet where they can access documentation anytime, anywhere through a secured network as well as helpful guidelines and workflows. Therapists are also offered a monthly webinar where they can access real time support from one of our supervisors.
To support their ongoing clinical development, therapists receive weekly and monthly supervision and have access to a specific email address where they can ask questions 24/7. - Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
- Excel - xlsx, xlsm, xlsb, xls, CSV
- End-of-contract data extraction
- We discuss exit planning from the start of the service so that we can establish expectations and agree processes. We can export data in a standard csv format or PDF via secure email if required, however, all clients have full visibility of patient records through the secure integration of iaptus, eliminating the need to transfer data outside of the system. Alternative formats and processes may be available and can be discussed during contract negotiations.
- End-of-contract process
-
We work to agreed contract terms, however, the nature of our contracts allow flexibility to upscale and downscale without notice, unless explicitly agreed from the outset. At the end of a contract, we simply cease to receive clinical data through iaptus, and cease to undertake any clinical services for the client.
All data is archived for the required period of 8 years through iaptus. This is included in the service we provide, and within the contract price.
Our service is designed to be easy-to-use and flexible. At contract end, client accounts can be deactivated immediately so there is no further data flow.
Customers only pay for referrals completed and processed through Xyla Digital Therapies, with no additional costs apart from DNAs and cancellations. Please see SLA for further information. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
Our service has been designed to enable accessible mental health to all patients referred to our service. Documentation has been created with the needs of our patients in mind, including:
• Information is in plain language and concise as possible
• The service is accessible via different communication channels
Information is accessible on websites that give users some control over their access to the information, as they can alter the font size, colour and contrast. Any additional information is sent via secure email, with user guides and documentation available, including frequently asked questions.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- All parts of the service can be delivered through mobile devices. This includes a designated app for communications. Functionality is web-based, responsive and can change appearance and layout according to screen dimensions. There is no functionality that is hindered by using apps or mobile devices.
- Service interface
- No
- User support accessibility
- None or don’t know
- API
- No
- Customisation available
- Yes
- Description of customisation
-
Xyla is extremely flexible, and the service can be customised in multiple ways to meet local demand. We provide a range of services including assessment, getting help and getting more help therapy. Our clients can choose to use parts of our service in isolation or in conjunction with others.
We ensure we always work in close partnership with our clients and adapt our offering based on local needs. Prior to implementation we find out the local requirement, and through ongoing account management we ensure this evolves in line with service needs.
Scaling
- Independence of resources
- We can gain real-time visibility of our staffing levels across any timeframe using the capacity planning report and diary functions in iaptus. In addition to this, we review both monthly and historic data to capture seasonal trends which enables us to manage staff numbers proactively and effectively. Our staffing partner Pulse ensures we have access to over 2000 CYP trained therapists. Pulse is well-established in recruitment and has an advanced compliance department; their speedy process allows us to be agile and effectively scale our workforce on demand.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
We can access and monitor granular pieces of information using iaptus, in line with the data set. This includes service performance, therapist performance, patient demographics and waiting times. Additional metrics we use to assess our service performance are:
- time into assessment
- time into treatment
- routine outcome measures
- session attendance
We also monitor our therapists on a weekly basis to ensure they are positively contributing to our overall goals and offer support through on going supervision and training. - Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Degaussing
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- Data export is completed securely via the infrastructure provider. Data export and reports are configured to meet user requirements as part of the implementation process.
- Data export formats
-
- CSV
- ODF
- Other
- Other data export formats
-
- Overnight extracts - Tab delimited text files.
- Report extracts .xls or CSV
- Data import formats
- Other
- Other data import formats
- It is not possible for users to import data
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- From the outset of a new contract and during implementation, Xyla agrees service delivery plans with technology partners to manage expectations around capabilities and service up-time. Given the nature of our service, and our clients’ needs, we remain agile and flexible in our approach. We do this through regular account management allowing us to forecast in advance the level of availability required to meet service demands. In addition to this, we have robust contingency plans that allow us to effectively adapt resources and functions to accommodate any last-minute changes that may arise. If we are unable to meet the demand of our clients, we do not charge for our service; it is only when a clinical contact has been completed that a charge applies.
- Approach to resilience
- This information is available on request.
- Outage reporting
- We communicate any issues clearly and quickly. Our onsite staff ensure reporting. We use email notifications to ensure ongoing communication throughout any outage.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- User profiles and restrictions will determine level of access as provided and vetted. Access is controlled by Xyla, so we can clearly define who has permission to clinical and sensitive information, and at what level. Different permissions can be granted depending on different levels of required access, and this is all controlled within the admin back-end of the system, centralised IT functions and IT partners. In addition, a monthly audit of user access rights is taken place by internal staff.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- Cyber Essentials Plus
- Information security policies and processes
-
Our robust suite of policies underpins our ISO27001, IG Toolkit and Cyber Essentials accreditation. Our Information Security Management System has processes for all governance and security aspects, including staff training, data protection and retention,
data transfer, hardware and access procedures.
Senior Managers (e.g. HR, IT, Operations) form our Information Governance committee, which reports to the Board, ensuring a whole-group and multi-role focus, and reviews performance and procedures.
Procedures for suspected/ actual information security incident (including near miss) mandate how each staff member should report, and what action is needed.
We record all incidents on InPhjase to ensure a consistent approach to collecting information, and mandatory steps ensure escalation to appropriate managers, and undertaking investigations within agreed timescales.
Our Clinical Director and Caldicott Guardian reports to ICO/ relevant third parties.
Information Governance committee reviews incidents to verify actions were appropriate and lessons are learned. To ensure policies are followed, all staff undertake training on Information Governance during induction, ensuring a baseline of knowledge.
Responsibility for Information Governance is included in staff code of conduct. This is reinforced by system protocols (e.g. mandatory password resets to approved complexity level). ISMS and documentation are available on intranet, not hard copy, ensuring version control. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Supplier-defined controls comply with configuration and change management processes within ISO27001. this is covered in our statement of applicability within the ISMS (Information Security Management System) following industry best practice as outlined in Cloud security principle 5 that significant changes are planned and communicated in good time. Changes are tracked in accordance with ISO27001. This ensures that all automated tests are run on every change as well as manual testing. Risk is assessed and any appropriate action taken to reduce risk to an acceptable level in accordance with our clinical risk policy.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
We conduct internal vulnerability assessments to assess risks we expose our environment to. This is backed by Search Results Web results CVE - Common Vulnerabilities and Exposures (CVE) and National Vulnerability Database (NVD) security bulletins which are delivered to us daily.
we utilise tools such as Qualys to conduct vulnerability scans of both our external facing infrastructure and internal infrastructure. we conduct penetration tests on our systems and applications a tleast annually and carry out remediation works based on the findings of the test. Internal processes facilitate the triage and patching process within 48 hours of a vulnerability being identified. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Generation of audit events, forwarded into our SIEM solution for effective identification of suspicious activity. Generated events analysed within the SIEM by SOC team.
Endpoint protection on servers with real-time protection enabled. Updated regularly to contain active threats as they appear. Creates event/alarm into SIEM.
When a potential compromise is discovered the information security team will investigate to determine if compromise is legitimate and active.
Compromise is isolated by revoking access/resetting password. A thorough investigation takes place to identify the initial vector of the compromise and follow the incident response process.
Incidents are prioritised, critical incidents are responded to immediately. - Incident management type
- Supplier-defined controls
- Incident management approach
-
Predefined process compliant with ISO72001-controls, coupled with Incident Response Policy.
SEIM-solution collates all information security events. Tuned to escalate alarms based on TTP/IOCs as well as anomalous patterns.
Reviewed by external SOC team who triage alerts to the Acacium Information security team for investigation.
Users can report incidents via Service-Desk-or-Information-Security-team which creates a ticket for investigation for the Analysis and Containment of any incidents.
Post-incident-review identifies lessons learnt and identifies opportunity for improvement, a post incident report is produced and given to relevant stakeholders and the board members.
Incident management process is regularly tested with tabletop exercises involving board members/technical-leads/incident-response-teams. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
- Health and Social Care Network (HSCN)
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 30%
- Between £250,000 and £500,000
- 31%
- Between £500,001 and £1,000,000
- 32%
- Between £1,000,001 and £2,500,000
- 33%
- Between £2,500,001 and £5,000,000
- 34%
- Over £5,000,001
- 35%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Alcumus ISOQAR
- ISO/IEC 27001 accreditation date
- Monday 12 June 2023
- What the ISO/IEC 27001 doesn’t cover
-
Our service is fully covered:
Scope of Registration:
The management of information security in the provision of staffing services for the health,
social care & life sciences industries. This includes the provision of community and complex
care services utilising digital solutions. In accordance with SOA version 1.8. - ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- QAS International
- ISO 9001 accreditation date
- Friday 29 September 2023
- What the ISO 9001 doesn’t cover
- Any services not relating to specialist healthcare solutions.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 9346ce34-769a-41a9-99c5-367fddab6296
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 8436e2c3-62ee-49d2-8e77-b49738978194
- Other security certifications
- Yes
- Any other security certifications
- Data Protection Register (ICO)
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Ensuring new workers are informed of their right to join a trade union
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
- Plans to respond flexibly and adapt approaches to community engagement and initiatives
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Working conditions which promote an inclusive working environment and promote retention and progression
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of issues relating to entering the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
-