getUBetter self-management digital therapy
getUBetter is a digital health platform that enables patients to self-manage musculoskeletal conditions and women’s pelvic health. The platform supports recovery and prevention by following pathways defined by local healthcare providers and connects patients to local treatments and services. Add-on packages are available to support orthopaedic peri-op, pain-management and comorbidities.
Features
- Patient pathway management: safety netting, recovery, referral, rehab, waiting-list, prevention
- One app for all common minor injury and conditions
- Bespoke content and pathways configured to each place in ICS/organisation
- Accessed via self-referral or prescription by clinical teams
- Self-referral to local treatment and services (NHS/non-NHS and community)
- Questionnaires, nudges, video content and risk stratification to guide patient
- NHS app login and a Digital Triage and Referral System.
- Real-time data analytics dashboard
- Medical device registration (CE marking)
- Data security, evidence-based and approved by NICE
Benefits
- Creation of lived experience pathway improving patient self-reliance recovery
- Safe self-management re-assuring patient confidence in recovery engagement
- Improved patient access to associated local health knowledge and expertise
- Reduction in unnecessary burden on primary, secondary and emergency healthcare
- Automated referral system reducing clinical manual triage time
- Enables patient immediate access to easy-to-use standardised healthcare
- Significant reduction in patient prescribed strong opioids
- Reduced referrals and appointments onto physio services
- Reduced GP appointments, impatient activity, 111 and 999 calls
- Managed self-care enabling reduction in patient numbers on waiting list
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
6 1 4 8 4 0 9 4 6 5 7 9 1 7 7
Contact
GET U BETTER LIMITED
Gavin Ford
Telephone: 07952228499
Email: contact@getubetter.com
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Community cloud
- Service constraints
- All maintenance work is planned in advance to ensure minimal disruption levels to customers and such works are normally carried out between 00:00--02:00 am. getUBetter Apps operate on iOS on 13.0 onward and Android on 5.1 onward
- System requirements
-
- A Smartphone , PC or Tablet
- Access to the internet
- Web Browser: Google Chrome, Safari, Firefox, Microsoft Edge
User support
- Email or online ticketing support
- Yes
- Support response times
- We respond to 90% of patient user questions directly, via in-app help options, and the remaining via patient emails to our customer service inbox. All incoming customer queries are allocated a priority status and managed as individual support tickets, tracked and if necessary escalated to appropriate team member for more specific support. All enquires are handled to our specified service levels.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
All patient and client user support is provided as part of our contract cost. For the duration of our contracts, we provide professional, consistent and focussed support. This includes named consistent project mgr, project and engagement representative and clinical representative. Additional support is called on according to need. This forms a relationship within which clients and getUBetter can work in a collaborative iterative and supportive manner so to increases awareness, understanding and the sharing of techniques to drive patient adoption of digital self-management.
We manage all in app-user and emerging technical enquiries as matter of priority and measure our performance against service level targets such as time to respond and customer satisfaction and service availability. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Users are supported to start using getUBetter through simple, low-friction onboarding embedded within existing NHS pathways.
# We make access as simple as possible via a few different routes; either self-refer from posters, GP websites or more direct referral/signposting directed by the patient healthcare service. Access is enabled from all in-scope healthcare settings so can include GP practices, MSK services, CAT/MATS teams, all Hospital trust settings, pharmacies, occupational health services and re-hab settings. Tools to signpost users include; SMS, web link, QR codes, email, letters or simply word of mouth.
# We work closely with clinical and non-clinical teams to support and enable access. Our deployment process includes a share and set up of all the knowledge the health care setting needs to understand when, how and why to signpost patients to getUBetter. This would typically include delivering remote awareness sessions, providing training resources, producing localised communication materials (including social media templates), Community and Outreach days and supporting integration with triage and communication platforms. These activities help embed getUBetter into local patient pathways and promote engagement in self-management.
# Additional support is provided at assessment days and community or outreach events to help patients access and begin using the app. - Service documentation
- Yes
- Documentation formats
-
- Other
- Other documentation formats
- Microsoft Word
- End-of-contract data extraction
- As part of our standard contract support provisions, we provide a data extraction facility. If and when the getUBetter service has been terminated, and dependent upon Data Controller definitions, the client will be provided with an opportunity to receive CSV formatted data, collected for their registered patients. Specific details of inclusive data will be discussed as part of the off-boarding service.
- End-of-contract process
- This contact provides for an Exit Plan, setting out the requirements and actions to support the client and getUBetter execute a safe and controlled withdrawal of the getUBetter application and support. Our exit plan will consider supporting all the associated health services so might include primary, secondary, or other healthcare providers that have benefitted from access to the getUBetter service under that contract. The exit is planned around a 'deactivation' event whereby all users of the getUBetter service will be informed; of the decision, timeline and actions required prior to deactivation; informed of deactivation and supporting guidance when it happens; and directed to the alternate resources available after deactivation. Typically, we stop all new patient users registering within getUBetter at deactivation and aim to support all existing users for a short period after deactivation. All in-app patient users are directed to locally hosted information pages for a further understanding of de-activation.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- MacOS
- Windows
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Our application is a hybrid application so applicable to both android and iOS platforms. The platform is also available to tablet and desktop web users. The only difference is that for the mobile or tablet patient user downloads the application to a device whereas desktop option is via sign-in option on our website www.getubetter.com (also a second option for tablet users)
- Service interface
- No
- User support accessibility
- WCAG 2.2 AA
- API
- No
- Customisation available
- Yes
- Description of customisation
-
The getUBetter service enables multiple customisation themes...
(1) Clinical; Clinical recovery pathways are customised to reflect local pathway requirements. Working with local clinical teams we ensure the in-app user patient users are guided and signposting through a self-management pathway that reflects the current local clinical care pathway. For example, patients users are directed to identified local clinical settings; signposted, and provided access, to local treatment and services.
(2) Patient in-app user; getUBetter clinical pathways are branded to user GP practice with logos and contact details so maintain sense of connection for user to healthcare within user self-management experience
(3) Reporting. Real-time data dashboard specific to the ICS sub divided to Trusts, PCN GP practices
(4) Onward referrals. Once 'in-service' the ICS team have opportunity to activate and automate the Digital Referral Triage Service, so enable patients, when necessary, to self-refer into local Physiotherapy services.
Scaling
- Independence of resources
- Our partnership with our UK based Cloud Assured hosting structure provides the infrastructure to enable rapid provision, scale up and speed of data transfer to meet demand. All data is held within Cloud Assured servers configured to ensure data is neither compromised nor affected by other ICS customers. Our application is powered to enable a flexible platform and data model that can accommodate approximately 200,000 active, concurrent users and 10,000 condition pathways. We monitor and audit the technology stack so assure our clients we can safely scale across all in-service regions.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
A key aspect of our support programme is the sharing of statistics and insight collected from our data sources, typically considering patient adoptions and in-app behaviours. We aim to provide a sense of impacts and benefit realisations via frequent consistent reporting packs that illustrate key performance indicators as defined in contract or asked of in project set ups.
A key insight will be the interpretation and realisation of projected service benefits, patient demographics and access behaviours to associated services. - Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
- Physical access control, complying with SSAE-18 / ISAE 3402
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Dependent upon the requirement and agreed definition of Data Controller responsibilities getUBetter offer bespoke data extracts on one-off or regular basis
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- Private network or public sector network
- Data protection within supplier network
- Other
- Other protection within supplier network
- Our network service is protected using encrypted sessions over resilient fibre optic connections, regularly and independently validated by the NCSC Assured Service - Telecoms (CAS-T) scheme. Our Cloud hosting service provider conducts regular independent Security Health Check Test to assure all data is protected to the UK standards. We hold no patient data anywhere other the UK. Data is transmitted to patient devices over the public internet with appropriate security applications and access to application enabled using multifactor authentication controls to include 2-factor authentication. Our platforms are SSL secured with access control applied to all data sources.
Availability and resilience
- Guaranteed availability
- GetUBetter strive to achieve 99.99% service availability. There is no financial compensation if target service levels are not achieved.
- Approach to resilience
-
Our data centre service is UK hosted. the locations have been visited and assessed during formal accreditation activities undertaken by accreditors and assessors from the National Cyber Security Centre, Home Office (PASF) and by BSI and Lloyd's Register (LR) external assessors during routine ISO9001, ISO20000, ISO22301, ISO27001, ISO27017 and ISO27018 certification assessments.
All data centres are protected by a robust framework of physical, technical and logical security controls, which ensure the data, applications and ICT infrastructure are afforded the highest possible levels of protection and resilience. As part of our business continuity capability we maintain, evaluate and improve our availability and resilient as defined by the Well-architected framework so adopt best practices to build and secure a high-performing and resilient cloud system. - Outage reporting
-
Our service resides within Cloud Hosting facility who operate a Network Operations Centre (NOC) that supports the service on a 24/7 basis, which is responsible for monitoring the health of the Cloud platform and carrying out routine tasks. A framework of monitoring tools, such as SMS and outage support channels, provides an early warning system that allows for the identification of potential service issues before they can impact us and our customers. In the event of service disruption, the NOC is the primary focal point for major incident management. It co-ordinates the recovery actions with us to ensure remedial actions are completed.
Service disruptions are also communicated via the Service Status webpage to use, and we email project sponsors in our Customer base details on the incident. This will provide the status of an issue in addition to the follow up report that will describe what, when, how and why the incident occurred.
Our disaster recovery policy details how we manage, respond, recover and report to appropriate services any data breach triggered by any service outage
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
-
Access to any data and getUBetter servers is managed by a strict access policy for our Cloud facility to include several technical controls to ensure only authorised getUBetter individuals can authenticate to and access the getUBetter services for which they have an identified and approved business need. We are required to have a unique username and password and MFA authenticator process.
Access Control Policy places specific responsibilities on “super user” or administrative accounts, which are not used routinely for normal support or development tasks. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- No audit information available
- Access to supplier activity audit information
- You control when users can access audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- Although not certified, we follow controls and standards, and subsequently bi-annually assessed on a quarterly basis, on standards to reflect ISO27001 security standards, and are cyber essentials plus certified. We follow GDPR principles through our information governance processes and provide evidence of all as part of our contractual obligations.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- As a registered medical device, CE compliant getUBetter operates a quality management system for all configuration and change management requirements, aligned to ISO13485. The application and related components are tracked through their lifetime and all change enabled via our internal ticketing system and controlled application test and our release management processes. All changes are tested in a pre and postproduction environment supported as appropriate by clinical oversight to any clinical based changes. We provide evidence of all appropriate clinical safety controls as part of our contractual obligations.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
Our Release Management Policy covers the identification and assessment of threats, vulnerabilities and exploits which could impact our technical stack and/or services.
Servers are monitored and updated ensuring the latest security patches are applied within 2 weeks of issue. If no patch is available, where possible a manual fix is Implemented until an official patch is released.
Monthly and Annual penetration testing of servers is conducted using OWASPs top 10 vulnerabilities.
For urgent matters we deploy patches in 12 hours and for less so, 36 hours. Our hosting provider is CSA CCM compliant and listed on the CSA STAR registry. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
Our hosting provider have Assured Elevated Platforms protected by a GPG13 aligned protective monitoring system externally provided by e2e-assure. This monitors and alerts on the twelve control areas documented within GPG13 (PMC1-12) at the DETER Level and includes the production and retention of user activity logs to support monitoring, incident identification, response and investigative activities. It also includes activities related to the formal notification to the relevant authorities.
Additionally, we maintain our own SIEM control mechanism, defined by the NSCS cyber assessment framework to; manage the risk; protect against attack; detect security events; minimise impacts to monitor and track threats. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
The Cloud facility and our SIEM retains tools to monitor the live service and provide real time live service monitoring information. Feedback on the live service is reviewed by the development team and acted on as required.
Patient user’s report incidents via a contact@getubeter.com mailbox.
Where the service is interrupted due to service incidents, a web page or dialog will be displayed to advise users.
Safety incident communication is managed by our service desk and where necessary user service bulletins provide instructions for dealing with safety incidents through the application help pages.
Root cause analysis is completed for all incidents - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
- Public Services Network (PSN)
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- At initial stage of engagement, we provide a demo workshop to all interested commissioner stakeholder individuals. If the associated organisation chooses to pursue their interest further, we provide access to our demo version of the product. The demo app provides the full user-experience, in a test, not live, environment.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 15%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Fde0883b-aa60-47ec-8dd4-43b3f7741814
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 2747a3bf-f876-49bf-a667-68af0b211fd3
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-