Graphnet Shared Care Record
Graphnet Shared Record Integration Exchange Platform provides real-time, secure, unified shared care records via Clinical & Patient Portals; system integration/interoperability; CareConnect FHIR standards support; data capture forms, care plans, End of Life including workflow; mobile solutions; Personal Health Records, Population Health, Analytics and innovative long term condition management solutions.
Features
- Real-time shared record solutions, used by 120,000+ care professionals
- Engaging and intuitive to use, with local configuration options
- Browser and mobile access, including support for offline working
- Seamless and secure navigation from local systems
- Pre-configured data feeds available from leading care systems
- Secure access, robust consent models and comprehensive audit trails
- Simple creation of rule-based forms, including assessments and plans
- Innovative use of wearable technologies/Apps/monitoring devices
- Patient Portal enabling citizen engagement in their care
- Proven business intelligence and reporting
Benefits
- Safer, more targeted, coordinated and timely care across settings
- Reductions in A&E attendances, unscheduled admissions and Length of Stay
- Cost savings for unwarranted activities, e.g., appointments, admissions and tests
- Improved communication and access to information for care professionals
- Reduced clinical risk e.g. through more efficient medicines reconciliation
- ‘Do once and share’: A reduction in duplication of effort
- A reduction in the need for, and use of, paper
- Improved management of complex and life-limiting conditions
- Enablement of patient participation and engagement in their care
- Better outcomes and improved quality of life
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
6 3 7 7 7 5 5 1 3 1 1 5 2 7 4
Contact
GRAPHNET HEALTH LIMITED
Lisa Haslam
Telephone: 03330771988
Email: salesandbids@graphnethealth.com
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- The service is based upon a very 'open' software stack and deployment model. Specifically though; - Browser access must be based on the approved list below - Mobile device access must be based on supported mobile operating systems (IOS, Android as primary platforms) - Mobile device management is not included - just the clinical applications - The local deployment model *may* by constrained by local IG and security policies regarding presentation of secure information via N3 or public networks.
- System requirements
-
- Microsoft Edge (Chromium, not including use in IE Mode)
- Google Chrome
- Firefox
User support
- Email or online ticketing support
- Yes
- Support response times
- Support is available on commencement of the project and we offer a variety of support packages. Each support package includes full details of call priority rankings and the corresponding response times agreed with the customer.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- Options to suit customer's need. Typically 9 - 5.30pm, 24/7 or other daily times possible subject to agreed SLA and commercials. Costings depend on the number of product and user licences required. Support engineers are supplied as part of the Service Desk provision as specified under the Service Level T&Cs for each customer.
- Support available to third parties
- No
Onboarding and offboarding
- Getting started
-
When onboarding a user, Graphnet distinguishes between -
1. The ‘Organisations’ providing Health and Social Care Services.
2. The individual users employed by the Health and Social Care organisations.
3. Patients using the Shared Record.
Helping ‘Organisations’ involves;-
•Supporting organisations to provide an interface or data feed into the Shared Care Record (SCR).
•Supporting ‘In Context Single Sign-On (SSO) from the organisations Electronic Patient Record (EPR) into the SCR.
•Information Governance – we have an information governance team who help the customer attain the necessary DPIAs and with any public consultation etc.
•Project Management – including the supply of fully populated Prince artefacts such as Project Initiation Documentation, project plans, risk logs etc.
Supporting the individual users involves;-
•Training - Graphnet provides a tailored Train the Trainer programme and specialist training for end users (including both clinicians and specialist users such as system administrators). We have clinicians who support this.
•On line videos and eLearning packages.
•Drop in sessions and floorwalking support.
Supporting patients;-
In order to enthuse patient engagement and ensure patients are fully informed as to their rights around data sharing a series of patient inclusive events will be hosted to explain the SCR and the benefits available. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
In each agreement Graphnet provides a Project Initiation Document (PID), a component of which is an agreed exit plan detailing how data would be provided back to the customer should the contract end. The documentation always includes details of Graphnet’s obligations to transfer data and will detail an agreed format.
The exit plan details the various aspects of the shared record, specifically.
Data Sharing: Data supplied from the provider organisations into the Shared Record.
Care Planning: Data entered directly into the Shared Record.
Population Health: Data analysed including feeds direct to the Population Health platform.
Personal Health Record: Data supplied by the citizen.
Users can then extract their data at the end of the contract through a process facilitated by Graphnet. This involves accessing a designated data extraction tool. Users can select the data they wish to export, specifying the format and destination for the extracted data. Graphnet also commit to provide additional support to ensure a smooth transition and compliance with data protection regulations. Clear communication and documentation will be provided to support users throughout the extraction process adhering to industry best practices and regulatory requirements. - End-of-contract process
-
6 to 12 months prior to the contract expiry, Graphnet will work with the customers senior leadership, finance and contract management teams to discuss what options are available. Options to discuss would include.
Non-Renewal: Clearly we hope that all contracts are renewed, but in some rare cases contracts do expire. In such cases where appropriate provisions are made such that any information entered into the Shared Record is returned in a format agreed with the customer and that here is a managed transition to a new system.
Renewal: Contract is renewed. Contracted components and/or participant organisations may alter.
Should the contract no longer be required Graphnet will offer the provision of other reasonable termination assistance at the Authority’s request at the Supplier’s standard rates (e.g. to assist with data migration to the replacement contractor’s system). In addition, if necessary, a “read only licence” for historic data is offered. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Linux or Unix
- MacOS
- Windows
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
The clinicians view of the Shared Record is via a Web Browser. The Patients view of the Shared Record is via the App.
Subject to Role Based Access Controls (RBAC) a Clinician can see the whole or part of the Shared Record including Primary, Secondary, Social, Emergency and 3rd Sector data. Clinicians can create Care Plans which are shared to other NHS and provider organisations.
App access is for the Patient to view information and is metered to ensure only Patient facing content is surfaced. Patients can add data to their record such as measurements (BP/weight etc.) or care preferences. - Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Graphnet Shared Care Record has a clean, modern and intuitive user interface, designed in collaboration with a wide-range of our users. The system uses native operating systems, with screens designed for each device to achieve the best user experience. Secure access to information is rapid, with meaningful landing page views, pre-configured to meet the requirements of specific groups of users. Consistent screen layouts and unambiguous, familiar navigation tools simplify use and engage users. Landing page summary tiles display key information, with further details a click away.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- Our solution has been designed taking into account the W3C Web Content Accessibility Guidelines and also to meet NHS CUI guidelines and general user experience (UX) standards such as material design and iOS human interface guidelines for mobile products. We undergo testing during the design process to support colour blindness, high contrast settings and use of iconography as well as colour in key areas of the application, and the system works with screen readers via the browser and is tested with leading screen readers. We offer an intuitive system. In particular: • Information tiles can be configured to present data in a variety of formats, font sizes etc. • Tiles have a simple and clear layout, with a consistent, easy to read text spacing, and colour contrast • Graphnet Shared Care Record uses a standard CUI interface, users can interact with both keyboard and mouse, navigation is consistent throughout. • Headings and labels describing content, simple and unambiguous • Icons are intuitive, graphics are used where possible to simplify content meaning.
- API
- Yes
- What users can and can't do using the API
- The data accessible via APIs will depend on the permissions of both the user and the system integrating with the APIs. The majority of data is available to be queried via FHIR APIs, which are the preferred APIs for third parties to use as they are well supported with easily available libraries and tools. This includes data such as demographics, encounters, problems, allergies, immunisations, clinical observations, etc. Some datasets may not yet be fully available via FHIR, but we have other non-FHIR APIs which can be used if required until the required data is implemented in FHIR. APIs can also be used to contribute data into the shared record directly if applicable.
- API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Graphnet utilises Roles Based Access Controls (RBAC) to govern both the extent of the patient data users can see, but also the format of such data. Within each of the 5 RBAC levels, there are multiple different specific job roles each of which can be configured to a specific view. This allows, amongst other things, for users to define which landing page is most pertinent to their role.
RBAC allows for further levels of customisation. These are:
Functional access: what functions the user can access in the system.
Data access: which categories of the patient’s information the user can view
Users access can be customised by utilising the “Patient Groups” functionality, allowing configuration of which organisations records users can access.
SysAdmin functionality from Graphnet Shared Care Record management module allows further means of tailoring the solution to meet your local preferences and configuration requirements
.
• Choice of Data Integrations
• Choice of Optional Modules
• Choice of 3rd party system interoperability integrations.
There can also be local forms in a system such as assessments and care plans which can be designed and customised locally.
Configuration would be implemented either by Graphnet or customer authorised staff.
Scaling
- Independence of resources
- We use Platform-as-a-Service capabilities within Microsoft Azure Cloud to ensure our high scalability and availability requirements are met. Our application tiers utilise auto-scaling based on system demand, as well as clustering at the data layers with appropriately scaled resources (including headroom and automatic data expansion). In addition, we have in-depth monitoring capabilities allowing us to observe capacity and be proactively alerted when thresholds are met before end-user performance is adversely affected. This is a key consideration in our design approach which influences the hardware platform, software design and associated processes covering Support and Maintenance, Business Continuity and Disaster Recovery.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Monitoring utilisation is a key aspect of Gaphnet’s customer management as usage underpins value for money. Some Key Performance Indicators include:
•Total users accessing the system
•Unique users accessing the system
•Number of Patient records accessed
•Number of tiles viewed
•Organisations accessing the system
•Number of API calls and response times
•Number of patients with care plans
•Care plans viewed
•Population Health reports run per month
•Number of Population Health users
•Number of Remote Monitoring alerts
•Performance
•Availability
•Calls closed within and out of SLA
•Screen/transaction response performance via Azure - Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
-
Users export their data through a user-friendly interface provided by Graphnet. Upon accessing the designated export feature, users can select the specific datasets they wish to export, choosing from various formats such as CSV, Excel, or PDF. Our solution offers options to customize the export settings, allowing users to tailor the output to their requirements.
These extracts can be ad-hoc or scheduled. Bespoke extracts can also be setup using Microsoft Azure functionality into any supported system, and this service is further enhanced by our population health module that has rich features for data analysis and extraction. - Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- Other
- Other protection between networks
- Graphnet deploys the industry leading Cloudflare application security service across all customer systems which provides enhanced protection of customer data against increasingly sophisticated Internet based threat actors. It acts as a gateway from the Internet to the application interface and examines all traffic passing through it protecting against the following threats: distributed denial of service attacks, rogue bots, cross site scripting, zero-day vulnerability attacks and Web Application Firewall functionality based on the ‘OWASP Top 10’. If required, IP “allow lists” can be also applied to the interface to manage where connections can originate from.
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
Graphnet's guaranteed availability is 99.9% excluding agreed maintenance windows out of hours.
Graphnet recognise that each solution provided are all critical for the provision of safe and effective care. To that end Graphnet have multiple systems and procedures to ensure the solution(s) are available to users.
When deployment issues are logged they are immediately triaged to determine the extent to which the availability has been affected. The levels of severity and the associated resolution time are detailed below.
P1 (Critical) Entire system unavailable/unusable. Resolution: within four hours
P2 (High) Significant loss of the service but the impacted business function is not halted. Resolution: within eight Hours.
P3 (Medium) Significant loss of the service but the impacted business function is not halted. Resolution: Resolved within one hundred and twenty Hours.
P4 (Low) defined as Intermittent or partial faults resulting in loss of non-critical functionality where the software is still useable or there is a suitable alternative. Resolution: within twenty days
The recovery time objective (RTO) is four hours and the recovery point objective (RPO) is 0.5 hours from the initial incident. - Approach to resilience
-
Graphnet recognise the fact that sharing patient data from disparate Electronic Patient Records (EPRs) into a single patient record is now fundamentally relied upon for the provision of safe patient care.
Graphnet's hosted Azure service is robust, secure and highly available hosting service. Microsoft Azure meets a broad set of international and industry-specific compliance standards, such as ISO 27001, HIPAA, FedRAMP, SOC 1 and SOC 2, as well as country-specific standards.
Graphnet maintain numerous Operational standards which are designed to further ensure the provision of a resilient service. These include:
Business Continuity Process: Mitigation against, fire, bombing, flooding and area wide outage etc.
Quality & Security Processes: Ensure quality solutions are deployed safely and securely.
Risk Assessment Processes: Continually reviewing recognised risks and mitigation processes.
Access Controls: Ensure only approved staff have access to customer environments.
Penetration Testing: To mitigate against malicious attacks.
In the rare case of a system outage, Graphnet will declare a “Priority 1” incident whereby support services are as a norm extended to 24/7 with a target resolution of 4 hours. - Outage reporting
- All outages are recorded as part of the incident management process and should a problem be detected then the service desk will inform the customer by phone, email, and via the automated Jira alerting system that also gives a link to a dashboard. There are alerts configured for the application that trigger an automated ticket creation in Jira (service desk) and these are automatically sent to the customer. Thus the customers are alerted in 3 separate ways, telephone, email and Jira alert. We also have the ability to utilise Atlassian's Status Page to report on Unplanned Outages and Deployment downtime windows. This is reserved for common shared infrastructure components that impact could impact several or all our customers.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- All Graphnet Shared Care Record applications support in-built Role Based Access Control (RBAC) functionality which manages which functions a user has access to and which views of data they are able to see. The system includes 25 pre-configured roles, which align with the National Registration Authority Smart Card access roles and are grouped into 5 granular levels of system functionality. Graphnet Shared Care Record has a well-established concept of Patient Groups, which supports the ability to control which users, roles and groups of users have access to which groups of patients. System Administrators can also further refine permissions, as required.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
-
We comply with NHS standards and best practice guidelines. Standards/accreditations include; •ISO27001:2022 •ISO9001:2015 •Data Security and Protection Toolkit •Cyber Essentials Plus.
Graphnet's ICO Registration is Z1045461. Other SCCIs/ISNs applicable to shared care record solutions, including DCB 0129 and DSCN14-2009. - Information security policies and processes
-
We have ISO 27001 and Cyber Essentials Plus certification, supported by policies ensuring compliance with Information Governance and Information Security requirements. These include:
•Access Control
•Quality and Security Policy
•Clean Screen and Clear Desk
•Control of Records
•Secure Software and Solution Development
•Key Management and Encryption
•Data Transfer (Encryption)
•Secure Disposal
•Acceptable Use
•Network Control
•Password Management
•Cyber Incident Response Plan
•Business Continuity Plan
Additional guidance and policies provide assurance for our Data Processor obligations and internal responsibilities.
We have a Governance Board which our CFO and SIRO, Information Governance Manager (Data Protection Officer), Information Security Manager, ISO Compliance Manager, sit on. Through these key roles we ensure policies are reviewed and amended in light of any issues arising, audit reviews and process changes etc.
Policies are available to all staff via our employee hub which requires staff to read all required policies.
We incorporate Crown Commercial Service’s Generic Standard GDPR clauses in all our contracts where we process personal data; we process in compliance with Article 32. Where services use the “cloud” this processing adheres to the fourteen National Cyber Security Centre cloud service security principles as applicable to UK OFFICIAL and the cloud host complies with ISO27018. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
To ensure the security and reliability of Graphnet's solutions, Graphnet follow a 5 phase configuration and change management process.
Development and QA and internal only proof of concept (POC) activities
Customer facing POC work.
Build of all pre-production systems that may go on to hold customer or
Graphnet data (deployment phase work)
BAU customer systems provided by Graphnet including all UAT,
Sandpit, Training, Testing, Production or Live systems.
All systems managed out or curtailed (including part of customer and
data egress) where there is a requirement for secure planning for data
clearance and reuse for other purposes or secure disposal. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Graphnet monitors NHS CSOC Cyber Alerts, US-CERT and other industry sources for intelligence regarding threats, vulnerabilities and exploits.
Vulnerability assessments of the application and its components are performed within Azure and any findings are investigated and appropriate remedial actions taken.
Vulnerabilities are managed through a cycle of regular patching for the IaaS elements within 14 days of the patches being made available. The Microsoft Azure platform handles the patching of the hardware infrastructure and PaaS components. Any out of band, critical or high severity patches or fixes will be applied according to the suppliers’ guidelines. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- The application undergoes continuous monitoring by a third-party Security Operation Centre (SOC) using Microsoft's Sentinel, Defender for Cloud, and Azure policies. Anomalies trigger alerts, including suspicious/malicious activities. Audit logs for Azure, web app, and SQL server activities are retained for one year, while application logs are kept indefinitely. The SOC responds to alerts within agreed SLAs, escalating critical issues to Graphnet staff. Operational support receives email alerts for audit findings, investigating them promptly. Proactive monitoring addresses environmental triggers like low disk space and high CPU usage. Anti-malware software ensures vigilance against malicious software or activities.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Incidents are formally managed through Graphnet's Support Desk, using an ITIL focused call logging application to record, track and manage issues through all stages of the incident lifecycle. The Service Desk is also briefed on the service responses agreed through the customer contracts and use the incident logging application to monitor incidents’ service level response times. Problems are identified through incident reviews and managed through diagnosis, resolution and planned changes. These reviews of issues attempt to identify trends/recurrent issues; when identified, these undergo a root cause analysis and recommendations are made for changes to the product based on the analysis.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
- Health and Social Care Network (HSCN)
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- Where practical, we accommodate requests. For instance, if a customer seeks a system showcasing real-life data from GP and Acute systems, it incurs substantial third-party costs. However, a test version with dummy data may suffice, which we can provide without such expense.
- Link to free trial
- We do not have a generic link as each customer's requirements are slightly different. We make test systems available on request with them configured as per the customer's requirements.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- BSI Assurance UK Limited
- ISO/IEC 27001 accreditation date
- Monday 15 July 2024
- What the ISO/IEC 27001 doesn’t cover
- Our 27001 covers the full business operation without exclusions. Graphnet holds Certification number IS 614375 and operates Information Management Systems which comply with the requirements of ISO/IEC 27001:2022 for: All automated information systems under the direct control of Graphnet Health Ltd. All employees and agents of Graphnet Health Limited. All employees and agents of other organisations who directly or indirectly make use of or support the use of information systems under the direct control of Graphnet Health Limited.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- BSI Assurance UK Limited
- ISO 9001 accreditation date
- Monday 11 March 2024
- What the ISO 9001 doesn’t cover
- Our 9001 covers the full business operation without exclusions. Graphnet holds Certification number FS 614373 and operates a Quality Management System which complies with the requirements of ISO/IEC 9001:2015 with no exceptions.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 51f753d9-3a05-43aa-90d0-054a83d271a4
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 9a259fc6-6ab9-413e-aa1d-c1968dbc6f89
- Other security certifications
- Yes
- Any other security certifications
-
- Data Security and Protection Toolkit (NHS Digital ODS code 8GX89)
- Data Protection Act 1998 (DPA)
- Level 3 compliance with NHS IGSoC
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Volunteering opportunities for staff
-