Skip to main content

Help us improve the Digital Marketplace - send your feedback

VITALHUB UK LIMITED

Strata Pathways

Strata is a real-time, web-based e-referral and care-coordination platform that links directory-of-service information across whole health economies. It matches patient needs to available resources, supports seamless transitions between services, reduces inappropriate readmissions, and enables bi-directional referrals. Integrating with EPR/PAS systems, Strata improves patient flow, capacity use and care outcomes.

Features

  • Aggregation & Integration of transitions Across Health & Social care
  • Recommendation Algorithm
  • Powerful Transition and Triage Engine
  • Single Point of Access (SPoA)
  • Single Point of Discharge (SPoD)
  • Central Intake workflow
  • Emergency department booking

Benefits

  • Enhanced Coordination
  • Improved Efficiency
  • Comprehensive Reporting
  • Single managed referral platform for all referrals types & sources
  • Coherent System Integration
  • Optimized Patient Experience
  • Provide visibility on capacity and demand
  • Automation to streamline referral workflow
  • Clear visibility of all exceptions in workflow
  • Visible, actionable and configurable KPIs enable improved response times

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at operationsuk@vitalhub.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

7 1 4 6 3 0 1 6 1 1 0 3 8 5 7

Contact

VITALHUB UK LIMITED Mr. Colin Garrod
Telephone: +442045833142
Email: operationsuk@vitalhub.com

About your service

Service categories

Applications

Production and operations

  • Other operations
Multi cloud support
No

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Strata PathWays can be used standalone or integrated with other Strata or third party systems.
Strata PathWays offers a service user/ patient facing portal enabling wider access where appropriate, empowering the patient to self-manage.
e.g. PAS, EMR, EPR, SCR, video consultation etc.
Cloud deployment model
Public cloud
Service constraints
No. Strata PathWays is provided as a managed service. Maintenance & down time is planned with clients in advance.
System requirements
  • Access to internet connected device
  • Access to up to date internet browser
  • Valid user account

User support

Email or online ticketing support
Yes
Support response times
Strata PathWays is a cloud-based solution accessible and supported around the clock, 24/7/365. Every component of the system remains consistently available. As a global provider, we adopt a 'follow the sun' approach to support and maintenance, ensuring assistance is available at any hour. Depending on priority, tickets receive a response within 20 minutes to 4 hours.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
No
Onsite support
Yes
Support levels
Standard Support Level: Included in the base cost, this level ensures that all NHS clients receive equal treatment and access to support services. It includes 24x7x365 availability for support, with all parts of the system accessible at all times, provided clients have internet access. Scheduled upgrades and maintenance are communicated in advance and conducted outside of normal business hours.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
We assist users in getting started with Strata PathWays by providing comprehensive implementation support and training programs. Our service is delivered as a Software as a Service (SaaS) managed solution, ensuring ease of access and implementation. The process begins with project initiation, followed by scoping and business process design to tailor the platform to the specific needs of the organization. We assist in digitization, configuration, and deployment, complemented by a structured training program.

Training sessions are provided to administrators and users at the outset of the project and can be ongoing as needed. These sessions can be conducted onsite or virtually, depending on the client's preferences and logistical considerations. Our dedicated account managers work closely with client leads to determine the frequency, location, and scheduling of training sessions.

The training program aims to enable users to derive maximum value from the solution while also equipping them with the skills to address specific requirements. Additionally, we provide full documentation customized to the implemented service, ensuring users have access to comprehensive resources for ongoing support and reference. Overall, our goal is to facilitate a smooth and effective onboarding process, empowering users to leverage the full capabilities of Strata PathWays.
Service documentation
Yes
Documentation formats
  • PDF
  • Other
Other documentation formats
  • Word Docx format
  • Video training
End-of-contract data extraction
When concluding the contract, Strata Health collaborates with clients to establish a secure and appropriate exit strategy. We typically request advance termination notices to formalize the exit plan and ensure adequate support for the client.

At the termination of the contract, Strata Health provides clients with a full copy of the production database housed within Strata PathWays. Designated client users have the capability to extract data themselves via the management console. Alternatively, clients may opt for Strata Health to perform the data extraction on their behalf. This extraction is conducted securely as a SQL database extract, and the data is transferred to an external hard drive, DVD, or a secure FTP location designated by the client.

Upon request, Strata Health can also supply destruction certificates or any other necessary documentation to ensure the secure handling of data.
End-of-contract process
Upon reaching the end of the contract, Strata's Account Management & Implementation teams collaborate with clients to establish a seamless exit strategy. To ensure a smooth transition, termination notices are requested in advance of the contract end date, facilitating the formalization of the exit plan and providing essential client support.

Included in the contract, Strata provides a complete copy of the live database housed within PathWays upon termination of service. Designated client users can independently extract data via the management console. Alternatively, clients may opt for Strata to perform the extraction, providing the data securely as a SQL database on an external hard drive, DVD, or a designated SFTP location.

Additional services, such as a full destruction & data removal process, including necessary destruction certificates, are available upon request and are subject to an agreed-upon charge. Strata will deactivate all API links to client systems upon termination.

Should a client require service extension in compliance with approved regulations, Strata will provide assistance, with charges incurred at the contracted monthly rate for any portion of each monthly period beyond the contract termination date.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Training materials are provide via in-person or remote sessions, via video training guides with descriptive audio or via cheat sheets and manuals.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
None. The platform, features & functions remain the same.
Service interface
No
User support accessibility
None or don’t know
API
Yes
What users can and can't do using the API
With Strata PathWays' JSON RESTful APIs and web-based API explorer, users can efficiently integrate and interact with the system. Through the API, users can set up the service by creating and configuring various components such as patient profiles, referral forms, workflows, and user permissions. This enables seamless integration with existing systems and customization to meet specific organizational needs. Additionally, users can make changes to existing configurations, update patient information, modify referral processes, and adjust workflow parameters, empowering them to adapt the system to evolving requirements and optimize operational efficiency. Our web-based API explorer provides a user-friendly interface for interactive testing of API endpoints, documentation viewing, and understanding of required data structures. However, users must have appropriate permissions and authorization for accessing and modifying sensitive data or system configurations. While the API allows extensive customization, complex configurations may require additional expertise or support from our technical team. Overall, Strata PathWays' API facilitates efficient management and customization of the system, ensuring data security and regulatory compliance while meeting the diverse needs of healthcare organizations.
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
  • PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Clients can extensively customise Strata PathWays to suit their specific requirements and preferences. This includes tailoring clinical pathways, forms, data schemas, smart templates, and recommendation algorithm. Through collaboration with our team, clients can articulate their customization needs, whether it involves adapting existing functionalities or developing new features. Our experts work closely with clients to understand their unique workflow processes, organisational goals, and regulatory requirements. Once identified, customization is implemented to align the platform with the organization's local practices and best practices in healthcare. This level of customisation ensures that the platform seamlessly integrates into existing workflows and maximizes operational efficiency. Users with appropriate permissions and access rights can initiate and oversee customization efforts, ensuring that changes align with organisational objectives and comply with relevant regulations. Overall, Strata PathWays offers a flexible and adaptable solution that empowers clients to tailor the platform according to their specific needs, promoting efficiency, compliance, and optimal patient care.

Scaling

Independence of resources
Our scalable infrastructure allows us to adjust service capacity based on demand, mitigating the impact of increased usage on individual clients. With fully resilient architecture across multiple sites and adherence to ISO processes, our stand-alone service operates on virtual servers, providing quick expansion capabilities as needed. This ensures uninterrupted performance and reliability for all users, independent of the demand placed by others on the platform.

Analytics

Service usage metrics
Yes
Metrics types
We leverage New Relic APM to manage Strata PathWays, cloud infrastructure, and system activity and ensure peak performance. Additionally, our Strata IQ Business Intelligence solution enables access to a wide range of reports and dashboards, providing insights into user and patient flow data. Clients can monitor various metrics such as access, referral volume, activity, outcomes, and more, empowering them to comprehend the flow within and around care networks. This facilitates the commissioning of appropriately sized services based on supply and demand dynamics and facilitates the identification of bottlenecks in processes for efficient resolution.
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least every 6 months
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
  • Other
Other data at rest protection approach
All client data, including backups, is stored within the customer’s designated region (e.g., UK clients in UK zones). There is no replication outside the approved jurisdiction, ensuring compliance with data residency laws. AWS provides raw block storage, and Strata Health applies its own controls under the AWS shared responsibility model to maintain encryption and security of hosted data.
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Users have the flexibility to export their data through the management or reporting console in various formats, including CSV, spreadsheet, JSON, XML, SQL, ETL, or Database table. Alternatively, users can opt for Strata to facilitate the extraction process and securely return the data. This can be provided as a secure SQL database, delivered on an external hard drive, DVD, or transferred to a designated SFTP location specified by the client.
Data export formats
  • CSV
  • Other
Other data export formats
  • SQL
  • JSON
  • ETL
Data import formats
  • CSV
  • Other
Other data import formats
  • JSON
  • ETL
  • SQL

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Legacy SSL and TLS (under version 1.2)
  • Other
Other protection between networks
Strata employs several safeguards to ensure customer and vendor data remains segregated. All customer instances are deployed to dedicated, segregated VPCs. All traffic inter/intra VPC leverages TLS 256-bit encryption; environments leverage Transit VPC + firewall isolation; environments are configured with strict least-privilege access; all environments are deployed with IDS/IPS monitoring for intrusion prevention and data exfiltration.
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Other
Other protection within supplier network
Strata employs SentinelOne XDR to monitor all traffic and data within its network to provide additional protection.

Availability and resilience

Guaranteed availability
We provide base 99.5 availability of the service under our standard SLA. Our Service Level Agreement is include with the Terms and Conditions and in the event of an outage Strata will work with the clients to agree any monetary compensation based on lost whole service days. SLA's of up to 99.9 are available.
Approach to resilience
Strata PathWays ensures robust resilience through its deployment in the AWS cloud, utilizing geolocated VPCs for enhanced datacentre setup. Each VPC offers a logical isolated network within a specific geographical region, with customizable network configurations and segregated layers across multiple zones within the same region. With hot standbys in multiple zones, data and applications are fully replicated, enabling seamless traffic rerouting in the event of a disaster. Our yearly DR testing ensures policy alignment with testing outcomes, while data recovery mechanisms and regular backups, including hourly or nightly database backups and VM snapshots, ensure data integrity and availability. Detailed datacentre setup resilience information is available upon request.
Outage reporting
Our service relies on New Relic to meticulously track every aspect of our solution in real-time, ensuring we stay informed about any potential outages. With New Relic's capabilities, we maintain client dashboards, offering a comprehensive real-time view of our solution's status. Moreover, our system features an API for seamless integration with client systems, enabling automated alerting processes. If a service disruption occurs, our support desk is promptly notified for swift resolution, while clients receive notifications via email, in-system alerts, and other agreed communication channels, ensuring they are kept informed throughout the process.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Limited access network (for example PSN)
  • Username or password
  • Other
Other user authentication
LDAP/SAML/OAuth
Strata Health enforces strong authentication controls aligned with ISO/IEC 27001, 27017, and 27018. Access is governed by ISP14 and ISP35, ensuring named accounts, role‑based access, and least‑privilege principles. All customer portals support two‑factor authentication using secure passwords plus PVQs or email/SMS one‑time codes. Supported federation options include SAML 2.0, OAuth 2.0, and OpenID Connect with approved identity providers. Passwords follow strict complexity rules and are encrypted in transit and at rest using TLS 1.2+ and AES‑256 per ISP30. Authentication activity is logged and monitored under ITP04 to ensure auditability, security, and GDPR compliance.
Access restrictions in management interfaces and support channels
Strata Health Solutions employs Role-Based Access Control (RBAC) to manage access in management interfaces and support channels. Client leadership retains control over access permissions, dictating which individuals or groups can access specific system features based on their roles and levels. RBAC ensures that users only have access to the features and parts of the system aligned with their designated roles. This granular control extends to management consoles and support channels, ensuring that access is restricted appropriately across all aspects of the Strata platform.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Limited access network (for example PSN)
  • Username or password
  • Other
Description of management access authentication
LDAP/SAML/OAuth
The solution employs RBAC - management services are controlled via configured roles. Where appropriate, access to management services can be further restricted via MFA.

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
ISO/IEC 270017, ISO/IEC 270018, ISO/IEC 9001
Information security policies and processes
VHUK follows the corporate suite of ISO 27001, ISO 9001, NHS Cyber Essentials Plus, and UK GDPR–aligned information security policies, covering governance, access control, asset management, information classification, cryptography, HR and user responsibilities, incident management, operations and network security, physical security, supplier management, change control, design and development, business continuity, internal audit, non‑conformance, customer feedback, and document control. VHUK reports into the Global Security, Compliance, and Privacy governance structure, with local control owners accountable for UK execution. Compliance is ensured through mandatory training, control ownership, evidence collection, internal and external audits, supplier reviews, access reviews, incident response processes, and corrective action tracking.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
VHUK follows ISO 27001 & 9001, CE+, GDPR, & SOC‑aligned configuration & change management processes. All configuration items & service components are maintained in the corporate CMDB, with approved baselines applied & monitored for compliance.
All changes to infrastructure, applications, & configurations follow a formal ITIL‑based Change Management process, including logging, risk assessment, testing, review, & approval. Security & privacy impacts—such as PHI/PII, access control, vulnerabilities, & availability—are mandatory considerations.
Compliance is ensured through mandatory training, local control ownership, continuous monitoring, audits, CAB oversight, evidence collection, incident review, & corrective action tracking, ensuring controlled, secure, & auditable changes.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
All servers are covered by a comprehensive monthly patching and maintenance schedule. Any important or urgent patches are applied out of schedule, with important patches within 2 weeks of a patch becoming available, and critical patches within 24hrs. Patches are always applied to Dev, UAT and Staging environments first to prevent issues with production environments.
Servers are actively monitored by a variety of tools including Spiceworks which highlight out of date software version numbers to the internal support team for action.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
We use tools to monitor logs and highlight potential compromises; anything discovered will be raised to a priority one ticket in our system and responded to within 1 hour. if there has been a compromise this will be remediated and logged as a security incident in our ISO 27001 based business management system in order that it is treated to prevent recurrence.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
VHUK follows an ISO27001 and CE+ aligned Incident Management Policy and Procedure to ensure incidents are reported, assessed, and resolved promptly to maintain secure and available services. All incidents must be reported immediately to management or the InfoSec Team. Incidents are logged with full details and initial actions taken. The InfoSec Team assesses severity and coordinates containment, eradication, and recovery, with high risk incidents escalated in line with corporate timeframes. Security incidents are recorded pursuant with ISO27001 procedures to support tracking, root cause analysis, corrective actions, and prevention of recurrence. Corporate Security provides oversight, with VHUK responsible for local compliance.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
Yes
Connected networks
  • Public Services Network (PSN)
  • Scottish Wide Area Network (SWAN)
  • Health and Social Care Network (HSCN)
  • Other
Other public sector networks
NHS Network (N3)

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Bristish Assessment Bureau
ISO/IEC 27001 accreditation date
Wednesday 30 July 2025
What the ISO/IEC 27001 doesn’t cover
N/A
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
British Assessment Bureau
ISO 9001 accreditation date
Wednesday 30 July 2025
What the ISO 9001 doesn’t cover
N/A
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
6a42672e-b586-48b2-b6c9-f1f6c81c8129
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
42ba2f56-2d16-4cb1-925a-0d87644122b9
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
    • Plans for positive actions with community groups.
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
    • Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Understanding of the issues affecting the development of new skills by target cohort
    • Understanding of issues relating to entering the contract workforce
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at operationsuk@vitalhub.com. Tell them what format you need. It will help if you say what assistive technology you use.