National Association of Sessional GPs - LocumDeck
The NASGP is a national membership body for portfolio/sessional GPs (& clinicians) working in out of hosital services. Our digital workplace platform is a decentralised distributive system which allows GPs to add their profile and directly engage in clinical practice onsite and remotely via the NHS GP in the Cloud.
Features
- Daily flexible workforce data captured through digital platform
- Secure cloud-based infrastructure supporting members in-person and remote consultation
- Decentralised digital system aggregating local and national sessional activity
- Workforce web page reports derived from daily platform data
- Verified NHS organisation onboarding supporting trusted data collection
- Direct digital engagement of locums through availability and session management
- Integrated booking, invoicing and sessional activity data sources
- Digital platform supporting direct GPto service engagement
- Secure identity management and two-factor authentication for members
- National membership-led workforce model enabled by digital tooling
Benefits
- Receive clear workforce insight without managing digital platforms
- Understand local sessional capacity using daily workforce data
- Inform commissioning/provision decisions with evidence-based workforce reporting
- Reduce agency reliance through direct engagement with local GP capacity
- Support service planning using consistent national workforce intelligence
- Improve continuity by enabling repeat engagement with known clinicians
- Enable neighbourhood workforce planning without additional system costs
- Access interpreted data rather than raw, unmanaged datasets
- Respond to workforce pressures using timely NASGP-provided insight
- Align workforce strategy with NHS transformation and neighbourhood delivery
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
7 2 3 2 8 3 2 6 9 5 0 0 9 2 0
Contact
PRACTEUS LTD
Richard Fieldhouse
Telephone: 07966229058
Email: richard.fieldhouse@nasgp.org.uk
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Adult Social Care
- Children's Social Care
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- There are no service constraints we are aware of
- System requirements
-
- Secure web browser
- Internet connection (eg Broadband, mobile etc)
- Desktop, tablet, smart device etc
User support
- Email or online ticketing support
- Yes
- Support response times
-
We provide support Monday to Friday, 9am to 5pm, excluding Bank and Public Holidays.
We provide support via telephone and email.
We aim to anwer all calls immediately and respond to all emails within 2 hours. - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
We provide support Monday to Friday, 9am to 5pm, excluding Bank and Public Holidays.
We provide support via telephone and email.
We aim to anwer all calls immediately and respond to all emails within 2 hours. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
To ensure a smooth and efficient start for our users, our team and platform feature integrated user documentation and guides, providing context sensitive help on every page and function. We provide onboarding support and how to optimise the sessional GP (clinicians).
This design allows GP practices, and primary/urgent/community care organisations to quickly familiarise themselves and get started within approximately five minutes. Sessional GPs (clinicians), requiring a more detailed setup to personalise their profiles and preferences, can expect to complete their onboarding in about 45 minutes.
Recognising the diverse needs of our users and members, we also offer complimentary online training sessions. These sessions are designed to maximise the platform’s utility and ensure users can leverage all its features effectively from the outset. - Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
- We provide export facilities for much of the data, otherwise users can submit a support ticket to request a copy of their data.
- End-of-contract process
- At the end of the contract, GP practices and PCOs can continue to use the service for free, sessional GP (clinical) members have to start paying to use the NASGP members digital platform (LocumDeck).
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Our solution works on mobile devices in the same way as it does on desktop or laptop, with full functionality.
- Service interface
- No
- User support accessibility
- WCAG 2.2 AA
- API
- No
- Customisation available
- Yes
- Description of customisation
- Users have full control over any settings related to working as a clinician. Users can customise dates, times, rates, terms, essential paperwork, payment details, session/clinic types and much more. All this is done on the web interface through any PC or smartphone web browser.
Scaling
- Independence of resources
-
To ensure our service remains unaffected by varying user demands, we utilise monitoring software to manage the scale requirements of the cloud infrastructure.
Our monitoring systems proactively manage capacity and performance, alerting on spikes in resource usage and unusual activity. These measures guarantee consistent, reliable service for all users, irrespective of demand peaks.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Our service metrics align with NHS England's Digital Services Framework, providing comprehensive insights into the deployment of sessional clinical capacity in primary care.
Metrics include the total number of GPs/clinicians and services utilising our digital platform (LocumDeck) for work management, sessions completed, engagement levels across practices and PCOs, average hours worked per clinician, rates, and analysis of unused capacity.
Additionally, we track hours worked per locum and calculate the average hourly rate to offer a transparent view of locum activity and financial trends. These metrics facilitate a deep understanding of service utilisation, helping to optimise sessional clinical capacity deployment. - Reporting types
-
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Encryption of all physical media
- Other
- Other data at rest protection approach
- UK ISO27001
- Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- All users can export invoices, NHS pensions forms and financial reports and much more as they use the NASGPs digital platform LocumDeck on a day to day basis.
- Data export formats
-
- CSV
- Other
- Other data export formats
- Data import formats
-
- CSV
- Other
- Other data import formats
- XLSX
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
-
Data at rest is held on a dedicated server supported by IONOS. The server is securely accessed by whitelisted IP addresses.
IONOS SIEM software constantly monitors and analyses security alerts, guaranteeing users high availability and secure products. The IONOS data centres are ISO 27001 certified.
Availability and resilience
- Guaranteed availability
- 99.9% uptime with georedundant hosting services. data is mirrored in two data centres to protect against outages.
- Approach to resilience
- Data backups are held securely off site via Acronis backup Service. Data In storage or in transit is protected by AES-256 encryption and stored in SSAE-18 certified Tier 4 Data Centers. The service also uses ransomware protection for added security. Access to storage is 2 factor authentication.
- Outage reporting
- We offer in application notifications for planned maintenance and email alerts for any outages.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
-
Access to management interfaces and support channels is strictly controlled through role-based access control (RBAC) mechanisms, ensuring only authorised personnel can access sensitive functions based on their job requirements.
Authentication processes, including multi-factor authentication (MFA), safeguard against unauthorised access. Regular audits and reviews of access rights ensure compliance with our strict security policies.
User activities within these interfaces are logged and monitored for any irregularities, with immediate action taken to address potential security breaches. This comprehensive approach ensures that access is securely restricted, maintaining the integrity and confidentiality of our systems and the data they contain. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- We maintain security governance by adhering to industry best practices. We stay informed about the latest vulnerabilities and threats by keeping up-to-date with OWASP's Top 10 and monitoring other relevant security news and alerts. We have established processes and procedures to manage access requests, respond to security incidents, and handle the leaver requests. Our policy documentation and playbooks are integral to these efforts, ensuring that our team has clear guidelines to follow. Additionally, we partner with IONOS to monitor our physical infrastructure, leveraging their expertise in best practices to ensure our systems are secure and resilient.
- Information security policies and processes
-
Our information security policies and processes are designed to ensure the highest level of protection for all data we handle, fully compliant with industry standards and legal requirements, including GDPR and the NHS's own stringent data security guidelines. We adopt a comprehensive security framework that encompasses data encryption in transit and at rest, regular security audits, and rigorous access controls to safeguard sensitive information.
Our reporting structure for information security incidents is hierarchical, starting with immediate notification to our dedicated Information Security Officer (ISO). The ISO is responsible for assessing the incident's impact, coordinating with our response team to mitigate risks, and initiating an investigation to prevent future occurrences. This process is supported by continuous staff training on data protection best practices and the importance of maintaining the confidentiality and integrity of the data.
To ensure adherence to our policies, we conduct regular reviews and updates in line with evolving security standards and threats. Internal audits and compliance checks are performed routinely to identify and rectify any discrepancies. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Our approach ensures the integrity and security of our service throughout each component's lifecycle.
All service components are documented and tracked from inception through deployment and updates.
Changes undergo a rigorous assessment process, evaluating potential security impacts before implementation. This includes a comprehensive review by our security team to identify vulnerabilities or risks associated with the change.
We employ a structured change approval process, requiring sign-off from stakeholders, including security, operational, and development leads.
Regular audits of our change management practices ensure compliance with our strict security policies, maintaining high levels of data protection and service reliability. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Our vulnerability management process proactively identifies and mitigates threats to ensure the security of our services.
We conduct regular, comprehensive vulnerability scans and assessments to detect potential threats, utilising leading security intelligence sources and advisories from industry-standard bodies such as the National Cyber Security Centre (NCSC) and software vendors for up-to-date threat information.
Upon identifying vulnerabilities, we prioritise patch deployment based on the severity of the threat, with critical patches deployed within 24 hours.
Our security team continuously monitors for new vulnerabilities, ensuring our services remain resilient against emerging threats and our response strategy is swift and effective. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Our protective monitoring process employs advanced detection techniques to identify potential security breaches swiftly.
Through continuous monitoring and analysis of system activity, we detect anomalies and signs of compromise.
Upon identifying a potential threat, our dedicated incident response team is immediately engaged, ensuring a rapid response within 1 hour for critical incidents.
Actions include isolating affected systems, mitigating the threat, and conducting a thorough investigation to prevent future occurrences.
We leverage leading security intelligence to stay ahead of potential threats, ensuring our systems and data remain secure and resilient against cyber attacks. - Incident management type
- Supplier-defined controls
- Incident management approach
-
Our incident management process encompasses predefined protocols for common scenarios, ensuring swift action.
Users report incidents through a dedicated support channel, ensuring clarity and accessibility. Upon notification, our team promptly assesses, prioritizes, and addresses the issue, with critical incidents receiving immediate attention.
We communicate regularly with affected users, providing detailed reports that outline the incident's nature, the steps taken to mitigate its impact, and measures to prevent future occurrences.
This approach guarantees a transparent, responsive resolution process, fostering trust and security within our user community. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
-
The NASGPs digital platform (LocumDeck) is always free to the booking organisation. For members, we offer a free three month introductory period, where they get full use of the platform and NASGP community forum if they've never been a member before.
We also incentivse members if they connect booking organisations. - Link to free trial
- For GPs https://www.nasgp.org.uk/join/free-trial/, for practices https://www.nasgp.org.uk/for-practices/
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 2.5%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 7.5%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 12.5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 4b230b23-0671-4ccb-9b63-9ad98a1e10bd
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-