Skip to main content

Help us improve the Digital Marketplace - send your feedback

PRACTEUS LTD

National Association of Sessional GPs - LocumDeck

The NASGP is a national membership body for portfolio/sessional GPs (& clinicians) working in out of hosital services. Our digital workplace platform is a decentralised distributive system which allows GPs to add their profile and directly engage in clinical practice onsite and remotely via the NHS GP in the Cloud.

Features

  • Daily flexible workforce data captured through digital platform
  • Secure cloud-based infrastructure supporting members in-person and remote consultation
  • Decentralised digital system aggregating local and national sessional activity
  • Workforce web page reports derived from daily platform data
  • Verified NHS organisation onboarding supporting trusted data collection
  • Direct digital engagement of locums through availability and session management
  • Integrated booking, invoicing and sessional activity data sources
  • Digital platform supporting direct GPto service engagement
  • Secure identity management and two-factor authentication for members
  • National membership-led workforce model enabled by digital tooling

Benefits

  • Receive clear workforce insight without managing digital platforms
  • Understand local sessional capacity using daily workforce data
  • Inform commissioning/provision decisions with evidence-based workforce reporting
  • Reduce agency reliance through direct engagement with local GP capacity
  • Support service planning using consistent national workforce intelligence
  • Improve continuity by enabling repeat engagement with known clinicians
  • Enable neighbourhood workforce planning without additional system costs
  • Access interpreted data rather than raw, unmanaged datasets
  • Respond to workforce pressures using timely NASGP-provided insight
  • Align workforce strategy with NHS transformation and neighbourhood delivery

Pricing

  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at richard.fieldhouse@nasgp.org.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

7 2 3 2 8 3 2 6 9 5 0 0 9 2 0

Contact

PRACTEUS LTD Richard Fieldhouse
Telephone: 07966229058
Email: richard.fieldhouse@nasgp.org.uk

About your service

Service categories

Applications

Production and operations

Service industry and public sector operations

  • Healthcare
  • Adult Social Care
  • Children's Social Care
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
There are no service constraints we are aware of
System requirements
  • Secure web browser
  • Internet connection (eg Broadband, mobile etc)
  • Desktop, tablet, smart device etc

User support

Email or online ticketing support
Yes
Support response times
We provide support Monday to Friday, 9am to 5pm, excluding Bank and Public Holidays.

We provide support via telephone and email.

We aim to anwer all calls immediately and respond to all emails within 2 hours.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
We provide support Monday to Friday, 9am to 5pm, excluding Bank and Public Holidays.

We provide support via telephone and email.

We aim to anwer all calls immediately and respond to all emails within 2 hours.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
To ensure a smooth and efficient start for our users, our team and platform feature integrated user documentation and guides, providing context sensitive help on every page and function. We provide onboarding support and how to optimise the sessional GP (clinicians).

This design allows GP practices, and primary/urgent/community care organisations to quickly familiarise themselves and get started within approximately five minutes. Sessional GPs (clinicians), requiring a more detailed setup to personalise their profiles and preferences, can expect to complete their onboarding in about 45 minutes.

Recognising the diverse needs of our users and members, we also offer complimentary online training sessions. These sessions are designed to maximise the platform’s utility and ensure users can leverage all its features effectively from the outset.
Service documentation
Yes
Documentation formats
HTML
End-of-contract data extraction
We provide export facilities for much of the data, otherwise users can submit a support ticket to request a copy of their data.
End-of-contract process
At the end of the contract, GP practices and PCOs can continue to use the service for free, sessional GP (clinical) members have to start paying to use the NASGP members digital platform (LocumDeck).
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Our solution works on mobile devices in the same way as it does on desktop or laptop, with full functionality.
Service interface
No
User support accessibility
WCAG 2.2 AA
API
No
Customisation available
Yes
Description of customisation
Users have full control over any settings related to working as a clinician. Users can customise dates, times, rates, terms, essential paperwork, payment details, session/clinic types and much more. All this is done on the web interface through any PC or smartphone web browser.

Scaling

Independence of resources
To ensure our service remains unaffected by varying user demands, we utilise monitoring software to manage the scale requirements of the cloud infrastructure.

Our monitoring systems proactively manage capacity and performance, alerting on spikes in resource usage and unusual activity. These measures guarantee consistent, reliable service for all users, irrespective of demand peaks.

Analytics

Service usage metrics
Yes
Metrics types
Our service metrics align with NHS England's Digital Services Framework, providing comprehensive insights into the deployment of sessional clinical capacity in primary care.

Metrics include the total number of GPs/clinicians and services utilising our digital platform (LocumDeck) for work management, sessions completed, engagement levels across practices and PCOs, average hours worked per clinician, rates, and analysis of unused capacity.

Additionally, we track hours worked per locum and calculate the average hourly rate to offer a transparent view of locum activity and financial trends. These metrics facilitate a deep understanding of service utilisation, helping to optimise sessional clinical capacity deployment.
Reporting types
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Encryption of all physical media
  • Other
Other data at rest protection approach
UK ISO27001
Data sanitisation process
Yes
Equipment disposal approach
In-house destruction process
Data sanitisation type
Deleted data can’t be directly accessed / Cryptographic Erasure

Data importing and exporting

Data export approach
All users can export invoices, NHS pensions forms and financial reports and much more as they use the NASGPs digital platform LocumDeck on a day to day basis.
Data export formats
  • CSV
  • Other
Other data export formats
PDF
Data import formats
  • CSV
  • Other
Other data import formats
XLSX

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
  • TLS (version 1.2 or above)
  • Other
Other protection within supplier network
Data at rest is held on a dedicated server supported by IONOS. The server is securely accessed by whitelisted IP addresses.

IONOS SIEM software constantly monitors and analyses security alerts, guaranteeing users high availability and secure products. The IONOS data centres are ISO 27001 certified.

Availability and resilience

Guaranteed availability
99.9% uptime with georedundant hosting services. data is mirrored in two data centres to protect against outages.
Approach to resilience
Data backups are held securely off site via Acronis backup Service. Data In storage or in transit is protected by AES-256 encryption and stored in SSAE-18 certified Tier 4 Data Centers. The service also uses ransomware protection for added security. Access to storage is 2 factor authentication.
Outage reporting
We offer in application notifications for planned maintenance and email alerts for any outages.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is strictly controlled through role-based access control (RBAC) mechanisms, ensuring only authorised personnel can access sensitive functions based on their job requirements.

Authentication processes, including multi-factor authentication (MFA), safeguard against unauthorised access. Regular audits and reviews of access rights ensure compliance with our strict security policies.

User activities within these interfaces are logged and monitored for any irregularities, with immediate action taken to address potential security breaches. This comprehensive approach ensures that access is securely restricted, maintaining the integrity and confidentiality of our systems and the data they contain.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
We maintain security governance by adhering to industry best practices. We stay informed about the latest vulnerabilities and threats by keeping up-to-date with OWASP's Top 10 and monitoring other relevant security news and alerts. We have established processes and procedures to manage access requests, respond to security incidents, and handle the leaver requests. Our policy documentation and playbooks are integral to these efforts, ensuring that our team has clear guidelines to follow. Additionally, we partner with IONOS to monitor our physical infrastructure, leveraging their expertise in best practices to ensure our systems are secure and resilient.
Information security policies and processes
Our information security policies and processes are designed to ensure the highest level of protection for all data we handle, fully compliant with industry standards and legal requirements, including GDPR and the NHS's own stringent data security guidelines. We adopt a comprehensive security framework that encompasses data encryption in transit and at rest, regular security audits, and rigorous access controls to safeguard sensitive information.

Our reporting structure for information security incidents is hierarchical, starting with immediate notification to our dedicated Information Security Officer (ISO). The ISO is responsible for assessing the incident's impact, coordinating with our response team to mitigate risks, and initiating an investigation to prevent future occurrences. This process is supported by continuous staff training on data protection best practices and the importance of maintaining the confidentiality and integrity of the data.

To ensure adherence to our policies, we conduct regular reviews and updates in line with evolving security standards and threats. Internal audits and compliance checks are performed routinely to identify and rectify any discrepancies.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Our approach ensures the integrity and security of our service throughout each component's lifecycle.

All service components are documented and tracked from inception through deployment and updates.

Changes undergo a rigorous assessment process, evaluating potential security impacts before implementation. This includes a comprehensive review by our security team to identify vulnerabilities or risks associated with the change.

We employ a structured change approval process, requiring sign-off from stakeholders, including security, operational, and development leads.

Regular audits of our change management practices ensure compliance with our strict security policies, maintaining high levels of data protection and service reliability.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Our vulnerability management process proactively identifies and mitigates threats to ensure the security of our services.

We conduct regular, comprehensive vulnerability scans and assessments to detect potential threats, utilising leading security intelligence sources and advisories from industry-standard bodies such as the National Cyber Security Centre (NCSC) and software vendors for up-to-date threat information.

Upon identifying vulnerabilities, we prioritise patch deployment based on the severity of the threat, with critical patches deployed within 24 hours.

Our security team continuously monitors for new vulnerabilities, ensuring our services remain resilient against emerging threats and our response strategy is swift and effective.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Our protective monitoring process employs advanced detection techniques to identify potential security breaches swiftly.

Through continuous monitoring and analysis of system activity, we detect anomalies and signs of compromise.

Upon identifying a potential threat, our dedicated incident response team is immediately engaged, ensuring a rapid response within 1 hour for critical incidents.

Actions include isolating affected systems, mitigating the threat, and conducting a thorough investigation to prevent future occurrences.

We leverage leading security intelligence to stay ahead of potential threats, ensuring our systems and data remain secure and resilient against cyber attacks.
Incident management type
Supplier-defined controls
Incident management approach
Our incident management process encompasses predefined protocols for common scenarios, ensuring swift action.

Users report incidents through a dedicated support channel, ensuring clarity and accessibility. Upon notification, our team promptly assesses, prioritizes, and addresses the issue, with critical incidents receiving immediate attention.

We communicate regularly with affected users, providing detailed reports that outline the incident's nature, the steps taken to mitigate its impact, and measures to prevent future occurrences.

This approach guarantees a transparent, responsive resolution process, fostering trust and security within our user community.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
The NASGPs digital platform (LocumDeck) is always free to the booking organisation. For members, we offer a free three month introductory period, where they get full use of the platform and NASGP community forum if they've never been a member before.

We also incentivse members if they connect booking organisations.
Link to free trial
For GPs https://www.nasgp.org.uk/join/free-trial/, for practices https://www.nasgp.org.uk/for-practices/

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
2.5%
Between £500,001 and £1,000,000
5%
Between £1,000,001 and £2,500,000
7.5%
Between £2,500,001 and £5,000,000
10%
Over £5,000,001
12.5%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
4b230b23-0671-4ccb-9b63-9ad98a1e10bd
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
    • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
    • Actions to invest in the physical and mental health and wellbeing of the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at richard.fieldhouse@nasgp.org.uk. Tell them what format you need. It will help if you say what assistive technology you use.