Automated Care Navigation
Automated Care Navigation provides AI-powered patient request categorisation, intelligent routing, and automated appointment booking aligned with NHS Digital standards. Services include 99.5% uptime, real-time processing, and integration with existing clinical workflows.
Commitments include GDPR compliance and reducing administrative burden through diversions and direct booking, routing patients to the right care.
Features
- AI-Powered Patient Request Categorisation
- Intelligent Pathway Routing (Pharmacy, Nurse, GP, etc)
- Direct Appointment Booking for Routine Care
- Pharmacy Diversion with Clinical Safeguarding
- Smart Form with Dynamic Follow-up Questions
- Analytics and Configuration via the Healthtech-1 Hub
- Seamless Integration with Existing Workflow Systems
Benefits
- Significant Time Savings for GP Practice Staff
- Faster Patient Access to Appropriate Care
- Reduced Inappropriate GP Appointments
- Increased Pharmacy First Utilisation
- Lower Triage Workload Through Automation
- Improved Patient Satisfaction via Self-Service Booking
- Data-Driven Insights into Patient Demand
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
7 9 2 7 6 1 2 3 2 2 9 7 2 4 2
Contact
HEALTHTECH 1 LTD
Matthew Payne
Telephone: 020 3856 7772
Email: hello@healthtech1.uk
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Healthtech-1 Automated Registrations, Healthtech-1 Bookable.
- Cloud deployment model
- Public cloud
- Service constraints
- Compatible with EMIS and SystmOne clinical systems.
- System requirements
- EMIS or SystmOne
User support
- Email or online ticketing support
- Yes
- Support response times
-
Live Chat: 16 mins
Email: 1 hour - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- We use a service provided by Intercom to manage our live chat and email support, which aims to meet WCAG 2.2 AA standard. We expect Intercom to have therefore completed user testing for assistive technology users.
- Onsite support
- No
- Support levels
- All support is free. We provide live chat and email support, with a phone number to call if needed or at certain times of the year. Our Growth (sales) Team and our Support Team work closely to identify any GP practices who require additional support or a higher level of attention (such as groups of GP practices or ICB rollouts).
- Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
We support users to start using the tool through a combination of guided onboarding, self-serve documentation, and live support.
When a GP practice or organisation goes live, they receive onboarding guidance explaining how the tool works, how appointment types and availability are configured, and how appointments are made visible to patients.
Users access the tool through the Healthtech-1 Hub, where they can manage appointments, monitor activity, and review analytics. Comprehensive online documentation is available via the Healthtech-1 Help Centre, including step-by-step guidance on configuration, usage, and best practice.
Live support is available via chat and email during business hours, with optional training sessions or walkthroughs available where required. This combination ensures organisations can adopt the tool quickly and confidently. - Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
-
Users can extract their data in line with the termination provisions set out in the Healthtech-1 Terms and Conditions.
When the contract ends, the Healthcare Organisation (as data controller) may request that Healthtech-1 either returns all Personal Data or securely deletes it, at the organisation’s choice. Healthtech-1 will comply with this request and provide confirmation that all copies of the Personal Data have been deleted within 90 days of termination, unless otherwise agreed between the parties.
In practice, data extraction is coordinated through Healthtech-1 support to ensure the transfer is secure, appropriate, and consistent with data protection obligations. Data can be returned in a commonly used electronic format suitable for the Healthcare Organisation’s records and systems.
Any outstanding invoices must be settled before termination, and once termination takes effect, the organisation’s licence to use the service ends. Data handling following termination is carried out in accordance with the Terms, the Data Processing Agreement, and applicable UK GDPR requirements, ensuring continuity, control, and assurance for the Healthcare Organisation. - End-of-contract process
- Any outstanding invoices must be settled before termination, and once termination takes effect, the organisation’s licence to use the service ends. Data handling following termination is carried out in accordance with the Terms, the Data Processing Agreement, and applicable UK GDPR requirements, ensuring continuity, control, and assurance for the Healthcare Organisation.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The patient facing elements of the service are developed to be the same but formatted differently for mobile devices to ensure accessibility, usability, and readability.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- GP practice staff interact with the service via a web-based interface called the Healthtech-1 Hub for analytics, configuration, and oversight. Users can see analytics about patient requests and pathway outcomes, review AI categorisation performance, and configure practice-specific settings. Patient requests that require staff action are delivered to the practice's existing workflow system, where staff manage and respond to them using familiar tools. Patients interact through a responsive web form that collects their request, validates their identity via SMS, and guides them through pathway selection and appointment booking.
- Accessibility standards
- None or don’t know
- Description of accessibility
- The Healthtech-1 Hub is designed with accessibility as a core requirement from the outset. We follow recognised software engineering best practice to ensure the service is usable by a wide range of users. The Hub is fully responsive and works across desktop, tablet, and mobile devices, with clear layouts, consistent navigation, and sufficient colour contrast. We use semantic HTML and accessible components to support assistive technologies, including screen readers and keyboard-only navigation. Forms and interactive elements are designed to be perceivable, operable, and understandable. Accessibility is embedded into our development and testing processes, with ongoing review to maintain compatibility standards.
- Accessibility testing
-
We do not currently run dedicated, formal user testing programmes with users of assistive technology. However, accessibility is considered throughout design and development, and we carry out internal testing to support users who rely on assistive technologies.
Our interface testing includes manual keyboard-only navigation testing to ensure all core functionality can be accessed without a mouse, and checks to confirm that pages, forms, and interactive elements are compatible with common screen readers through the use of semantic HTML, appropriate labelling, and logical focus order. We also test responsive behaviour across devices and browsers to ensure consistent usability.
Accessibility issues identified during development or through customer feedback are prioritised and addressed as part of our regular product improvement cycle. As the Healthtech-1 Hub continues to evolve, we intend to expand our accessibility testing approach, including more structured testing with users of assistive technology where appropriate, to further strengthen usability and compliance with recognised accessibility standards.
This approach ensures accessibility considerations are embedded pragmatically and proportionately within our development and testing processes. - API
- No
- Customisation available
- Yes
- Description of customisation
-
Users of Healthtech-1 Care Navigation can customise the service at the GP practice level.
What can be customised: Practices can configure which pathways are available (e.g., enable/disable pharmacy diversions, nurse direct booking), set clinician capabilities for request matching, and set which appointment types are offered for direct booking. Practices can also customise patient-facing messaging and configure integration preferences with their existing workflows.
How users can customise: Customisation is managed through practice onboarding and configuration with Healthtech-1, and can be adjusted independently via the Healthtech-1 Hub Settings page or in collaboration with Healthtech-1 Support.
Who can customise: Customisation is carried out by authorised GP practice users (such as practice managers, partners or administrators). Patients do not customise the service itself, but benefit from locally tailored triage journeys that reflect their chosen practice's requirements. This approach ensures consistency, safety, and regulatory compliance while allowing flexibility for local needs.
Scaling
- Independence of resources
- We design the service to scale automatically so that demand from one user does not impact others. Healthtech-1 uses virtual machines and virtual smartcards, allowing us to dynamically spin up large numbers of automated processing bots as demand increases. This ensures registrations are processed in parallel rather than queued behind other organisations’ activity. During peak periods, such as university registration season in September, the platform routinely handles registrations at very high volumes, processing a patient every few seconds at peak demand. This elastic, isolated architecture ensures consistent performance, reliability, and service levels for all users regardless of overall system load.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Healthtech-1 provides a range of service metrics for the tool through the Hub’s analytics and reporting features.
Metrics include:
Growth in published and bookable appointment volumes over time
Appointment utilisation rates (booked vs available)
Trends in appointment supply and demand
Changes in appointment list size and capacity
Usage patterns across practices or organisations
These metrics are available through real-time dashboards, regular reports, and reports on request. They support operational insight, capacity planning, and evaluation of access and utilisation initiatives. - Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Encryption of all physical media
- Other
- Other data at rest protection approach
- Healthtech-1 is hosted on Microsoft Azure. All data at rest, including databases, backups, and storage volumes, is encrypted using industry-standard encryption managed by the cloud platform. Physical media is protected by Azure’s datacentre security controls, including restricted physical access, monitoring, and secure hardware lifecycle management. Healthtech-1 does not operate or access physical storage devices directly. Logical access to encrypted data is further restricted through role-based access controls and secure authentication, ensuring that only authorised personnel and services can access data in line with NHS and UK GDPR requirements.
- Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
- Users can export data from Healthtech-1 in several ways. Individual patient registrations can be exported as PDFs of the completed registration form directly from the service. Practices can also access data extracts from analytics and reporting features to review activity, volumes, and trends. Where more specific requirements exist, the Healthtech-1 support and operations team can provide tailored reports and data extracts, including identifying specific cohorts of patients, at no additional cost. In line with normal practice, GP staff manage operational data within the Healthtech-1 Hub and their clinical system, with supported data exports available on request.
- Data export formats
- CSV
- Data import formats
- Other
- Other data import formats
- Not Applicable.
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
Healthtech-1 is designed to be highly available and resilient. We use cloud-based infrastructure with monitoring and automated recovery to minimise service disruption and maintain consistent access for users.
We aim to provide at least 99.5% service availability per calendar month, measured against the availability of the patient registration service. Availability excludes downtime caused by third-party systems, scheduled maintenance, or events outside our reasonable control. We actively monitor our systems for outages and material errors and respond promptly to incidents.
Support is provided during published support hours, with prioritised response for critical outages. Where issues occur, we work closely with users to restore service and minimise operational impact.
While we set clear availability targets, the service is provided on a best-efforts basis and does not include automatic financial refunds or service credits if availability targets are not met. This reflects the usage-based pricing model, where charges apply only to completed automated registrations. Any service issues are reviewed as part of ongoing service improvement and customer support processes.
This approach ensures transparency on availability expectations while maintaining flexibility and value for NHS organisations. - Approach to resilience
-
Healthtech-1 is designed using a resilient, cloud-based architecture that minimises single points of failure. The service runs on scalable infrastructure with automated monitoring, allowing components to be restarted or replaced quickly in the event of failure.
Processing workloads are distributed and can scale dynamically to meet demand, including during peak periods such as university registration season. Where automation is used, tasks can be handled in parallel to avoid bottlenecks.
Data is protected through secure hosting environments, strict access controls, and alignment with NHS and UK GDPR requirements. The service also depends on trusted third-party platforms (such as clinical systems and messaging providers), and resilience planning accounts for upstream dependencies.
Details of underlying datacentre configuration and infrastructure resilience are available on request, in line with government cloud security guidance. - Outage reporting
-
Healthtech-1 reports and manages service outages through a combination of proactive monitoring and responsive user-reported channels.
The service is continuously monitored for availability and performance issues. Where an outage or degradation is detected, incidents are logged and managed by the operations team in line with internal incident response procedures. At present, Healthtech-1 does not operate a public status dashboard or outage API.
Users can report suspected outages or issues directly through Healthtech-1 Support channels, including live chat, email, and phone. The live chat system includes automatic routing and AI-assisted triage, which helps identify and prioritise urgent or service-impacting issues so they are escalated quickly to the appropriate technical team. This ensures that critical incidents are addressed promptly, even outside of routine workflows.
Where an outage materially affects service delivery, affected users are informed through direct communications (such as email or in-service messages) and provided with updates as the issue is investigated and resolved. Following resolution, Healthtech-1 may share a summary of the incident and remedial actions taken, where appropriate.
This approach balances clear communication, rapid escalation, and proportionate transparency for an NHS-facing SaaS service.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Multi-Factor Authentication (MFA)
- Access restrictions in management interfaces and support channels
- Access to Healthtech-1 management interfaces and support systems is restricted using role-based access controls and the principle of least privilege. Only authorised staff with a legitimate business need are granted access to administrative tools, production systems, or support platforms. Access is protected through secure authentication, with permissions reviewed regularly and removed promptly when roles change or staff leave. Support channels are restricted to approved users, and sensitive actions require additional verification. All access to management and support systems is logged and monitored to support auditability and rapid investigation of any unauthorised or inappropriate access.
- Access restriction testing frequency
- At least once a year
- Management access authentication
- Multi-Factor Authentication (MFA)
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- Healthtech-1 follows a proportionate, risk-based approach to security governance aligned with the UK Government’s Software Security Code of Practice. Security responsibilities are clearly owned within the organisation, with oversight from senior leadership. We embed security into product design and engineering through secure development practices, access controls, and regular review of risks and controls. We maintain documented security, data protection, and incident management policies, and review these as the service evolves. Third-party suppliers are assessed for security and NHS compliance, and staff are trained on information governance and secure handling of data.
- Information security policies and processes
-
Healthtech-1 follows documented information security policies and operational processes designed to protect patient and organisational data and to meet UK GDPR and NHS requirements. Core policies include information security, access control, data protection, incident management, business continuity, and supplier security.
Security responsibilities are clearly defined, with overall accountability held at senior leadership level. Day-to-day adherence is managed by the engineering and operations teams, with escalation routes in place for security incidents, data breaches, or policy non-compliance.
Access to systems and data is granted on a least-privilege basis and reviewed regularly. Changes to infrastructure or application code follow controlled change processes, including review and testing. Security incidents are logged, investigated, and managed in line with an incident response process, with notification and remediation where required.
Staff receive onboarding and ongoing training covering information governance, data protection, and secure handling of data. Compliance with policies is reinforced through regular reviews, audit evidence (including DSPT-aligned documentation), and supplier due-diligence checks. Policies are reviewed and updated as the service, risks, or regulatory requirements evolve.
We have both an internal lead for Information Governance and Data Protection as well as an external Data Protection Officer. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Healthtech-1 manages configuration and change through controlled, auditable processes. Service components, infrastructure, and application code are tracked through version control and infrastructure-as-code tooling across their lifecycle, from development to deployment and retirement. Changes are proposed, reviewed, and approved by authorised engineers, with peer review and testing prior to release. Each change is assessed for potential security, data protection, and service impact, with higher-risk changes requiring additional review. Deployments are monitored post-release, and changes can be rolled back if issues are identified. This approach ensures traceability, controlled change, and protection of service availability and security.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Healthtech-1 manages vulnerabilities through a risk-based, ongoing process. Potential threats are identified through a combination of automated tooling, code review, dependency monitoring, and infrastructure alerts. We also monitor information from trusted sources, including cloud providers, software vendors, NHS guidance, and security advisories. Identified vulnerabilities are assessed for severity, likelihood, and potential impact on patient data or service availability. Patches and mitigations are prioritised accordingly, with critical security updates deployed as soon as practicable and typically within hours or days, depending on risk. Remediation actions are tracked, tested, and reviewed to ensure effectiveness.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Healthtech-1 uses protective monitoring to identify, investigate, and respond to potential security incidents. We monitor system logs, access activity, application behaviour, and infrastructure alerts to detect unusual or unauthorised activity. Alerts are automatically flagged to the operations team, with higher-risk events prioritised for immediate review. When a potential compromise is identified, access can be restricted, affected components isolated, and investigations initiated in line with our incident response process. Incidents are assessed and responded to promptly, with critical security issues escalated immediately and typically addressed within hours.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Healthtech-1 operates defined incident management processes covering both clinical safety incidents and cyber/security incidents. Pre-defined response procedures exist for common events, including service outages, data issues, and suspected security incidents. Users can report incidents via Healthtech-1 Support channels, including live chat, email, and phone, with urgent issues prioritised for rapid escalation. Incidents are logged, triaged, and managed by the operations team, with clinical input where patient safety may be affected. Where appropriate, users are provided with incident updates and post-incident reports outlining root cause, impact, and corrective actions taken.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
- Health and Social Care Network (HSCN)
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- The full service is available for a limited time free period.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 10%
- Between £250,000 and £500,000
- 15%
- Between £500,001 and £1,000,000
- 20%
- Between £1,000,001 and £2,500,000
- 30%
- Between £2,500,001 and £5,000,000
- 40%
- Over £5,000,001
- 50%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 8908fe50-d3e3-4201-bbff-4f739596029a
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 59151264-eb30-42ac-afc5-51553ceabc62
- Other security certifications
- Yes
- Any other security certifications
- NHS DSPT
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Introducing transparency to pay and reward processes
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of issues relating to entering the contract workforce
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-