Skip to main content

Help us improve the Digital Marketplace - send your feedback

HEALTHTECH 1 LTD

Automated Care Navigation

Automated Care Navigation provides AI-powered patient request categorisation, intelligent routing, and automated appointment booking aligned with NHS Digital standards. Services include 99.5% uptime, real-time processing, and integration with existing clinical workflows.

Commitments include GDPR compliance and reducing administrative burden through diversions and direct booking, routing patients to the right care.

Features

  • AI-Powered Patient Request Categorisation
  • Intelligent Pathway Routing (Pharmacy, Nurse, GP, etc)
  • Direct Appointment Booking for Routine Care
  • Pharmacy Diversion with Clinical Safeguarding
  • Smart Form with Dynamic Follow-up Questions
  • Analytics and Configuration via the Healthtech-1 Hub
  • Seamless Integration with Existing Workflow Systems

Benefits

  • Significant Time Savings for GP Practice Staff
  • Faster Patient Access to Appropriate Care
  • Reduced Inappropriate GP Appointments
  • Increased Pharmacy First Utilisation
  • Lower Triage Workload Through Automation
  • Improved Patient Satisfaction via Self-Service Booking
  • Data-Driven Insights into Patient Demand

Pricing

  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at hello@healthtech1.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

7 9 2 7 6 1 2 3 2 2 9 7 2 4 2

Contact

HEALTHTECH 1 LTD Matthew Payne
Telephone: 020 3856 7772
Email: hello@healthtech1.uk

About your service

Service categories

Applications

Production and operations

Service industry and public sector operations

  • Healthcare
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Healthtech-1 Automated Registrations, Healthtech-1 Bookable.
Cloud deployment model
Public cloud
Service constraints
Compatible with EMIS and SystmOne clinical systems.
System requirements
EMIS or SystmOne

User support

Email or online ticketing support
Yes
Support response times
Live Chat: 16 mins
Email: 1 hour
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
Yes
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
WCAG 2.2 AA
Web chat accessibility testing
We use a service provided by Intercom to manage our live chat and email support, which aims to meet WCAG 2.2 AA standard. We expect Intercom to have therefore completed user testing for assistive technology users.
Onsite support
No
Support levels
All support is free. We provide live chat and email support, with a phone number to call if needed or at certain times of the year. Our Growth (sales) Team and our Support Team work closely to identify any GP practices who require additional support or a higher level of attention (such as groups of GP practices or ICB rollouts).
Support available to third parties
Yes
AI chatbot
Yes

Onboarding and offboarding

Getting started
We support users to start using the tool through a combination of guided onboarding, self-serve documentation, and live support.

When a GP practice or organisation goes live, they receive onboarding guidance explaining how the tool works, how appointment types and availability are configured, and how appointments are made visible to patients.

Users access the tool through the Healthtech-1 Hub, where they can manage appointments, monitor activity, and review analytics. Comprehensive online documentation is available via the Healthtech-1 Help Centre, including step-by-step guidance on configuration, usage, and best practice.

Live support is available via chat and email during business hours, with optional training sessions or walkthroughs available where required. This combination ensures organisations can adopt the tool quickly and confidently.
Service documentation
Yes
Documentation formats
HTML
End-of-contract data extraction
Users can extract their data in line with the termination provisions set out in the Healthtech-1 Terms and Conditions.

When the contract ends, the Healthcare Organisation (as data controller) may request that Healthtech-1 either returns all Personal Data or securely deletes it, at the organisation’s choice. Healthtech-1 will comply with this request and provide confirmation that all copies of the Personal Data have been deleted within 90 days of termination, unless otherwise agreed between the parties.

In practice, data extraction is coordinated through Healthtech-1 support to ensure the transfer is secure, appropriate, and consistent with data protection obligations. Data can be returned in a commonly used electronic format suitable for the Healthcare Organisation’s records and systems.

Any outstanding invoices must be settled before termination, and once termination takes effect, the organisation’s licence to use the service ends. Data handling following termination is carried out in accordance with the Terms, the Data Processing Agreement, and applicable UK GDPR requirements, ensuring continuity, control, and assurance for the Healthcare Organisation.
End-of-contract process
Any outstanding invoices must be settled before termination, and once termination takes effect, the organisation’s licence to use the service ends. Data handling following termination is carried out in accordance with the Terms, the Data Processing Agreement, and applicable UK GDPR requirements, ensuring continuity, control, and assurance for the Healthcare Organisation.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The patient facing elements of the service are developed to be the same but formatted differently for mobile devices to ensure accessibility, usability, and readability.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
GP practice staff interact with the service via a web-based interface called the Healthtech-1 Hub for analytics, configuration, and oversight. Users can see analytics about patient requests and pathway outcomes, review AI categorisation performance, and configure practice-specific settings. Patient requests that require staff action are delivered to the practice's existing workflow system, where staff manage and respond to them using familiar tools. Patients interact through a responsive web form that collects their request, validates their identity via SMS, and guides them through pathway selection and appointment booking.
Accessibility standards
None or don’t know
Description of accessibility
The Healthtech-1 Hub is designed with accessibility as a core requirement from the outset. We follow recognised software engineering best practice to ensure the service is usable by a wide range of users. The Hub is fully responsive and works across desktop, tablet, and mobile devices, with clear layouts, consistent navigation, and sufficient colour contrast. We use semantic HTML and accessible components to support assistive technologies, including screen readers and keyboard-only navigation. Forms and interactive elements are designed to be perceivable, operable, and understandable. Accessibility is embedded into our development and testing processes, with ongoing review to maintain compatibility standards.
Accessibility testing
We do not currently run dedicated, formal user testing programmes with users of assistive technology. However, accessibility is considered throughout design and development, and we carry out internal testing to support users who rely on assistive technologies.

Our interface testing includes manual keyboard-only navigation testing to ensure all core functionality can be accessed without a mouse, and checks to confirm that pages, forms, and interactive elements are compatible with common screen readers through the use of semantic HTML, appropriate labelling, and logical focus order. We also test responsive behaviour across devices and browsers to ensure consistent usability.

Accessibility issues identified during development or through customer feedback are prioritised and addressed as part of our regular product improvement cycle. As the Healthtech-1 Hub continues to evolve, we intend to expand our accessibility testing approach, including more structured testing with users of assistive technology where appropriate, to further strengthen usability and compliance with recognised accessibility standards.

This approach ensures accessibility considerations are embedded pragmatically and proportionately within our development and testing processes.
API
No
Customisation available
Yes
Description of customisation
Users of Healthtech-1 Care Navigation can customise the service at the GP practice level.

What can be customised: Practices can configure which pathways are available (e.g., enable/disable pharmacy diversions, nurse direct booking), set clinician capabilities for request matching, and set which appointment types are offered for direct booking. Practices can also customise patient-facing messaging and configure integration preferences with their existing workflows.

How users can customise: Customisation is managed through practice onboarding and configuration with Healthtech-1, and can be adjusted independently via the Healthtech-1 Hub Settings page or in collaboration with Healthtech-1 Support.

Who can customise: Customisation is carried out by authorised GP practice users (such as practice managers, partners or administrators). Patients do not customise the service itself, but benefit from locally tailored triage journeys that reflect their chosen practice's requirements. This approach ensures consistency, safety, and regulatory compliance while allowing flexibility for local needs.

Scaling

Independence of resources
We design the service to scale automatically so that demand from one user does not impact others. Healthtech-1 uses virtual machines and virtual smartcards, allowing us to dynamically spin up large numbers of automated processing bots as demand increases. This ensures registrations are processed in parallel rather than queued behind other organisations’ activity. During peak periods, such as university registration season in September, the platform routinely handles registrations at very high volumes, processing a patient every few seconds at peak demand. This elastic, isolated architecture ensures consistent performance, reliability, and service levels for all users regardless of overall system load.

Analytics

Service usage metrics
Yes
Metrics types
Healthtech-1 provides a range of service metrics for the tool through the Hub’s analytics and reporting features.

Metrics include:

Growth in published and bookable appointment volumes over time

Appointment utilisation rates (booked vs available)

Trends in appointment supply and demand

Changes in appointment list size and capacity

Usage patterns across practices or organisations

These metrics are available through real-time dashboards, regular reports, and reports on request. They support operational insight, capacity planning, and evaluation of access and utilisation initiatives.
Reporting types
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
  • Other locations
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Encryption of all physical media
  • Other
Other data at rest protection approach
Healthtech-1 is hosted on Microsoft Azure. All data at rest, including databases, backups, and storage volumes, is encrypted using industry-standard encryption managed by the cloud platform. Physical media is protected by Azure’s datacentre security controls, including restricted physical access, monitoring, and secure hardware lifecycle management. Healthtech-1 does not operate or access physical storage devices directly. Logical access to encrypted data is further restricted through role-based access controls and secure authentication, ensuring that only authorised personnel and services can access data in line with NHS and UK GDPR requirements.
Data sanitisation process
Yes
Equipment disposal approach
In-house destruction process
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure

Data importing and exporting

Data export approach
Users can export data from Healthtech-1 in several ways. Individual patient registrations can be exported as PDFs of the completed registration form directly from the service. Practices can also access data extracts from analytics and reporting features to review activity, volumes, and trends. Where more specific requirements exist, the Healthtech-1 support and operations team can provide tailored reports and data extracts, including identifying specific cohorts of patients, at no additional cost. In line with normal practice, GP staff manage operational data within the Healthtech-1 Hub and their clinical system, with supported data exports available on request.
Data export formats
CSV
Data import formats
Other
Other data import formats
Not Applicable.

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Healthtech-1 is designed to be highly available and resilient. We use cloud-based infrastructure with monitoring and automated recovery to minimise service disruption and maintain consistent access for users.

We aim to provide at least 99.5% service availability per calendar month, measured against the availability of the patient registration service. Availability excludes downtime caused by third-party systems, scheduled maintenance, or events outside our reasonable control. We actively monitor our systems for outages and material errors and respond promptly to incidents.

Support is provided during published support hours, with prioritised response for critical outages. Where issues occur, we work closely with users to restore service and minimise operational impact.

While we set clear availability targets, the service is provided on a best-efforts basis and does not include automatic financial refunds or service credits if availability targets are not met. This reflects the usage-based pricing model, where charges apply only to completed automated registrations. Any service issues are reviewed as part of ongoing service improvement and customer support processes.

This approach ensures transparency on availability expectations while maintaining flexibility and value for NHS organisations.
Approach to resilience
Healthtech-1 is designed using a resilient, cloud-based architecture that minimises single points of failure. The service runs on scalable infrastructure with automated monitoring, allowing components to be restarted or replaced quickly in the event of failure.

Processing workloads are distributed and can scale dynamically to meet demand, including during peak periods such as university registration season. Where automation is used, tasks can be handled in parallel to avoid bottlenecks.

Data is protected through secure hosting environments, strict access controls, and alignment with NHS and UK GDPR requirements. The service also depends on trusted third-party platforms (such as clinical systems and messaging providers), and resilience planning accounts for upstream dependencies.

Details of underlying datacentre configuration and infrastructure resilience are available on request, in line with government cloud security guidance.
Outage reporting
Healthtech-1 reports and manages service outages through a combination of proactive monitoring and responsive user-reported channels.

The service is continuously monitored for availability and performance issues. Where an outage or degradation is detected, incidents are logged and managed by the operations team in line with internal incident response procedures. At present, Healthtech-1 does not operate a public status dashboard or outage API.

Users can report suspected outages or issues directly through Healthtech-1 Support channels, including live chat, email, and phone. The live chat system includes automatic routing and AI-assisted triage, which helps identify and prioritise urgent or service-impacting issues so they are escalated quickly to the appropriate technical team. This ensures that critical incidents are addressed promptly, even outside of routine workflows.

Where an outage materially affects service delivery, affected users are informed through direct communications (such as email or in-service messages) and provided with updates as the issue is investigated and resolved. Following resolution, Healthtech-1 may share a summary of the incident and remedial actions taken, where appropriate.

This approach balances clear communication, rapid escalation, and proportionate transparency for an NHS-facing SaaS service.

Identity and authentication

User authentication needed
Yes
User authentication
Multi-Factor Authentication (MFA)
Access restrictions in management interfaces and support channels
Access to Healthtech-1 management interfaces and support systems is restricted using role-based access controls and the principle of least privilege. Only authorised staff with a legitimate business need are granted access to administrative tools, production systems, or support platforms. Access is protected through secure authentication, with permissions reviewed regularly and removed promptly when roles change or staff leave. Support channels are restricted to approved users, and sensitive actions require additional verification. All access to management and support systems is logged and monitored to support auditability and rapid investigation of any unauthorised or inappropriate access.
Access restriction testing frequency
At least once a year
Management access authentication
Multi-Factor Authentication (MFA)

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
Healthtech-1 follows a proportionate, risk-based approach to security governance aligned with the UK Government’s Software Security Code of Practice. Security responsibilities are clearly owned within the organisation, with oversight from senior leadership. We embed security into product design and engineering through secure development practices, access controls, and regular review of risks and controls. We maintain documented security, data protection, and incident management policies, and review these as the service evolves. Third-party suppliers are assessed for security and NHS compliance, and staff are trained on information governance and secure handling of data.
Information security policies and processes
Healthtech-1 follows documented information security policies and operational processes designed to protect patient and organisational data and to meet UK GDPR and NHS requirements. Core policies include information security, access control, data protection, incident management, business continuity, and supplier security.

Security responsibilities are clearly defined, with overall accountability held at senior leadership level. Day-to-day adherence is managed by the engineering and operations teams, with escalation routes in place for security incidents, data breaches, or policy non-compliance.

Access to systems and data is granted on a least-privilege basis and reviewed regularly. Changes to infrastructure or application code follow controlled change processes, including review and testing. Security incidents are logged, investigated, and managed in line with an incident response process, with notification and remediation where required.

Staff receive onboarding and ongoing training covering information governance, data protection, and secure handling of data. Compliance with policies is reinforced through regular reviews, audit evidence (including DSPT-aligned documentation), and supplier due-diligence checks. Policies are reviewed and updated as the service, risks, or regulatory requirements evolve.

We have both an internal lead for Information Governance and Data Protection as well as an external Data Protection Officer.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Healthtech-1 manages configuration and change through controlled, auditable processes. Service components, infrastructure, and application code are tracked through version control and infrastructure-as-code tooling across their lifecycle, from development to deployment and retirement. Changes are proposed, reviewed, and approved by authorised engineers, with peer review and testing prior to release. Each change is assessed for potential security, data protection, and service impact, with higher-risk changes requiring additional review. Deployments are monitored post-release, and changes can be rolled back if issues are identified. This approach ensures traceability, controlled change, and protection of service availability and security.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Healthtech-1 manages vulnerabilities through a risk-based, ongoing process. Potential threats are identified through a combination of automated tooling, code review, dependency monitoring, and infrastructure alerts. We also monitor information from trusted sources, including cloud providers, software vendors, NHS guidance, and security advisories. Identified vulnerabilities are assessed for severity, likelihood, and potential impact on patient data or service availability. Patches and mitigations are prioritised accordingly, with critical security updates deployed as soon as practicable and typically within hours or days, depending on risk. Remediation actions are tracked, tested, and reviewed to ensure effectiveness.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Healthtech-1 uses protective monitoring to identify, investigate, and respond to potential security incidents. We monitor system logs, access activity, application behaviour, and infrastructure alerts to detect unusual or unauthorised activity. Alerts are automatically flagged to the operations team, with higher-risk events prioritised for immediate review. When a potential compromise is identified, access can be restricted, affected components isolated, and investigations initiated in line with our incident response process. Incidents are assessed and responded to promptly, with critical security issues escalated immediately and typically addressed within hours.
Incident management type
Supplier-defined controls
Incident management approach
Healthtech-1 operates defined incident management processes covering both clinical safety incidents and cyber/security incidents. Pre-defined response procedures exist for common events, including service outages, data issues, and suspected security incidents. Users can report incidents via Healthtech-1 Support channels, including live chat, email, and phone, with urgent issues prioritised for rapid escalation. Incidents are logged, triaged, and managed by the operations team, with clinical input where patient safety may be affected. Where appropriate, users are provided with incident updates and post-incident reports outlining root cause, impact, and corrective actions taken.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
Yes
Connected networks
Health and Social Care Network (HSCN)

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
The full service is available for a limited time free period.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
10%
Between £250,000 and £500,000
15%
Between £500,001 and £1,000,000
20%
Between £1,000,001 and £2,500,000
30%
Between £2,500,001 and £5,000,000
40%
Over £5,000,001
50%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
8908fe50-d3e3-4201-bbff-4f739596029a
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
59151264-eb30-42ac-afc5-51553ceabc62
Other security certifications
Yes
Any other security certifications
NHS DSPT

Social value

Section B - Commitment for Future: Delivery
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
    • Introducing transparency to pay and reward processes
    • Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Understanding of issues relating to entering the contract workforce
    • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
    • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
    • Actions to invest in the physical and mental health and wellbeing of the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at hello@healthtech1.uk. Tell them what format you need. It will help if you say what assistive technology you use.