Surgery Hero
Surgery Hero helps people prepare for and recover from their surgery. We do this by giving our members a tailored programme that’s designed to tackle their specific modifiable risk factors as well as coaching to support them throughout.
Features
- Patient Optimisation
- Remote access
- Health Data Centre
- Digital Prehabilitation
- Learn Content
- Remote monitoring
- Self Management
- Health coaching
- Security built in by design
- Digital Rehabilitation
Benefits
- Increased Patient Activation and Self Management
- Reduced length of stay following surgery
- Reduced readmissions following surgery
- Reduced cancellations for surgery
- Earlier return to work of patients following surgery
- Learn content to power self management
- Empowered patients who can self manage
- Improved surgical outcomes
- Reduced costs related to surgery
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 1 3 0 1 0 6 1 4 4 5 1 0 6 2
Contact
Sword Health
Luke Eastwood
Telephone: 07596496242
Email: l.eastwood@swordhealth.com
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
- N/A
- System requirements
- Recent versions of ios and android
User support
- Email or online ticketing support
- Yes
- Support response times
- Within 1 working day
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- NA
- Onsite support
- Yes
- Support levels
- Extensive support and training at point of purchase, onboarding and thereafter as required
- Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
- Training materials and demos provided online before onsite training and onboarding is conducted in person.
- Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- Option to do so by contacting Surgery Hero staff
- End-of-contract process
-
Hosting services
Peri-operative support and coaching
Reporting
All included in contract price - a detailed service level agreement can be provided for services. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- No
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Mobile device only
- Service interface
- No
- User support accessibility
- WCAG 2.2 AA
- API
- No
- Customisation available
- Yes
- Description of customisation
-
Some elements are customisable, learn content, reporting schedule and logos and branding.
Customisation will be conducted via Surgery Hero staff during onboarding and training with the payor.
Scaling
- Independence of resources
- Our cloud provider enables easy scaling with increased demand without affecting level of services provided
Analytics
- Service usage metrics
- Yes
- Metrics types
- Quarterly business reviews and reports can be emailed / shared at agreed time intervals
- Reporting types
-
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
- Other
- Other data at rest protection approach
- Data is encrypted in transit and at rest. Stringent access controls are deployed to prevent unauthorised access data. Internally pseudoanonymisation techniques are used. Surgery Hero meets the standards of NHS DSTP, DTAC & and is cyber essentials certified.
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- A request can be made to Surgery Hero staff. There is not an automated process to do so.
- Data export formats
- CSV
- Data import formats
- Other
- Other data import formats
- Can be entered manually in data centre of the app
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- 99.9%, measured on a monthly basis.
- Approach to resilience
-
Data collected on the platform is hosted by in the cloud in a manner that is ISO 27001 (International Standard for Information Security Management) compliant.
Communications are encrypted and authenticated using TLS1.2 (protocol), ECDHE_RSA with P-256 (key exchange), and AES-128-GCM (cipher) using 2048 bit keys. Public Surgery Hero sites, such as those potentially accessed from hospital systems that may be running old versions of Windows that do not support TLS 1.2, accept TLS 1 and TLS 1.1.
All data is encrypted regardless of its classification and access control can be defined to the field level if required. DynamoDB encryption at rest provides enhanced security by encrypting all data at rest using encryption keys stored in AWS Key Management Service (AWS KMS). This functionality helps reduce the operational burden and complexity involved in protecting sensitive data. - Outage reporting
- Email alerts
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Username or password
- Access restrictions in management interfaces and support channels
- System access and the associated security is controlled by taking full advantage of our cloud providers Access Management solution. Multi Factor Authentication is used by all users with access to the infrastructure. Only authorised users have access to health data.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Username or password
Audit information for users
- Access to user activity audit information
- You control when users can access audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- You control when users can access audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
-
Cyber Essentials
NHS DSPT
NHS DTAC - Information security policies and processes
-
We maintain a robust, risk-based Information Security Management System (ISMS) aligned to ISO27001, GDPR, & UK NHS requirements. Our policy suite includes asset management, access control (including role-based permissions and mandatory multi-factor authentication), incident response, change management, supplier security and business continuity plans.
Governance is overseen by our Senior Director or Risk and Compliance, our appointed Data Protection Officer (DPO), and Privacy official who have direct access to senior leadership.
All staff complete annual mandatory training, routine internal audits and monthly KPI reviews to confirm policy adherence. Deviations are escalated via our incident log, with corrective actions tracked in our management review process and zero-tolerance disciplinary follow-through for non-compliance. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- There is a dedicated change management procedure that must be followed by staff. This procedure is reviewed at least annually
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Vulnerability management approach meets the standards of ISO 27001 and cyber essentials (Surgery Hero has been accredited with both these certifications).
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Dedicated incident reporting procedures and responding to incident procedures that have be built in line with ISO27001 / Soc2 / HiTrust accreditation.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Dedicated ISMS procedures to handle reporting and responding to incidents that conforms with recognised standards.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- Yes
- Any other security certifications
-
- HITRUST CSF
- SOC 2 Type II
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
-