Skip to main content

Help us improve the Digital Marketplace - send your feedback

SCHAPPIT LTD

FootFall

FootFall is a complete digital solution that enables patients to engage with your practice online. FootFall transforms the way your patients access care and how you manage demand. Website, two-way messaging, batch messaging, questionnaires, NHS App/Login, patient triage, video consultations, appointment booking, EHR integration, digital assistant, pharmacy first referrals, dashboard.

Features

  • 50+ SNOMED-coded digital forms integrated with clinical systems
  • Direct EHR integration exporting episodes with SNOMED coding
  • Video consultations launched from dashboard via SMS or email
  • Real-time appointment booking integrated with EMIS/Optum and SystmOne/TPP
  • NHS-compliant, mobile-first patient website improving access and engagement
  • Pharmacy First referral identification built into FootFall dashboard
  • Patient Digital Assistant answers queries, guides services, reduces calls
  • Desktop application enables seamless workflow with chosen clinical system
  • ISO27001, CE+, DCB0129, DSPT, DTAC, IM1, Digital Asynchronous Consultation System
  • Two-way messaging, attach images/documents, batch messaging, NHS Login/App, message scheduling

Benefits

  • Improved efficiency across practices, supporting capacity and service recovery
  • Faster patient access through digital forms and online self-service
  • Accurate clinical records with SNOMED-coded data flowing into EHRs
  • Reduced admin workload through automated form and record integration
  • Convenient video consultations without travel or waiting room delays
  • Flexible appointment booking improves access and reduces missed appointments
  • Consistent, compliant websites improve trust and accessibility for patients
  • Clear patient navigation reduces confusion and unnecessary practice contact
  • Smarter referrals direct patients quickly to Pharmacy First services
  • Instant patient answers reduce phone calls and reception pressure

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at carl.nancollas@siliconpractice.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

8 3 6 1 2 7 7 4 3 2 2 8 6 9 3

Contact

SCHAPPIT LTD Carl Nancollas
Telephone: 07740673857
Email: carl.nancollas@siliconpractice.co.uk

About your service

Service categories

Applications

Production and operations

Service industry and public sector operations

  • Healthcare
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
Our platform is hosted on AWS Cloud, leveraging its robust, scalable, and secure infrastructure to ensure optimal performance and reliability. We follow a zero planned downtime process, meaning all updates and enhancements are implemented with minimal service interruption. We ensure changes are compatible with existing functionality while continuously improving and introducing new features, enabling our users to enjoy uninterrupted access at all times.
System requirements
  • Video consultation requires an inbuilt/external camera, speakers and microphone
  • Browser required, Google Chrome, Microsoft Edge, Mozilla Firefox, Opera, Safari
  • Internet Connection - Minimum connection speed 2Mbps

User support

Email or online ticketing support
Yes
Support response times
We provide customer support Monday to Friday, 08:00–17:00, excluding Bank Holidays. All support requests receive an initial response within one working day. Simple updates, such as text amendments, practice or ICB news, and policy changes, are typically completed within one working day. Where a request requires additional time, we will confirm timescales within one working day. Practices that do not use our editing facility can still access full support for queries and guidance. Each ICB and practice is assigned a dedicated Silicon Practice Account Manager, available via email and telephone for non-change-related support, within agreed escalation routes and service expectations.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Silicon Practice provides user support built around accessibility, responsiveness, and a user-centred approach, ensuring every user can access guidance when needed. Support also serves as a key channel for feedback, helping us continually improve our platform.

We provide support Monday to Friday, 08:00–17:00 (excluding Bank Holidays), with first responses to email requests typically within one working day. Simple updates or queries are resolved quickly, while more complex requests receive an estimated resolution timeframe within one working day.

Each ICB and practice is assigned a dedicated Silicon Practice Account Manager, contactable via email or telephone. Our team follows defined incident management procedures, triaging and assigning priority levels based on impact and type of issue. Severity levels are aligned with NHS England Incident Management and Severity guidelines.

All support, including guidance, troubleshooting, and escalation, is included at no additional charge. For critical outages, the team provides immediate prioritisation and escalation to minimise disruption, ensuring users have reliable access and confidence in the platform at all times.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Silicon Practice delivers a structured, flexible onboarding process tailored to the needs of each organisation. A typical implementation timeframe takes between 4–6 weeks, depending on the level of customisation required. Our team uses Zoho Projects to track each stage of deployment, ensuring transparency and clear milestones throughout the process.

We begin by taking information from your existing website, customising your forms, and reviewing your FootFall site with you prior to going live. Your involvement focuses on providing feedback on branding, reviewing the site before launch, and arranging staff attendance at our online video training sessions. For practices requiring rapid deployment, FootFall can be implemented within 2 weeks. In these cases, initial customisation is limited to enable a fast roll-out, with full branding, text, and features transitioned at a later date agreed with the ICB.

Silicon Practice provides full remote training for all users, supported by extensive training content, including documentation, video tutorials, and guidance. Additional training can be arranged at any point during the contract to support new staff or evolving organisational needs. This approach ensures a seamless, efficient rollout, empowering staff to manage patient demand effectively from day one.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
  • Other
Other documentation formats
YouTube Training/Support Videos
End-of-contract data extraction
Silicon Practice will, at the choice of the Data Controller, delete or return all the Personal Data to the Data Controller after the end of the provision of Services relating to Processing, and delete existing copies unless retention of the Personal Data is required by UK law.
End-of-contract process
Contracts with Silicon Practice run for the period specified in each Order Form or Call-Off Contract, including any optional extension periods. Termination rights and notice requirements are also set out within the relevant Order Form or Call-Off Contract. Where contract extensions are permitted, we request customers provide at least 4 weeks’ notice before the end of the current term.

If a contract is not extended, Silicon Practice follows a structured exit and offboarding plan, facilitated by a dedicated Customer Success Manager in collaboration with nominated customer stakeholders. The plan outlines key actions for all parties, a communication strategy, notice period activities, service switch-off, post-exit procedures, and the secure transfer of information to any new provider.

All data is managed safely throughout the offboarding process to ensure compliance and continuity. At the conclusion of the contract, user accounts are disabled, and no further messages can be sent through the platform, ensuring secure closure of the service while maintaining the integrity and privacy of patient data.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Built with a mobile-first approach, FootFall ensures patients enjoy a seamless experience across both mobile and desktop. Messaging via FootFall and SMS along with sending photos, completing online consultations, and video consultations, every interaction is intuitive and efficient. NHS-compliant design and patient-focused navigation make accessing care simple, while self-help resources empower patients and reduce practice workload. By combining convenience, accessibility, and engagement, FootFall enhances patient satisfaction, drives efficiency, and positions your practice at the forefront of modern, connected healthcare no matter if you are using a mobile or desktop to access FootFall.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
The service interface includes a patient-facing website and a secure staff dashboard working seamlessly together.

The mobile-first, NHS-compliant website helps patients quickly find information, complete forms, book appointments, start online or video consultations, and access self-help tools, including the Patient Digital Assistant, reducing calls and walk-ins.

The staff dashboard provides a single view of all patient interactions, bringing together forms, messages, bookings and referrals. SNOMED-coded data can be exported directly into clinical systems, helping practices manage demand efficiently while reducing administrative workload.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
Interface testing is carried out across singular components, patterns and the complete journeys which are expected to be done through the service (such as requesting an appointment or checking when the surgery is open).

We include assistive technology testing for needs such as learning and cognitive disabilities, limited mobility, and low or no vision. This consists of interactions with screen magnification or zoom controls, screen readers (like NVDA, VoiceOver), changing content presentation (colour contrast, text spacing), alternative input and full keyboard navigation.

User research and early designs factor in access needs and are kept at the forefront throughout an iterative process with testing at each stage of development; using tried and tested components from the NHS digital service manual or our own library of custom design components and patterns.

Our products are pilot tested and once deployed, used daily by patient and practice users across a large demographic - we welcome and encourage continual feedback to improve accessibility and usability for all.
API
No
Customisation available
Yes
Description of customisation
NHS GP Practices can customise various aspects of the service to meet the needs of patients and staff. Websites can be personalised with practice branding, layouts, colours, and content, providing clear information for patients. Forms can be tailored with specific fields, mandatory inputs, and submission rules, making it easy to collect patient details, appointment requests, or feedback. Auto replies can be set up with custom messages to acknowledge appointment requests or enquiries immediately. Reply templates allow staff to provide consistent, accurate responses to common patient questions efficiently. Form routing ensures submissions are automatically directed to the relevant clinician, admin team, or department, streamlining workflow. KPIs (Key Performance Indicators) can be defined and displayed through customised dashboards and reports, helping the practice monitor patient access, appointment response times, and service performance.

Customisation is managed directly through the platform’s user-friendly interface. Administrators or staff with the appropriate permissions can adjust settings, ensuring secure and controlled access. By tailoring these features, the service supports GP Practices in improving efficiency, maintaining clear communication with patients, and delivering high-quality, responsive care.

Scaling

Independence of resources
We have monitoring services in place to assess the demand on our services and can scale-up capacity quickly in periods of intense usage.

Analytics

Service usage metrics
Yes
Metrics types
We provide real-time dashboards enabling practices to track online requests, showing new, in-progress and queued submissions, alongside average closing times and close rates. Volumes can be viewed by hour, day, week or month, supporting workforce planning by identifying peak demand. Practices can analyse activity by request type and submission source, including patients, proxies or staff. Outcome reporting shows how consultations were resolved, including appointments, video consultations and response-time breaches. Additional insights demonstrate reductions in appointments, visits and phone calls. Dashboards are also available for PCNs and ICBs, enabling cross-practice visibility, comparison and assurance that requests remain open during core hours.
Reporting types
Real-time dashboards
Resource tagging
Yes
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CHECK service provider
Protecting data at rest
Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Physical Destruction / Hardware containing data is completely destroyed

Data importing and exporting

Data export approach
If an organisation requests a Documented Data Extract, we will provide a .CSV file with every piece of Data submitted to that organisation.
Data export formats
Other
Other data export formats
PDF
Data import formats
  • CSV
  • Other
Other data import formats
  • PNG
  • IMG
  • JPEG
  • PDF

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
We use Amazon Web Services (AWS) infrastructure within the UK regions and availability zones, providing a resilient, cloud-based environment designed for high availability and fault tolerance. Data is replicated in real time across multiple AWS Availability Zones, ensuring continuity and rapid failover in the event of an outage. All patient-identifiable data is encrypted to NHS encryption standards (AES-256). The AWS environment and associated services are ISO 27001 certified. The service is available 24/7/365 with a minimum 99.9% uptime commitment.
Approach to resilience
Our service is built on Amazon Web Services (AWS) infrastructure within UK regions and Availability Zones, delivering a resilient, cloud-based environment engineered for high availability and fault tolerance. Patient-identifiable data is encrypted to NHS standards (AES-256) and replicated in real time across multiple AWS Availability Zones, ensuring continuity and rapid failover in the unlikely event of an outage. The entire environment is ISO 27001 certified, giving our clients confidence in the security and compliance of our platform.

We provide 24/7/365 availability with a minimum 99.9% uptime commitment, supported by continuous monitoring systems that alert our team to any system faults or server failures, allowing prompt resolution.

Our software is continuously updated to meet evolving legislation and regulatory requirements. Updates are first identified by our Principal Developer in collaboration with the Compliance Manager, then gaps are assessed and an action plan is produced. These are incorporated into the development plan and linked directly to the software release process. This is overseen by our Clinical Safety Officer.

This combination of resilient architecture, robust monitoring, rigorous compliance, and proactive software management ensures our service remains secure, reliable, and consistently available to support patients and healthcare providers.
Outage reporting
When any issue arises that may impact system availability, our Helpdesk and Account Management Team act swiftly to keep all users informed. We proactively issue updates and guidance through multiple channels. This ensures that users are immediately aware of the situation, understand any potential impact, and receive timely instructions on next steps or workarounds.

In the unlikely event of a system outage, our Helpdesk is fully prepared to provide direct technical assistance. Users can contact the team via phone, email, or online support channels to receive guidance, troubleshooting support, and updates on restoration timelines. All communications are coordinated to ensure clarity, transparency, and consistency, minimising uncertainty and maintaining user confidence.

Our approach combines proactive notification, multi-channel communication, and responsive technical support to ensure that any disruption is managed efficiently and with minimal impact. By prioritising timely information and accessible assistance, we uphold our commitment to service continuity and user satisfaction.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
Access restrictions in management interfaces and support channels
Access to the management interface is controlled via role-based permissions. One staff account, usually the practice manager, is designated as an administrator and can create additional accounts, assigning roles such as standard user or administrator. Certain dashboard features, such as overall reports, are restricted to administrators. Support is provided via a dedicated email address, shared only with practice administrators to protect sensitive information, though access is not strictly restricted to avoid loss of important communications.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Silicon Practice operates within a robust information security and governance framework aligned to recognised national standards and regulatory guidance. Our policies and controls are informed by ISO 27001, NHS England requirements and Cyber Essentials, including CE+. This ensures that information security, privacy, and governance are embedded across all areas of the organisation.

Information security oversight is led through a dedicated governance function that adopts a structured, risk-based approach to protecting our systems, services, and data. A documented security strategy is maintained and reviewed on an ongoing basis to ensure it remains appropriate as regulatory guidance, organisational needs, and the threat landscape evolve.

Key policies include vulnerability management, supported by regular penetration testing; secure development practices that enforce privacy and security by design; and Data Protection Impact Assessments for all new products, system changes, and data-sharing activities. These policies and assessments are reviewed at least annually.

The Silicon Practice platform is hosted within Amazon Web Services (AWS) infrastructure. All data is encrypted both in transit and at rest in accordance with NHS encryption standards.

All employees undertake mandatory information security and data protection training on joining the organisation, with regular refresher training delivered thereafter, ensuring continued awareness, compliance, and accountability.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
All development work goes through a pull request testing process: developers submit completed feature code for review, which is added to the relevant release branch upon passing peer code review. All releases and final builds are tested to ensure they maintain compliant and do not introduce further or critical bugs. We carry out regular penetration testing of all products to assess for any potential security impacts.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Threats to Silicon Practice services are assessed based on the risk they pose to our business, customers, or patient data, including UK GDPR, information security, and clinical safety considerations. Any threats to data confidentiality, integrity, or availability are treated as high priority. Patches are deployed via scheduled releases to our servers, typically in the evening to minimise downtime. Updates are applied across all hosted FootFall websites and dashboards simultaneously. Release schedules are planned in advance, though urgent patches can be deployed the same day. Threat intelligence is sourced from cybersecurity advisory services and official notices.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
We run multiple forms of malware scanning in our environments. New files being uploaded by users are scanned and are either made available if safe or quarantined if not. We also have a WAF. We also monitor and log all access to production databases and websites.
Once reported, we aim to remediate any security incidents as soon as possible.
Incident management type
Supplier-defined controls
Incident management approach
Service requests, feedback and complaints are raised via our support email or phone number, both of which are provided to practices upon onboarding. Any incidents may be reported through these channels and then are logged through our helpdesk.
We then ensure our Service Level Agreements (SLAs) are upheld and resolve any incident as soon as we can with full resource behind it. Full reports are written and circulated to those affected for any major incidents including a full root cause analysis.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
We offer a 4-week free trial in a controlled environment, providing access to a GP website, dashboard, and patient digital assistant. You can complete forms, triage, communicate with patients, and explore the Pharmacy First referral module. Training is included to showcase the full solution safely.
Link to free trial
https://outlook.office365.com/book/SolutionDemonstration@siliconpractice.co.uk/?ismsaljsauthenabled=true

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
3%
Between £250,000 and £500,000
8%
Between £500,001 and £1,000,000
15%
Between £1,000,001 and £2,500,000
20%
Between £2,500,001 and £5,000,000
22%
Over £5,000,001
25%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Alcumus
ISO/IEC 27001 accreditation date
Friday 21 June 2024
What the ISO/IEC 27001 doesn’t cover
All parts of the service are covered
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
654c1d7c-5ff3-4431-8f07-d909c87c9875
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
F46f4f82-4586-411d-9b18-263c82719091
Other security certifications
Yes
Any other security certifications
  • NHS DSPT assurance - Standards Exceeded (ODS code 8KC12)
  • Fully compliant with DCB0129
  • ICO Registration (ZA074234)

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Plans to engage the contract workforce in deciding the most important workplace issues to address
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at carl.nancollas@siliconpractice.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.