FootFall
FootFall is a complete digital solution that enables patients to engage with your practice online. FootFall transforms the way your patients access care and how you manage demand. Website, two-way messaging, batch messaging, questionnaires, NHS App/Login, patient triage, video consultations, appointment booking, EHR integration, digital assistant, pharmacy first referrals, dashboard.
Features
- 50+ SNOMED-coded digital forms integrated with clinical systems
- Direct EHR integration exporting episodes with SNOMED coding
- Video consultations launched from dashboard via SMS or email
- Real-time appointment booking integrated with EMIS/Optum and SystmOne/TPP
- NHS-compliant, mobile-first patient website improving access and engagement
- Pharmacy First referral identification built into FootFall dashboard
- Patient Digital Assistant answers queries, guides services, reduces calls
- Desktop application enables seamless workflow with chosen clinical system
- ISO27001, CE+, DCB0129, DSPT, DTAC, IM1, Digital Asynchronous Consultation System
- Two-way messaging, attach images/documents, batch messaging, NHS Login/App, message scheduling
Benefits
- Improved efficiency across practices, supporting capacity and service recovery
- Faster patient access through digital forms and online self-service
- Accurate clinical records with SNOMED-coded data flowing into EHRs
- Reduced admin workload through automated form and record integration
- Convenient video consultations without travel or waiting room delays
- Flexible appointment booking improves access and reduces missed appointments
- Consistent, compliant websites improve trust and accessibility for patients
- Clear patient navigation reduces confusion and unnecessary practice contact
- Smarter referrals direct patients quickly to Pharmacy First services
- Instant patient answers reduce phone calls and reception pressure
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 3 6 1 2 7 7 4 3 2 2 8 6 9 3
Contact
SCHAPPIT LTD
Carl Nancollas
Telephone: 07740673857
Email: carl.nancollas@siliconpractice.co.uk
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- Our platform is hosted on AWS Cloud, leveraging its robust, scalable, and secure infrastructure to ensure optimal performance and reliability. We follow a zero planned downtime process, meaning all updates and enhancements are implemented with minimal service interruption. We ensure changes are compatible with existing functionality while continuously improving and introducing new features, enabling our users to enjoy uninterrupted access at all times.
- System requirements
-
- Video consultation requires an inbuilt/external camera, speakers and microphone
- Browser required, Google Chrome, Microsoft Edge, Mozilla Firefox, Opera, Safari
- Internet Connection - Minimum connection speed 2Mbps
User support
- Email or online ticketing support
- Yes
- Support response times
- We provide customer support Monday to Friday, 08:00–17:00, excluding Bank Holidays. All support requests receive an initial response within one working day. Simple updates, such as text amendments, practice or ICB news, and policy changes, are typically completed within one working day. Where a request requires additional time, we will confirm timescales within one working day. Practices that do not use our editing facility can still access full support for queries and guidance. Each ICB and practice is assigned a dedicated Silicon Practice Account Manager, available via email and telephone for non-change-related support, within agreed escalation routes and service expectations.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Silicon Practice provides user support built around accessibility, responsiveness, and a user-centred approach, ensuring every user can access guidance when needed. Support also serves as a key channel for feedback, helping us continually improve our platform.
We provide support Monday to Friday, 08:00–17:00 (excluding Bank Holidays), with first responses to email requests typically within one working day. Simple updates or queries are resolved quickly, while more complex requests receive an estimated resolution timeframe within one working day.
Each ICB and practice is assigned a dedicated Silicon Practice Account Manager, contactable via email or telephone. Our team follows defined incident management procedures, triaging and assigning priority levels based on impact and type of issue. Severity levels are aligned with NHS England Incident Management and Severity guidelines.
All support, including guidance, troubleshooting, and escalation, is included at no additional charge. For critical outages, the team provides immediate prioritisation and escalation to minimise disruption, ensuring users have reliable access and confidence in the platform at all times. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Silicon Practice delivers a structured, flexible onboarding process tailored to the needs of each organisation. A typical implementation timeframe takes between 4–6 weeks, depending on the level of customisation required. Our team uses Zoho Projects to track each stage of deployment, ensuring transparency and clear milestones throughout the process.
We begin by taking information from your existing website, customising your forms, and reviewing your FootFall site with you prior to going live. Your involvement focuses on providing feedback on branding, reviewing the site before launch, and arranging staff attendance at our online video training sessions. For practices requiring rapid deployment, FootFall can be implemented within 2 weeks. In these cases, initial customisation is limited to enable a fast roll-out, with full branding, text, and features transitioned at a later date agreed with the ICB.
Silicon Practice provides full remote training for all users, supported by extensive training content, including documentation, video tutorials, and guidance. Additional training can be arranged at any point during the contract to support new staff or evolving organisational needs. This approach ensures a seamless, efficient rollout, empowering staff to manage patient demand effectively from day one. - Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
- YouTube Training/Support Videos
- End-of-contract data extraction
- Silicon Practice will, at the choice of the Data Controller, delete or return all the Personal Data to the Data Controller after the end of the provision of Services relating to Processing, and delete existing copies unless retention of the Personal Data is required by UK law.
- End-of-contract process
-
Contracts with Silicon Practice run for the period specified in each Order Form or Call-Off Contract, including any optional extension periods. Termination rights and notice requirements are also set out within the relevant Order Form or Call-Off Contract. Where contract extensions are permitted, we request customers provide at least 4 weeks’ notice before the end of the current term.
If a contract is not extended, Silicon Practice follows a structured exit and offboarding plan, facilitated by a dedicated Customer Success Manager in collaboration with nominated customer stakeholders. The plan outlines key actions for all parties, a communication strategy, notice period activities, service switch-off, post-exit procedures, and the secure transfer of information to any new provider.
All data is managed safely throughout the offboarding process to ensure compliance and continuity. At the conclusion of the contract, user accounts are disabled, and no further messages can be sent through the platform, ensuring secure closure of the service while maintaining the integrity and privacy of patient data. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Built with a mobile-first approach, FootFall ensures patients enjoy a seamless experience across both mobile and desktop. Messaging via FootFall and SMS along with sending photos, completing online consultations, and video consultations, every interaction is intuitive and efficient. NHS-compliant design and patient-focused navigation make accessing care simple, while self-help resources empower patients and reduce practice workload. By combining convenience, accessibility, and engagement, FootFall enhances patient satisfaction, drives efficiency, and positions your practice at the forefront of modern, connected healthcare no matter if you are using a mobile or desktop to access FootFall.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
-
The service interface includes a patient-facing website and a secure staff dashboard working seamlessly together.
The mobile-first, NHS-compliant website helps patients quickly find information, complete forms, book appointments, start online or video consultations, and access self-help tools, including the Patient Digital Assistant, reducing calls and walk-ins.
The staff dashboard provides a single view of all patient interactions, bringing together forms, messages, bookings and referrals. SNOMED-coded data can be exported directly into clinical systems, helping practices manage demand efficiently while reducing administrative workload. - Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
Interface testing is carried out across singular components, patterns and the complete journeys which are expected to be done through the service (such as requesting an appointment or checking when the surgery is open).
We include assistive technology testing for needs such as learning and cognitive disabilities, limited mobility, and low or no vision. This consists of interactions with screen magnification or zoom controls, screen readers (like NVDA, VoiceOver), changing content presentation (colour contrast, text spacing), alternative input and full keyboard navigation.
User research and early designs factor in access needs and are kept at the forefront throughout an iterative process with testing at each stage of development; using tried and tested components from the NHS digital service manual or our own library of custom design components and patterns.
Our products are pilot tested and once deployed, used daily by patient and practice users across a large demographic - we welcome and encourage continual feedback to improve accessibility and usability for all. - API
- No
- Customisation available
- Yes
- Description of customisation
-
NHS GP Practices can customise various aspects of the service to meet the needs of patients and staff. Websites can be personalised with practice branding, layouts, colours, and content, providing clear information for patients. Forms can be tailored with specific fields, mandatory inputs, and submission rules, making it easy to collect patient details, appointment requests, or feedback. Auto replies can be set up with custom messages to acknowledge appointment requests or enquiries immediately. Reply templates allow staff to provide consistent, accurate responses to common patient questions efficiently. Form routing ensures submissions are automatically directed to the relevant clinician, admin team, or department, streamlining workflow. KPIs (Key Performance Indicators) can be defined and displayed through customised dashboards and reports, helping the practice monitor patient access, appointment response times, and service performance.
Customisation is managed directly through the platform’s user-friendly interface. Administrators or staff with the appropriate permissions can adjust settings, ensuring secure and controlled access. By tailoring these features, the service supports GP Practices in improving efficiency, maintaining clear communication with patients, and delivering high-quality, responsive care.
Scaling
- Independence of resources
- We have monitoring services in place to assess the demand on our services and can scale-up capacity quickly in periods of intense usage.
Analytics
- Service usage metrics
- Yes
- Metrics types
- We provide real-time dashboards enabling practices to track online requests, showing new, in-progress and queued submissions, alongside average closing times and close rates. Volumes can be viewed by hour, day, week or month, supporting workforce planning by identifying peak demand. Practices can analyse activity by request type and submission source, including patients, proxies or staff. Outcome reporting shows how consultations were resolved, including appointments, video consultations and response-time breaches. Additional insights demonstrate reductions in appointments, visits and phone calls. Dashboards are also available for PCNs and ICBs, enabling cross-practice visibility, comparison and assurance that requests remain open during core hours.
- Reporting types
- Real-time dashboards
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- If an organisation requests a Documented Data Extract, we will provide a .CSV file with every piece of Data submitted to that organisation.
- Data export formats
- Other
- Other data export formats
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- PNG
- IMG
- JPEG
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- We use Amazon Web Services (AWS) infrastructure within the UK regions and availability zones, providing a resilient, cloud-based environment designed for high availability and fault tolerance. Data is replicated in real time across multiple AWS Availability Zones, ensuring continuity and rapid failover in the event of an outage. All patient-identifiable data is encrypted to NHS encryption standards (AES-256). The AWS environment and associated services are ISO 27001 certified. The service is available 24/7/365 with a minimum 99.9% uptime commitment.
- Approach to resilience
-
Our service is built on Amazon Web Services (AWS) infrastructure within UK regions and Availability Zones, delivering a resilient, cloud-based environment engineered for high availability and fault tolerance. Patient-identifiable data is encrypted to NHS standards (AES-256) and replicated in real time across multiple AWS Availability Zones, ensuring continuity and rapid failover in the unlikely event of an outage. The entire environment is ISO 27001 certified, giving our clients confidence in the security and compliance of our platform.
We provide 24/7/365 availability with a minimum 99.9% uptime commitment, supported by continuous monitoring systems that alert our team to any system faults or server failures, allowing prompt resolution.
Our software is continuously updated to meet evolving legislation and regulatory requirements. Updates are first identified by our Principal Developer in collaboration with the Compliance Manager, then gaps are assessed and an action plan is produced. These are incorporated into the development plan and linked directly to the software release process. This is overseen by our Clinical Safety Officer.
This combination of resilient architecture, robust monitoring, rigorous compliance, and proactive software management ensures our service remains secure, reliable, and consistently available to support patients and healthcare providers. - Outage reporting
-
When any issue arises that may impact system availability, our Helpdesk and Account Management Team act swiftly to keep all users informed. We proactively issue updates and guidance through multiple channels. This ensures that users are immediately aware of the situation, understand any potential impact, and receive timely instructions on next steps or workarounds.
In the unlikely event of a system outage, our Helpdesk is fully prepared to provide direct technical assistance. Users can contact the team via phone, email, or online support channels to receive guidance, troubleshooting support, and updates on restoration timelines. All communications are coordinated to ensure clarity, transparency, and consistency, minimising uncertainty and maintaining user confidence.
Our approach combines proactive notification, multi-channel communication, and responsive technical support to ensure that any disruption is managed efficiently and with minimal impact. By prioritising timely information and accessible assistance, we uphold our commitment to service continuity and user satisfaction.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to the management interface is controlled via role-based permissions. One staff account, usually the practice manager, is designated as an administrator and can create additional accounts, assigning roles such as standard user or administrator. Certain dashboard features, such as overall reports, are restricted to administrators. Support is provided via a dedicated email address, shared only with practice administrators to protect sensitive information, though access is not strictly restricted to avoid loss of important communications.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Silicon Practice operates within a robust information security and governance framework aligned to recognised national standards and regulatory guidance. Our policies and controls are informed by ISO 27001, NHS England requirements and Cyber Essentials, including CE+. This ensures that information security, privacy, and governance are embedded across all areas of the organisation.
Information security oversight is led through a dedicated governance function that adopts a structured, risk-based approach to protecting our systems, services, and data. A documented security strategy is maintained and reviewed on an ongoing basis to ensure it remains appropriate as regulatory guidance, organisational needs, and the threat landscape evolve.
Key policies include vulnerability management, supported by regular penetration testing; secure development practices that enforce privacy and security by design; and Data Protection Impact Assessments for all new products, system changes, and data-sharing activities. These policies and assessments are reviewed at least annually.
The Silicon Practice platform is hosted within Amazon Web Services (AWS) infrastructure. All data is encrypted both in transit and at rest in accordance with NHS encryption standards.
All employees undertake mandatory information security and data protection training on joining the organisation, with regular refresher training delivered thereafter, ensuring continued awareness, compliance, and accountability. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- All development work goes through a pull request testing process: developers submit completed feature code for review, which is added to the relevant release branch upon passing peer code review. All releases and final builds are tested to ensure they maintain compliant and do not introduce further or critical bugs. We carry out regular penetration testing of all products to assess for any potential security impacts.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Threats to Silicon Practice services are assessed based on the risk they pose to our business, customers, or patient data, including UK GDPR, information security, and clinical safety considerations. Any threats to data confidentiality, integrity, or availability are treated as high priority. Patches are deployed via scheduled releases to our servers, typically in the evening to minimise downtime. Updates are applied across all hosted FootFall websites and dashboards simultaneously. Release schedules are planned in advance, though urgent patches can be deployed the same day. Threat intelligence is sourced from cybersecurity advisory services and official notices.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
We run multiple forms of malware scanning in our environments. New files being uploaded by users are scanned and are either made available if safe or quarantined if not. We also have a WAF. We also monitor and log all access to production databases and websites.
Once reported, we aim to remediate any security incidents as soon as possible. - Incident management type
- Supplier-defined controls
- Incident management approach
-
Service requests, feedback and complaints are raised via our support email or phone number, both of which are provided to practices upon onboarding. Any incidents may be reported through these channels and then are logged through our helpdesk.
We then ensure our Service Level Agreements (SLAs) are upheld and resolve any incident as soon as we can with full resource behind it. Full reports are written and circulated to those affected for any major incidents including a full root cause analysis. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- We offer a 4-week free trial in a controlled environment, providing access to a GP website, dashboard, and patient digital assistant. You can complete forms, triage, communicate with patients, and explore the Pharmacy First referral module. Training is included to showcase the full solution safely.
- Link to free trial
- https://outlook.office365.com/book/SolutionDemonstration@siliconpractice.co.uk/?ismsaljsauthenabled=true
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 3%
- Between £250,000 and £500,000
- 8%
- Between £500,001 and £1,000,000
- 15%
- Between £1,000,001 and £2,500,000
- 20%
- Between £2,500,001 and £5,000,000
- 22%
- Over £5,000,001
- 25%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Alcumus
- ISO/IEC 27001 accreditation date
- Friday 21 June 2024
- What the ISO/IEC 27001 doesn’t cover
- All parts of the service are covered
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 654c1d7c-5ff3-4431-8f07-d909c87c9875
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- F46f4f82-4586-411d-9b18-263c82719091
- Other security certifications
- Yes
- Any other security certifications
-
- NHS DSPT assurance - Standards Exceeded (ODS code 8KC12)
- Fully compliant with DCB0129
- ICO Registration (ZA074234)
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Plans to engage the contract workforce in deciding the most important workplace issues to address
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
-