Skip to main content

Help us improve the Digital Marketplace - send your feedback

VITALHUB UK LIMITED

LifeBox

LifeBox is a digital perioperative solution that enables patients to complete preoperative assessments online while accessing clear, tailored information about their procedure and preparation. By digitising workflows, it reduces paper use and in-person appointments, supports carbon-reduction goals, improves data accuracy, and helps hospitals deliver safer, more efficient surgical pathways.

Features

  • Enables patients to complete pre-assessment steps electronically
  • Allows patients to complete healthcare questionnaires
  • View procedure-specific videos, attend video consultations, and upload files securely
  • Provides clinical staff with tools to manage patient profiles
  • Enables hospital super users to manage staff accounts & roles
  • Offers bespoke reporting capabilities
  • Provides options for nurses to assist patients in completing questionnaire

Benefits

  • Streamlines pre-assessment processes to enhance efficiency and reduce delays
  • Offers a user-friendly digital journey
  • Tailored educational videos and remote consultations
  • Pathology integration
  • Reduces reliance on paper-based processes
  • Ensures accurate and detailed patient information
  • Supports organisation-specific assessment
  • Facilitates secure sharing of sensitive files

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at operationsuk@vitalhub.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

9 4 5 1 7 6 0 3 3 9 6 3 1 7 1

Contact

VITALHUB UK LIMITED Mr. Colin Garrod
Telephone: +442045833142
Email: operationsuk@vitalhub.com

About your service

Service categories

Applications

Production and operations

  • Other operations
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Private cloud
Service constraints
No
System requirements
  • Access to the internet
  • Device with latest Edge, Chrome, Firefox, or supported Safari

User support

Email or online ticketing support
Yes
Support response times
We maintain a 10 minutes response time for requests that come via Intercom Support
User can manage status and priority of support tickets
No
Phone support
No
Web chat support
Yes
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
WCAG 2.2 AA
Web chat accessibility testing
None
Onsite support
Yes
Support levels
Support is provided via web chat 9-5 (UK time) Monday to Friday. All support requests are made via this route and where necessary escalated/referred to additional teams to ensure resolution to the query. This support is provided within the license cost of LifeBox.
Support available to third parties
Yes
AI chatbot
Yes

Onboarding and offboarding

Getting started
A structured onboarding approach which includes initial set up and configuration, role based access provisioning and clear guidance on how to use the Product. Users are provided with training materials and in-product guidance to support adoption as well as Live product demonstration via virtual calls or on site. Ongoing support is available via an in-application chat function, enabling users to raise questions or issues directly within the Product. Where required, we provide additional support during early use to ensure users are confident and able to use the service effectively.
Service documentation
Yes
Documentation formats
  • PDF
  • Other
Other documentation formats
In-application 'e-learning' video modules
End-of-contract data extraction
Output documents generated by the Product are typically retained, printed and stored in the patient records by the hospital as part of routine clinical record keeping. Where requested, the Processor can also provide a data extract in a standard, machine readable format (CSV, Excel) to enable the hospital to maintain a local copy. Any data provided in this extract is handled securely in line with UK GDPR and NHS information governance standards.
End-of-contract process
End of Contract Procedures:

Data Retention and Access:
Output documents generated by the Product are typically retained, printed and stored in patient records by the hospital.

Data Extraction (optional)
If requested, the Processor can provide a secure data extract in standard, machine readable formats so the hospital can maintain a local copy.

Secure Deletion
Any remaining personal or special category data held by the Processor is securely deleted in accordance with UK GDPR and NHS Information Governance requirements unless otherwise instructed in writing.

Support and Handover
The Processor provides guidance and support for any data extraction or transition activities to ensure continuity of service and proper record keeping.

Documentation
Relevant policies, training materials and guidance remain available to the hospital to support ongoing use of exported data.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Our documentation is designed to be accessible to all users, including clear language, structured headings, readable fonts and sufficient colour contrast. Documentation is provided in digital formats that can be easily navigated, and we make reasonable adjustments to accommodate individual accessibility needs during both onboarding and off boarding processes.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
None - we leverage responsive design
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
The service interface is accessed in LifeBox in the same way as all other LifeBox services.
Accessibility standards
None or don’t know
Description of accessibility
Patients should be able to:

- Use our solutions on most web browsers and devices
- Navigate most of the website using just a keyboard
- Change colours, contrast levels and fonts
- Zoom in up to at least 300% and still see most content

To ensure no patient is left behind, for patients that are unable or prefer not to access our solutions through the web, hospitals will support them through our “Assisted Digital” pathway. This will mean that the hospital will complete the patient's Health Questionnaire on their behalf, and patients will not need an online account.
Accessibility testing
None
API
Yes
What users can and can't do using the API
LifeBox offers the following outbound functions via it's FHIR-conformant API:

- POST Conditions
- POST DocumentReference resources
- GET Patient resources
- POST AllergyIntolerance resources

LifeBox offers the following inbound functions via it's FHIR-conformant API:

- GET CapabilityStatement resource
- POST Echo
- GET Echo
- PUT Patient resource
- GET Patient Resource
- PUT Episode
API documentation
Yes
API documentation formats
Other
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
LifeBox enables hospitals to customise the following:

- The procedure code system to use for episodes (OPCS, CCSD, etc.)
- Preoperative Health Questionnaires (TO COME)
- Postoperative Health Questionnaires
- Items and categories in Work plan
- Content in system-generated emails (logo, sign off, and FROM email address)

All of the above can be customised by the LifeBox Support team.

Scaling

Independence of resources
Our AWS hosted service uses elastic, scalable components such as serverless compute and managed databases, allowing increased demand to be met by adding capacity rather than stressing fixed servers. Performance stability is maintained through automatic scaling, ensuring resources expand as load increases. For heavy or burst style workloads, we use queue based and batch processing to prevent impact on interactive users. Performance metrics—including latency, errors, and saturation—are actively monitored, with alerts enabling rapid response to abnormal demand.

Analytics

Service usage metrics
Yes
Metrics types
We provide service user metrics to support service monitoring, continuous improvement and reporting requirements. Depending on the service and client requirements, metrics include:
- Number of registered users and active users
- User engagement (number of episodes, completion rates)
- Service utilisation over time
- Operational metrics e.g. response times and system availability; days between episode creation, HQ completion, optimisation; procedural information.

Metrics are available via regular reporting on a weekly basis or on request and provided using secure data exports to support local analysis and in line with UK GDPR, Data Protection Act 2018 and other NHS governance standards.
Reporting types
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • Other locations
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
  • Other
Other data at rest protection approach
LifeBox is hosted on AWS and AWS publish their comprehensive audit programs including ISO27001 and SOCII.
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
Data Erasure

Data importing and exporting

Data export approach
Data exports are generated via AWS Quicksight analytics dashboard by Lifebox authorised users only. Exports are provided predominantly in common, open format such as Excel whereby the user can filter by date range or other user defined criteria where appropriate. Exports are delivered securely and in line with UK GDPR, Data Protection Act 2018 and NHS information governance standards. Where required, we can also support secure data extracts to enable local analysis and reporting.
Data export formats
  • CSV
  • Other
Other data export formats
Excel
Data import formats
  • CSV
  • Other
Other data import formats
Excel

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • Other
Other protection between networks
We secure data connectivity with a multi layered model supporting both public internet and private NHS integrations. Public traffic uses HTTPS with enforced TLS 1.2+, strong ciphers, and AWS CloudFront/API Gateway to block outdated protocols. For private NHS access, we support HSCN connectivity via AWS Direct Connect with Cloud Gateway and Transit Gateways, ensuring dedicated, non internet routes. Trust-specific integrations can use IPSec Site to Site VPNs terminating at an AWS Virtual Private Gateway for encrypted links into our private VPC. Network Security Groups and ACLs restrict inbound traffic to allow listed NHS or Trust IP ranges only.
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Other
Other protection within supplier network
All data stored in Amazon DynamoDB is encrypted using AWS Key Management Service (KMS). Similarly, objects in Amazon S3 (documents) are encrypted at rest with strict lifecycle policies.
All patient and application data is encrypted at rest using AWS KMS across DynamoDB and S3. Internal service communication within VPCs is protected by TLS. Production, Training, and Non Production environments run in separate AWS accounts to isolate risk. Access follows least privilege principles using granular IAM roles, Bastion restricted database access, and strict Security Groups. Security posture is maintained through centralized logging and real time monitoring via Logz.io, CloudWatch, and BetterStack.

Availability and resilience

Guaranteed availability
We deliver high service availability through a cloud-native, serverless architecture hosted on AWS (UK Region).
Our application leverages fully managed services, including AWS Lambda for compute, API Gateway for traffic management, and DynamoDB for data storage which inherently provide high availability and automatic scaling to match demand without manual intervention.

To ensure consistent uptime and rapid issue resolution, we employ a comprehensive application monitoring stack:

Active Availability Monitoring: We use BetterStack to continuously verify API uptime and responsiveness from external endpoints.

Performance Monitoring: Amazon CloudWatch is configured to detect performance anomalies in real-time.

Error Tracking: Sentry and logz.io provide real-time error detection and centralized logging, allowing us to identify misconfigurations or code-level issues immediately.

Infrastructure Health: We monitor AWS Health events to track the status of the underlying cloud infrastructure services.
Approach to resilience
Our service achieves resilience primarily through its serverless design and comprehensive testing strategy:

Serverless Infrastructure: We utilise AWS Lambda and API Gateway for compute and DynamoDB for data. These fully managed services abstract away physical infrastructure management, automatically handling resource scaling and recovery. This ensures the application remains resilient and responsive to demand without the need for manual workload management.

Segregated Environments: We maintain strictly isolated environments for Production, Training, and Non-Production within the UK. This separation ensures that updates or testing activities do not impact the stability of the live service.

Automated Verification: We employ a rigorous testing regime to ensure application resilience, including full Unit Test coverage, End-to-End integration tests, Cypress UI automation, and FHIR integration testing for healthcare workflows.

Proactive Monitoring: We use a modern telemetry stack (BetterStack, CloudWatch, Sentry, and logz.io) to detect and rectify application-level issues or misconfigurations immediately.
Outage reporting
We rely on automated monitoring coupled with standard support channels to report status:

Automated Detection: Our monitoring tools (BetterStack, CloudWatch, Sentry, logz.io) track API availability and performance in real-time. These systems alert our engineering team to any service interruptions immediately.

Customer Reporting: If an outage is confirmed, we communicate directly with affected customers via our established Service Desk and support channels.

Incident Follow-up: Significant incidents are managed via our internal incident response process. Once resolved, we provide a summary or Post-Incident Report (PIR) detailing the cause and the steps taken to prevent recurrence.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
  • Other
Other user authentication
End‑users authenticate via Amazon Cognito using either username/password or federated SSO (e.g. NHSmail, Zesty). Two‑factor authentication via SMS is used for account activation, and fine‑grained access control is enforced via Cognito tokens and Lambda authorisers on API Gateway/AppSync.
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is restricted using role‑based IAM in a dedicated sign‑in account, with cross‑account roles into production that are least‑privilege, time‑bound and auditable. Only authorised support and operations staff can assume these roles when required.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
  • Other
Description of management access authentication
Management access is authenticated using individual AWS IAM users with mandatory MFA in a dedicated sign‑in account. Administrators and support staff authenticate with username/password + MFA, then assume tightly scoped IAM roles into the production and non‑production accounts using short‑lived STS credentials, in line with AWS best practices. Programmatic access is via AWS Vault to ensure secure handling of credentials.

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
Cyber Essentials, Cyber Essentials plus, DSPT organisation code 8JF22, ISO9001, ISO14001
Information security policies and processes
VHUK follows the corporate suite of ISO 27001, ISO 9001, NHS Cyber Essentials Plus, and UK GDPR–aligned information security policies, covering governance, access control, asset management, information classification, cryptography, HR and user responsibilities, incident management, operations and network security, physical security, supplier management, change control, design and development, business continuity, internal audit, non‑conformance, customer feedback, and document control. VHUK reports into the Global Security, Compliance, and Privacy governance structure, with local control owners accountable for UK execution. Compliance is ensured through mandatory training, control ownership, evidence collection, internal and external audits, supplier reviews, access reviews, incident response processes, and corrective action tracking.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
VHUK follows ISO 27001 & 9001, CE+, GDPR, & SOC‑aligned configuration & change management processes. All configuration items & service components are maintained in the corporate CMDB, with approved baselines applied & monitored for compliance.
All changes to infrastructure, applications, & configurations follow a formal ITIL‑based Change Management process, including logging, risk assessment, testing, review, & approval. Security & privacy impacts—such as PHI/PII, access control, vulnerabilities, & availability—are mandatory considerations.
Compliance is ensured through mandatory training, local control ownership, continuous monitoring, audits, CAB oversight, evidence collection, incident review, & corrective action tracking, ensuring controlled, secure, & auditable changes.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
All servers are covered by a comprehensive monthly patching and maintenance schedule. Any important or urgent patches are applied out of schedule, with important patches within 2 weeks of a patch becoming available, and critical patches within 24hrs. Patches are always applied to Dev, UAT and Staging environments first to prevent issues with production environments.
Servers are actively monitored by a variety of tools including Spiceworks which highlight out of date software version numbers to the internal support team for action.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
We use tools to monitor logs and highlight potential compromises; anything discovered will be raised to a priority one ticket in our system and responded to within 1 hour. if there has been a compromise this will be remediated and logged as a security incident in our ISO 27001 based business management system in order that it is treated to prevent recurrence.
Incident management type
Supplier-defined controls
Incident management approach
VHUK follows an ISO27001 and CE+ aligned Incident Management Policy and Procedure to ensure incidents are reported, assessed, and resolved promptly to maintain secure and available services. All incidents must be reported immediately to management or the InfoSec Team. Incidents are logged with full details and initial actions taken. The InfoSec Team assesses severity and coordinates containment, eradication, and recovery, with high risk incidents escalated in line with corporate timeframes. Security incidents are recorded pursuant with ISO27001 procedures to support tracking, root cause analysis, corrective actions, and prevention of recurrence. Corporate Security provides oversight, with VHUK responsible for local compliance.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Bristish Assessment Bureau
ISO/IEC 27001 accreditation date
Wednesday 30 July 2025
What the ISO/IEC 27001 doesn’t cover
N/A
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
British Assessment Bureau
ISO 9001 accreditation date
Wednesday 30 July 2025
What the ISO 9001 doesn’t cover
N/A
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
6a42672e-b586-48b2-b6c9-f1f6c81c8129
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
42ba2f56-2d16-4cb1-925a-0d87644122b9
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
    • Plans for positive actions with community groups.
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
    • Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Understanding of the issues affecting the development of new skills by target cohort
    • Understanding of issues relating to entering the contract workforce
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at operationsuk@vitalhub.com. Tell them what format you need. It will help if you say what assistive technology you use.