LifeBox
LifeBox is a digital perioperative solution that enables patients to complete preoperative assessments online while accessing clear, tailored information about their procedure and preparation. By digitising workflows, it reduces paper use and in-person appointments, supports carbon-reduction goals, improves data accuracy, and helps hospitals deliver safer, more efficient surgical pathways.
Features
- Enables patients to complete pre-assessment steps electronically
- Allows patients to complete healthcare questionnaires
- View procedure-specific videos, attend video consultations, and upload files securely
- Provides clinical staff with tools to manage patient profiles
- Enables hospital super users to manage staff accounts & roles
- Offers bespoke reporting capabilities
- Provides options for nurses to assist patients in completing questionnaire
Benefits
- Streamlines pre-assessment processes to enhance efficiency and reduce delays
- Offers a user-friendly digital journey
- Tailored educational videos and remote consultations
- Pathology integration
- Reduces reliance on paper-based processes
- Ensures accurate and detailed patient information
- Supports organisation-specific assessment
- Facilitates secure sharing of sensitive files
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 4 5 1 7 6 0 3 3 9 6 3 1 7 1
Contact
VITALHUB UK LIMITED
Mr. Colin Garrod
Telephone: +442045833142
Email: operationsuk@vitalhub.com
About your service
- Service categories
-
Applications
Production and operations
- Other operations
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
- No
- System requirements
-
- Access to the internet
- Device with latest Edge, Chrome, Firefox, or supported Safari
User support
- Email or online ticketing support
- Yes
- Support response times
- We maintain a 10 minutes response time for requests that come via Intercom Support
- User can manage status and priority of support tickets
- No
- Phone support
- No
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- None
- Onsite support
- Yes
- Support levels
- Support is provided via web chat 9-5 (UK time) Monday to Friday. All support requests are made via this route and where necessary escalated/referred to additional teams to ensure resolution to the query. This support is provided within the license cost of LifeBox.
- Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
- A structured onboarding approach which includes initial set up and configuration, role based access provisioning and clear guidance on how to use the Product. Users are provided with training materials and in-product guidance to support adoption as well as Live product demonstration via virtual calls or on site. Ongoing support is available via an in-application chat function, enabling users to raise questions or issues directly within the Product. Where required, we provide additional support during early use to ensure users are confident and able to use the service effectively.
- Service documentation
- Yes
- Documentation formats
-
- Other
- Other documentation formats
- In-application 'e-learning' video modules
- End-of-contract data extraction
- Output documents generated by the Product are typically retained, printed and stored in the patient records by the hospital as part of routine clinical record keeping. Where requested, the Processor can also provide a data extract in a standard, machine readable format (CSV, Excel) to enable the hospital to maintain a local copy. Any data provided in this extract is handled securely in line with UK GDPR and NHS information governance standards.
- End-of-contract process
-
End of Contract Procedures:
Data Retention and Access:
Output documents generated by the Product are typically retained, printed and stored in patient records by the hospital.
Data Extraction (optional)
If requested, the Processor can provide a secure data extract in standard, machine readable formats so the hospital can maintain a local copy.
Secure Deletion
Any remaining personal or special category data held by the Processor is securely deleted in accordance with UK GDPR and NHS Information Governance requirements unless otherwise instructed in writing.
Support and Handover
The Processor provides guidance and support for any data extraction or transition activities to ensure continuity of service and proper record keeping.
Documentation
Relevant policies, training materials and guidance remain available to the hospital to support ongoing use of exported data. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Our documentation is designed to be accessible to all users, including clear language, structured headings, readable fonts and sufficient colour contrast. Documentation is provided in digital formats that can be easily navigated, and we make reasonable adjustments to accommodate individual accessibility needs during both onboarding and off boarding processes.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- None - we leverage responsive design
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- The service interface is accessed in LifeBox in the same way as all other LifeBox services.
- Accessibility standards
- None or don’t know
- Description of accessibility
-
Patients should be able to:
- Use our solutions on most web browsers and devices
- Navigate most of the website using just a keyboard
- Change colours, contrast levels and fonts
- Zoom in up to at least 300% and still see most content
To ensure no patient is left behind, for patients that are unable or prefer not to access our solutions through the web, hospitals will support them through our “Assisted Digital” pathway. This will mean that the hospital will complete the patient's Health Questionnaire on their behalf, and patients will not need an online account. - Accessibility testing
- None
- API
- Yes
- What users can and can't do using the API
-
LifeBox offers the following outbound functions via it's FHIR-conformant API:
- POST Conditions
- POST DocumentReference resources
- GET Patient resources
- POST AllergyIntolerance resources
LifeBox offers the following inbound functions via it's FHIR-conformant API:
- GET CapabilityStatement resource
- POST Echo
- GET Echo
- PUT Patient resource
- GET Patient Resource
- PUT Episode - API documentation
- Yes
- API documentation formats
- Other
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
LifeBox enables hospitals to customise the following:
- The procedure code system to use for episodes (OPCS, CCSD, etc.)
- Preoperative Health Questionnaires (TO COME)
- Postoperative Health Questionnaires
- Items and categories in Work plan
- Content in system-generated emails (logo, sign off, and FROM email address)
All of the above can be customised by the LifeBox Support team.
Scaling
- Independence of resources
- Our AWS hosted service uses elastic, scalable components such as serverless compute and managed databases, allowing increased demand to be met by adding capacity rather than stressing fixed servers. Performance stability is maintained through automatic scaling, ensuring resources expand as load increases. For heavy or burst style workloads, we use queue based and batch processing to prevent impact on interactive users. Performance metrics—including latency, errors, and saturation—are actively monitored, with alerts enabling rapid response to abnormal demand.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
We provide service user metrics to support service monitoring, continuous improvement and reporting requirements. Depending on the service and client requirements, metrics include:
- Number of registered users and active users
- User engagement (number of episodes, completion rates)
- Service utilisation over time
- Operational metrics e.g. response times and system availability; days between episode creation, HQ completion, optimisation; procedural information.
Metrics are available via regular reporting on a weekly basis or on request and provided using secure data exports to support local analysis and in line with UK GDPR, Data Protection Act 2018 and other NHS governance standards. - Reporting types
-
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- Other locations
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Other
- Other data at rest protection approach
- LifeBox is hosted on AWS and AWS publish their comprehensive audit programs including ISO27001 and SOCII.
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Data Erasure
Data importing and exporting
- Data export approach
- Data exports are generated via AWS Quicksight analytics dashboard by Lifebox authorised users only. Exports are provided predominantly in common, open format such as Excel whereby the user can filter by date range or other user defined criteria where appropriate. Exports are delivered securely and in line with UK GDPR, Data Protection Act 2018 and NHS information governance standards. Where required, we can also support secure data extracts to enable local analysis and reporting.
- Data export formats
-
- CSV
- Other
- Other data export formats
- Excel
- Data import formats
-
- CSV
- Other
- Other data import formats
- Excel
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- Other
- Other protection between networks
- We secure data connectivity with a multi layered model supporting both public internet and private NHS integrations. Public traffic uses HTTPS with enforced TLS 1.2+, strong ciphers, and AWS CloudFront/API Gateway to block outdated protocols. For private NHS access, we support HSCN connectivity via AWS Direct Connect with Cloud Gateway and Transit Gateways, ensuring dedicated, non internet routes. Trust-specific integrations can use IPSec Site to Site VPNs terminating at an AWS Virtual Private Gateway for encrypted links into our private VPC. Network Security Groups and ACLs restrict inbound traffic to allow listed NHS or Trust IP ranges only.
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Other
- Other protection within supplier network
-
All data stored in Amazon DynamoDB is encrypted using AWS Key Management Service (KMS). Similarly, objects in Amazon S3 (documents) are encrypted at rest with strict lifecycle policies.
All patient and application data is encrypted at rest using AWS KMS across DynamoDB and S3. Internal service communication within VPCs is protected by TLS. Production, Training, and Non Production environments run in separate AWS accounts to isolate risk. Access follows least privilege principles using granular IAM roles, Bastion restricted database access, and strict Security Groups. Security posture is maintained through centralized logging and real time monitoring via Logz.io, CloudWatch, and BetterStack.
Availability and resilience
- Guaranteed availability
-
We deliver high service availability through a cloud-native, serverless architecture hosted on AWS (UK Region).
Our application leverages fully managed services, including AWS Lambda for compute, API Gateway for traffic management, and DynamoDB for data storage which inherently provide high availability and automatic scaling to match demand without manual intervention.
To ensure consistent uptime and rapid issue resolution, we employ a comprehensive application monitoring stack:
Active Availability Monitoring: We use BetterStack to continuously verify API uptime and responsiveness from external endpoints.
Performance Monitoring: Amazon CloudWatch is configured to detect performance anomalies in real-time.
Error Tracking: Sentry and logz.io provide real-time error detection and centralized logging, allowing us to identify misconfigurations or code-level issues immediately.
Infrastructure Health: We monitor AWS Health events to track the status of the underlying cloud infrastructure services. - Approach to resilience
-
Our service achieves resilience primarily through its serverless design and comprehensive testing strategy:
Serverless Infrastructure: We utilise AWS Lambda and API Gateway for compute and DynamoDB for data. These fully managed services abstract away physical infrastructure management, automatically handling resource scaling and recovery. This ensures the application remains resilient and responsive to demand without the need for manual workload management.
Segregated Environments: We maintain strictly isolated environments for Production, Training, and Non-Production within the UK. This separation ensures that updates or testing activities do not impact the stability of the live service.
Automated Verification: We employ a rigorous testing regime to ensure application resilience, including full Unit Test coverage, End-to-End integration tests, Cypress UI automation, and FHIR integration testing for healthcare workflows.
Proactive Monitoring: We use a modern telemetry stack (BetterStack, CloudWatch, Sentry, and logz.io) to detect and rectify application-level issues or misconfigurations immediately. - Outage reporting
-
We rely on automated monitoring coupled with standard support channels to report status:
Automated Detection: Our monitoring tools (BetterStack, CloudWatch, Sentry, logz.io) track API availability and performance in real-time. These systems alert our engineering team to any service interruptions immediately.
Customer Reporting: If an outage is confirmed, we communicate directly with affected customers via our established Service Desk and support channels.
Incident Follow-up: Significant incidents are managed via our internal incident response process. Once resolved, we provide a summary or Post-Incident Report (PIR) detailing the cause and the steps taken to prevent recurrence.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Other
- Other user authentication
- End‑users authenticate via Amazon Cognito using either username/password or federated SSO (e.g. NHSmail, Zesty). Two‑factor authentication via SMS is used for account activation, and fine‑grained access control is enforced via Cognito tokens and Lambda authorisers on API Gateway/AppSync.
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is restricted using role‑based IAM in a dedicated sign‑in account, with cross‑account roles into production that are least‑privilege, time‑bound and auditable. Only authorised support and operations staff can assume these roles when required.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Other
- Description of management access authentication
- Management access is authenticated using individual AWS IAM users with mandatory MFA in a dedicated sign‑in account. Administrators and support staff authenticate with username/password + MFA, then assume tightly scoped IAM roles into the production and non‑production accounts using short‑lived STS credentials, in line with AWS best practices. Programmatic access is via AWS Vault to ensure secure handling of credentials.
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- Cyber Essentials, Cyber Essentials plus, DSPT organisation code 8JF22, ISO9001, ISO14001
- Information security policies and processes
- VHUK follows the corporate suite of ISO 27001, ISO 9001, NHS Cyber Essentials Plus, and UK GDPR–aligned information security policies, covering governance, access control, asset management, information classification, cryptography, HR and user responsibilities, incident management, operations and network security, physical security, supplier management, change control, design and development, business continuity, internal audit, non‑conformance, customer feedback, and document control. VHUK reports into the Global Security, Compliance, and Privacy governance structure, with local control owners accountable for UK execution. Compliance is ensured through mandatory training, control ownership, evidence collection, internal and external audits, supplier reviews, access reviews, incident response processes, and corrective action tracking.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
VHUK follows ISO 27001 & 9001, CE+, GDPR, & SOC‑aligned configuration & change management processes. All configuration items & service components are maintained in the corporate CMDB, with approved baselines applied & monitored for compliance.
All changes to infrastructure, applications, & configurations follow a formal ITIL‑based Change Management process, including logging, risk assessment, testing, review, & approval. Security & privacy impacts—such as PHI/PII, access control, vulnerabilities, & availability—are mandatory considerations.
Compliance is ensured through mandatory training, local control ownership, continuous monitoring, audits, CAB oversight, evidence collection, incident review, & corrective action tracking, ensuring controlled, secure, & auditable changes. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
All servers are covered by a comprehensive monthly patching and maintenance schedule. Any important or urgent patches are applied out of schedule, with important patches within 2 weeks of a patch becoming available, and critical patches within 24hrs. Patches are always applied to Dev, UAT and Staging environments first to prevent issues with production environments.
Servers are actively monitored by a variety of tools including Spiceworks which highlight out of date software version numbers to the internal support team for action. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- We use tools to monitor logs and highlight potential compromises; anything discovered will be raised to a priority one ticket in our system and responded to within 1 hour. if there has been a compromise this will be remediated and logged as a security incident in our ISO 27001 based business management system in order that it is treated to prevent recurrence.
- Incident management type
- Supplier-defined controls
- Incident management approach
- VHUK follows an ISO27001 and CE+ aligned Incident Management Policy and Procedure to ensure incidents are reported, assessed, and resolved promptly to maintain secure and available services. All incidents must be reported immediately to management or the InfoSec Team. Incidents are logged with full details and initial actions taken. The InfoSec Team assesses severity and coordinates containment, eradication, and recovery, with high risk incidents escalated in line with corporate timeframes. Security incidents are recorded pursuant with ISO27001 procedures to support tracking, root cause analysis, corrective actions, and prevention of recurrence. Corporate Security provides oversight, with VHUK responsible for local compliance.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Bristish Assessment Bureau
- ISO/IEC 27001 accreditation date
- Wednesday 30 July 2025
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- British Assessment Bureau
- ISO 9001 accreditation date
- Wednesday 30 July 2025
- What the ISO 9001 doesn’t cover
- N/A
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 6a42672e-b586-48b2-b6c9-f1f6c81c8129
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 42ba2f56-2d16-4cb1-925a-0d87644122b9
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
- Plans for positive actions with community groups.
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of issues relating to entering the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-