Public View
Public View is a healthcare analytics service for NHS and health bodies across the UK public sector, connecting hundreds of public data sources and providing intuitive dashboards, benchmarking, advanced analytical tools including SPC, and the latest National Oversight Framework (NOF) metrics to support quality improvement and informed decision-making.
Features
- NHS performance and metric monitoring from published data
- Mobile‑optimised access with offline app support
- Ranking, trend, change, delta and SPC charts
- National Oversight Framework dashboard (NOF)
- HCPS metric predicting aggregate performance and CQC rating
- Upload local metrics via Excel or API
- Hundreds of KPIs for custom scorecards
- Quick links to metric definitions and data sources
- Report Pack creation directly into PowerPoint
Benefits
- Supports creation of full NHS Integrated Performance Reports
- Enables organisation‑wide engagement with unlimited users
- Ensures accuracy for board reporting and audit
- Compare performance across any NHS provider or system
- Benchmark across multiple custom peer groups simultaneously
- Improve quality using SPC and benchmarking tools
- Toggle between custom peer‑based targets instantly
- View dashboards back to 2008 with track‑back
- Create custom specialty and indicator scorecards
- Integrate benchmarking into local dashboards via database service
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 6 7 3 2 6 0 9 0 5 4 5 4 1 6
Contact
BCN GROUP LTD.
Mr Ric Kelly
Telephone: 0345 095 7000
Email: mark.day@bcn.co.uk
About your service
- Service categories
-
Application Development and Deployment
Analytics and business intelligence
- Business Intelligence
- Advanced and predictive analytics
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- No specific constraints depending on architect agreed with customer
- System requirements
- None
User support
- Email or online ticketing support
- Yes
- Support response times
-
Standard Support Hours - Monday - Friday 08:00 - 18:00Hrs
Extended Support Hours - Monday - Friday 07:00 - 19:00Hrs
Out of Hours Support - P1 ONLY - 24/7 (Excluding Christmas Day)
Priority 1: Standard / Extended Hours - Response Within 30 minutes
Priority 1: (Out of Hours) Response Within 60 minutes
Priority 2: Standard / Extended Hours – Response Within 2 hours
Priority 3 or 4: Standard / Extended Hours – Response Within 4 hours
Priority 5: Standard / Extended Hours – Response Within 4 hours - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- EN 301 549
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Availability
BCN Managed Cloud is designed and maintained to achieve a target availability of 99.9% measured on a calendar month.
Support Hours
50+ dedicated support engineers across 3 UK offices provide technical support 24 hours a day, 7 days a week, 365 days a year.
* This includes proactive monitoring and alerting of core services. *Waking Hours = 7am to 7pm Monday to Friday (from manned helpdesk)
Ticket Severity
All tickets logged to the Service Desk will be allocated a severity level based on the following methodology. This will ensure that reporting on service levels may be achieved to the optimum format.
1 - Catastrophic business disruption
2 - Severe business disruption or user critical issue
3 - Business disruption or multiple user issue
4 - Minor business disruption or user issue
5 - Job or Task
Service Desk Staff will evaluate the Incident and allocate a priority level after which it will be assigned to the appropriate staff. This will be based on the required skill set to resolve the incident in a timely manner. - Support available to third parties
- No
Onboarding and offboarding
- Getting started
-
A dedicated account manager will be aligned to ensure a smooth transition and support the onboarding process and user adoption.
Onsite/Online Training is provided alongside user guides.
Webinars and community forum are also encouraged for users to join and participate in. - Service documentation
- Yes
- Documentation formats
-
- Other
- Other documentation formats
-
- Microsoft Word
- Video
- End-of-contract data extraction
- At contract end, users can export all information available to them directly from the Public View platform before access is withdrawn. This includes exporting reports, scorecards, and benchmarking outputs using the built‑in reporting and download features. Any public NHS data used within the service remains accessible from its original national sources, as Public View only consolidates publicly available datasets. Because the service restricts onward sharing without approval, users should complete all required exports during their active subscription to ensure they retain any insights or materials they have generated.
- End-of-contract process
- At contract end, users can export all information available to them directly from the Public View platform before access is withdrawn. This includes exporting reports, scorecards, and benchmarking outputs using the built‑in reporting and download features. Any public NHS data used within the service remains accessible from its original national sources, as Public View only consolidates publicly available datasets. Because the service restricts onward sharing without approval, users should complete all required exports during their active subscription to ensure they retain any insights or materials they have generated.
- Documentation accessibility standard
- EN 301 549
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- MacOS
- Windows
- ChromeOS
- Other
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- No feature differences. Layouts will auto adapt dependent on screen configuration.
- Service interface
- No
- User support accessibility
- EN 301 549
- API
- No
- Customisation available
- Yes
- Description of customisation
- Trust branding such as logo and colour themes can be customised. Some customisation's will need to be provided by BCN, whereas some can be provided by the customer via the browser.
Scaling
- Independence of resources
- Public View is designed so each organisation accesses its own secured account, protected by unique credentials that must not be shared, ensuring separation of access between users and organisations. The service consolidates publicly available NHS data into a central platform and presents it through dashboards and scorecards, meaning all customers view the same underlying public datasets without competing for proprietary computational resources. Public View does not guarantee continuous availability, but its architecture allows each subscriber to independently access benchmarking outputs without affecting another subscriber’s performance or data access
Analytics
- Service usage metrics
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- Data is kept in standard data formats and can be extracted at any time by the customer using standard Microsoft or other products.
- Data export formats
-
- CSV
- Other
- Other data export formats
- PowerBI
- Data import formats
-
- CSV
- Other
- Other data import formats
- Any source that Power BI can connect to
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Legacy SSL and TLS (under version 1.2)
- Other
- Other protection between networks
- Ublic View is accessed as a secure web application hosted in Azure. Traffic to the service is over HTTPS within Microsoft Edge/CDN boundaries; Public View also notes limited use of Cloudflare for anonymous usage data, indicating a controlled, secured edge for site access. We align with the UK NCSC Cloud Security Principle 1 (Data‑in‑transit protection) by using industry‑standard encrypted transport (e.g., TLS) and strong service authentication, consistent with NCSC guidance to protect against eavesdropping, tampering, and impersonation using standard protocols such as TLS/IPsec or VPN where appropriate.
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Legacy SSL and TLS (under version 1.2)
- Other
- Other protection within supplier network
- Ublic View is accessed as a secure web application hosted in Azure. Traffic to the service is over HTTPS within Microsoft Edge/CDN boundaries; Public View also notes limited use of Cloudflare for anonymous usage data, indicating a controlled, secured edge for site access. We align with the UK NCSC Cloud Security Principle 1 (Data‑in‑transit protection) by using industry‑standard encrypted transport (e.g., TLS) and strong service authentication, consistent with NCSC guidance to protect against eavesdropping, tampering, and impersonation using standard protocols such as TLS/IPsec or VPN where appropriate.
Availability and resilience
- Guaranteed availability
- Our service is delivered using Microsoft Azure’s enterprise‑grade cloud platform and is architected to meet NHS expectations for high availability and service continuity. Availability is primarily dependent on Azure’s underlying infrastructure; however, our deployment follows Azure best‑practice high‑resilience patterns, including multi‑zone data replication and automated database failover to minimise disruption in the event of a regional or platform‑level incident. Our data protection measures align with NHS DSP Toolkit principles, incorporating encrypted backups stored both within Azure and in an independent off‑platform location to ensure recoverability in the event of severe system failure or data loss. These controls support rapid restoration, maintain service continuity, and ensure that essential functions remain available to NHS users in accordance with recognised assurance and governance standards.
- Approach to resilience
- We use Microsoft Azure’s physically secure, geographically separated Availability Zones to maintain service continuity during localised failures. Data is replicated across zones with automated failover, and we maintain encrypted backups both within Azure and in an independent off‑platform location to support rapid recovery and ensure resilience in line with NCSC expectations.
- Outage reporting
- Email alerts
Identity and authentication
- User authentication needed
- No
- Access restrictions in management interfaces and support channels
- We supply permissions based on the customers active directory.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- No audit information available
- Access to supplier activity audit information
- No audit information available
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- Organisation chart available on request. Upon induction, staff handbook, policies and procedures are provided. Specific IG policies around Information Security which are also in the staff handbook are included. We are also fully compliant with GDPR guidelines. Ongoing documented review to ensure policies are being followed as well as one-to-one systems to enforce policy processes.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Development and test copies of the solution will be held on our network. Bug fixes and enhancements will be logged in our ticketing system. Those tickets approved for implementation will be implemented on our development environment and then promoted to test where unit and integration testing will take place. Changes will be promoted to our production environment though a formal and documented change control process. Full version control of all parts of the solution will provide roll back options should they be required. Bug fixes will be implemented on an ad-hoc basis, enhancements will be released on a monthly cycle.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- This runs in the Microsoft environment, the office 365 and Azure vulnerability management approach applies.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- This runs in the Microsoft environment O365 and Azure, these processes are applied.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- BCN operates a mature, ISO‑aligned Incident Management process designed to ensure rapid, consistent, and secure handling of service or security incidents. Our approach follows the ISO/IEC 27035 lifecycle, covering preparation, identification, assessment, response, and lessons learned. All incidents are logged, analysed, and managed using standardised procedures to minimise impact and maintain service continuity. Supported by robust technical controls, governance, and continual improvement practices, our framework ensures the confidentiality, integrity, and availability of systems. This structured process enables fast containment, clear communication, and effective remediation across all managed services.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- Full access to Public View for a limited time. Please contact BCN direct for access to the Public View platform sales@bcn.co.uk
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 5%
- Between £250,000 and £500,000
- 10%
- Between £500,001 and £1,000,000
- 15%
- Between £1,000,001 and £2,500,000
- 20%
- Between £2,500,001 and £5,000,000
- 20%
- Over £5,000,001
- 20%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- SGS United Kingdom Ltd
- ISO/IEC 27001 accreditation date
- Sunday 13 July 2025
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- SGS United Kingdom Ltd
- ISO 9001 accreditation date
- Tuesday 8 July 2025
- What the ISO 9001 doesn’t cover
- N/A
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 052f6698-37b9-4ac9-b227-cacfc5cd7a9f
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 63c519cc-b513-414c-937a-7be3f1156af7
- Other security certifications
- Yes
- Any other security certifications
- NHS DSPT
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Ensuring new workers are informed of their right to join a trade union
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
- How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
- How the supplier will work with NGOs, trade unions or other businesses to address modern slavery risk
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
- Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
- Other measures to offer development opportunities for the target cohort(s) in the contract workforce
- Understanding of issues relating to entering the contract workforce
- Creation of outreach activities to create a pipeline of employees for the future contract delivery
-