Data Led Prioritisation for Outpatient Services
Factor 50 will work with an NHS trust to use patient level healthcare data to identify which patients in their waiting lists are carrying the most invisible risk - allowing the trust to more effectively use their scarce resources. This product was jointly developed with Sheffield Teaching Hospital.
Features
- Risk stratification through clinical lens of your outpatient waiting list
- Uses trust data (and primary care) and wearables data
- Multiple views - list views, patient level views, stakeholder views
- New cases are flagged when new data becomes available
- Robust platform ingests and validates the data...
- ...before running through a scoring engine
- Web based portal present insight to admin staff and clinicians
- ... allowing basic workflow of tasks and actions
- Supports Diabetes, Heart Failure, Renal and Rheumatology specialties
- Integrates with Continuous Glucose Monitor (CGM) device data
Benefits
- See clinical risk of patients in your follow-up waiting lists
- Based on criteria written and refined by leading UK consultants
- Uses data that the trust (or health system) has...
- ...but that hasn't been actively reviewed
- Easy to get set-up with low up front costs
- Creates measurable improvement in HbA1c of diabetes patients
- Releases 20-25% of outpatient follow-up activity
- Tackles health inequalities- using data to identify those greatest need
- Improve New:Follow-up ratios and reduce waiting times
- Certified MHRA Medical Device
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 7 0 2 3 7 6 2 3 1 6 9 6 4 5
Contact
FACTOR 50 LTD
Mark Hawkins
Telephone: 07879 885330
Email: mark@factor-50.co.uk
About your service
- Service categories
-
Application Development and Deployment
Analytics and business intelligence
- Advanced and predictive analytics
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- No
- System requirements
- Access to secure file transfer servers (or similar)
User support
- Email or online ticketing support
- Yes
- Support response times
- Typically within 2 hours, Monday to Friday.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- No
- Support levels
-
All clients will be given a named technical relationship manager who will work with the client to agree the appropriate support model.
Our service is built on highly available, scalable and fault-tolerant public cloud services, and deployed across multiple data centres. This ensures that: the service is available 24/7, 365 days per year: deployments require only minimal service disruption, and there is no need for extended pre-planned maintenance windows or outages; the service is highly resilient and backed up regularly to permit rapid resumption of service in the unlikely event of an outage.
In the event of any issue, queries/tickets can be raised via email. Response to support queries will be given within 48 working hours (i.e. excluding weekends), although every effort will be made to respond as soon as is feasible. While no phone or webchat support is provided as standard, the team are easily reached by phone during working hours
Standard support is covered under the SaaS licence cost; bespoke support models and/or onsite support is available should it be required (though may carry additional cost). - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
The service has been designed to be intuitive to the user, and we provide clear user documentation that covers functionality available across core user groups: Clinical staff; Admin and service management staff; Data and analytical teams.
Documentation covers: User registration and login; Workflow management; MI outputs; Data flows and exports.
Some documentation will be specific to the implementation employed by the customer, and where this occurs we will provide documentation tailored to that specific implementation.
We can provide onsite training upon request. - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- Any data stored within the service will be indexed against the user organisation(s) meaning that it can be readily extracted in a range of formats (including .csv), which can be returned to the user organisation via the same file or data sharing capabilities as is used for the normal running of the service.
- End-of-contract process
-
The contract covers the set-up and implementation of the service (including appropriate documentation and training etc.), and its ongoing use and support. At the end of the contract, an organisation would no longer have access to the service, as is standard under a SaaS arrangement. Should organisations wish to restart the service at a later date, setup costs may be waived should this reflect a resumption of the previous normal running of the service i.e. the service is simply "switched back on".
Organisations would be provided with such data as they require for audit purposes prior to any data purging required to honour IG obligations.
Any activities that go over and above that described above would be considered, but may carry an additional cost. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
Onboarding and offboarding is typically delivered 1:1 to cater to individual needs.
Other accessible dimensions include:
- written in Plain-English
- with step by step guides
- with visual examples.
For onboarding we expect to spend time with each of our users and can adapt and tailor the message and pace to the audience
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
We tend to find the majority of our users are administrators and clinicians and use Desktop/Laptop PCs to access our service. An ipad (ie tablet) can also be used.
This is ideal due to the breadth of information presented.
However, if the need arose, our service is accessible over mobile phone. - Service interface
- No
- User support accessibility
- None or don’t know
- API
- No
- Customisation available
- Yes
- Description of customisation
-
Factor 50 will work closely with clinical staff to understand their clinical requirements and ensure these are accomodated within the platform, in a way that is also consistent with the latest national guidelines.
Data imports and exports can also be configured in order to support the scorecards in use, as well as to meet the MI requirements of the customer.
Bespoke development to meet specific customer need will be considered but will carry additional costs.
Scaling
- Independence of resources
-
Our service is built on scalable public cloud technologies, to avoid capacity bottlenecks.
Load tests are run at 10x expected load, to ensure this scaling works as expected in practice.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
The precise metrics may vary according to the specifics of an implementation and/or user configuration.
However, metrics likely to include: Number of patients on the waiting list; The % that fall into user specified risk segments; trends over time.
These metrics will be segmented by: List (Specialty and/or sub-specialities); Individual clinics/sessions; Risk stratification levels; Ethnic and deprivation measures. - Reporting types
-
- Real-time dashboards
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
-
Any data stored within the service will be indexed against the user organisation(s) meaning that it can be readily extracted in a range of formats (including .csv), which can be returned to the user organisation via the same file or data sharing capabilities as is used for the normal running of the service.
The majority of pertinent data is available in MI views.
Ad hoc data extracts may also be provided upon request, but this may carry additional cost. - Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- The Clinician Portal is usually available 24/7/365, with scoring runs completed within 24 hours of data being supplied. Explicit SLAs can be discussed and agreed as part of the on-boarding process.
- Approach to resilience
- Our service is built on highly available and fault-tolerant public cloud services, and deployed across multiple data centres for resilience.
- Outage reporting
- Outages will be reported via email alerts.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- Role based authentication and access control are in place
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- Between 6 months and 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- Between 6 months and 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
-
Secure design & development:
Developers trained to code securely, with mandatory peer reviews before production release. All changes undergo automated GitHub Advanced Security checks, including dependency scanning, vulnerability alerts and static code analysis.
Build environment security:
Software built on VMs within secure Azure Virtual Network. Images and VMs are created via automated, logged processes with restricted access.
Deployment & maintenance:
The cloud-hosted platform requires no customer installation. Releases are centrally managed and deployed only after full review and testing.
Customer communication:
Maintain regular, transparent communication, promptly notifying clients of incidents and providing at least one year’s notice of unsupported software. - Information security policies and processes
-
Factor 50 has a comprehensive set of information security policies - which are available upon request.
Due to our focus on healthcare, much of the structure is designed to mirror what is required for the NHS Data and Security Protection toolkit.
These policies include detail on reporting structure and how we ensure policies are met. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
All changes are implemented via source control, and peer reviewed prior to being deployed to test environments.
Any changes to sensitive areas such as login are subject to an additional review, and significant changes to those areas trigger a fresh penetration test. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
A combination of vulnerability assessment approaches are implemented including static code scanning, tracking open source dependencies, implementing cloud vendor recommendations, penetration testing and staying abreast of industry news.
We utilise public cloud managed services, which are patched constantly. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
All logs are aggregated in a central location and reviewed automatically by machine learning algorithms supported by our public cloud provider.
Any alerts generated are reviewed by our staff within one working day. - Incident management type
- Supplier-defined controls
- Incident management approach
-
Users can report incidents via email. We will then invoke our incident management process and respond with an incident reference.
Users will be kept informed of progress, and incident reports will be made available on request. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
-
In a few circumstances, we have offered a free proof of concept.
This is a 3 month project where we will score a whole cohort and risk stratify it as a one-off exercise. - Link to free trial
- N/a
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
-