Workforce Management Services for Healthcare
Holt Doctors provides an end-to-end booking system, LMS, for managing your temporary staff (bank, collaborative bank, agency, DE). Designed specifically for the healthcare sector, it continues to adapt to market changes with multiple compliance and cost management controls in place, and supported by 100+ agencies in the healthcare sector.
Features
- Workforce Management - Bank, Collaborative Bank, Agency, Direct Engagement
- Self-Fill APP for Candidates
- Remote Access from Any Device
- Budget controls, real time reporting, dashboard, and management information
- ISO27001 accredited - extensive security and access controls
- Integration with third party systems - standard API
- Online timesheets - all payment processes accommodated
- Multiple automated processes and checks - including compliance
- Out of hours bookings
- Full control of end to end booking process
Benefits
- Designed specifically for healthcare workforce management
- Accessible from any device - and self-fill candidate APP
- Full visibility and control of your temporary workforce
- Multiple budget and workforce planning tools - reduction in costs
- Full training and 24/7 support
- Experienced implementation team - 2-6 week implementation
- Established processes and procedures - no drop in fill rates
- Meets interoperability requirements
- Unlimited users - no costly licence fees
- Multiple compliance and cost management controls
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 9 5 9 2 9 9 8 2 9 3 7 8 0 5
Contact
HOLT MEDICAL RECRUITMENT LIMITED
Tracy Ward
Telephone: 0208 099 6943
Email: contracts@holtdoctors.co.uk
About your service
- Service categories
-
Application Development and Deployment
Analytics and business intelligence
- Business Intelligence
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- No
- System requirements
- Access to modern browser, or smart phone.
User support
- Email or online ticketing support
- Yes
- Support response times
- You have 24/7 access to our experienced LMS support team to help with queries on using LMS – we log all calls, responses and resolution times, and the service levels we commit to will be agreed. LMS utilise the JIRA reporting system. Support is by phone, online and email . LMS help desk may be contacted for immediate assistance from 8am to 6pm (week days) , with out-of-hours service provided by phone 24/7. LMS support team acknowledge and estimate time for resolution within 2 working hours. Resolution times will be dependent on priority level (see terms and conditions).
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- We will provide full training to all individuals at the client identified during the on boarding process as requiring access to LMS (client authorised users), as well as training manuals and videos (updated as required). On site training is in a variety of formats - floor walking, one to one and classroom - and applicable to specific job roles (finance, HR etc). Ongoing training support is provided via webinars (includes refresher training, training on new functionality/enhancements or updates) as well as face to face training for new starters, where agreed with client. Each client will have a dedicated account manager. Pricing for training and support is included as part of agreed set up costs (see rate card).
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
We provide clients with training tailored according to job roles in a variety of formats and at varying times through on-boarding and then ongoing. This includes initial classroom style overview, one to one “hands on” workstation training, floor walking and webinars. We also provide our clients' suppliers with relevant training via webinars. A training manual is provided with release notes also issued as applicable (with training if required).
We also provide our clients and their suppliers with 24/7 support. - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- With regard to client or their suppliers' data held within the LMS software platform we will ensure such data is transferred to the client or supplier(as relevant) within 30 days of the date of termination and such data will be in .csv format. The data will be subsequently deleted from our servers and the software platform (see service definition document for further details) subject to data protection legislation requirements.
- End-of-contract process
-
At the end of the contract a client can have customised data extracts. We agree the exit plan with the client at the outset of the contract as to what they will require so we can inform them and also agree any additional relevant costs (see service definition document).
We request details from the client at the outset of the contract as to what they will require so we can inform them and agree relevant costs. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- We will discuss accessibility requirements with the client as part of initial implementation so that we can ensure onboarding and offboarding documentation meets the accessibility standards needed by the client.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Chrome
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The mobile web portal for candidates is a fully responsive application.
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- Our website for LMS is the service interface.
- Accessibility standards
- None or don’t know
- Description of accessibility
-
We do not use a lot of symbols within the system but where we do there are mouseovers/rollovers that explain what they are/what they do.
All of the web pages can be magnified without loss of function, and text can be highlighted to be read out to a user (through available APPs)
There are no trigger points based only on colour. Bold is used to indicate items that have not been reviewed.
We do not use captchas.
Our system provides information only, not sensory experiences. - Accessibility testing
- We have not done any interface testing with users of assistive technology.
- API
- Yes
- What users can and can't do using the API
- The API is for programmers to work with, and they can use the API to connect the database to different front ends if they wish. They can send data to the system and retrieve data from it. Where they have specific and unique requirements an API can be written for the client (subject to cost).
- API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
We can customise any aspect of the software subject to cost.
A client can acquire a right to a copy of the code to modify it as they see fit.
There are multiple opportunities to modify how the product behaves.
Scaling
- Independence of resources
- We constantly monitor processor utilisation, upgrading architecture in line with demands for maximum number of concurrent users. We monitor the load time of key pages, and how long reports take to run, with pages that describe the longest time any given report has taken to run. If they are taking longer than is good practice, this indicates that the hardware needs to be upgraded or database queries need further optimisation. Our IT team provide 24/7 support, constantly monitoring the system and reporting to us immediately if there are any concerns so we have time to react.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
We can provide clients with metrics on how many people logged on at any one time, what reports have been run and by whom. All activities in the system are recorded by user - with a full audit trail available.
We have developed numerous standard reports, and as reporting functionality is an integral part of LMS, it is easy to add more.
Reports can be generated into excel multisheet format. Graphs/ dashboard indicators can be added. Reports can be in most formats , automated, with alerts for set criteria. - Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- LMS Recruitment Systems Limited - for the healthcare sector
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- In-house
- Protecting data at rest
- Physical access control, complying with another standard
- Data sanitisation process
- No
- Equipment disposal approach
- A third-party destruction service
Data importing and exporting
- Data export approach
-
LMS can provide pull or push feeds for Data Warehousing in various formats and protocols e.g. direct to MySQL, XML/JSON/CSV feed over http or by file transfer or we can create a custom feed if the integration layer needs a different format and/or protocol.
As regards reporting from LMS, reports can be generated into excel multisheet format. Graphs and dashboard indicators can be added according to client preferences. Reports can be in most formats, can be automated, with alerts sent if set criteria are exceeded/not reached. - Data export formats
-
- CSV
- Other
- Other data export formats
-
- Excel
- XML
- Data import formats
-
- CSV
- Other
- Other data import formats
- TSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Legacy SSL and TLS (under version 1.2)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Legacy SSL and TLS (under version 1.2)
Availability and resilience
- Guaranteed availability
-
We guarantee 99% availability. To date we have achieved 99.99%.
By way of example, these are our Key Performance Indicators which are included in our terms and conditions:
Service Availability - 24 hours, 7 days a week, 365 days per year.
99% availability - agreed downtime with the written consent of the Client’s Authorised Officer will be exempt. - Approach to resilience
- Available on request.
- Outage reporting
- There is a public dashboard, plus email notifications are sent by email to key contacts at each client.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Username or password
- Other
- Other user authentication
- User name and password, and location.
- Access restrictions in management interfaces and support channels
-
This is done programmatically, by configuring users at certain levels.
Each user account has a type (client staff, supplier, candidate), a level and a set of feature permissions, so it is possible, for example, to only give access to a feature to users of level 5 or above. Feature permissions are specific to each user type and new feature permissions can be added for all user types. - Access restriction testing frequency
- At least once a year
- Management access authentication
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- All of our processes are ISO27001 accredited - with staff trained regularly in these processes, with internal audits taking place as well to confirm compliance.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
The Change Management Team comprises: a member of the Senior Management Team, the LMS IT Manager, LMS Business Analyst and our Projects and Implementation Manager (from clients' perspective).
Full assessment is made of the change, the potential (including security) impact, timescales and the work required .
Each requirement goes through our project management process which include testing for requirement, identifying change points/responsibilities, robustness of change, re-briefing where necessary or can result in ‘no action’ where the change can be absorbed within current procedures.
Code reviews, testing and deployment overseen by IT manager.
Release notes/training issued as applicable. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Threats are assessed from technology news and system log files and evaluated for applicability and potential severity. Patches to services can be deployed within a day, depending on the complexity of the work.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- User and system activity is logged. Identification of potential compromises depends on triggering of system alerts on activity levels or manual review of logs. Response would be to evaluate the level of compromise and respond accordingly, depending on the severity. Response to identified incidents would be the same day.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Pre-defined processes are in place for common incidents (e.g. user suspects their account is compromised). Users report incidents to the LMS help desk by telephone or email. Incidents are reported to the system owner using a standard format.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0.5%
- Between £1,000,001 and £2,500,000
- 1%
- Between £2,500,001 and £5,000,000
- 1%
- Over £5,000,001
- 1%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Intertek
- ISO/IEC 27001 accreditation date
- Friday 25 July 2025
- What the ISO/IEC 27001 doesn’t cover
- The certification covers the operations department of our group.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- British Assessment Bureau
- ISO 9001 accreditation date
- Sunday 2 February 2025
- What the ISO 9001 doesn’t cover
- The certification covers our full Quality Management System.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-