APPENDIX A - ELECTRONIC HEALTH RECORDS RFP - FINAL.xlsx
XLSX spreadsheet 20 KB Posted
- Attached to
- 9280-25-R-IFBD-00030 State and local contract opportunity
- Solicitation number
- 3160007167
- Issued by
- Greene County, Mississippi
About this file
This is a requirements document (Appendix A) detailing the functional specifications for an Electronic Health Records (EHR) system for what appears to be a university health center (USM - University of Southern Mississippi). The document outlines extensive requirements for an EHR system including bi-directional interfaces with multiple systems including PeopleSoft, LabDAQ, LabCorp, ProPharm One, eRad, and Availity. Key functionalities required include appointment scheduling, patient portal capabilities, pharmacy integration, laboratory management, billing and financial management, secure messaging, and automated appointment reminders. The system must be HIPAA and FERPA compliant, with specific emphasis on security requirements and data encryption both in transit and at rest.
The technical requirements specify that the solution can be either cloud-hosted or on-premise, must support Oracle database technology if on-premise, and must integrate with SAML/SSO, Shibboleth, or Microsoft Azure Active Directory for authentication. The system must provide comprehensive audit trails, role-based security, and support current state and federal privacy laws including GDPR where applicable. The vendor must provide implementation services, training, and 24/7 customer support. The document uses a Required/Optional (R/O) designation system to indicate which specifications are mandatory versus desired features.
View the file
Other files for this state and local contract opportunity
| File | Type | Posted |
|---|---|---|
| USM RFP 25-30 LEGAL AD.pdf | ||
| download.pdf | ||
| RFP 25-30 ELECTRONIC HEALTH RECORDS - FINAL.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Sheet1
| Req/Opt | Functional Review | Yes/No | Additional Details |
| R | Ability for the site to define and modify reason for visit | ||
| R | Ability for the site to define and modify appointment type | ||
| R | Ability for the site to define and modify schedule templates for each provider | ||
| R | Ability to modify a provider's daily schedule without having to modify the template | ||
| R | Ability to define and modify multiple schedule templates for each provider | ||
| R | Ability for the site to define and modify which patient chart data elements display in the header of the chart | ||
| O | Ability for the site to define and modify colors for abnormal labs to display | ||
| O | Ability for the site to define and modify common groupings of CPT/HCPCS and associated diagnoses for ease of ordering lab tests and/or procedures | ||
| O | Ability for the site and each provider to define and modify commonly used phrases for ease of charting | ||
| O | Ability for the site to define and modify data elements that will display on the daily dashboard of patients to be seen | ||
| R | Integrated access to Up-To-Date | ||
| R | Integrated access to the Mississippi Prescription Monitoring Program (MS PMP) via Bamboo which is the vendor with which the site is currently contracted | ||
| R | Ability for the EHR to log/document in the patient's chart that the Mississippi State Board of Pharmacy controlled substance database was queried | ||
| O | Ability for the site to define and modify which users can and cannot apply unapplied insurance and patient balances | ||
| O | Ability for the site to define and modify which users can and cannot reverse applied unapplied balances for insurance and patient balances | ||
| O | Ability for the site to define and modify which users can and cannot perform insurance payment adjustments | ||
| O | Ability for the site to define and modify which users can and cannot perform balance transfers | ||
| R | EHR company should provide updated CPT, HCPCS, ICD10 changes as appropriate in a timely manner as released by the appropriate entity | ||
| R | Abilty for the site to monitor interfaces. Ability to view raw data going across the interface is preferred. | ||
| R | Ability for the site to restart interfaces if needed | ||
| R | Ability for the site to be able to upload images documents (insurance card, physical forms, driver license, etc) from various sources (cell phone, etc) | ||
| O | Ability for the site to define and modify import images formats | ||
| R | Ability for bi-directional interface with eRad for radiology orders, images and returning reports from radiologists. Please provide written plan for implementation with eRad. | ||
| R | Provide separate testing instance of the EHR where testing of functionality, updates,etc can be tested before updates are moved to the production instance of the EHR. Maintain test environment | ||
| R | Ability to send automated appointment reminders whereby the site can define and modify mode of reminder (email, text ) and frequency | ||
| R | Ability to send site defined/modified Good Faith Estimate email based on type of visit | ||
| R | Provide robust claims scrubbing queue or similar functionality | ||
| O | Provide ability to search charts based on Alert type | ||
| R | Provide robust lab queue where lab staff can monitor pending lab orders, mark specimens as collected, mark labs as performed, indicate performing and collecting user, and indicate result status | ||
| R | Provide robust pharmacy queue where pharmacy staff can see pending prescriptions | ||
| R | Provide robust radiology queue where radiology staff can monitor pending radiology orders | ||
| R | Ability for specified users to merge duplicate charts | ||
| O | Ability for each user to modify font size | ||
| R | Ability for specified users to set up new users, modify user rights and reset passwords | ||
| R | Ability to have user proxies setup ( one user can proxy for another to approve documents, review lab results, address tasks, etc) or similar functionality | ||
| R | The system must provide a direct interface with the university’s campus registration system (i.e. PeopleSoft) to allow for patient demographic information to be displayed in the EHR. This should include, at a minimum, the following: patient name, date of birth, sex assigned at birth, marital status, AKA, International student indicator, Cell phone, social security number, institutional id, institutional employee id to indicate if the patient is a USM employee, eligibility indicator ( is student/patient currentlly enrolled and eligible to be seen in the clinic), Academic information to include: division, school, GPA, major, full time indicator, residence status, entry term, credit hours, class, level, NCAA code to indicate sport if an athlete, race, ethnicities, Holds: bursar, financial, veteran status. These are examples of the data elements to be included and not a total list. | ||
| R | Provide scheduling management through appointment, walk-in, group, couple, and recurring scheduling | ||
| R | Immunization tracking and compliance | ||
| R | Provide an image indexing function in order to retrieve scanned images and also allow for attaching the image to the patient’s chart | ||
| O | Provide medication inventory management in order to control inventory, recall reporting, and automate dispensing | ||
| R | Provide a financial management tool in order to allow for cash, check, credit and debit, Bursar, and Insurance payments | ||
| R | Provide a library of standard reports for all financial and clinical functions of the clinic | ||
| R | Provide a query builder report tool for custom reporting capability for shared reports and single user reports | ||
| R | Provide a library for online access to forms and reports | ||
| O | Provide a referral management system and allow for tracking of inbound and outbound referrals | ||
| R | Provide a task management function (i.e. to-do list). Allow ease of work flow management and internal communications from within the task | ||
| R | Provide integrated help documentation along with a help system access from within the application | ||
| R | Provide a patient web portal function which allows for online appointment scheduling, secure messaging, online health forms, patient chat function. Provide a vendor hosted web portal service. Must have the ability for the site to define and modify if ineligible patients can or cannot make appointments via the portal based on the Peoplesoft eligibility indicator | ||
| R | System must interface with the current in-house laboratory information system, LabDAQ by CompuGroup Medical, in order to allow for bi-directional interface. Please provide a written plan of execution to implement connectivity tothe Laboratory Information Sytem. | ||
| R | Must interface with the current outsourced reference lab, LabCorp, in order to allow for bi-directional interface | ||
| R | Ability to indicate to Labcorp via interface if a lab should be billed to Moffitt Health Center. | ||
| R | Must have bi-directional interface with the current in-house retail pharmacy software solution, Pro-Pharm One by Kalos, Inc., to include prescription, patient demographic and insurance information to transmit to ProPharm from the EHR and for detailed prescription, payment, sales tax,etc to come back to the EHR from Propharm. Please provide a written plan of execution to implement connectivity to ProPharm. | ||
| R | Ability for the EHR to appropriately separate and handle sales tax, prescription, over the counter,etc data and store appropriately in the EHR to allow for balancing of charges | ||
| O | Ability for the site to define and modify patient alerts | ||
| R | Ability for specified users to view data audits on demand for all files and data | ||
| R | Ability to securely message patients within the EHR and log this communication on the chart | ||
| R | Integration with Qualtrics for patient satisfaction surveys. Ability for site to define and modify frequency of surveys | ||
| R | Ability to automatically print site defined patient labels upon patient check in | ||
| R | Ability to define and modify password policies OR system must be able to meet USM specified password policies. | ||
| O | Ability for the site to define and modify task types | ||
| R | Ability for the site to define and modify a header that will be displayed on all screens of the patient chart | ||
| R | Provide nurse pool functionality where messages can be sent to a nurse pool and a site defined group of nurses can respond to and manage the messages in the pool | ||
| R | Must interface with the current in-house billing software, Availity, in order to submit claims by means of paper and electronic format | ||
| R | Must provide an X12 interface for the development and maintenance of Electronic Data Interchange (EDI) standards | ||
| R | Must provide automated email and text appointment reminders which are site defined and can be modified by the site | ||
| O | Must provide a self-check-in function | ||
| R | System must be certified and maintain certification with Sure Scripts (EPCS) in order to allow authorized participants in the Sure Scripts network to transmit prescriptions, including new and renewal prescriptions to participating pharmacies of the patient’s choosing. Appropriate fob or other HIPAA compliant mechanism must be utilized for electronic prescribing of controlled substances | ||
| R | Allow automated lab result posting to the web portal with ability for the site to define and modify which lab results automatically publish to the portal upon resulting and which lab results publish to the portal only after a provider reviews and signs off on the results | ||
| R | Automated export of finances in a format that can be imported into Oracle PeopleSoft. Must have the ability to send charges and corrected charges (retract previously sent charges) | ||
| R | Ability to setup mutiple fee schedules | ||
| R | Ability to upload .jpg images standard format 400x400 of student photos and import those photos into the Electronic Health Records system database. | ||
| R | Allow for screen customization by user | ||
| R | Must be HIPAA compliant. Specifically, the system must have the capability to meet all of the security requirements outlined in 45 CFR Part 164 Subpart C- Security Standards for the Protection of Electronic Protected Health Information. | ||
| R | Must be FERPA compliant | ||
| R | Must have have proven experience in higher education institutions focused on student health services | ||
| R | Must provide implementation. Provide detailed plan of implementation to include all training and interfaces | ||
| O | Provide on-site training. Please provide written training plan. | ||
| O | Provide 24/7 customer support | ||
| R | If a On Premise solution, must support Oracle database technology. If so, please provide what versions are compatible with the the system. | ||
| R | Ability for the EHR to be hosted at USM or Cloud functionality | ||
| R | What is the maximum amount of time estimated for conversion of all electronic medical records to provide minimal interruption of services? | ||
| R | Must provide HIPAA compliant backup of EHR including redundant copies. Include explanation of backup plan | ||
| Technical Team Review | |||
| R | In response to HIPAA requirements, health record network traffic cannot "mix" with university network traffic. The communication of health records must be encrypted in transit. Does the system encrypt data in transit? Please explain. | ||
| R | The University technology security team recommends that the data residing in the health records database be encrypted. Does the system encrypt data at rest? Please explain how the system complies with this recommendation. | ||
| R | Does the system interface with an Oracle database so that "active" individuals in Oracle PeopleSoft can be identified as qualifying for health services and process and update this information in the proposed system? If so, what versions are compatible with the proposed system? | ||
| R | If On Premise, What is the preferred server operating system for the system? | ||
| R | Must be web accessible. | ||
| R | Must be accessible from Apple iPhone or iPad and Android phone and tablet devices. | ||
| R | Must be 508 compliant. | ||
| O | Should support CMMI. | ||
| R | Must allow export of data to either a delimited file or CSV. | ||
| O | Should allow customizable session timeout capabilities. | ||
| O | Should have API availability to automate interface to and from other systems. | ||
| R | Authenticate users with SAML/SSO, Shibboleth, or Microsoft Azure Active Directory. | ||
| R | Should have role-based security – to allow access to services. | ||
| R | Explain what type of documentation or help system is included in the solution. | ||
| Hosted Solution Requirements | |||
| R | Must secure data in transit and at rest. If encryption of data at rest is not available, please provide alternative measures. If encryption of data is available and imposes additional cost, that cost should be reflected in the proposal. | ||
| R | Vendor shall have in place a system recovery plan, including policies around regular backups and restoration and recovery of data within 24 hours of an outage or request. | ||
| Security And Access Control | |||
| R | Must provide centralized account management functionality (account creation, deletion, lock-outs, etc..). | ||
| R | Must have the ability to segment constituent data to accommodate varying security levels for different users. | ||
| R | Must support role-based user permissions and accesses. Role-based permissions govern each user's rights to add, edit,and view information within the system. | ||
| O | Should provide attribute-based access control for granting permissions to add, edit,and view information within the system. | ||
| R | Must provide a capability for logging of user management, administrative activity, and of user activity. | ||
| R | Must allow the university admistrator to view user data on system use, (logins, uploads, modifications, etc). | ||
| R | Must provide an audit trail/logging for any action in the database, including real-time notifications. | ||
| R | Must provide a system capability for auditing/logging. | ||
| R | Must have the ability to track and display the history of information stored in the application. | ||
| R | Must have the ability to support current State and Federal privacy laws and general data protection (GDPR) policies where applicable | ||
| R | Where applicable, web portal shall meet ISO/IEC 40500:2012 [Web Content Accessibility Guidelines (WCAG) 2.1 AA] at a minimum. | ||
| R | Must have the ability to segment data according to a data security model. | ||
| R | Must provide read-only data fields, or the prevention of overwriting certain data fields. | ||
| R | Must provide a method for all data imports and exports, and must use a secure file transfer such as Secure File Transfer Protocol (SFTP). | ||
| O | Must support integration with third-party multi-factor authentication providers. | ||
| R | The solution shall allow secure login leveraging LDAP, SAML, Active Directory, or Shibboleth security integration and determine level of access via identified fields within LDAP. | ||
| R | Must allow for granular role-based control of access to profile data and workflows; including full access, limited access, and view only access; based on the individual user. | ||
| R | Must allow the administrator to assign security roles to users. | ||
| R | Must not use or provide default credentials. | ||
| System | |||
| R | Vendor must implement software upgrades and updates to the system with prior notification to the University. | ||
| O | Must have the ability to import and export data on demand with built-in utility for data import/export. | ||
| O | Must have a documented web services based API for completing custom integration with other applications. | ||
| O | Use publicly open APls: The API must be publically accessible and freely available to encourage innovation and partnership. All data within the CRM must be consumable through this API. | ||
| R | Those submitting proposals should be prepared to provide a campus demo if requested |
File details come from the government source that posted it. Updated .