APPENDIX A - ELECTRONIC HEALTH RECORDS RFP - FINAL.xlsx

XLSX spreadsheet 20 KB Posted

Attached to
9280-25-R-IFBD-00030 State and local contract opportunity
Solicitation number
3160007167
Issued by
Greene County, Mississippi

About this file

This is a requirements document (Appendix A) detailing the functional specifications for an Electronic Health Records (EHR) system for what appears to be a university health center (USM - University of Southern Mississippi). The document outlines extensive requirements for an EHR system including bi-directional interfaces with multiple systems including PeopleSoft, LabDAQ, LabCorp, ProPharm One, eRad, and Availity. Key functionalities required include appointment scheduling, patient portal capabilities, pharmacy integration, laboratory management, billing and financial management, secure messaging, and automated appointment reminders. The system must be HIPAA and FERPA compliant, with specific emphasis on security requirements and data encryption both in transit and at rest.

The technical requirements specify that the solution can be either cloud-hosted or on-premise, must support Oracle database technology if on-premise, and must integrate with SAML/SSO, Shibboleth, or Microsoft Azure Active Directory for authentication. The system must provide comprehensive audit trails, role-based security, and support current state and federal privacy laws including GDPR where applicable. The vendor must provide implementation services, training, and 24/7 customer support. The document uses a Required/Optional (R/O) designation system to indicate which specifications are mandatory versus desired features.

View the file

Other files for this state and local contract opportunity

Other files attached to 9280-25-R-IFBD-00030, newest first.
File Type Posted
USM RFP 25-30 LEGAL AD.pdf PDF
download.pdf PDF
RFP 25-30 ELECTRONIC HEALTH RECORDS - FINAL.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Sheet1

Req/OptFunctional ReviewYes/NoAdditional Details
RAbility for the site to define and modify reason for visit
RAbility for the site to define and modify appointment type
RAbility for the site to define and modify schedule templates for each provider
RAbility to modify a provider's daily schedule without having to modify the template
RAbility to define and modify multiple schedule templates for each provider
RAbility for the site to define and modify which patient chart data elements display in the header of the chart
OAbility for the site to define and modify colors for abnormal labs to display
OAbility for the site to define and modify common groupings of CPT/HCPCS and associated diagnoses for ease of ordering lab tests and/or procedures
OAbility for the site and each provider to define and modify commonly used phrases for ease of charting
OAbility for the site to define and modify data elements that will display on the daily dashboard of patients to be seen
RIntegrated access to Up-To-Date
RIntegrated access to the Mississippi Prescription Monitoring Program (MS PMP) via Bamboo which is the vendor with which the site is currently contracted
RAbility for the EHR to log/document in the patient's chart that the Mississippi State Board of Pharmacy controlled substance database was queried
OAbility for the site to define and modify which users can and cannot apply unapplied insurance and patient balances
OAbility for the site to define and modify which users can and cannot reverse applied unapplied balances for insurance and patient balances
OAbility for the site to define and modify which users can and cannot perform insurance payment adjustments
OAbility for the site to define and modify which users can and cannot perform balance transfers
REHR company should provide updated CPT, HCPCS, ICD10 changes as appropriate in a timely manner as released by the appropriate entity
RAbilty for the site to monitor interfaces. Ability to view raw data going across the interface is preferred.
RAbility for the site to restart interfaces if needed
RAbility for the site to be able to upload images documents (insurance card, physical forms, driver license, etc) from various sources (cell phone, etc)
OAbility for the site to define and modify import images formats
RAbility for bi-directional interface with eRad for radiology orders, images and returning reports from radiologists. Please provide written plan for implementation with eRad.
RProvide separate testing instance of the EHR where testing of functionality, updates,etc can be tested before updates are moved to the production instance of the EHR. Maintain test environment
RAbility to send automated appointment reminders whereby the site can define and modify mode of reminder (email, text ) and frequency
RAbility to send site defined/modified Good Faith Estimate email based on type of visit
RProvide robust claims scrubbing queue or similar functionality
OProvide ability to search charts based on Alert type
RProvide robust lab queue where lab staff can monitor pending lab orders, mark specimens as collected, mark labs as performed, indicate performing and collecting user, and indicate result status
RProvide robust pharmacy queue where pharmacy staff can see pending prescriptions
RProvide robust radiology queue where radiology staff can monitor pending radiology orders
RAbility for specified users to merge duplicate charts
OAbility for each user to modify font size
RAbility for specified users to set up new users, modify user rights and reset passwords
RAbility to have user proxies setup ( one user can proxy for another to approve documents, review lab results, address tasks, etc) or similar functionality
RThe system must provide a direct interface with the university’s campus registration system (i.e. PeopleSoft) to allow for patient demographic information to be displayed in the EHR. This should include, at a minimum, the following: patient name, date of birth, sex assigned at birth, marital status, AKA, International student indicator, Cell phone, social security number, institutional id, institutional employee id to indicate if the patient is a USM employee, eligibility indicator ( is student/patient currentlly enrolled and eligible to be seen in the clinic), Academic information to include: division, school, GPA, major, full time indicator, residence status, entry term, credit hours, class, level, NCAA code to indicate sport if an athlete, race, ethnicities, Holds: bursar, financial, veteran status. These are examples of the data elements to be included and not a total list.
RProvide scheduling management through appointment, walk-in, group, couple, and recurring scheduling
RImmunization tracking and compliance
RProvide an image indexing function in order to retrieve scanned images and also allow for attaching the image to the patient’s chart
OProvide medication inventory management in order to control inventory, recall reporting, and automate dispensing
RProvide a financial management tool in order to allow for cash, check, credit and debit, Bursar, and Insurance payments
RProvide a library of standard reports for all financial and clinical functions of the clinic
RProvide a query builder report tool for custom reporting capability for shared reports and single user reports
RProvide a library for online access to forms and reports
OProvide a referral management system and allow for tracking of inbound and outbound referrals
RProvide a task management function (i.e. to-do list). Allow ease of work flow management and internal communications from within the task
RProvide integrated help documentation along with a help system access from within the application
RProvide a patient web portal function which allows for online appointment scheduling, secure messaging, online health forms, patient chat function. Provide a vendor hosted web portal service. Must have the ability for the site to define and modify if ineligible patients can or cannot make appointments via the portal based on the Peoplesoft eligibility indicator
RSystem must interface with the current in-house laboratory information system, LabDAQ by CompuGroup Medical, in order to allow for bi-directional interface. Please provide a written plan of execution to implement connectivity tothe Laboratory Information Sytem.
RMust interface with the current outsourced reference lab, LabCorp, in order to allow for bi-directional interface
RAbility to indicate to Labcorp via interface if a lab should be billed to Moffitt Health Center.
RMust have bi-directional interface with the current in-house retail pharmacy software solution, Pro-Pharm One by Kalos, Inc., to include prescription, patient demographic and insurance information to transmit to ProPharm from the EHR and for detailed prescription, payment, sales tax,etc to come back to the EHR from Propharm. Please provide a written plan of execution to implement connectivity to ProPharm.
RAbility for the EHR to appropriately separate and handle sales tax, prescription, over the counter,etc data and store appropriately in the EHR to allow for balancing of charges
OAbility for the site to define and modify patient alerts
RAbility for specified users to view data audits on demand for all files and data
RAbility to securely message patients within the EHR and log this communication on the chart
RIntegration with Qualtrics for patient satisfaction surveys. Ability for site to define and modify frequency of surveys
RAbility to automatically print site defined patient labels upon patient check in
RAbility to define and modify password policies OR system must be able to meet USM specified password policies.
OAbility for the site to define and modify task types
RAbility for the site to define and modify a header that will be displayed on all screens of the patient chart
RProvide nurse pool functionality where messages can be sent to a nurse pool and a site defined group of nurses can respond to and manage the messages in the pool
RMust interface with the current in-house billing software, Availity, in order to submit claims by means of paper and electronic format
RMust provide an X12 interface for the development and maintenance of Electronic Data Interchange (EDI) standards
RMust provide automated email and text appointment reminders which are site defined and can be modified by the site
OMust provide a self-check-in function
RSystem must be certified and maintain certification with Sure Scripts (EPCS) in order to allow authorized participants in the Sure Scripts network to transmit prescriptions, including new and renewal prescriptions to participating pharmacies of the patient’s choosing. Appropriate fob or other HIPAA compliant mechanism must be utilized for electronic prescribing of controlled substances
RAllow automated lab result posting to the web portal with ability for the site to define and modify which lab results automatically publish to the portal upon resulting and which lab results publish to the portal only after a provider reviews and signs off on the results
RAutomated export of finances in a format that can be imported into Oracle PeopleSoft. Must have the ability to send charges and corrected charges (retract previously sent charges)
RAbility to setup mutiple fee schedules
RAbility to upload .jpg images standard format 400x400 of student photos and import those photos into the Electronic Health Records system database.
RAllow for screen customization by user
RMust be HIPAA compliant. Specifically, the system must have the capability to meet all of the security requirements outlined in 45 CFR Part 164 Subpart C- Security Standards for the Protection of Electronic Protected Health Information.
RMust be FERPA compliant
RMust have have proven experience in higher education institutions focused on student health services
RMust provide implementation. Provide detailed plan of implementation to include all training and interfaces
OProvide on-site training. Please provide written training plan.
OProvide 24/7 customer support
RIf a On Premise solution, must support Oracle database technology. If so, please provide what versions are compatible with the the system.
RAbility for the EHR to be hosted at USM or Cloud functionality
RWhat is the maximum amount of time estimated for conversion of all electronic medical records to provide minimal interruption of services?
RMust provide HIPAA compliant backup of EHR including redundant copies. Include explanation of backup plan
Technical Team Review
RIn response to HIPAA requirements, health record network traffic cannot "mix" with university network traffic. The communication of health records must be encrypted in transit. Does the system encrypt data in transit? Please explain.
RThe University technology security team recommends that the data residing in the health records database be encrypted. Does the system encrypt data at rest? Please explain how the system complies with this recommendation.
RDoes the system interface with an Oracle database so that "active" individuals in Oracle PeopleSoft can be identified as qualifying for health services and process and update this information in the proposed system? If so, what versions are compatible with the proposed system?
RIf On Premise, What is the preferred server operating system for the system?
RMust be web accessible.
RMust be accessible from Apple iPhone or iPad and Android phone and tablet devices.
RMust be 508 compliant.
OShould support CMMI.
RMust allow export of data to either a delimited file or CSV.
OShould allow customizable session timeout capabilities.
OShould have API availability to automate interface to and from other systems.
RAuthenticate users with SAML/SSO, Shibboleth, or Microsoft Azure Active Directory.
RShould have role-based security – to allow access to services.
RExplain what type of documentation or help system is included in the solution.
Hosted Solution Requirements
RMust secure data in transit and at rest. If encryption of data at rest is not available, please provide alternative measures. If encryption of data is available and imposes additional cost, that cost should be reflected in the proposal.
RVendor shall have in place a system recovery plan, including policies around regular backups and restoration and recovery of data within 24 hours of an outage or request.
Security And Access Control
RMust provide centralized account management functionality (account creation, deletion, lock-outs, etc..).
RMust have the ability to segment constituent data to accommodate varying security levels for different users.
RMust support role-based user permissions and accesses. Role-based permissions govern each user's rights to add, edit,and view information within the system.
OShould provide attribute-based access control for granting permissions to add, edit,and view information within the system.
RMust provide a capability for logging of user management, administrative activity, and of user activity.
RMust allow the university admistrator to view user data on system use, (logins, uploads, modifications, etc).
RMust provide an audit trail/logging for any action in the database, including real-time notifications.
RMust provide a system capability for auditing/logging.
RMust have the ability to track and display the history of information stored in the application.
RMust have the ability to support current State and Federal privacy laws and general data protection (GDPR) policies where applicable
RWhere applicable, web portal shall meet ISO/IEC 40500:2012 [Web Content Accessibility Guidelines (WCAG) 2.1 AA] at a minimum.
RMust have the ability to segment data according to a data security model.
RMust provide read-only data fields, or the prevention of overwriting certain data fields.
RMust provide a method for all data imports and exports, and must use a secure file transfer such as Secure File Transfer Protocol (SFTP).
OMust support integration with third-party multi-factor authentication providers.
RThe solution shall allow secure login leveraging LDAP, SAML, Active Directory, or Shibboleth security integration and determine level of access via identified fields within LDAP.
RMust allow for granular role-based control of access to profile data and workflows; including full access, limited access, and view only access; based on the individual user.
RMust allow the administrator to assign security roles to users.
RMust not use or provide default credentials.
System
RVendor must implement software upgrades and updates to the system with prior notification to the University.
OMust have the ability to import and export data on demand with built-in utility for data import/export.
OMust have a documented web services based API for completing custom integration with other applications.
OUse publicly open APls: The API must be publically accessible and freely available to encourage innovation and partnership. All data within the CRM must be consumable through this API.
RThose submitting proposals should be prepared to provide a campus demo if requested

File details come from the government source that posted it. Updated .