ATTACHMENT H - Solution Matrix- RFP 758 2500000171 Kentucky Analytics Platform Solution (KAPS).xlsx
XLSX spreadsheet 82 KB Posted
- Attached to
- Kentucky Analytics Platform Solution (KAPS) State and local contract opportunity
- Solicitation number
- RFP-758-2500000171-5
- Issued by
- Kentucky
About this file
This document is an Attachment H Solution Matrix for the Kentucky Cabinet for Health and Family Services (CHFS) RFP 758 2500000171, detailing requirements for a Kentucky Analytics Platform Solution (KAPS). The RFP seeks a comprehensive analytics platform with extensive technical specifications covering areas such as access and presentation, application services, data governance, infrastructure, integration, security, reporting, and support services. The solution must meet mandatory and desired requirements across multiple technical domains, with vendors required to respond using a specific matrix that defines how they will meet each requirement through options like out-of-the-box functionality, configuration, modification, or third-party solutions.
The solution matrix encompasses stringent compliance requirements, including adherence to federal standards such as HIPAA, NIST SP 800-53, Section 508, and FedRAMP, with specific emphasis on security, data protection, and integration capabilities. Key technical requirements include support for multi-lingual translation, robust data governance, comprehensive reporting and analytics tools, secure data management, integration with the Kentucky Online Gateway (KOG), and the ability to handle complex healthcare data formats. The platform must support various user roles, provide advanced security controls, enable detailed audit logging, and offer flexible training and support services. While specific pricing is not detailed in this document, vendors are instructed to include cost information in a separate cost proposal, with the understanding that the solution will be evaluated based on its ability to meet the extensive technical and compliance requirements outlined in the matrix.
View the file
Other files for this state and local contract opportunity
Show all 19
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Instructions
| Kentucky CHFS - KAPS RFP |
| Instructions for Solution Matrix Response Spreadsheet |
| Purpose of Solution Matrix: |
| This matrix shall be completed by the Vendor. It will be used as a record of how the Vendor will meet CHFS' expectations. This matrix will be evaluated and scored. |
| Definitions: | |
| Mandatory/Shall, Will, Must | Interchangeable and means the requirement is non-negotiable. |
| Desired/Should | Interchangeable and means the requirement is highly encouraged; however, Vendors may offer other methods of achieving the same goal. |
| Table: Definition of "Solution Response" Column Codes | ||
| The Vendor shall provide a response to all criteria provided in the "Solution Response" column using the options provided in the drop-down list (see Table below for Codes and Definitions). No other responses should be provided other than those in the drop-down list. | ||
| Code | Code Description | Code Definition |
| OOB | Out of the Box | The functionality is provided without configurations, modification, or a third-party application or provision of services. |
| CFG | Configuration | The functionality is provided; however, it must be configured to meet CHFS' requirements. Configuration does not require the development of new program code. |
| MIN | Minor Modification | The functionality must be developed or coded to meet CHFS' requirements. A minor modification is defined as a work effort of less than forty (40) hours for design, development and testing. Provide a brief explanation in the Explanation column. Cost must be included in Vendor's Cost Form. Cost must NOT be provided in this matrix. |
| MAJ | Major Modification | The functionality must be developed or coded to meet CHFS' requirements. A major modification is defined as a work effort of more than forty (40) hours for design, development and testing. Provide a brief explanation in the Explanation column. Cost must be included in Vendor's Cost Form. Cost must NOT be provided in this matrix. |
| TPS | Third-Party Solution | The functionality can be met by implementing a third-party solution. When selecting this option, Vendors must use the Explanation column to identify the third-party solution and describe their relationship with the third-party provider. |
| FUT | Future Solution | The functionality is planned in a future product release as Out-of-the-Box with Configuration. When selecting this option, Vendors must use the Explanation column to provide the release date and other relevant details. |
| OTH | Other | If the Vendor's approach for meeting the requirement is not addressed by one of the previous options, please select this category. When selecting this option, Vendors must use the Explanation column to explain their approach to meeting the requirement. |
| NOT | Not Available | The functionality is not available. If a requirement is mandatory and "Not Available" is checked, Vendor will be deemed as non-responsive and will not move on in the evaluation process. Provide a brief explanation in the Explanation column. |
| Explanation Column: |
| Vendor should provide an explanation for responses marked as "MIN," "MAJ," "FUT," "TPS," "OTH," and "NOT" as instructed above. |
| Requirement Category | Category Description |
| Access and Presentation | Accessibility and System Presentation |
| Application and Shared Services | Specific needs of the solution in terms of hardware, software, and other resources |
| Data and Information Management Services | Policies, plans, and programs that protect and control data and information assets through their life cycles |
| Data Governance | Processes, policies, roles, metrics, and standards that ensure effective and efficient use of data |
| Infrastructure | Physical and virtual resources that are required to support the operation of the solution |
| Integration and Interface | Requirements and resources that are required to integrate different systems, applications, or data |
| Project Management | Requirements that need specific knowledge, skills, or techniques to deliver project value |
| Reporting, Analytics, and Administration | Analytics, Reporting, Tool Functionality, and Resourced requirement to manage and maintain the system |
| Responsibilities | Vendor activities |
| Segregated Envrionment | Requirements and resources that are required to support the Segregated Envrionment |
| Security | Requirements and resources that are required to support the solution security |
| Support Services | Requirements and resources that are required to support operations for the solution |
| Testing | Requirements for DDI and M&O |
| Training | Requirements and resources that are required to support training on the solution |
| System Certification Management | Resources and tasks supporting system certification by federal partners |
RFP Solution Matrix
| Vendor Name: | |||||
| Tab Name: | Attachment H -Solution Matrix - RFP 758 2500000171 Kentucky Analytics Platform Solution (KAPS) | ||||
| Cost, if any, must be included in Cost Proposal only. | |||||
| ID # | Category | Description | Mandatory or Desired | Solution Response | Explanation |
| APR-001 | Access and Presentation | The solution should utilize standard e-mail protocols (e.g. IMAP, MAPI, POP3, SMTP, etc.) for communications delivered to a user's email address. | Desired | ||
| APR-002 | Access and Presentation | The solution shall include a Section 508 Product Assessment Package as part of their System Development Life Cycle (SDLC), and shall perform regularly scheduled (i.e., automatic) scans and manual testing for Section 508(c) compliance for all types of user interface screens (static, dynamic, Web, mobile, etc.). | Mandatory | ||
| APR-003 | Access and Presentation | The solution should provide a mobile version, with scaled functionality, for mobile browsing on small form factor devices and mobile computing platforms (i.e., “smart” phones, tablets, and PDA applications) in a manner suitable for use. | Desired | ||
| APR-004 | Access and Presentation | The solution should allow any web browser-based component to operate consistently and fully across all web browsers in widespread use, including support at the minimum for the following desktop/mobile browser platforms: |
1. Microsoft Edge
2. Google Chrome.
3. Mozilla Firefox.
4. Apple Safari.
| Identify a complete list of browsers (including version numbers) that the system supports, along with justification for proposing the specific list of browsers and their proposed approach for ensuring cross-browser capability. Cabinet for Health and Family Services (CHFS) will approve the list of browsers as part of test plan. | Desired | |||
| APR-005 | Access and Presentation | The solution should provide the capability for context-sensitive help functions at multiple levels, including but not limited to: page help, field-level help, and system-wide help. | Desired | |
| APR-006 | Access and Presentation | The solution shall allow interfaces to be fully accessible and enable persons with vision disabilities or vision loss to fully utilize the system through the use of screen reader programs according to Section 508. Include support, at the minimum, for Freedom Scientific's Job Access With Speech (JAWS) software. | Mandatory | |
| APR-007 | Access and Presentation | The Vendor should supply the software licenses for CHFS user to be able to support and utilize the solution by a defined number of employees. | Desired | |
| APR-008 | Access and Presentation | The Vendor should provide concurrent software licenses to allow authorized users access to all applications. | Desired | |
| ASV-001 | Application and Shared Services | The solution should provide the ability to support various output formats for generated documentation, including but not limited to PDF, Postscript, XML, HTML, Excel and other formats as required by business requirements. | Desired | |
| ASV-002 | Application and Shared Services | The Vendor shall support multi-lingual translation of all alt tags and metadata, for Section 508 compliance, in particular English and Spanish. | Mandatory | |
| ASV-003 | Application and Shared Services | The solution should support the creation of secure, read-only, and non-alterable output (e.g. secure PDF) in compliance with CHFS IT standards for sensitive output content. | Desired | |
| ASV-004 | Application and Shared Services | The solution should provide ISP Management capability and the ability to define configurable distribution lists of output recipients. | Desired | |
| DG-001 | Data Governance | The solution should provide tools for maintaining and managing the solution Metadata. Metadata should include, at a minimum; source system, transformations, latency, business definitions, etc., as defined by CHFS during Requirement Validation Sessions. | Desired | |
| DG-002 | Data Governance | The Vendor should provide Data Quality Management for the data coming into the solution. | Desired | |
| DG-003 | Data Governance | The Vendor should provide CHFS with access to the tool used for Data Quality Management. | Desired | |
| DG-004 | Data Governance | The Vendor should provide CHFS access with Data Governance tools for the solution. | Desired | |
| DG-005 | Data Governance | The solution should provide the ability to scale as needed in the cloud. | Desired | |
| DG-006 | Data Governance | The solution should provide physical and logical separation of data between user roles. | Desired | |
| DG-007 | Data Governance | The solution should provide the ability to integrate with the Commonwealth’s current and future Identity Management solution. | Desired | |
| DG-008 | Data Governance | The Vendor should make recommendations in any area in which they feel improvements can be made. | Desired | |
| DG-009 | Data Governance | The solution shall support standard domains including but not limited to HL7, CDA, FHIR, X12, SNOMED, LOINC, RxNorm, ICD-9/ICD-10. | Mandatory | |
| DG-010 | Data Governance | The Vendor shall implement CHFS master data management standards and maintain compliance as these standards evolve. | Mandatory | |
| DIN-001 | Data and Information Management Services | The solution should provide the capability to integrate data from multiple data sources for analysis and reporting needs. | Desired | |
| DIN-002 | Data and Information Management Services | The Vendor should propose a Data Model that supports structured, semi-structured, and unstructured datasets. | Desired | |
| DIN-003 | Data and Information Management Services | The Vendor should provide industry accepted data modeling tool(s) that supports all layers of design, reporting, Entity Relationship Diagram (ERD), and Graphical User Interface (GUI). | Desired | |
| DIN-004 | Data and Information Management Services | The Vendor should provide a Data Modeling tool(s) that is interoperable with other data management tools including metadata management tool, and catalog and lineage tools. | Desired | |
| DIN-005 | Data and Information Management Services | The solution should store and analyze structured, semi-structured and unstructured data. | Desired | |
| DIN-006 | Data and Information Management Services | The solution should provide the ability for users, and the solution, to create and store de-identified data in the solution, and use it to summarize according to the rules defined by CHFS. | Desired | |
| DIN-007 | Data and Information Management Services | The solution shall provide functionality for masking and encryption of sensitive or personally identifying information. | Mandatory | |
| DIN-008 | Data and Information Management Services | The solution should provide tools to manage external data sources allowing inclusion of data from not only Structured Query Language (NoSQL) Database Management Systems (DBMSs). | Desired | |
| DIN-009 | Data and Information Management Services | The solution should consistently and uniformly leverage comprehensive naming and metadata standards for data model definitions. | Desired | |
| DIN-010 | Data and Information Management Services | The solution should utilize well-structured, relational data models for all data stores, which align with the business domain model. | Desired | |
| DIN-011 | Data and Information Management Services | The Vendor should provide a Data Model tool(s) that can: |
1. Build a logical data model;
2. Build a physical data model based on the logical one;
3. Create Data Definition Language (DDL) from the physical data model;
| 4. Support an editor function that enables users to quickly view and easily update with multiple object types or multiple properties. | Desired | |||
| DIN-012 | Data and Information Management Services | The solution should store and retrieve audio and video files. | Desired | |
| DIN-013 | Data and Information Management Services | The solution should provide data dictionary features that allow metadata to be defined and documented. | Desired | |
| DIN-014 | Data and Information Management Services | The solution should support data synchronization and replication capabilities, as needed. | Desired | |
| DIN-015 | Data and Information Management Services | The solution should provide the capability to maintain referential integrity throughout the system. | Desired | |
| DIN-016 | Data and Information Management Services | The solution should provide a data model design that supports data normalization and synchronization so that no orphaned records are found. (e.g., records that do not have parent values). | Desired | |
| DIN-017 | Data and Information Management Services | The solution shall provide capability to maintain consistency of data in conversion process. | Mandatory | |
| DIN-018 | Data and Information Management Services | The solution should provide monitoring capability for long running, blocking processes that may affect system performance or user experience. | Desired | |
| DIN-019 | Data and Information Management Services | The solution should provide a self-service web portal be designed to have 24x7 access to the data stores supporting its online self-service features. | Desired | |
| DIN-020 | Data and Information Management Services | The solution should fully support automatic, non-disruptive, rules-based data archival and subsequent restoration within a time defined by CHFS. | Desired | |
| DIN-021 | Data and Information Management Services | The solution should provide a comprehensive strategy for extracting data from existing systems in a way that maintains necessary referential integrity relationships for related data. | Desired | |
| DIN-022 | Data and Information Management Services | The solution should provide flexibility and recoverability load processes and include abilities to stop, start, cancel, restart, or reload. | Desired | |
| DIN-023 | Data and Information Management Services | The solution should provide report processing statistics that include, but are not limited to, load execution time, duration, and counts. | Desired | |
| DIN-024 | Data and Information Management Services | The solution should provide capability to include appropriate reporting of failures, error conditions, and unexpected terminations. | Desired | |
| DIN-025 | Data and Information Management Services | The solution should synchronize with centralized data dictionary and allow synchronization with centralized data dictionary features that allow metadata definitions and documentation. | Desired | |
| DIN-026 | Data and Information Management Services | The solution should provide capability to develop and maintain menu-driven help screens, up-to-date manuals, Data Element Dictionary, and other instructional materials, which assist CHFS, or its designee, designated users in their use of the solution. | Desired | |
| DIN-027 | Data and Information Management Services | The solution should provide data retention, including current and purged history files, in CHFS-defined format, for a CHFS-defined number of years. | Desired | |
| DIN-028 | Data and Information Management Services | The solution shall provide capability to encrypt backup data at all times and manage encryption keys. | Mandatory | |
| DIN-029 | Data and Information Management Services | The solution should provide capability to refresh, replace, update, append, or restore all data including historical data based on a schedule defined by CHFS, or as requested by CHFS. | Desired | |
| DIN-030 | Data and Information Management Services | The solution should manage automated and manual procedures for recording all information in the solution and reconciling solution data with data in source systems. | Desired | |
| DIN-031 | Data and Information Management Services | The solution should provide the ability to load and make available external datasets approved by CHFS into the solution for review by limited users. | Desired | |
| DIN-032 | Data and Information Management Services | At a minimum, the Vendor should create existing Data Marts to understand trends as defined by CHFS, with the ability for CHFS to create user-defined data marts as needed. | Desired | |
| DIN-033 | Data and Information Management Services | The solution should provide the ability to create, coordinate, and maintain field names consistent with the source system. In case of conflict use the hierarchy defined by CHFS. | Desired | |
| DIN-034 | Data and Information Management Services | The solution should provide functions to translate the data into flat files, Excel, XML, JSON, and SOAP for exchange as required by CHFS or it's designees. | Desired | |
| DIN-035 | Data and Information Management Services | The solution shall provide the ability to correlate, analyze, and report on all logged user (application and administration operations) events and associated data. | Mandatory | |
| DIN-036 | Data and Information Management Services | The solution shall provide the ability to convert and transform health care records in Health Level 7 (HL/7), Health Level 7 Clinical Document Architecture (HL/7 CDA) and Fast Healthcare Interoperability Resources (FHIR) format for query and analytics. | Mandatory | |
| DIN-037 | Data and Information Management Services | No Commonwealth data will be viewed, maintained, or stored outside the contiguous United States. All commonwealth data shall be encrypted, both in-transit and at rest. | Mandatory | |
| DIN-038 | Data and Information Management Services | The Vendor should provide a listing and description of planned System Releases and participate in periodic System Release coordination meetings with the Commonwealth to discuss, coordinate, and share detailed information regarding upcoming System Releases, and any impacts to the system. | Desired | |
| DIN-039 | Data and Information Management Services | The Vendor should create and provide release notes that meet the Service Deliverable requirements as defined in the Service Deliverables section of this RFP to document and communicate the solution modifications included in each System Release, at an agreed upon timeframe. | Desired | |
| DIN-040 | Data and Information Management Services | The Vendor should conduct a walk-through of a System Release and the system Release Notes with the Commonwealth, provide test documentation, and respond to questions. | Desired | |
| DIN-041 | Data and Information Management Services | The Vendor should coordinate, implement, and validate approved Solution Releases and confirm successful completion in writing to the Commonwealth. | Desired | |
| DIN-042 | Data and Information Management Services | The solution should provide the ability for automated reports, and dashboards, on a pre-agreed to schedule. | Desired | |
| DIN-043 | Data and Information Management Services | The solution should provide the ability to confirm that no records processed or loaded in the application are physically deleted. | Desired | |
| DIN-044 | Data and Information Management Services | The solution should provide the ability to monitor and report the health and status of all applications, services, and system components. The Vendor should also report these metrics to CHFS. | Desired | |
| DIN-045 | Data and Information Management Services | The vendor should provide a list of available data marts and dashboards that can be configured for the Commonwealth to support and enhance optimal care delivery and coordination, healthcare policies , programs and operations, as well as for Social Determinants of Health (SDOH). | Desired | |
| INF-001 | Infrastructure | The solution shall provide a process for masking, sanitizing, scrambling, or de-sensitizing sensitive data (e.g. Personally Identifiable Information [PII]/ Protected Health Information [PHI]) when extracting data from the production environment for use in non-production environments. | Mandatory | |
| INF-002 | Infrastructure | The Vendor should explain and illustrate the high availability design in the proposed solution, including the high availability scheme proposed (e.g. Active/Active, Active/Passive), in accordance with this requirement. | Desired | |
| INF-003 | Infrastructure | The Vendor should, at a minimum, implement, host, operate, maintain, and manage all infrastructure including all hardware, software, and middleware necessary for successful operation of all systems and services under the scope of work of the Contract. | Desired | |
| INF-004 | Infrastructure | The Vendor should take responsibility for the end-to-end oversight and management of all environments, including ensuring performance metrics and Service Level Agreement (SLAs) are met. | Desired | |
| INF-005 | Infrastructure | The Vendor should retain all responsibility and costs for all software, hardware, and infrastructure Maintenance and Operations necessary to fulfill their obligations of this RFP. | Desired | |
| INF-006 | Infrastructure | The solution should provide the ability for all cloud resources and requests to be cost tagged. (e.g., resource tags, cost allocation tags). | Desired | |
| INF-007 | Infrastructure | The Vendor should ensure that the solution tools are available to run 24/7, with exception of pre-approved scheduled maintenance downtimes. | Desired | |
| INF-008 | Infrastructure | The Vendor should provide annual test reports to CHFS within five (5) business days of exercise, Business Continuity (BC)/ Disaster Recovery (DR) Plan reports within one (1) business day of incident, and BC/DR Plan updates within one (1) business day of identified deficiency. | Desired | |
| INT-001 | Integration and Interface | The solution should provide the ability to identify member, and provider, relationships between CHFS entities. | Desired | |
| INT-002 | Integration and Interface | The solution, and Vendor, shall comply with open architecture standards (non-proprietary), using guidance from Medicaid Information Technology Architecture (MITA), for ease of information exchange with both internal and external entities. | Mandatory | |
| INT-003 | Integration and Interface | The solution shall provide the ability to monitor service usage and execution history for enforcing adherence to established Service Level Agreements. | Mandatory | |
| INT-004 | Integration and Interface | The solution should provide the ability to track all metadata artifacts in the registry/repository according to a taxonomy to be defined by the Vendor. | Desired | |
| INT-005 | Integration and Interface | The solution should provide the ability to Include exception handling, correlation, and message logging capabilities. | Desired | |
| INT-006 | Integration and Interface | The solution should provide the ability to monitor and report on business processes against established key performance indicators Key Performance Indicator (KPIs). KPIs are defined during requirements gathering. | Desired | |
| INT-007 | Integration and Interface | The solution should provide the ability to allow for grouping, activation, and suppression of alerts based on configurable rules and/or thresholds. | Desired | |
| INT-008 | Integration and Interface | The solution should provide the ability to allow all workflows to complete following system outages, system maintenance, and disaster recovery scenarios. | Desired | |
| INT-009 | Integration and Interface | The solution should provide the ability to define a methodology and functionality to resolve conflicts between the same data elements from different sources. | Desired | |
| INT-010 | Integration and Interface | The solution should provide the ability to accurately reflect changes to data throughout multiple Data Marts. | Desired | |
| INT-011 | Integration and Interface | The solution should provide the ability to maintain an incremental history of dataset for analytical needs. | Desired | |
| INT-012 | Integration and Interface | The solution should provide the ability to view activities during integration including, but not limited to, job schedules, transform, load processing, and job run times. | Desired | |
| INT-013 | Integration and Interface | The solution should provide the ability to maintain audit logs from data integration activity. | Desired | |
| INT-014 | Integration and Interface | The solution should provide the ability to run reports and provide analytics on audit logs from data integration activity. | Desired | |
| INT-015 | Integration and Interface | The solution should provide processes to show balance of the solution updates after every load, using control counts on the update files and processes. | Desired | |
| INT-016 | Integration and Interface | The solution should provide the ability to control and execute all aspects of the Extract, Transform, Load (ETL)/ Extract, Load, Transform (ELT) process, including coding the extracts from the required transactional source systems. | Desired | |
| INT-017 | Integration and Interface | The Vendor shall supply a Geographic Information System (GIS) tool product compatible with the solution's application software to break down the Commonwealth into regions, perform density mapping geocoding, and other functions as defined by CHFS. The GIS tool product is to include routing and zip coding with the ability to use Census Tract. GIS tool must have ability to suppress specified data elements. | Mandatory | |
| INT-018 | Integration and Interface | The solution shall meet data transfer and encryption standards per HIPAA, Family Educational Rights and Privacy Act (FERPA) (Workforce), IRS data standards, etc., and or CHFS policies and guidelines. | Mandatory | |
| INT-019 | Integration and Interface | The solution should support a variety of output capabilities including Compact Disk (CD), Digital Video Disk (DVD), tape, FTP, and other methods as determined by the Commonwealth. | Desired | |
| INT-020 | Integration and Interface | The solution should provide the ability, by user role, to retrieve data from any solution table via Open Data Base Connectivity (ODBC) and other available interfaces. | Desired | |
| INT-021 | Integration and Interface | The solution should provide the ability to grant access to specific individuals, departments, or groups of people for independent Data Mart by the user who created it. | Desired | |
| INT-022 | Integration and Interface | The solution should provide users the ability to create and alter Data Marts and reports. | Desired | |
| INT-023 | Integration and Interface | The solution shall be "claims-aware," and support authentication and authorization via security assertions provided by Kentucky Online Gateway (KOG). See atachment R KOG Integration. | Mandatory | |
| INT-024 | Integration and Interface | The Vendor shall demonstrate how the proposed solution integrates with KOG for self-service user provisioning while providing a seamless user experience. | Mandatory | |
| INT-025 | Integration and Interface | Vendor should implement effective configuration management to ensure proper configuration of the solution consistent with the business requirements, effective management of change and version control, effective management of system releases, and maintenance of adequate documentation to support future configuration. | Desired | |
| INT-026 | Integration and Interface | The Vendor should collaborate with CHFS to provide a Turnover Plan to CHFS for approval, and update the Turnover and Closeout Plan, at a minimum, on an annual basis. | Desired | |
| INT-027 | Integration and Interface | The Vendor should implement the CHFS-approved Turnover Plan within nine (9) months of Contract/Amendment end date or as requested by CHFS. | Desired | |
| INT-028 | Integration and Interface | The Vendor should provide updates as indicated in the Turnover Plan, as requested approximately four (4) months prior to the end of the Contract, Contract Amendment, or any Contract extension, for: |
a. Replacements for all data and reference files, computer programs, control language, and system software;
| b. All other documentation as required by CHFS or its agent to run acceptance tests. | Desired | ||
| INT-029 | Integration and Interface | The solution should be accessible using a wide range of mobile devices. Allow any mobile device to operate consistently and fully, including Section 508 compliance, including, but not limited to, support for the following : |
1. Android;
| 2. iPhone Operating System (iOS);. | Desired | |||
| INT-030 | Integration and Interface | The solution should integrate with the State Data Hub (SDH) where applicable. | Desired | |
| INT-031 | Integration and Interface | The Vendor should be responsible for designing, developing, and testing all physical interfaces, file-sharing, and batch processes required for data interchange. | Desired | |
| INT-032 | Integration and Interface | The Vendor should consider additional files defined during the solution implementation Planning and Design as in the project's scope. | Desired | |
| PM-001 | Project Management | The Vendor shall support the Commonwealth's compliance with the IV&V function requirement as defined in 45 CFR Part 95.626. | Mandatory | |
| PM-002 | Project Management | Vendor should not invoice hours spent by Vendor staff on change requests or system maintenance modifications and upgrade activities. | Desired | |
| PM-003 | Project Management | The Vendor should designate a full-time project manager, as defined in the staffing approach section of this RFP, to manage the implementation of the solution. | Desired | |
| PM-004 | Project Management | The Vendor should provide all staff as required to meet the business and technical requirements related to the solutions' operations as defined in the RFP and ensure the successful maintenance, operation, and support of all services of the solution. | Desired | |
| PM-005 | Project Management | The Vendor should locate all project, maintenance, operations, and support staff in the United States. | Desired | |
| PM-006 | Project Management | The Vendor should prepare updated solution documentation for submission to federal review partners twenty (20) business days, at a minimum, prior to federal certification gate/milestone reviews. | Desired | |
| PM-007 | Project Management | The Vendor should provide an updated version of the solution documentation following federal partner gate/milestone reviews twenty (20) business days, at a minimum, following the completion of the gate/milestone review. | Desired | |
| PM-008 | Project Management | Key Staff placement and changes should be managed in accordance with Attachment A of this RFP. | Desired | |
| PM-009 | Project Management | The Vendor shall conduct an initial criminal background check/investigation on all new hires as well as conduct follow-up criminal investigations as requested for all assigned staff. The costs for the initial criminal background check will be the responsibility of the Vendor. If CHFS requests additional checks, the cost will be covered as a pass-through cost. | Mandatory | |
| PM-010 | Project Management | The Vendor should initiate CHFS-requested and approved audit activities within ten (10) business days of request by CHFS or another date agreed to by CHFS. | Desired | |
| PM-011 | Project Management | The Vendor should correct and reissue invoices within twenty (20) business days of CHFS notification of necessary correction. The Vendor will maintain a 100% accuracy rate on all invoices submitted to CHFS. | Desired | |
| PM-012 | Project Management | The Vendor should maintain complete and detailed records of all meetings related to the Contract, System Development Life Cycle (SDLC) documents, presentations, project artifacts and any other interaction and post and maintain these artifacts in the CHFS agreed to project repository within 24 hours of the meeting or interaction. | Desired | |
| PM-013 | Project Management | The Vendor should review and update KPIs and SLAs with CHFS minimally on a bi-annual basis or more frequently as requested by CHFS. | Desired | |
| PM-014 | Project Management | CHFS expects an overall Project Management and Administration approach that adheres to recognized industry standards and principles for both project management and quality control. The Vendor’s proposed approach and methodology must embody the essence and directives derived from these principles and standards, and apply them across the spectrum of the project as they relate to all required project documents, plans, and deliverables. | Desired | |
| PM-015 | Project Management | The Vendor should obtain CHFS approval for all Project Deliverables and adhere to the following: |
a. For each Project Deliverable the Vendor, will prepare and submit an Deliverable Expectation Document (DED) that includes an outline and expected reviewers for CHFS review before a Project Deliverable is developed and submitted to CHFS;
b. Conduct formal Project Deliverable reviews with CHFS prior to receiving approval as prescribed by CHFS. CHFS will provide input into all Project Deliverable designs and contents;
c. Conduct, upon request by CHFS, review meetings to clarify CHFS findings on rejected Project Deliverables;
d. Perform all revisions to Project Deliverables before the Project Deliverable is resubmitted to CHFS for subsequent review;
e. Meet accepted standards of practice adopted by CHFS for final versions of Project Deliverables and milestones;
| f. Submit, at the discretion of CHFS, interim Project Deliverables to CHFS for their advance review to promote schedule progress without resetting the Project Deliverable schedule. | Desired | |||
| PM-016 | Project Management | The Vendor should ensure project management processes and procedures are flexible to accommodate different sized maintenance and modification projects throughout the life of the Contract. | Desired | |
| PM-017 | Project Management | The Vendor should include project risk and issue management processes as part of their project management approach. | Desired | |
| PM-018 | Project Management | The Vendor should use an agreed upon Repository, with advanced search capabilities, as a comprehensive repository of documents and other materials related to the project. The Vendor is required to update and version the content of these items so the information is current. Items to incorporate include: |
a. Contact/Phone Lists;
b. Business Process Models;
c. Workflow Designs;
d. RFP and Proposal Documents;
e. Design decisions linked to RFP requirements, proposal responses;
f. High-level and detail-level documents, test results, and other Deliverables;
g. Schedules and calendars;
h. Microsoft Project work plan;
i. Minutes and agendas;
j. Issue tracking tool and other documents;
k. Policy documentation;
l. System documentation;
m. Change orders and related documents;
n. All Deliverables;
| o. Other items related to the project over the lifetime of the Contract. | Desired | |||
| PM-019 | Project Management | The Vendor should facilitate meetings and provide reporting to communicate Contract status on a CHFS-approved frequency. | Desired | |
| PM-020 | Project Management | The Vendor should provide information and data as requested by CHFS to fulfill requests for litigation, subpoenas, audits, assessments, open record requests or other legal actions at no cost to CHFS. | Desired | |
| PM-021 | Project Management | The Vendor should maintain a CHFS-approved sign-off authority process for verbal and written communication of decisions, approvals, and work requests that is documented and archived in a highly accessible, secure, central location. | Desired | |
| PM-022 | Project Management | The Vendor should generate monthly personnel invoicing reports one (1) week following the end of the invoice period. | Desired | |
| PM-023 | Project Management | The Vendor should provide CHFS documentation of all audit results, develop and implement corrective action plans for deficiencies, and hold an exit conference with CHFS-designated Stakeholders, if requested. Vendor will correct all deficiencies identified through the course of an audit as part of maintenance. | Desired | |
| PM-024 | Project Management | The Vendor should be available to attend virtual, or onsite meetings with CHFS staff and partners at the CHFS designated facility upon CHFS’s request. | Desired | |
| PM-025 | Project Management | The Vendor should complete solution implementation within 12 months of the date of project initiation unless otherwise agreed to in the contract, or unless the Commonwealth proposes an alternate timeline during Design, Development, and Implementation (DDI). | Desired | |
| RPT-001 | Reporting, Analytics, and Administration | The solution should provide capability to run analytics on audio, and video, files at the direction of CHFS. | Desired | |
| RPT-002 | Reporting, Analytics, and Administration | The solution should provide capability to collect and analyze retrospective health services data on program members. | Desired | |
| RPT-003 | Reporting, Analytics, and Administration | The solution should provide capability to geoposition the provider/member details and calculate driving distances. | Desired | |
| RPT-004 | Reporting, Analytics, and Administration | The solution should provide capability to analyze the drug usage of program members and review the dispensing patterns of pharmacies and prescribing physicians. Also, capability to produce reports identifying aberrant usage or prescribing practices. | Desired | |
| RPT-005 | Reporting, Analytics, and Administration | The solution should provide tools to detect, analyze and support structured, semi-structured, and unstructured queries and reporting. | Desired | |
| RPT-006 | Reporting, Analytics, and Administration | The solution should provide capability for CHFS staff to perform analytical work using the tools provided by the Vendor. | Desired | |
| RPT-007 | Reporting, Analytics, and Administration | The solution should have the capability to use 7+ years of data for predictive and trend analytics. | Desired | |
| RPT-008 | Reporting, Analytics, and Administration | The solution should provide reporting capabilities that do not negatively impact performance of the solution. | Desired | |
| RPT-009 | Reporting, Analytics, and Administration | The solution should support initiation of reports through various methods including, but not limited to, on-demand requests, scheduled requests, and event-driven requests. | Desired | |
| RPT-010 | Reporting, Analytics, and Administration | The solution should provide ad-hoc reporting, and dashboard, capabilities that support drill-down and drill-up functionality. | Desired | |
| RPT-011 | Reporting, Analytics, and Administration | The solution should provide ad-hoc reporting capabilities that enable end users to create reports using defined, user-friendly metadata elements. | Desired | |
| RPT-012 | Reporting, Analytics, and Administration | The solution should provide ad-hoc reporting capabilities that leverage pre-defined relationships and table joins to minimize the risk of executing poorly performing ad-hoc queries. | Desired | |
| RPT-013 | Reporting, Analytics, and Administration | The solution should provide Tableau as one of the Visualization tools. | Desired | |
| RPT-014 | Reporting, Analytics, and Administration | The solution should provide the ability to collect and summarize data for specific user communities (e.g., data marts or cubes) such as program analysis staff, research group, and financial management unit. | Desired | |
| RPT-015 | Reporting, Analytics, and Administration | The solution should provide the ability to maintain a Commonwealth-approved listing of all reports. The listing must include at least the following information for each report: | ||
| a) | Report name | |||
| b) | Report description | |||
| c) | Users | |||
| d) | Data source | |||
| e) | Frequency | |||
| f) | Format | |||
| g) | Ability to sort and organize report listings by Commonwealth user-defined configurations | |||
| h) | Query logic | |||
| i) | Meta data | |||
| j) | Hot link to most recent report | |||
| k) | Hot link to the data dictionary. | Desired | ||
| RPT-016 | Reporting, Analytics, and Administration | The Vendor should provide a Commonwealth approved report generation schedule for all scheduled reports, with direct access of report scheduling. | Desired | |
| RPT-017 | Reporting, Analytics, and Administration | The solution should provide the ability to support a variety of media for displaying requested information online, as well as including both hard and soft copies of report results. Output standards meet Industry Standards for legibility, timeliness, and appropriateness of presentation to the purpose of the information. | Desired | |
| RPT-018 | Reporting, Analytics, and Administration | The solution should have the ability to house multiple department-level style-guides that allow a user to create production reports utilizing a chosen style-guide. | Desired | |
| RPT-019 | Reporting, Analytics, and Administration | The solution should have the ability to refresh, or change, reports at any time. | Desired | |
| RPT-020 | Reporting, Analytics, and Administration | The Vendor should develop, and maintain, CHFS approved user manuals for the report access and delivery process online. | Desired | |
| RPT-021 | Reporting, Analytics, and Administration | The Vendor should enable a comprehensive report archival process that is compliant with current Commonwealth and Federal records retention standards. | Desired | |
| RPT-022 | Reporting, Analytics, and Administration | The solution should provide the ability for: |
- Ad hoc queries
- Pre-defined reports
- Geographical mapping
- Statistical analysis
| - Clinical analysis. | Desired | |||
| RPT-023 | Reporting, Analytics, and Administration | The solution should provide the ability for dashboards to include benchmarking for CHFS defined criteria. | Desired | |
| RPT-024 | Reporting, Analytics, and Administration | The solution should provide the ability for the user to design, develop, and implement standard, preformatted reports. | Desired | |
| RPT-025 | Reporting, Analytics, and Administration | The solution should provide the ability to match HEDIS (Healthcare Effectiveness Data and Information Set) reports to Federal requirements. | Desired | |
| RPT-026 | Reporting, Analytics, and Administration | The solution should provide the ability for a report library that can be indexed and searched and can retrieve published reports. | Desired | |
| SB-01 | Segregated Envrionment | The Vendor’s proposed Segregated Envrionment should allow for the creation, maintenance, and adjustment of space partitioning and allotments, as requested, and approved by the Commonwealth. | Desired | |
| SB-02 | Segregated Envrionment | The Vendor’s proposed solution should allow authorized users permission to store reports and query results generated within Segregated Envrionment area(s) for retrieval from the report library. | Desired | |
| SB-03 | Segregated Envrionment | The Vendor’s proposed solution should enable the extraction and filtering of data from the data sources within the Segregated Envrionment. | Desired | |
| SB-04 | Segregated Envrionment | The Vendor’s proposed solution should include the ability to replicate all/part of the permanent table structures (within Commonwealth-approved space limitations) into Segregated Envrionment tables, in order that structured query language can be used within the user-created Segregated Envrionment tables. | Desired | |
| SB-05 | Segregated Envrionment | The Vendor’s proposed solution should provide scalable Segregated Envrionment areas and required IT infrastructure, design, and implementation support for all necessary components. | Desired | |
| SCM-001 | System Certification Management | The Vendor shall deliver the necessary information and content to the Commonwealth that makes it possible to provide a Certification Management Plan (CMP), describing the process the Vendor will use to support CMS certification of a multi-Vendor, integrated, enterprise wide, Medicaid solution. The Vendor will remain current with changes made to the certification requirements and update its plan accordingly. The CMP will include and comply with the following: |
a) All Federal certification requirements outlined in the CMS State Medicaid Manual (SMM)
| b) All intake review, certification review, and operational readiness review requirements as defined by the Commonwealth and CMS under the Streamlined Modular Certification (SMC) process. | Mandatory | |||
| SCM-002 | System Certification Management | The Vendor shall prepare and communicate all reports and documentation necessary for submission to federal partners to support all certification reviews. | Mandatory | |
| SCM-003 | System Certification Management | The Vendor shall provide an identified certification lead to support all certification activities throughout all certification phases, activities, and processes over the life of the contract. | Mandatory | |
| SCM-004 | System Certification Management | The Vendor should provide an updated version of the systems documentation following federal certification reviews within twenty (20) business days following the completion of any subsequent certification review date for all certification phases throughout the life of the Contract. | Desired | |
| SCM-005 | System Certification Management | The Vendor shall provide architecture and design that complies with CMS Conditions and Standards (C&S) to ensure enhanced Federal funding. | Mandatory | |
| SCM-006 | System Certification Management | The Vendor shall provide both system and business operations staff to support the Commonwealth in the completion of the solution specific federal partner required assessments and certification forms, checklists, evidence, reports, materials, and required artifacts. | Mandatory | |
| SCM-007 | System Certification Management | The Vendor shall provide ongoing support for compliance with established Key Performance Indicator (KPI) metrics in support of all Federal certification efforts over the life of the contract. | Mandatory | |
| SCM-008 | System Certification Management | The Vendor shall provide source documentation that includes solution specific federal partner manuals and required documentation, reports, requirement/outcome crosswalks, evaluation criteria artifacts/materials, required evidence/testing scenarios, and MITA capability supporting documentation, and submit to appropriate federal partner sites. | Mandatory | |
| SCM-009 | System Certification Management | The Vendor should provide subject matter expertise to answer questions or provide insight during the certification process, including onsite, in person interviews. | Desired | |
| SCM-010 | System Certification Management | The Vendor should provide system access and/or a walkthrough of facility and operations site, if required by the Commonwealth or the federal certification team. The Commonwealth will provide the Vendor with advanced notification of such a request. | Desired | |
| SCM-011 | System Certification Management | The Vendor shall support the Commonwealth in, and throughout, the entire federal certification process as it relates to the implementation of the solution, with any action items or requests/recommendations being completed by the Vendor within five (5) business days unless otherwise agreed upon by the Commonwealth. This support includes all work necessary to resolve CMS SMC action items or corrective actions, at no additional cost to the Commonwealth. | Mandatory | |
| SEC-001 | Security | The solution shall meet formal security standards (e.g., Health Insurance Portability and Accountability Act [HIPAA], System and Organization Controls [SOC ]1, 2 or 3, International Organization for Standardization [ISO]27002, FedRAMP, Statement of Standards for Attestation Engagements [SSAE 16/SAS70-II], SOX, PCI-DSS, ISAE3402, Safe Harbor, National Institute of Standards and Technology [NIST] SP 800-53, etc.) or other regulatory certification requirements defined by CHFS. | Mandatory | |
| SEC-002 | Security | The solution shall provide the ability to monitor and enforce all access criteria in accordance with Commonwealth and Federal security access and management policies and provide a flexible security management solution capable of maintaining compliance with future Commonwealth and federal security access and management policies. | Mandatory | |
| SEC-003 | Security | The solution shall provide a Commonwealth-approved, user centered designed and intuitive interface for Security Administrators to grant, track, manage, and revoke access for individuals. The solution shall also provide auditing capabilities for approved audit resources. | Mandatory | |
| SEC-004 | Security | The Vendor shall ensure all systems undergo Industry Standard security testing (e.g., penetration, physical security, web application, social engineering, and vulnerability tests) minimally on an annual basis, or as requested by CHFS. This security testing will be conducted at no additional cost to the Commonwealth and by a Commonwealth‑approved third party that maintains no financial or controlling relationship with the Vendor. | Mandatory | |
| SEC-005 | Security | The Vendor should provide documented testing results and produce corrective action plans for any deficiencies identified as well as be responsible for modifications to remain compliant based on the terms and conditions of the Contract. | Desired | |
| SEC-006 | Security | The Vendor will maintain a Security Breach Response Team in accordance with Attachment A. This includes communications to a defined list of personnel at CHFS tied to Continuity of Operations/Disaster Recovery (COOP/DR). CHFS staff will be informed of response plan, including specific steps and timeframes for resolution. | Mandatory | |
| SEC-007 | Security | The solution shall provide the ability to support compliance with federal and commonwealth laws, regulations and policies relevant to system security, confidentiality and safeguarding of information, including, but not limited to: |
* Patient Protection and Affordable Care Act (ACA), Public Law 111–148;
* HIPAA Privacy Rule, 45 CFR Part 160 and Subparts A and E of Part 164, established under the Health Insurance Portability and Accountability Act, Public Law 104-191 (42 USC 1320d) to protect the security, confidentiality, and integrity of health information;
* HIPAA Security Rule, 45 CFR Part 160 and Subparts A and C of Part 164, established under the Health Insurance Portability and Accountability Act, Public Law 104-191 (42 USC 1320d) to protect individuals’ electronic personal health information that is created, received, used, or maintained by a covered entity;
* Health Insurance Portability and Accountability Act of 1996 (HIPAA), pursuant to sections 1104 and 1501 of ACA, including the privacy, security and transaction requirements;
* Internal Revenue Code (IRC) ss. 6103, 7213, and 7213A
* IRS Publication 1075, all requirements addressing handling and storage of federal tax information (FTI) data pursuant to IRC section 6103;
* Privacy Act of 1974;
* Federal Information Security Management Act (FISMA) of 2002;
* Health Information Technology for Economic and Clinical Health Act of 2009 (HITECH);
* Federal Enterprise Architecture Security and Privacy Profile, (FEA-SPP) version 3.0;
* Federal Information Processing Standards (FIPS),…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .