Extracted text (via pymupdf)
326638 characters
SERIAL # 230056-RFP
CONTRACT CORRECTIONAL ELECTRONIC HEALTH
RECORD 230056-RFP
This contract is entered into this 12th day of APRIL, 2023 by and between Maricopa County (County), a
political subdivision of the State of Arizona, and Fusion Capital Management, LLC dba Fusion Health, a
New Jersey corporation (Contractor) for the purchase of an Electronic Health Record (EHR) system for
Correctional Health Services (CHS).
1.0
CONTRACT TERM
This contract is for a term of FIVE years, beginning on the 12th of APRIL, 2023 and ending the 30th
of APRIL, 2028.
2.0
OPTION TO RENEW
The County may, at its option and with the concurrence of the Contractor, renew the term of this
contract up to a maximum of FIVE additional year(s), (or at the County’s sole discretion, extend the
contract on a month-to-month basis for a maximum of six months after expiration). The Contractor
shall be notified in writing by the Office of Procurement Services of the County’s intention to renew
the contract term at least 60 calendar days prior to the expiration of the original contract term.
3.0
CONTRACT COMPLETION
In preparation for contract completion, the Contractor shall make all reasonable efforts for an
orderly transition of its duties and responsibilities to another provider and/or to the County. This
may include, but is not limited to, preparation of a transition plan and cooperation with the County
or other providers in the transition. The transition includes the transfer of all records and other data
in the possession, custody, or control of the Contractor that are required to be provided to the
County either by the terms of this agreement or as a matter of law. The provisions of this clause
shall survive the expiration or termination of this agreement.
4.0
PRICE ADJUSTMENTS
Any requests for reasonable price adjustments must be submitted 60 calendar days prior to
contract expiration. Requests for adjustment in cost of labor and/or materials must be supported
by appropriate documentation. The reasonableness of the request will be determined by comparing
the request with the Consumer Price Index or by performing a market survey. If County agrees to
the adjusted price terms, County shall issue written approval of the change and provide an updated
version of the contract. The new change shall not be in effect until the date stipulated on the
updated version of the contract.
SERIAL 230056-RFP
5.0
PAYMENTS
5.1
As consideration for performance of the duties described herein, County shall pay
Contractor the sum(s) stated in Exhibit A-1 – Pricing Sheet.
5.2
Payment shall be made upon the County’s receipt of a properly completed invoice.
5.3
INVOICES
5.3.1
The Contractor shall submit one legible copy of their detailed invoice before
payment(s) will be made. Incomplete invoices will not be processed. At a minimum,
the invoice must provide the following information:
•
Company name, address, and contact information
•
County bill-to name and contact information
•
Contract serial number
•
County purchase order number
•
Project name and/or number
•
Invoice number and date
•
Payment terms
•
Date of service or delivery
•
Quantity
•
Contract item number(s)
•
Arrival and completion time
•
Description of purchase (product or services)
•
Pricing per unit of purchase
•
Extended price
•
Freight (if applicable)
•
Mileage with rate (if applicable)
•
Total amount due
5.3.2
Labor, services, and maintenance must be billed as a separate line item.
5.3.3
Problems regarding billing or invoicing shall be directed to the department as listed
on the purchase order.
5.3.4
Payment shall only be made to the Contractor by Accounts Payable through the
Maricopa County Vendor Express Payment Program. This is an electronic funds
transfer (EFT) process. After contract award, the Contractor shall complete the
Vendor Registration Form accessible from the County Department of Finance
Vendor
Registration
Web
Site
https://www.maricopa.gov/5169/Vendor-
Information.
5.3.5
Discounts offered in the contract shall be calculated based on the date a properly
completed invoice is received by the County.
5.3.6
EFT payments to the routing and account numbers designated by the Contractor
shall include the details on the specific invoices that the payment covers. The
Contractor is required to discuss remittance delivery capabilities with their
designated financial institution for access to those details.
5.4
APPLICABLE TAXES
5.4.1
It is the responsibility of the Contractor to determine any and all applicable taxes
and include those taxes in their proposal. The legal liability to remit the tax is on
the entity conducting business in Arizona. Tax is not a determining factor in
contract award.
SERIAL 230056-RFP
5.4.2
The County will look at the price or offer submitted and will not deduct, add, or alter
pricing based on speculation or application of any taxes, nor will the County
provide Contractor any advice or guidance regarding taxes. If you have questions
regarding your tax liability, seek advice from a tax professional prior to submitting
your bid. You may also find information at https://www.azdor.gov/Business.aspx.
Once your bid is submitted, the offer is valid for the time specified in this solicitation,
regardless of mistake or omission of tax liability. If the County finds overpayment
of a project due to tax consideration that was not due, the Contractor will be liable
to the County for that amount, and by contracting with the County agrees to remit
any overpayments back to the County for miscalculations on taxes included in a
bid price.
5.4.3
Tax Indemnification: Contractor and all subcontractors shall pay all Federal, State,
and local taxes applicable to their operation and any persons employed by the
Contractor. Contractor shall, and require all subcontractors to, hold Maricopa
County harmless from any responsibility for taxes, damages, and interest, if
applicable, contributions required under Federal and/or State and local laws and
regulations, and any other costs including: transaction privilege taxes,
unemployment
compensation
insurance,
Social
Security,
and
workers’
compensation. Contractor may be required to establish, to the satisfaction of
County, that any and all fees and taxes due to the City or the State of Arizona for
any license or transaction privilege taxes, use taxes, or similar excise taxes are
currently paid (except for matters under legal protest).
6.0
AVAILABILITY OF FUNDS
6.1
The provisions of this contract relating to payment for services shall become effective when
funds assigned for the purpose of compensating the Contractor as herein provided are
actually available to County for disbursement. The County shall be the sole judge and
authority in determining the availability of funds under this contract. County shall keep the
Contractor fully informed as to the availability of funds.
6.2
If any action is taken by, any State agency, Federal department, or any other agency or
instrumentality to suspend, decrease, or terminate its fiscal obligations under, or in
connection with, this contract, County may amend, suspend, decrease, or terminate its
obligations under, or in connection with, this contract. In the event of termination, County
shall be liable for payment only for services rendered prior to the effective date of the
termination, provided that such services are performed in accordance with the provisions
of this contract. County shall give written notice of the effective date of any suspension,
amendment, or termination under this section, at least 10 days in advance.
7.0
STRATEGIC ALLIANCE for VOLUME EXPENDITURES (SAVE)
The County is a member of the SAVE cooperative purchasing group. SAVE includes the State of
Arizona, many Phoenix metropolitan area municipalities, and many K-12 unified school districts.
Under the SAVE Cooperative Purchasing Agreement, and with the concurrence of the successful
respondent under this solicitation, a member of SAVE may access a contract resulting from a
solicitation issued by the County. If contractor does not want to grant such access to a member of
SAVE, state so in contractor’s bid. In the absence of a statement to the contrary, the County will
assume that contractor does wish to grant access to any contract that may result from this bid. The
County assumes no responsibility for any purchases by using entities.
8.0
INTERGOVERNMENTAL COOPERATIVE PURCHASING AGREEMENTS (ICPAs)
County currently holds ICPAs with numerous governmental entities. These agreements allow those
entities, with the approval of the Contractor, to purchase their requirements under the terms and
conditions of the County contract. It is the responsibility of the non-County government entity to
perform its own due diligence on the acceptability of the contract under its applicable procurement
rules, processes, and procedures. Certain governmental agencies may not require an ICPA and
SERIAL 230056-RFP
may utilize this contract if it meets their individual requirements. Other governmental agencies may
enter into a separate Statement of Work with the Contractor to meet their own requirements. The
County is not a party to any uses of this contract by other governmental entities.
9.0
VOLUNTARY EMPLOYEE DISCOUNTS
9.1
Contractors may voluntarily offer discounts to County employees for products or services
provided under this contract. Whether a Contractor offers or does not offer an employee
discount is not a factor considered in the evaluation of responses to this solicitation.
9.2
Any discount offered is part of a commercial transaction between the Contractor and
individual County employees and the County is not a party to the transaction. Any disputes
or issues arising from an individual commercial transaction between the Contractor and an
individual County employee is a matter between the Contractor and the employee. If a
discount is offered, the terms will be announced to County employees.
10.0
DUTIES
10.1
The Contractor shall perform all duties stated in Exhibit B – Scope of Work, or as otherwise
directed in writing by the procurement officer.
11.0
TERMS AND CONDITIONS
11.1
INDEMNIFICATION
11.1.1 To the fullest extent permitted by law, and to the extent that claims, damages,
losses, or expenses are not covered and paid by insurance purchased by the
contractor, the contractor shall defend, indemnify, and hold harmless the County
(as Owner), its agents, representatives, officers, directors, officials, and employees
from and against all third-party claims, damages, losses, and expenses (including,
but not limited to attorneys' fees, court costs, expert witness fees, and the costs
and attorneys' fees for appellate proceedings) arising out of, or alleged to have
resulted from, the negligent acts, errors, omissions, or mistakes relating to the
performance of this contract.
11.1.2 Contractor's duty to defend, indemnify, and hold harmless the County, its agents,
representatives, officers, directors, officials, and employees shall arise in
connection with any third-party claim, damage, loss, or expense that is attributable
to bodily injury, sickness, disease, death, or injury to, impairment of, or destruction
of tangible property, including loss of use resulting therefrom, caused by negligent
acts, errors, omissions, or mistakes in the performance of this contract, but only to
the extent caused by the negligent acts or omissions of the contractor, a
subcontractor, anyone directly or indirectly employed by them, or anyone for
whose acts they may be liable, regardless of whether or not such claim, damage,
loss, or expense is caused in part by a party indemnified hereunder.
11.1.3 The amount and type of insurance coverage requirements set forth herein will in
no way be construed as limiting the scope of the indemnity in this section.
11.1.4 The scope of this indemnification does not extend to the extent the County was
negligent.
11.2
INFRINGEMENT DEFENSE AND INDEMNIFICATION
11.2.1 Definitions
For purposes of this section:
SERIAL 230056-RFP
11.2.1.1 “Claim” means any cause of action in a third-party action, suit, or
proceeding against County alleging that Contractor software, or its
upgrades, modifications, or revisions, as of its delivery date under this
agreement, infringes a valid U.S. patent, copyright, or trademark.
11.2.1.2 “Participate and Share in the Costs” means Contractor will assist the
County in the defense of the Claim, to the extent agreed to by the
parties, except that Contractor shall be solely responsible for any and all
costs adjudged in a successful Claim against the County.
11.2.1.3 “Third-Party Products” means any products made by a party other than
Contractor, and may include, without limitation, products ordered by
County from third parties. However, components of Contractor branded
products are not Third-Party Products if they are both:
11.2.1.3.1 embedded in Third-Party Products (i.e., not recognizable
as standalone items); and
11.2.1.3.2 not identified as separate items on Contractor’s price list,
quotes, order specifications forms, or documentation.
11.2.2 Defense and Indemnity
Contractor shall defend, and Participate and Share in the Cost, in the full defense
of the County against any Claim, and will indemnify and hold harmless the County,
as provided for in this section, for any judgments, settlements, and court awarded
attorney’s fees resulting from a Claim where the claimant is adjudged the
successful party in the Claim. Contractor’s obligations under this section are
conditioned on the following:
11.2.2.1 County promptly notifies Contractor of the Claim, in writing, upon being
made aware of the Claim;
11.2.2.2 County gives Contractor lead authority control of the defense and (if
applicable) settlement of the Claim, provided that County’s legal counsel
may participate in such defense and settlement, at County’s expense;
and
11.2.2.3 County provides all information and assistance reasonably requested by
Contractor to handle the defense or settlement of the Claim.
11.2.3 Remedial Measures
If software becomes, or Contractor reasonably believes use of software may
become, the subject of a Claim, Contractor may, at its own expense and option:
11.2.3.1 procure for County the right to continue use of the product;
11.2.3.2 replace or modify the software; or
11.2.3.3 to the extent that neither 11.2.3.1 nor 11.2.3.2 are deemed commercially
practicable, refund to County a pro-rated portion of the applicable fees
for software based on a linear depreciation monthly over a 10-year
useful life, in which case County will cease all use of software and return
it to Contractor.
11.2.4 Exceptions
Contractor will have no defense or indemnity obligation for any Claim based on:
SERIAL 230056-RFP
11.2.4.1 modifications by someone other than Contractor;
11.2.4.2 software has been modified by Contractor in accordance with County-
provided specifications or instructions;
11.2.4.3 use or combination by the County of software with Third-Party Products,
open source, or freeware technology;
11.2.4.4 Third-Party Products, open source, or freeware technology;
11.2.4.5 a product that is used or located by County in a country other than the
country in which or for which it was supplied by Contractor;
11.2.4.6 possession or use of a product after Contractor has informed County of
modifications or changes required to avoid such Claim and offered to
implement those modifications or changes, if such Claim would have
been avoided by implementation of Contractor's suggestions and to the
extent County did not provide Contractor with a reasonable opportunity
to implement Contractor's suggestions; or
11.2.4.7 the amount of revenue or profits earned, or other value obtained by the
use of products, or the amount of use of the products.
11.2.5 The foregoing states Contractor’s entire liability, and County’s sole and exclusive
remedy, except as provided by law or equity, with respect to any infringement or
misappropriation of any intellectual property rights of another party.
11.3
SOURCE CODE ESCROW REQUIREMENT
11.3.1 Contractor shall provide all proprietary technology and materials covered under
this agreement that Maricopa County has purchased from Contractor for
safekeeping with a mutually acceptable software escrow service provider (escrow
agent) within 30 days of award, to include, but is not limited to, all source code,
any updates or fixes, and related materials and documents for commercial off-the-
shelf software (COTS), etc. (“deposit material”). The deposit material deposited
with the escrow agent shall be a snapshot of all source code and related material
maintained by Contractor. In this way, as beneficiary of the escrow agreement
between Contractor and escrow agent, Maricopa County will have access to all
source code of the products that they license for all versions of the software.
Furthermore, the escrowed code shall include all code specifically developed for
Maricopa County including, but not limited to, interfaces, Extraction-
Transformation-Loading (ETL) routines for data conversion, and all custom code.
Upon taking possession of the source code, Maricopa County will have the right to
use the source for products that they license in the versions currently installed on
the system or any subsequent versions archived with the escrow agent. Contractor
will make a deposit of the deposit material with the escrow agent upon any version
release or once every six months, whichever occurs first.
11.3.2 Maricopa County hereby agrees to pay the yearly standard fee for a beneficiary of
the source code.
11.3.3 Maricopa County shall have access to the source code in the event of any of the
following circumstances:
11.3.3.1 the sale, assignment, or transfer to any third party of any of Contractor’s
rights in the licensed product (or any portion thereof) if such sale,
assignment, or transfer would prevent Contractor from fully performing
any of its obligations under any agreement with Maricopa County;
SERIAL 230056-RFP
11.3.3.2 Contractor becomes insolvent or commits any affirmative act of
insolvency, or generally fails to pay, or admits in writing its inability to
pay, debts as they become due, makes a general assignment for the
benefit of creditors, files a voluntary petition of bankruptcy, suffers or
permits the appointment of a receiver for its business or assets,
becomes subject to any proceeding under, or case in, any bankruptcy
or insolvency law, or Contractor takes any action to authorize, or in the
furtherance of, any of the following:
11.3.3.2.1 Contractor
discontinues
providing
full
support
and
maintenance services for the licensed product in
accordance with its obligations pursuant to any agreement
with Maricopa County;
11.3.3.2.2 Contractor has ceased to do business or improperly refuses
to provide any services pursuant to any agreement with
Maricopa County;
11.3.3.2.3 Contract is terminated for default/ cause;
11.3.3.2.4 any change of control of Contractor or Contractor’s parent
company, where such party is acquired, directly or
indirectly, in a single transaction or series of related
transactions, or all or substantially all of the assets of such
party are acquired by any entity, or such party is merged
with or into another entity to form a new entity; or
11.3.3.2.5 any other circumstance in which Maricopa County is entitled
to access or use the applicable deposit materials (including,
but not limited to, the source code) under the express terms
of any agreement between Contractor and Maricopa
County.
11.3.4 Upon Maricopa County taking possession of the source code, Maricopa County
hereby agrees as follows:
11.3.4.1 Maricopa County accepts full and total responsibility for the safekeeping
of the source code. Maricopa County agrees that such source code shall
be subject to the restrictions of transfer, sale, and reproduction placed
on the software itself as stated in the software license signed by all
parties.
11.3.4.2 Maricopa County agrees to only use source code related to applications
for which they own a license.
11.3.4.3 Maricopa County agrees, if so ordered by a court of competent
jurisdiction, to compensate Contractor for any and all damages
Contractor suffers, to include reasonable attorney’s fees, resulting
directly or indirectly from, but not limited to, the mishandling, misuse, or
theft of the source code, regardless of intent, or the absence thereof, by
Maricopa County, its employees, agents, and third-party Contractors.
11.3.4.4 No license under any trademark, patent, copyright, or any other
intellectual property right, is either granted or implied by the disclosure
of the source code to Maricopa County. The Contractor’s disclosure of
the source code to Maricopa County shall not constitute any
representation, warranty, assurance, guarantee, or inducement by the
Contractor to Maricopa County of any kind, and, in particular, with
respect to the non-infringement of trademarks, patents, copyrights, or
SERIAL 230056-RFP
any other intellectual property rights, or other rights of third persons or
of Contractor.
11.3.5 Contractor will not be responsible for maintaining the source code. Furthermore,
Contractor will not be liable for any consequences related to the use of source
code modified by Maricopa County.
11.4
INSURANCE
11.4.1 Contractor, at Contractor’s own expense, shall purchase and maintain, at a
minimum, the herein stipulated insurance from a company or companies duly
licensed by the State of Arizona and possessing an AM Best, Inc. category rating
of B++. In lieu of State of Arizona licensing, the stipulated insurance may be
purchased from a company or companies, which are authorized to do business in
the State of Arizona, provided that said insurance companies meet the approval of
County. The form of any insurance policies and forms must be acceptable to
County.
11.4.2 All insurance required herein shall be maintained in full force and effect until all
work or service required to be performed under the terms of the contract is
satisfactorily completed and formally accepted. Failure to do so may, at the sole
discretion of County, constitute a material breach of this contract.
11.4.3 In the event that the insurance required is written on a claims-made basis,
Contractor warrants that any retroactive date under the policy shall precede the
effective date of this contract and either continuous coverage will be maintained,
or an extended discovery period will be exercised for a period of two years
beginning at the time work under this contract is completed.
11.4.4 Contractor’s insurance shall be primary insurance as respects County, and any
insurance or self-insurance maintained by County shall not contribute to it.
11.4.5 Any failure to comply with the claim reporting provisions of the insurance policies
or any breach of an insurance policy warranty shall not affect the County’s right to
coverage afforded under the insurance policies.
11.4.6 The insurance policies may provide coverage that contains deductibles or self-
insured retentions. Such deductible and/or self-insured retentions shall not be
applicable with respect to the coverage provided to County under such policies.
Contractor shall be solely responsible for the deductible and/or self-insured
retention and County, at its option, may require Contractor to secure payment of
such deductibles or self-insured retentions by a surety bond or an irrevocable and
unconditional letter of credit.
11.4.7 The insurance policies required by this contract, except Workers’ Compensation
and Errors and Omissions, shall name County, its agents, representatives, officers,
directors, officials, and employees as additional insureds.
11.4.8 The policies required hereunder, except Workers’ Compensation and Errors and
Omissions, shall contain a waiver of transfer of rights of recovery (subrogation)
against County, its agents, representatives, officers, directors, officials, and
employees for any claims arising out of Contractor’s work or service.
11.4.9 If available, the insurance policies required by this contract may be combined with
Commercial Umbrella Insurance policies to meet the minimum limit requirements.
If a Commercial Umbrella insurance policy is utilized to meet insurance
requirements, the Certificate of Insurance shall indicate which lines the
Commercial Umbrella Insurance covers.
SERIAL 230056-RFP
11.4.9.1 Commercial General Liability
Commercial General Liability (CGL) insurance and, if necessary,
Commercial Umbrella insurance with a limit of not less than $2,000,000
for each occurrence, $4,000,000 Products/Completed Operations
Aggregate, and $4,000,000 General Aggregate Limit. The policy shall
include coverage for premises liability, bodily injury, broad form property
damage, personal injury, products and completed operations and
blanket contractual coverage, and shall not contain any provisions which
would serve to limit third party action over claims. There shall be no
endorsement or modifications of the CGL limiting the scope of coverage
for liability arising from explosion, collapse, or underground property
damage.
11.4.9.2 Professional Liability Insurance
Technology Errors & Omission insurance: Such insurance shall cover
any and all errors, omissions, or negligent acts in the delivery of
products, services, and/or licensed programs under this contract.
•
Each claim
$5,000,000
In the event that the Technology Errors & Omission insurance required
by this contract is written on a claims-made basis, contractor warrants
that any retroactive date under the policy shall precede the effective date
of this contract and, either continuous coverage will be maintained or an
extended discovery period will be exercised for a period of two years,
beginning at the time work under this contract is completed.
11.4.9.3 Cyber, Network Security, and Privacy Liability
Cyber, Network Security and Privacy Liability Insurance with a limit of
not less than $5,000,000 per occurrence. The policy shall include, but
not be limited to; coverage for all directors, officers, agents and
employees of the Contractor, losses with respect to network risks (such
as data breaches, unauthorized access or use, and ID theft of data),
invasion of privacy (regardless of the type of media involved in the loss
of private information), crisis management, identity theft response costs,
breach notification costs, credit remediation, and credit monitoring,
defense, and claims expenses, regulatory defense costs plus fines and
penalties, cyber extortion, electronic data restoration expenses (data
asset protection), network business interruption, computer fraud
coverage, funds transfer loss, third-party fidelity, theft, no requirement
for arrest and conviction, and loss outside the premises of the named
insured.
11.4.10 Certificates of Insurance
11.4.10.1 Prior to contract award, Contractor shall furnish the County with valid
and complete Certificates of Insurance, or formal endorsements as
required by the contract in the form provided by the County, issued by
Contractor’s insurer(s), as evidence that policies providing the required
coverage, conditions and limits required by this contract are in full force
and effect. Such certificates shall identify this contract number and title.
11.4.10.2 In the event any insurance policy(ies) required by this contract is (are)
written on a claims-made basis, coverage shall extend for two years past
completion and acceptance of Contractor’s work or services and as
evidenced by annual certificates of insurance.
SERIAL 230056-RFP
11.4.10.3 If a policy does expire during the life of the Contract, a renewal certificate
must be sent to County 15 calendar days prior to the expiration date.
11.4.11 Cancellation and Expiration Notice
Applicable to all insurance policies required within the insurance requirements of
this contract, Contractor’s insurance shall not be permitted to expire, be
suspended, be canceled, or be materially changed for any reason without 30 days
prior written notice to Maricopa County. Contractor must provide to Maricopa
County, within two business days of receipt, if they receive notice of a policy that
has been or will be suspended, canceled, materially changed for any reason, has
expired, or will be expiring. Such notice shall be sent directly to Maricopa County
Office of Procurement Services and shall be mailed, or hand delivered to 301 W.
Jefferson St. Suite 700, Phoenix, AZ 85003, or emailed to the procurement officer
noted in the solicitation.
11.5
FORCE MAJEURE
11.5.1 Neither party shall be liable for failure of performance, nor incur any liability to the
other party on account of any loss or damage resulting from any delay or failure to
perform all or any part of this contract, if such delay or failure is caused by events,
occurrences, or causes beyond the reasonable control and without negligence of
the parties. Such events, occurrences, or causes include, but are not limited to,
acts of God/nature (including fire, flood, earthquake, storm, hurricane, or other
natural disaster), war, invasion, act of foreign enemies, hostilities (whether war is
declared or not), civil war, riots, rebellion, revolution, insurrection, military or
usurped power or confiscation, terrorist activities, nationalization, government
sanction, lockout, blockage, embargo, labor dispute, strike, and interruption or
failure of electricity or telecommunication service, and pandemic.
11.5.2 Each party, as applicable, shall give the other party notice of its inability to perform
and particulars in reasonable detail of the cause of the inability. Each party must
use best efforts to remedy the situation and remove, as soon as practicable, the
cause of its inability to perform or comply.
11.5.3 The party asserting Force Majeure as a cause for non-performance shall have the
burden of proving that reasonable steps were taken to minimize delay or damages
caused by foreseeable events, that all non-excused obligations were substantially
fulfilled, and that the other party was timely notified of the likelihood or actual
occurrence which would justify such an assertion, so that other prudent
precautions could be contemplated.
11.6
ORDERING AUTHORITY
Any request for purchase shall be accompanied by a valid purchase order issued by a
County department or directed by a Certified Agency Procurement Aid (CAPA) with a
purchase card for payment.
11.7
PROCUREMENT CARD ORDERING CAPABILITY
County may opt to use a procurement card (Visa or Master Card) to make payment for
orders under this contract.
SERIAL 230056-RFP
11.8
NO MINIMUM OR MAXIMUM PURCHASE OBLIGATION
This contract does not guarantee any minimum or maximum purchases will be made.
Orders will only be placed under this contract when the County identifies a need and proper
authorization and documentation have been approved.
11.9
PURCHASE ORDERS
11.9.1 County reserves the right to cancel purchase orders within a reasonable period of
time after issuance. Should a purchase order be canceled, the County agrees to
reimburse the Contractor for actual and documentable costs incurred by the
Contractor in response to the purchase order. The County will not reimburse the
Contractor for any costs incurred after receipt of County notice of cancellation, or
for lost profits, or for shipment of product prior to issuance of purchase order.
11.10
BACKGROUND CHECK
Respondents may be required to pass multiple background checks (e.g., Sheriff’s Office,
County Attorney's Office, Courts, as well as Maricopa County general government) to
determine if the respondent is acceptable to do business with the County. This applies to,
but is not limited to, the company, subcontractors, and employees, and the failure to pass
these checks shall deem the respondent non-responsible.
11.11
SUSPENSION OF WORK
The procurement officer may order the Contractor, in writing, to suspend, delay, or interrupt
all or any part of the work of this contract for the period of time that the procurement officer
determines appropriate for the convenience of the County. No adjustment shall be made
under this clause for any suspension, delay, or interruption to the extent that performance
would have been so suspended, delayed, or interrupted by any other cause, including the
fault or negligence of the Contractor. No request for adjustment under this clause shall be
granted unless the claim, in an amount stated, is asserted in writing as soon as practicable
after the termination of the suspension, delay, or interruption, but not later than the date of
final payment under the contract.
11.12
STOP WORK ORDER
11.12.1 The procurement officer may, at any time, by written order to the Contractor,
require the Contractor to stop all, or any part, of the work called for by this contract
for a period of 90 calendar days after the order is delivered to the Contractor, and
for any further period to which the parties may agree. The order shall be specifically
identified as a stop work order issued under this clause. Upon receipt of the order,
the Contractor shall immediately comply with its terms and take all reasonable
steps to minimize the incurrence of costs allocable to the work covered by the order
during the period of work stoppage. Within a period of 90 calendar days after a
stop work order is delivered to the Contractor, or within any extension of that period
to which the parties shall have agreed, the procurement officer shall either:
11.12.1.1 cancel the stop work order; or
11.12.1.2 terminate the work covered by the order as provided in the Termination
for Default or the Termination for Convenience clause of this contract.
11.12.1.3 The procurement officer shall make an equitable adjustment in the
delivery schedule and/or contract price, and the contract shall be
modified, in writing, accordingly, if the Contractor demonstrates that the
stop work order resulted in an increase in costs to the Contractor and/
or delays to the delivery schedule.
SERIAL 230056-RFP
11.13
TERMINATION FOR CONVENIENCE
Maricopa County may terminate the resultant contract for convenience by providing 60
calendar days advance notice to the Contractor.
11.14
TERMINATION FOR DEFAULT
11.14.1 The County may, by written Notice of Default to the Contractor, terminate this
contract in whole or in part if the Contractor fails to:
11.14.1.1 deliver the supplies or to perform the services within the time specified
in this contract or any extension;
11.14.1.2 make progress, such that the material deadlines will not be met; or
11.14.1.3 perform any of the other provisions of this contract.
11.14.2 The County’s right to terminate this contract under these subparagraphs may be
exercised if the Contractor does not cure such failure within 10 business days (or
more if authorized in writing by the County) after receipt of a Notice to Cure from
the procurement officer specifying the failure.
11.15
PERFORMANCE
It shall be the Contractor’s responsibility to meet the proposed performance requirements.
Maricopa County reserves the right to obtain services on the open market in the event the
Contractor fails to perform, and any price differential will be charged against the Contractor.
11.16
CONTRACTOR EMPLOYEE MANAGEMENT
11.16.1 Contractor shall endeavor to maintain the personnel proposed in their proposal
throughout the performance of this contract.
11.16.2 If Contractor personnel’s employment status changes, Contractor shall provide
County a list of proposed replacements with equivalent or greater experience.
11.16.3 Under no circumstances shall the implementation schedule to be impacted by a
personnel change on the part of the Contractor.
11.16.4 Contractor shall not reassign any key personnel identified in their proposal without
the express consent of the County.
11.16.5 County reserves the right to immediately remove from its premises any Contractor
personnel it determines to be a risk to County operations.
11.16.6 County reserves the right to request the replacement of any Contractor personnel
at any time, for any reason.
11.17
WARRANTY OF SERVICES
11.17.1 The Contractor warrants that all services provided hereunder will conform to the
requirements of the contract, including all descriptions, specifications, and
attachments made a part of this contract. County’s acceptance of services or
goods provided by the Contractor shall not relieve the Contractor from its
obligations under this warranty.
11.17.2 In addition to its other remedies, County may, at the Contractor's expense, require
prompt correction of any services failing to meet the Contractor's warranty herein.
Services corrected by the Contractor shall be subject to all the provisions of this
SERIAL 230056-RFP
contract in the manner and to the same extent as services originally furnished
hereunder.
11.18
INSPECTION OF SERVICES
11.18.1 The Contractor shall provide and maintain an inspection system acceptable to
County covering the services under this contract. Complete records of all
inspection work performed by the Contractor shall be maintained and made
available to County during contract performance and for as long afterwards as the
contract requires.
11.18.2 County has the right to inspect and test all services called for by the contract, to
the extent practicable at all times and places during the term of the contract.
County shall perform inspections and tests in a manner that will not unduly delay
the work.
11.18.3 Except for where services have been accepted by County pursuant to the Contract,
if any of the services do not conform to contract requirements, County may require
the Contractor to perform the services again in conformity with contract
requirements, at no cost to the County. When the defects in services cannot be
corrected by re-performance, County may:
11.18.3.1 require the Contractor to take necessary action to ensure that future
performance conforms to contract requirements; and
11.18.3.2 reduce the contract price to reflect the reduced value of the services
performed.
11.18.4 If the Contractor fails to promptly perform the services again or to take the
necessary action to ensure future performance in conformity with contract
requirements, County may:
11.18.4.1 by contract or otherwise, perform the services and charge to the
Contractor, through direct billing or through payment reduction, any cost
incurred by County that is directly related to the performance of such
service; or
11.18.4.2 terminate the contract for default.
11.19
USAGE REPORT
The Contractor shall furnish the County a usage report, upon request, delineating the
acquisition activity governed by the contract. The format of the report shall be approved by
the County and shall disclose the quantity and dollar value of each contract item by
individual unit of measure.
11.20
STATUTORY RIGHT OF CANCELLATION FOR CONFLICT OF INTEREST
Notice is given that, pursuant to A.R.S. § 38-511, the County may cancel any contract
without penalty or further obligation within three years after execution of the contract, if any
person significantly involved in initiating, negotiating, securing, drafting, or creating the
contract on behalf of the County is at any time, while the contract or any extension of the
contract is in effect, an employee or agent of any other party to the contract in any capacity
or consultant to any other party of the contract with respect to the subject matter of the
contract. Additionally, pursuant to A.R.S. § 38-511, the County may recoup any fee or
commission paid or due to any person significantly involved in initiating, negotiating,
securing, drafting, or creating the contract on behalf of the County from any other party to
the contract arising as the result of the contract.
SERIAL 230056-RFP
11.21
OFFSET FOR DAMAGES
In addition to all other remedies at Law or Equity, the County may offset from any money
due to the Contractor any amounts Contractor owes to the County for damages resulting
from breach or deficiencies in performance of the contract.
11.22
SUBCONTRACTING
11.22.1 The Contractor may not assign to another Contractor or subcontract to another
party for performance of the terms and conditions hereof without the written
consent of the County. All correspondence authorizing subcontracting must
reference the bid serial number and identify the job or project.
11.22.2 The subcontractor’s rate for the job shall not exceed that of the prime Contractor’s
rate, as bid in the pricing section, unless the prime Contractor is willing to absorb
any higher rates. The subcontractor’s invoice shall be invoiced directly to the prime
Contractor, who in turn shall pass-through the costs to the County, without mark-
up. A copy of the subcontractor’s invoice must accompany the prime Contractor’s
invoice.
11.23
AMENDMENTS
All amendments to this contract shall be in writing and approved/signed by both parties.
Maricopa County Office of Procurement Services shall be responsible for approving all
amendments for Maricopa County.
11.24
ADDITIONS/DELETIONS OF REQUIREMENTS
The County reserves the right to add and/or delete materials and services to a contract. If
a service requirement is deleted, payment to the Contractor will be reduced proportionately,
to the amount of service reduced in accordance with the bid price. If additional materials
or services are required from a contract, prices for such additions will be negotiated
between the Contractor and the County.
11.25
RIGHTS IN DATA
11.25.1 The County shall have the use of data and reports resulting from a contract without
additional cost or other restriction except as may be established by law or
applicable regulation. Each party shall supply to the other party, upon request, any
available information that is relevant to a contract and to the performance
thereunder.
11.25.2 Data, records, reports, and all other information generated for the County by a third
party as the result of a contract are the property of the County and shall be provided
in a format designated by the County or shall be and remain accessible to the
County into perpetuity.
11.26
ACCESS TO AND RETENTION OF RECORDS FOR THE PURPOSE OF AUDIT AND/OR
OTHER REVIEW
11.26.1 In accordance with Section MC1-372 of the Maricopa County Procurement Code,
the Contractor agrees to retain (physical or digital copies of) all books, records,
accounts, statements, reports, files, and other records and back-up documentation
relevant to this contract for six years after final payment or until after the resolution
of any audit questions, which could be more than six years, whichever is longest.
The County, Federal or State auditors and any other persons duly authorized by
the department shall have full access to and the right to examine, copy, and make
use of, any and all said materials.
SERIAL 230056-RFP
11.26.2 If the Contractor’s books, records, accounts, statements, reports, files, and other
records and back-up documentation relevant to this contract are not sufficient to
support and document that requested services were provided, the Contractor shall
reimburse Maricopa County for the services not so adequately supported and
documented.
11.27
AUDIT DISALLOWANCES
If at any time it is determined by the County that a cost for which payment has been made
is a disallowed cost, the County shall notify the Contractor in writing of the disallowance.
The course of action to address the disallowance shall be at sole discretion of the County,
and may include either an adjustment to future invoices, request for credit, request for a
check, or a deduction from current invoices submitted by the Contractor equal to the
amount of the disallowance, or to require reimbursement forthwith of the disallowed amount
by the Contractor by issuing a check payable to Maricopa County.
11.28
STRICT COMPLIANCE
Acceptance by County of a performance that is not in strict compliance with the terms of
the contract shall not be deemed to be a waiver of strict compliance with respect to all other
terms of the contract.
11.29
VALIDITY
The invalidity, in whole or in part, of any provision of this contract shall not void or affect
the validity of any other provision of the contract.
11.30
SEVERABILITY
The removal, in whole or in part, of any provision of this contract shall not void or affect the
validity of any other provision of this contract.
11.31
RELATIONSHIPS
11.31.1 In the performance of the services described herein, the Contractor shall act solely
as an independent Contractor, and nothing herein or implied herein shall at any
time be construed as to create the relationship of employer and employee, co-
employee, partnership, principal and agent, or joint venture between the County
and the Contractor.
11.31.2 The County reserves the right of final approval on proposed staff. Also, upon
request by the County, the Contractor will be required to remove any employees
working on County projects and substitute personnel based on the discretion of
the County within two business days, unless previously approved by the County.
11.32
NON-DISCRIMINATION
Contractor agrees to comply with all provisions and requirements of Arizona Executive
Order 2009-09, including flow down of all provisions and requirements to any
subcontractors. Executive Order 2009-09 supersedes Executive Order 99-4 and amends
Executive Order 75-5 and is hereby incorporated into this contract as if set forth in full
herein. During the performance of this contract, Contractor shall not discriminate against
any employee, client, or any other individual in any way because of that person’s age, race,
creed, color, religion, sex, disability, or national origin. (Arizona Executive Order 2009-09
can be viewed at https://apps.azsos.gov/public_services/register/2009/46/governor.pdf).
SERIAL 230056-RFP
11.33
WRITTEN CERTIFICATION PURSUANT to A.R.S. § 35-393.01
If vendor engages in for-profit activity and has 10 or more employees, and if this agreement
has a value of $100,000 or more, vendor certifies it is not currently engaged in, and agrees
for the duration of this agreement to not engage in, a boycott of goods or services from
Israel. This certification does not apply to a boycott prohibited by 50 U.S.C. § 4842 or a
regulation issued pursuant to 50 U.S.C. § 4842.
11.34
CERTIFICATION REGARDING DEBARMENT AND SUSPENSION
11.34.1 The undersigned (authorized official signing on behalf of the Contractor) certifies
to the best of his or her knowledge and belief that the Contractor, its current
officers, and directors:
11.34.1.1 are not presently debarred, suspended, proposed for debarment,
declared ineligible, or voluntarily excluded from being awarded any
contract or grant by any United States department or agency or any
state, or local jurisdiction;
11.34.1.2 have not within a three-year period preceding this contract:
11.34.1.2.1 been convicted of fraud or any criminal offense in
connection with obtaining, attempting to obtain, or as the
result of performing a government entity (Federal, State or
local) transaction or contract; or
11.34.1.2.2 been convicted of violation of any Federal or State antitrust
statutes or conviction for embezzlement, theft, forgery,
bribery, falsification or destruction of records, making false
statements, or receiving stolen property regarding a
government entity transaction or contract;
11.34.1.3 are not presently indicted or criminally charged by a government entity
(Federal, State or local) with commission of any criminal offenses in
connection with obtaining, attempting to obtain, or as the result of
performing a government entity public (Federal, State or local)
transaction or contract;
11.34.1.4 are not presently facing any civil charges from any governmental entity
regarding obtaining, attempting to obtain, or from performing any
governmental entity contract or other transaction; and
11.34.1.5 have not within a three-year period preceding this contract had any
public transaction (Federal, State or local) terminated for cause or
default.
11.34.2 If any of the above circumstances described in the paragraph are applicable to the
entity submitting a bid for this requirement, include with your bid an explanation of
the matter including any final resolution.
11.34.3 The Contractor shall include, without modification, this clause in all lower tier
covered transactions (i.e., transactions with subcontractors or sub-subcontractors)
and in all solicitations for lower tier covered transactions related to this contract. If
this clause is applicable to a subcontractor or sub-subcontractor, the Contractor
shall include the information required by this clause with their bid.
SERIAL 230056-RFP
11.35
VERIFICATION REGARDING COMPLIANCE WITH A.R.S. § 41-4401 AND FEDERAL
IMMIGRATION LAWS AND REGULATIONS
11.35.1 By entering into the contract, the Contractor warrants compliance with the
Immigration and Nationality Act (INA using E-Verify) and all other Federal
immigration laws and regulations related to the immigration status of its employees
and A.R.S. § 23-214(A). The Contractor shall obtain statements from its
subcontractors certifying compliance and shall furnish the statements to the
procurement officer upon request. These warranties shall remain in effect through
the term of the contract. The Contractor and its subcontractors shall also maintain
Employment Eligibility Verification forms (I-9) as required by the Immigration Reform
and Control Act of 1986, as amended from time to time, for all employees performing
work under the contract and verify employee compliance using the E-Verify system
and shall keep a record of the verification for the duration of the employee’s
employment or at least three years, whichever is longer. I-9 forms are available for
download at www.uscis.gov.
11.35.2 The County retains the legal right to inspect documents of Contractor and
subcontractor employees performing work under this contract to verify compliance
with paragraph 11.35.1 of this section. Contractor and subcontractor shall be given
reasonable notice of the County’s intent to inspect and shall make the documents
available at the time and date specified. Should the County suspect or find that the
Contractor or any of its subcontractors are not in compliance, the County will
consider this a material breach of the contract and may pursue any and all remedies
allowed by law, including, but not limited to: suspension of work, termination of the
contract for default, and suspension and/or debarment of the Contractor. All costs
necessary to verify compliance are the responsibility of the Contractor.
11.36
CONTRACTOR LICENSE REQUIREMENT
11.36.1 The Contractor shall procure all permits, insurance, and licenses, and pay the
charges and fees necessary and incidental to the lawful conduct of his/her
business, and as necessary complete any requirements, by any and all
governmental or non-governmental entities as mandated to maintain compliance
with and remain in good standing. The Contractor shall keep fully informed of
existing and future trade or industry requirements, and Federal, State, and local
laws, ordinances, and regulations which in any manner affect the fulfillment of a
contract and shall comply with the same. Contractor shall immediately notify both
Office of Procurement Services and the department of any and all changes
concerning permits, insurance, or licenses.
11.37
INFLUENCE
11.37.1 As prescribed in MC1-1203 of the Maricopa County Procurement Code, any effort
to influence an employee or agent to breach the Maricopa County Ethical Code of
Conduct or any ethical conduct, may be grounds for disbarment or suspension
under MC1-902.
11.37.2 An attempt to influence includes, but is not limited to:
11.37.2.1 A person offering or providing a gratuity, gift, tip, present, donation,
money, entertainment or educational passes or tickets, or any type of
valuable contribution or subsidy that is offered or given with the intent to
influence a decision, obtain a contract, garner favorable treatment, or
gain favorable consideration of any kind.
11.37.3 If a person attempts to influence any employee or agent of Maricopa County, the
chief procurement officer, or his designee, reserves the right to seek any remedy
SERIAL 230056-RFP
provided by the Maricopa County Procurement Code, any remedy in equity or in
the law, or any remedy provided by this contract.
11.37.4 ABSOLUTELY NO CONTACT BETWEEN THE RESPONDENT AND ANY
COUNTY PERSONNEL, OTHER THAN THE OFFICE OF PROCUREMENT
SERVICES, IS ALLOWED DURING THE SOLICITATION PROCESS UNLESS
THE COMMUNICATION IS IN REGARD TO PRE-EXISTING BUSINESS WITH
THE COUNTY. ANY COMMUNICATIONS REGARDING THE SOLICITATION,
ITS PARTICIPANTS, OR ANY DOCUMENTATION PRIOR TO THE CONTRACT
AWARD MAY BE GROUNDS FOR DISMISSAL OF THE RESPONDENT FROM
THE EVALUATION PROCESS.
11.38
CONFIDENTIAL INFORMATION
11.38.1 Any information obtained in the course of performing this contract may include
information that is proprietary or confidential to the County. This provision
establishes the Contractor’s obligation regarding such information.
11.38.2 The Contractor shall establish and maintain procedures and controls that are
adequate to assure that no information contained in its records and/or obtained
from the County or from others in carrying out its functions (services) under the
contract shall be used by or disclosed by it, its agents, officers, or employees,
except as required to efficiently perform duties under the contract. The Contractor’s
procedures and controls, at a minimum, must be the same procedures and controls
it uses to protect its own proprietary or confidential information. If, at any time
during the duration of the contract, the County determines that the procedures and
controls in place are not adequate, the Contractor shall institute any new and/or
additional measures requested by the County within 15 business days of the
written request to do so.
11.38.3 Any requests to the Contractor for County proprietary or confidential information
shall be referred to the County for review and approval, prior to any dissemination.
11.39
PUBLIC RECORDS
Under Arizona law, all offers submitted and opened are public records and must be
retained by the County at the Maricopa County Office of Procurement Services. Offers shall
be open to public inspection and copying after contract award and execution, except for
such offers or sections thereof determined to contain proprietary or confidential information
by the Office of Procurement Services. If an offeror believes that information in its offer or
any resulting contract should not be released in response to a public record request, under
Arizona law, the offeror shall indicate the specific information deemed confidential or
proprietary and submit a statement with its offer detailing the reasons that the information
should not be disclosed. Such reasons shall include the specific harm or prejudice which
may arise from disclosure. The records manager of the Office of Procurement Services
shall determine whether the identified information is confidential pursuant to the Maricopa
County Procurement Code.
11.40
INTEGRATION
This contract represents the entire and integrated agreement between the parties and
supersedes
all
prior
negotiations,
proposals,
communications,
understandings,
representations, or agreements, whether oral or written, expressed, or implied.
11.41
UNIFORM ADMINISTRATIVE REQUIREMENTS
By entering into this contract, the Contractor agrees to comply with all applicable provisions
of
Title
2,
Subtitle
A,
Chapter
II,
Part
200—UNIFORM
ADMINISTRATIVE
SERIAL 230056-RFP
REQUIREMENTS, COST PRINCIPLES, AND AUDIT REQUIREMENTS FOR FEDERAL
AWARDS contained in Title 2 C.F.R. § 200 et seq.
11.42
GOVERNING LAW
This contract shall be governed by the laws of the State of Arizona. Venue for any actions
or lawsuits involving this contract will be in Maricopa County Superior Court, Phoenix,
Arizona.
11.43
FORCED LABOR
11.43.1 By submitting a bid for this solicitation and/or entering into a contract as a result of
this solicitation, contractor agrees to comply with all applicable portions of Arizona
Revised Statutes Section 35-394. Contracting; procurement; prohibition; written
certification; remedy; termination; exception; definitions.
11.43.2 Contractor certifies that it does not currently, and agrees for the duration of the
contract, that it will not use:
11.43.2.1 The forced labor of ethnic Uyghurs in the People’s Republic of China.
11.43.2.2 Any goods or services produced by the forced labor of ethnic Uyghurs
in the People’s Republic of China.
11.43.2.3 Any contractors, subcontractors or suppliers that use the forced labor or
any good or services produced by the forced labor of ethnic Uyghurs in
the People’s Republic of China.
11.43.3 If contractor becomes aware during the term of the agreement that contractor is
not in compliance with this paragraph, the contractor shall notify the County within
five business days after becoming aware of the noncompliance. If the contractor
fails to provide a written certification to the County that the contractor has remedied
the noncompliance within 180 days after notifying the County of its noncompliance,
then the agreement terminates, except that if the agreement termination date
occurs before the end the 180-day period, the agreement terminates on the
agreement termination date.
11.44
PRICES
Contractor warrants that prices extended to County under this contract are no higher than
those paid by any other customer for these or similar services.
11.45
ORDER OF PRECEDENCE
In the event of a conflict in the provisions of this contract and Contractor’s license
agreement, if applicable, the terms of this contract shall prevail.
11.46
INCORPORATION OF DOCUMENTS
11.46.1 The following are to be attached to and made part of this Contract:
11.46.1.1 Exhibit A – Vendor Information
11.46.1.2 Exhibit A-1 - Pricing
11.46.1.3 Exhibit B – Scope of Work
11.46.1.4 Exhibit C – Office of Procurement Services Contractor Travel and Per
Diem Policy
SERIAL 230056-RFP
11.46.1.5 Exhibit D - Correctional Health Services’ Interfaces
11.46.1.6 Exhibit E - Correctional Health Services’ Business Associates
Agreement
11.46.1.7 Exhibit F – Fusion EULA
11.46.1.8 Exhibit G – Fusion Functional Response Matrix
11.47
NOTICES
All notices given pursuant to the terms of this contract shall be addressed to:
For County:
Maricopa County
Office of Procurement Services
301 W. Jefferson St., Suite 700
Phoenix, Arizona 85003-1647
For Contractor:
Michael Jakovcic
Fusion Capital management, LLC dba Fusion Health
10 Woodbridge Center Dr., Suite 200
Woodbridge, NJ 07095
11.48
INQUIRIES
11.48.1 Inquiries concerning information herein must be submitted prior to the question
deadline date/time posted in the e-procurement platform, Periscope S2G, using
the link in the “Q&A” tab.
11.48.2 Administrative telephone/email inquiries shall be addressed to:
MICHAEL GALE, PROCUREMENT OFFICER
TELEPHONE: (602) 506-4866
Michael.Gale@maricopa.gov
11.48.3 Inquiries may be submitted by telephone but must be followed up in writing. No
oral communication is binding on Maricopa County.
SERIAL 230056-RFP
Exhibit A – Vendor Information
COMPANY NAME:
Fusion Capital Management, LLC
DOING BUSINESS AS (dba):
Fusion Health
MAILING ADDRESS:
10 Woodbridge Center Drive, Suite 200
Woodbridge, NJ 07095
REMIT TO ADDRESS:
10 Woodbridge Center Drive, Suite 200
Woodbridge, NJ 07095
TELEPHONE NUMBER:
732-218-5705
FAX NUMBER:
732-218-5769
WWW ADDRESS:
www.Fusionehr.com
REPRESENTATIVE NAME:
Michael Jakovcic
REPRESENTATIVE TELEPHONE NUMBER:
732-218-5705
REPRESENTATIVE EMAIL ADDRESS
BD@fusionmgt.com
YES
NO
REBATE
WILL ALLOW OTHER GOVERNMENTAL ENTITIES TO
PURCHASE FROM THIS CONTRACT:
WILL ACCEPT PROCUREMENT CARD FOR PAYMENT:
PAYMENT TERMS: NET 30 DAYS
SERIAL 230056-RFP
Exhibit A-1 – Pricing
One Time Costs:
Cost Description
Year 1
Year 2
Year 3
Year 4
Year 5
Traveling Costs (Per
Exhibit 2)
$
4,000.00
$
10,000.00
$
-
$
-
$
-
Planning and Analysis
Costs
$
231,100.00
$
-
$
-
$
-
$
-
Configuration Costs
$
280,000.00
$
$
-
$
-
$
-
Development Costs
$
135,000.00
$
45,000.00
$
-
$
-
$
-
Interface Costs
$
280,000.00
$
$
-
$
-
$
-
Conversion and
Migration Costs
$
86,000.00
$
$
-
$
-
$
-
Training Costs
$
6,800.00
$
40,000.00
$
-
$
-
$
-
Customization Costs
$
-
$
-
$
-
$
-
$
-
Monthly Hosting Costs
$
-
$
-
$
-
$
-
$
-
Monthly Processing
Costs
$
-
$
-
$
-
$
-
$
-
Monthly Service Fees
$
-
$
-
$
-
$
-
$
-
Other One Time Fees
$
-
$
-
$
-
$
-
$
-
Maintenance fee
$
-
$
-
$
-
$
-
$
-
License Fees
(Licensing fees include
maintenance)
$
-
$
-
$
-
$
-
$
-
All Third Party Costs (If
applicable)
$
-
$
-
$
-
$
-
$
-
Go-Live/Deployment
$
-
$
70,000.00
$
-
$
-
$
-
Total:
$
1,022,900.00
$
165,000.00
$
-
$
-
$
-
Operational
Costs:
Cost Description
Year 1
Year 2
Year 3
Year 4
Year 5
Traveling Costs (Per
Exhibit 2)
$
-
$
-
$
-
$
-
$
-
Planning and Analysis
Costs
$
-
$
-
$
-
$
-
$
-
Configuration Costs
$
-
$
-
$
-
$
-
$
-
SERIAL 230056-RFP
Interface Costs
$
-
$
66,037.50
$
88,050.00
$
88,050.00
$
88,050.00
Development Costs
$
-
$ -
$
-
$
-
$
-
Conversion and
Migration Costs
$
-
$ -
$
-
$
-
$
-
Training Costs
$
-
$ -
$
-
$
-
$
-
Customization Costs
$
-
$ -
$
-
$
-
$
-
Monthly Hosting Costs
(These are annual costs,
not monthly)
$
-
$
90,000.00
$
124,200.00
$
128,547.00
$
133,046.15
Monthly Processing
Costs
$
-
$ -
$
-
$
-
$
-
Monthly Service Fees
$
-
$ -
$
-
$
-
$
-
Other One Time Fees
$
-
$ -
$
-
$
-
$
-
Maintenance fee
$
-
$ -
$
-
$
-
$
-
License Fees
$
-
$
501,000.00
$
691,380.00
$
715,578.30
$
740,623.54
All Third Party Costs (If
applicable)
$
-
$ -
$
-
$
-
$
-
Add Additional lines if
necessary
$
-
$ -
$
-
$
-
$
-
Total
$
-
$
657,037.50
$
903,630.00
$
932,175.30
$
961,719.69
Year 1
Year 2
Year 3
Year 4
Year 5
Total One Time Costs
$
1,022,900.00
$
165,000.00
$
-
$
-
$
-
Total Operational Costs
$
-
$
657,037.50
$
903,630.00
$
932,175.30
$
961,719.69
SERIAL 230056-RFP
One Time Costs:
Cost Description
Year 6
Year 7
Year 8
Year 9
Year 10
Traveling Costs (Per
Exhibit 2)
$
-
$
-
$
-
$
-
$
-
Planning and Analysis
Costs
$
-
$
-
$
-
$
-
$
-
Configuration Costs
$
-
$
-
$
-
$
-
$
-
Development Costs
$
-
$
-
$
-
$
-
$
-
Interface Costs
$
-
$
-
$
-
$
-
$
-
Conversion and
Migration Costs
$
-
$
-
$
-
$
-
$
-
Training Costs
$
-
$
-
$
-
$
-
$
-
Customization Costs
$
-
$
-
$
-
$
-
$
-
Monthly Hosting Costs
$
-
$
-
$
-
$
-
$
-
Monthly Processing
Costs
$
-
$
-
$
-
$
-
$
-
Monthly Service Fees
$
-
$
-
$
-
$
-
$
-
Other One Time Fees
$
-
$
-
$
-
$
-
$
-
Maintenance fee
$
-
$
-
$
-
$
-
$
-
License Fees
$
-
$
-
$
-
$
-
$
-
All Third Party Costs (If
applicable)
$
-
$
-
$
-
$
-
$
-
Go-Live/Deployment
$
-
$
-
$
-
$
-
$
-
Total:
$
-
$
-
$
-
$
-
$
-
Operational
Costs:
Cost Description
Year 6
Year 7
Year 8
Year 9
Year 10
Traveling Costs (Per
Exhibit 2)
$
-
$
-
$
-
$
-
$
-
Planning and Analysis
Costs
$
-
$
-
$
-
$
-
$
-
Configuration Costs
$
-
$
-
$
-
$
-
$
-
Interface Costs
$
88,050.00
$
88,050.00
$
88,050.00
$
88,050.00
$
88,050.00
SERIAL 230056-RFP
Development Costs
$
-
$ - $ - $ - $ -
Conversion and
Migration Costs
$
-
$ - $ - $ - $ -
Training Costs
$
-
$ - $ - $ - $ -
Customization Costs
$
-
$ - $ - $ - $ -
Monthly Hosting Costs
(These are annual costs,
not monthly)
$
137,702.76
$
142,522.40
$
147,510.60
$
152,673.50
$
158,017.10
Monthly Processing
Costs
$
-
$ - $ - $ - $ -
Monthly Service Fees
$
-
$ - $ - $ - $ -
Other One Time Fees
$
-
$ - $ - $ - $ -
Maintenance fee
$
-
$ - $ - $ - $ -
License Fees
(Licensing fees include
maintenance)
$
766,545.36
$
793,374.50
$
821,142.60
$
849,882.50
$
879,628.40
All Third Party Costs (If
applicable)
$
-
$ - $ - $ - $ -
Add Additional lines if
necessary
$
-
$ - $ - $ - $ -
Total
$
992,298.12
$
1,023,946.90
$
1,056,703.20
$
1,090,606.00
$
1,125,695.50
Year 6
Year 7
Year 8
Year 9
Year 10
Total One Time Costs
$
-
$ - $ - $ - $ -
Total Operational Costs
$
992,298.12
$
1,023,946.90
$
1,056,703.20
$
1,090,606.00
$
1,125,695.50
SERIAL 230056-RFP
Exhibit B – Scope of Work
1.
INTENT
1.1.
Maricopa County (County) is seeking a qualified contractor to provide an Electronic Health
Record
(EHR)
system
for
Correctional
Health
Services
(CHS):
https://www.maricopa.gov/1179/Correctional-Health-Services. CHS provides professional
healthcare services for all incarcerated individuals within the County jails.
1.2.
BACKGROUND
The Maricopa County Jail system is the fourth largest in the United States, with a daily
population of approximately 7,000 inmates and an estimated 100,000 bookings annually.
CHS operates nine clinic locations across six different jails, with approximately 250,000
patient encounters per year. The National Commission on Correctional Healthcare
(NCCHC) accredits CHS.
1.3.
CURRENT USAGE:
The proposed EHR system must accommodate the minimum volumes and concurrent
usage summarized below and detailed in EXHIBIT 5 - CORRECTIONAL HEALTH
SERVICES’ VOLUMES AND CONCURRENT USAGE.
1.3.1.
1,000 Estimated Devices/Accounts
1.3.2.
565 Users
1.3.3.
Appointments Created
1.3.3.1. Dental: 9,890
1.3.3.2. Medical: 169,341
1.3.3.3. Mental Health: 91,831
1.3.3.4. Psychiatric: 48,635
1.3.4.
Ancillary Orders
1.3.4.1. Pharmacy: 183,691
1.3.4.2. Laboratory: 80,116
1.3.4.3. Radiology: 7,959
1.3.5.
Other Documents
1.3.5.1. Referrals: 6,204
1.3.5.2. Forms: 4,251,797
1.3.6.
Maricopa County Jails – CHS Clinic Locations and Inmate Capacity
1.3.6.1. Fourth Avenue Jail: 1,992
1.3.6.2. Lower Buckeye Jail: 2,430
1.3.6.3. Estrella Jail: 1,671
1.3.6.4. Towers Jail: 720
1.3.6.5. Intake Transfer and Release Facility: 512
1.3.6.6. Watkins Jail: 8,925
1.3.7.
Anticipated Use for Scanned Files: Approximately two Terabytes (TB) annually
1.4.
CHS is seeking an improved EHR system to integrate medical, dental, and mental health
information while maximizing clinical communication and enhancing the quality and
continuity of patient care. The fully integrated EHR system must be flexible, user-friendly,
SERIAL 230056-RFP
and effectively manage all patient health records to meet NCCHC standards. The desired
system will streamline daily clinical processes, provide efficient data exchange for
information at the point of care, reduce medical errors, and minimize legal liability. CHS is
seeking an EHR system from an Application Service Provider (ASP) that meets the latest
Health Level Seven (HL7) standards and seamlessly interfaces with numerous platforms
associated with various internal and external stakeholders. The system must comply with
all Health Insurance Portability and Accountability Act (HIPAA) rules and standards, Health
Information Technology for Economic and Clinical Health (HITECH) regulations, and
Health IT Certification Criteria (2015 Edition) Final Rule. The EHR system must be
installed, tested, and fully implemented to go live by March 1, 2025.
1.5.
CHS operates within the wider interdepartmental County secured network maintained by
the Office of Enterprise Technology (OET): https://www.maricopa.gov/1500/Technology.
OET
and
Integrated
Criminal
Justice
Information
System
(ICJIS):
https://www.maricopa.gov/957/Integrated-Criminal-Justice-Information
handle
the
architecture and maintenance of networks, as well as the interfaces for data exchange
between County departments and with external organizations/agencies.
1.6.
The department of CHS will administer the awarded contract. Other governmental entities
under agreement with the County may have access to services provided hereunder (see
also Sections 3.18 and 3.19 below) The County reserves the right to add additional
contractors, at the County’s sole discretion, in cases where the currently listed contractors
are of an insufficient number or skill set to satisfy the County’s needs or to ensure adequate
competition on any project or task order work.
1.7.
The County intends to award a contractor that provides a proven and structured approach
to implementation. In this case, implementation refers to all efforts required to provide a
complete and functioning system and to prepare County staff to use it effectively. The
County will choose an EHR system that most closely meets its requirements for flexibility
and configurability, the functional requirements defined in this Request for Proposals
(RFP), and that permits interfacing and connecting to other internal and external systems.
1.8.
The County will consider proposals submitted by a contractor that proposes to work in
conjunction with subcontractors. However, the bidding contractor shall assume
responsibility for all work and services performed under the executed contract.
2.
SCOPE OF WORK
2.1.
COMPLIANCE
The proposed EHR system shall meet the following compliance requirements as listed in
the section below
2.1.1
Health Level Seven (HL7) standards: https://www.hl7.org/implement/standards
2.1.2
Health Insurance Portability and Accountability Act (HIPAA) rules and regulatory
standards: https://www.hhs.gov/hipaa/for-professionals/index.html
2.1.3
Health Information Technology for Economic and Clinical Health (HITECH) Act
Enforcement
Interim
Final
Rule:
https://www.hhs.gov/hipaa/for-
professionals/special-topics/hitech-act-enforcement-interim-final-rule/index.html
2.1.4
Health
IT
Certification
Criteria
(2015
Edition)
Final
Rule:
https://www.healthit.gov/topic/certification-ehrs/2015-edition
2.1.5
Certified Health IT Product List (CHPL): https://www.healthit.gov/topic/certified-
health-it-products-list-chpl
SERIAL 230056-RFP
2.1.6
National
Commission
on
Correctional
Healthcare
(NCCHC)
standards:
https://www.ncchc.org/standards/
2.1.7
Criminal
Justice
Information
System
(CJIS)
security
policy:
https://www.fbi.gov/services/cjis
2.1.8
Arizona
Criminal
Justice
Information
System
(ACJIS)
guidelines:
https://www.azdps.gov/organization/tsd/cjs
2.1.9
Centers for Medicare and Medicaid Services (CMS) E-prescribing criteria:
https://www.cms.gov/Medicare/E-Health/Eprescribing/Adopted-Standard-and-
Transactions
2.1.10 Drug Enforcement Agency (DEA) Interim Final Rule for controlled substances
certification:
https://www.deadiversion.usdoj.gov/fed_regs/rules/2020/fr0421_3.htm
2.1.11 Electronic Prescribing for Controlled Substances (EPCS) Certified Solution:
https://www.deadiversion.usdoj.gov/ecomm/e_rx/
2.2.
INTERFACES
The proposed EHR system shall seamlessly interface with numerous platforms associated
with internal and external stakeholders as listed in Exhibit 6: Correctional Health Services’
Interfaces.
2.3.
SYSTEM REQUIREMENTS
The proposed EHR system shall include the functionalities and supporting software
modules as listed in Attachment E: Functional Response Matrix to provide a seamless
overall experience for users.
2.3.1.
Enterprise Master Patient Index (EMPI), also known as a “unique identifier,” to
facilitate continuity of care across bookings for patients who return to custody.
2.3.2.
Compatible Biometric Technology
2.3.3.
Initial Screening
2.3.4.
Patient Management
2.3.5.
Patient Search
2.3.6.
Scheduling Appointments and Electronic Referrals (E-Referrals)
2.3.7.
Problem Lists and Chronic Disease Management
2.3.8.
Computerized Physician Order Entry (CPOE)
2.3.9.
Electronic Medication Administration Record (EMAR)
2.3.10. Ancillary Services Management
2.3.11. Clinical Documentation
2.3.12. Reports
2.3.13. Records Management
SERIAL 230056-RFP
2.3.14. User Access
2.3.15. Audit Trails
2.3.16. Technical Specifications
2.4.
QUICK RESPONSES
The contractor shall confirm capabilities as listed in Attachment E: Functional Response
Matrix.
2.5.
IMPLEMENTATION
Within 30 days of award the contractor must provide a detailed implementation plan that
models a standard practice implementation including migration of existing data and
includes the following:
2.5.1.
Implementation methodology: The plan must include flexible implementation
methods that will allow for increased communication, testing, and progress
tracking on a recurring basis.
2.5.2.
Task Level Information: The plan must include all activities necessary for a
successful project at multiple levels - primary activity, task level, and subtasks
levels as needed.
2.5.3.
Identification of All Resources: The plan must clearly identify the contractor
(including subcontractors), and other resources required, including County
resources, to successfully complete the project. The contractor must provide role
descriptions and the proposed number of personnel to be assigned for all
Implementation activities.
2.5.4.
Project Plan: The plan must include appropriate progress/Gantt chart-style project
schedule including all phases, activities, resources (by job title) as well as any
County resources required as part of the contractor’s implementation. Include
estimated durations for the activities, deliverable milestones, and dependencies.
2.6.
PLAN PROGRESS CHARTS
The contractor will provide a detailed response in Attachment E: Functional Response
Matrix regarding the project approach including Work Breakdown Structure (WBS),
resourcing, and Gantt charts that reflect the proposed schedule and all major milestones.
2.7.
TRAINING PLAN
The proposed EHR system must include a comprehensive training plan as listed in
Attachment E: Functional Response Matrix. The selected contractor shall work the with the
County to establish a strategic implementation approach in order to ensure the proper
components are configured and tested for the needs to the County. The contractor must
propose a methodology and tools for maintaining multiple environments (including data
refresh and migration capabilities to and from production) on an ongoing basis during and
after system implementation (provide testing environment). The contractor must also
propose and provide appropriate documentation, end-user training, and operations
procedures to enable departments to effectively maintain and utilize all environments.
SERIAL 230056-RFP
2.8.
SUPPORT AND MAINTENANCE AGREEMENT
The proposed EHR system must include support and maintenance services as listed in
Attachment E: Functional Response Matrix. The selected contractor must bring the range
of necessary capabilities and experience to support and maintain the EHR system.
2.9.
BUSINESS CONTINUITY; DISASTER RECOVERY; DATA BACKUP and RESTORE;
ARCHIVE, RETENTION and DISPOSAL PRACTICES
The proposed EHR system must include the mandatory requirements as listed in
Attachment E: Functional Response Matrix. The selected contractor must provide business
continuity practices and approaches as they relate to the daily operation and possible
interruptions of service (outages) and how the system implementation will cover any
disruptions in services. The proposed system shall meet the Federal, State, and local
Public Record Retention requirements for the effective and efficiently archive, retain, and
dispose of electronic data that is entered, stored, handled, and/or distributed by the
proposed system.
2.10.
HOSTING REQUIREMENTS
The proposed EHR system must include hosting requirements as listed in Attachment E:
Functional Response Matrix.
2.11.
DATA SECURITY
The proposed EHR system must conform to all requirements as pertaining to data security
as listed in Attachment E: Functional Response Matrix.
2.12.
NATIONAL
INSTITUTES
OF
STANDARDS
AND
TECHNOLOGY
(NIST)
QUESTIONNAIRE
Contractor shall submit response to NIST Questionnaire included in Attachment E:
Functional Response Matrix.
2.13.
PRODUCT HISTORY
The proposed EHR system must include the product history as listed in Attachment E:
Functional Response Matrix.
2.14.
Contractor shall provide a dedicated project manager that will work closely and effectively
with all County team members. The contractor will provide project management leadership
team to work with the County stakeholders and project manager. Contractor shall meet
with CHS staff at regular intervals to track project milestones and review escalations or
scope changes as needed.
2.15.
Software contractor must have been in the business of providing EHR solutions for at least
five years. Major version of software proposed must have been in production for at least
one year and must currently be in operation in at least two North American jurisdictions of
500,000 or more. The County prefers solutions that are installed in correctional settings.
2.16.
Contractor must confirm that they hold all title, interest and rights to the proposed system
and underlying source code (except open source) or that it is otherwise legally authorized
to directly license, sub-license, create derivative works, escrow, publicly display and
perform, distribute, and modify the proposed product(s).
SERIAL 230056-RFP
2.17.
TESTING REQUIREMENTS
2.17.1. Contractor shall provide a documented strategy for testing and quality assurance
of development and configuration by analysis and implementation consultants
shall be provided to the County project team for approval prior to commencement
of system configuration.
2.17.2. Contractor shall perform unit testing of the functionality of the system shall be
performed and documented by the contractor. Samples and results of tests may
be requested by the project team to ensure thorough testing is performed prior to
client turnover. Issues identified in testing shall be cataloged, updated upon
closure with final disposition, and provided to the project team prior to conducting
user acceptance testing (UAT). Items identified as issues will not be closed unless
written approval to do so is provided by the County.
2.17.3. Contractor will work directly with the County, and external contractors to test all
interfaces and transmissions of data. To eliminate constraints and delays in testing
and validation, a separate mirror environment (Dev/Test) for testing is required.
2.17.4. The contractor shall provide County with a UAT test catalog to aid in development
of test scripts. Contractor will allow the County a reasonable timeframe to execute
the test plan and retest items with issues.
2.17.5. County is responsible for executing test scripts for UAT and parallel testing.
Contractor will work with County to identify gaps in testing plan where possible.
2.17.6. Testing variances will be documented, categorized, and assigned impact through
a mutually agreed upon format.
2.17.7. If significant issues are found in UAT testing, a refresh and restore with an
additional cycle of UAT may be requested by the project leadership team. If an
environment becomes stale due to long testing timeframes, the project leadership
team may request a refresh or restore.
2.17.8. Contractor may, upon CHS request, provide a Penetration Testing Attestation
Letter, which shall describe the vulnerability assessment that was performed
against a mirrored environment; confirm that an industry standard methodology,
testing tools and national vulnerability database were used; and confirm that
identified vulnerabilities have been remediated or are being addressed in a plan
for remediation and actively monitored.
2.18.
PRODUCTION SUPPORT AND PRODUCT MANAGEMENT
The following items shall be delivered to County in advance of the go-no-go decision for
migration to production.
2.18.1. Provide a tool for reporting, tracking issues and resolution that provides status and
is accessible by County team as needed.
2.18.2. Upon successful delivery of the application, the contractor shall provide an
implementation strategy and proposed timeline for future product enhancements.
2.19.
POST GO LIVE SUPPORT
2.19.1. Contractor shall be expected to provide post go live support to County end users.
2.19.2. Contractor shall establish a quarterly review period for County team, provide
updates on Service Level Agreement, and address concerns as needed.
SERIAL 230056-RFP
2.19.3. Contractor is required to disclose anytime there are planned or unplanned outages
regardless of impact to the system.
2.19.4. Contractor shall provide a web-based helpdesk application to be utilized as the
main method of communications for the County to submit service/trouble tickets
and for the contractor to provide support status. Functionality must include and not
be limited to:
2.19.4.1.
format/methodology for entering service requests into the application;
2.19.4.2.
ability to track all service requests; and reports on response levels;
2.19.4.3.
tickets work status/resolution and other customer service level
statistics that will be essential for the County to measure the
adequacy of the level of services provided.
2.19.5. The online helpdesk service must be available 24 hours a day, 7 days a week 365
days per year. Additional toll-free telephone support service must be available
Monday thru Friday, 5 days a week, 8:00 a.m. to 5:00 p.m. MST.
2.20.
DATA MIGRATION
2.20.1. Contractor shall work with the County to come up with a conversion/migration
strategy and timeline.
2.20.2. Contractor shall convert/import/migrate all existing health records stored in
electronic format from the current EHR system into the new EHR system.
2.20.3. The system shall provide the ability to create and maintain a retention schedule
and destroy records and documents through batch processes that have met their
scheduled dates.
2.21.
DELIVERABLE ACCEPTANCE
2.21.1. Contractor will provide notice to County when a Deliverable has been delivered
("Notice of Delivery"). Upon Notice of Delivery, each Deliverable will be considered
accepted upon County's written confirmation of receipt of a Deliverable or five (5)
business days after Notice of Delivery if County has not provided written
confirmation of receipt ("Acceptance").
2.21.2. Contractor shall invoice County upon County's Acceptance. Deliverables will be
outlined in the implementation plan referenced in Section 2.5 of Exhibit B - Scope
of Work.
2.21.3. Annual Operational Costs shall be invoiced upon the date the first facility goes
live (aka Go-Live) and each anniversary thereafter.
SERIAL 230056-RFP
EXHIBIT C - OFFICE OF PROCUREMENT SERVICES CONTRACTOR TRAVEL AND
PER DIEM POLICY
1.0
All contract-related travel plans and arrangements shall be prior-approved by the County contract
administrator.
2.0
Lodging, per diem, and incidental expenses incurred in performance of Maricopa County/Special
District (County) contracts shall be reimbursed based on current U.S. General Services
Administration (GSA) domestic per diem rates for Phoenix, Arizona. Contractors must access the
following internet site to determine rates (no exceptions): www.gsa.gov.
2.1
Additional incidental expenses (i.e., telephone, fax, internet, and copying charges) shall
not be reimbursed. They should be included in the contractor’s hourly rate as an overhead
charge.
2.2
The County will not (under any circumstances) reimburse for contractor guest lodging, per
diem, or incidentals.
3.0
Commercial air travel shall be reimbursed as follows:
3.1
Coach airfare will be reimbursed by the County. Business class airfare may be allowed
only when preapproved in writing by the County contract administrator as a result of the
business needs of the County when there is no lower fare available.
3.2
The lowest direct flight airfare rate from the contractor’s assigned duty post (pre-defined at
the time of contract signing) will be reimbursed. Under no circumstances will the County
reimburse for airfares related to transportation to or from an alternate site.
3.3
The County will not (under any circumstances) reimburse for contractor guest commercial
air travel.
4.0
Rental vehicles may only be used if such use would result in an overall reduction in the total cost
of the trip, not for the personal convenience of the traveler. Multiple vehicles for the same set of
travelers for the same travel period will not be permitted without prior written approval by the County
contract administrator.
4.1
Purchase of comprehensive and collision liability insurance shall be at the expense of the
contractor. The County will not reimburse a contractor if the contractor chooses to purchase
this coverage.
4.2
Rental vehicles are restricted to sub-compact, compact, or mid-size sedans unless a larger
vehicle is necessary for cost efficiency due to the number of travelers. (NOTE: Contractors
shall obtain pre-approval in writing from the County contract administrator prior to rental of
a larger vehicle.)
4.3
County will reimburse for parking expenses if free, public parking is not available within a
reasonable distance of the place of County business. All opportunities must be exhausted
prior to securing parking that incurs costs for the County. Opportunities to be reviewed are
the DASH, shuttles, etc. that can transport the contractor to and from County buildings with
minimal costs.
4.4
County will reimburse for the lowest rate, long-term, uncovered (covered or enclosed
parking will not be reimbursed) airport parking only if it is less expensive than shuttle
service to and from the airport.
4.5
The County will not (under any circumstances) reimburse the contractor for guest vehicle
rental(s) or other any transportation costs.
SERIAL 230056-RFP
5.0
Contractor is responsible for all costs not directly related to the travel except those that have been
pre-approved by the County contract administrator. These costs include, but are not limited to, the
following: in-room movies, valet service, valet parking, laundry service, costs associated with
storing luggage at a hotel, fuel costs associated with non-County activities, tips that exceed the per
diem allowance, health club fees, and entertainment costs. Claims for unauthorized travel
expenses will not be honored and are not reimbursable.
6.0
Travel and per diem expenses shall be capped at 15 percent of project price unless otherwise
specified and approved by the County in individual contracts.
7.0
Contractor shall provide, (upon request) with their invoice(s), copies of receipts supporting travel
and per diem expenses, and, if applicable, with a copy of the written consent issued by the County
contract administrator. No travel and per diem expenses shall be paid by County without copies of
the written consent as described in this policy and copies of all receipts.
SERIAL 230056-RFP
EXHIBIT D - CORRECTIONAL HEALTH SERVICES’ INTERFACES
SECTION
PLATFORM
STAKEHOLDER
DESCRIPTION
STANDARD(S)
TYPE
FREQUENCY
2.4.1
PreBooking
Maricopa County
Sheriff’s Office
(MCSO)
PreBooking
Information
Extensible
Markup
Language (XML)
Bi-directional
Real Time
2.4.2
Sheriff’s Inmate
Electronic Data
(SHIELD)
Maricopa County
Sheriff’s Office
(MCSO)
Offender
Management
Extensible
Markup
Language (XML)
Bi-directional
Real Time
And
Daily Batch
2.4.3
Diamond
Diamond
Pharmacy
Services
Pharmacy
Health Level
Seven (HL7)
Bi-directional
Real Time
2.4.4
CareEvolve
Garcia Labs
Laboratory
Health Level
Seven (HL7)
Bi-directional
Real Time
2.4.5
TD Synergy
Public Health
Laboratory
Health Level
Seven (HL7)
Bi-directional
Real Time
2.4.6
Viztek Opal-
RAD
Opal Picture
Archiving and
Communication
Systems (PACS)
Radiology
Health Level
Seven (HL7);
Digital Imaging
and
Communications
in Medicine
(DICOM)
Bi-directional
Real Time
2.4.7
TridentCare
Rely Radiology
Radiology
Health Level
Seven (HL7)
Inbound
Real Time
2.4.8
Arizona Health
Care Cost
Containment
System
(AHCCCS)
Arizona Health
Care Cost
Containment
System
(AHCCCS)
Health Plans
Extensible
Markup
Language (XML)
Inbound
Real Time
2.4.9
Mercy Care
Mercy Maricopa
Regional
Behavioral
Health
Authorities
(RBHA)
Health Level
Seven (HL7)
Bi-directional
Real Time
And
Daily Batch
2.4.10
Mirth Connect
(Clinical Data
Repository)
Health Current, a
Contexture
Company
Health
Information
Exchange
(HIE)
Continuity of Care
Document (CCD)
Outbound
Real Time
2.4.11
Arizona
Department of
Health Services
(ADHS)
Arizona State
Immunization
Information
System (ASIIS)
Immunizations
Health Level
Seven (HL7)
Bi-directional
Real Time
2.4.12
Global Tel Link
(GTL)/
ViaPath
Global Tel Link
(GTL)/ViaPath/
Maricopa County
Sheriff’s Office
(MCSO)
Health Needs
Requests/
Grievances
Extensible
Markup
Language (XML)
Inbound
Real Time
2.4.13
Arizona
Department of
Health Services
(ADHS)
ASU Bio/Create
Survivors,
Reduce Victims
(CSRV)
Consulting/Point-
N-Click Solutions
COVID-19
Test Results
Health Level
Seven (HL7);
Comma-
Separated Values
(CSV)
Bi-directional
Daily Batch
2.4.14
Mirth Connect
(Clinical Data
Repository)
Health Current, a
Contexture
Company
Health
Information
Exchange
(HIE)
Continuity of Care
Document (CCD)
Bi-directional
Real Time
SERIAL 230056-RFP
EXHIBIT E - CORRECTIONAL HEALTH SERVICES’ BUSINESS ASSOCIATES
AGREEMENT
WHEREAS, CONTRACTOR has agreed to provide certain administrative services, activities or functions
in connection with the Plan (Services) pursuant to a master contract for services pursuant to RFP No.
230056 (Master Services Agreement) between CONTRACTOR and Employer (Sponsor); and
WHEREAS, the parties desire to enter into this Business Associate Agreement (Agreement), effective upon
the earlier of the Master Services Agreement effective date or the date of first receipt of protected health
information (PHI) from the Plan or Sponsor by CONTRACTOR, as set forth below for the purpose of
addressing the following law, as amended and clarified by the HIPAA Omnibus Rule or any regulation, rule
or guidance that may be issued after the effective date of this Agreement:
•
The Health Information Technology for Economic and Clinical Health Act (HITECH) enacted as
part of the American Recovery and Reinvestment Act of 2009 and the regulations promulgated
thereunder relating to the privacy and security of protected health information;
•
The “Standards for Privacy of Individually Identifiable Health Information,” 45 CFR Part 160
(specifically recognizing here 45 CFR Part 160, Subparts C, D, and E (“Enforcement Rule”)) and
Part 164, Subparts A and E (Privacy Rule);
•
The “Standards for Electronic Transactions,” 45 CFR Part 160, Subpart A and Part 162, Subpart A
and Subparts I through R (“Electronic Transaction Rule”);
•
The “Security Standards for the Protection of Electronic Protected Health Information,” 45 CFR Part
160 and Part 164, Subparts A and C (“Security Rule”); and
•
The “Standards for Breach Notification for Unsecured Protected Health Information,” 45 CFR Part
160 and Part 164, Subparts A and D (“Breach Notification Rule”).
NOW, THEREFORE, in consideration of the premises and other good and valuable consideration, the
receipt and sufficiency of which are hereby acknowledged, the Plan and CONTRACTOR agree as follows:
ARTICLE 1 DEFINITIONS
1.1
“Agent” shall have the meaning given to it in Section X.X. As provided by the Health
Insurance Portability and Accountability Act (HIPAA) an Agent and a Subcontractor are two
separate types of arrangements.
1.2
“Breach” shall have the meaning given to it by 45 CFR § 164.402.
1.3
“Business Associate” shall have the meaning given to it by 45 CFR § 160.103.
1.4
“Designated Record Set” shall have the meaning given to it by 45 CFR § 164.501.
1.5
“Health Care Operations” shall have the same meaning given to it in 45 CFR § 164.501.
1.6
“HIPAA” shall mean, collectively, the Privacy Rule, the Electronic Transaction Rule, the
Security Rule, and/or the Breach Notification Rule, each as amended and clarified by the
HIPAA Omnibus Rule.
1.7
“HIPAA Omnibus Rule” shall mean the “Modifications to the HIPAA Privacy, Security,
Enforcement, and Breach Notification Rules under the HITECH Act and the Genetic
Information Nondiscrimination Act (GINA),” 78 Federal Register 5566 (January 25, 2013).
1.8
“Individual” shall mean the person who is the subject of PHI and shall include a person who
qualifies as a personal representative in accordance with 45 CFR § 164.502(g).
SERIAL 230056-RFP
1.9
“Individual Rights Requests” shall mean requests under Article 3.
1.10
“Payment” shall have the same meaning given to it in 45 CFR § 164.501.
1.11
“PHI” or “protected health information”, defined at 45 CFR § 160.103, shall mean any
information, whether oral or recorded in any form or medium, that: (i) relates to the past,
present or future physical or mental health or condition of an Individual; the provision of
health care to an Individual; or the past, present or future payment for the provision of
health care to an Individual; and (ii) identifies the Individual or with respect to which there
is a reasonable basis to believe the information can be used to identify the Individual
1.12
“Plan” shall have the same meaning given to it as the group health plan or plans of the
Sponsor as set forth in 45 CFR § 160.103.
1.13
“Plan Administration Functions” shall have the same meaning given to it in 45 CFR §
164.504.
1.14
“Plan Administrator” shall mean the entity, individual, group or committee appointed by the
Sponsor, or its successor or successors with the authority to administer the Plan.
1.15
“Privacy Official” shall mean the person designated by the Plan to serve as its privacy
official within the meaning of 45 CFR § 164.530(a), and any person to whom the Privacy
Official has delegated any of his or her duties or responsibilities.
1.16
“Protected Information” shall mean PHI received from the Plan or created, received,
maintained or transmitted by CONTRACTOR on behalf of the Plan.
1.17
“Required by Law” shall have the same meaning given to it in 45 CFR § 164.103.
1.18
“Secretary” shall mean the Secretary of the United States Department of Health and
Human Services.
1.19
“Services” shall mean the activities, functions, and/or services that CONTRACTOR from
time to time renders to or on behalf of the Plan to the extent that those activities, functions,
and/or services are covered by HIPAA.
1.20
“Subcontractor” shall have the same meaning given to it in 45 CFR § 160.103.
1.21
“Unsecured PHI” shall mean Protected Information that is not secured through the use of
a technology or methodology that renders such Protected Information unusable,
unreadable or indecipherable to unauthorized individuals as specified in 45 CFR § 164.402.
ARTICLE 2 OBLIGATIONS AND ACTIVITIES OF CONTRACTOR
2.1
Status of CONTRACTOR. CONTRACTOR acknowledges and agrees that it is a Business
Associate of the Plan for purposes of the Privacy Rule.
2.2
Permitted Uses and Disclosures of Protected Information.
(a)
Permitted Uses. CONTRACTOR shall not use Protected Information other than as
permitted by this Agreement. CONTRACTOR may use Protected Information: (i)
in connection with the performance, management and administration of the
Services; (ii) for the proper business management and administration of
CONTRACTOR; (iii) to carry out CONTRACTOR’s legal responsibilities; (iv) to
report violations of law consistent with 45 CFR § 164.502(j); (v) to the extent and
for any purpose authorized by an Individual under 45 CFR § 164.508; and (vi) for
any purpose provided that no data is identifiable and data has been de-identified
pursuant to 45 CFR § 164.514(b) (including the separate de-identification guidance
issued by the Secretary on November 26, 2012). Notwithstanding the foregoing
SERIAL 230056-RFP
sentence, CONTRACTOR shall not use Protected Information in any manner that
violates the Privacy Rule, or that would violate the Privacy Rule if so, used by the
Plan (except for the purposes specified under 45 CFR § 164.504(e)(2)(i)(A) and
(B)).
(b)
Permitted Disclosures. CONTRACTOR shall not disclose Protected Information
other than as permitted by this Agreement. CONTRACTOR may disclose
Protected Information: (i) in connection with the performance, management and
administration of the Services; (ii) to report violations of law consistent with 45 CFR
§ 164.502(j); (iii) to the extent and for any purpose authorized by an Individual
under 45 CFR § 164.508; and (iv) for any purpose provided that no data is
identifiable and data has been de-identified pursuant to 45 CFR § 164.514(b)
(including the separate de-identification guidance issued by the Secretary on
November 26, 2012). In addition, CONTRACTOR may also disclose Protected
Information to a third party for the proper business management and administration
of CONTRACTOR and to carry out CONTRACTOR’s legal responsibilities,
provided that the disclosure is Required by Law or CONTRACTOR obtains, prior
to the disclosure: (i) reasonable assurances from the third party that the Protected
Information will be held confidentially and used or further disclosed only as
Required by Law or for the purpose for which it was disclosed to the third party;
and (ii) an agreement from the third party that the third party will notify
CONTRACTOR immediately of any instances in which it knows the confidentiality
of the information has been breached. Further, CONTRACTOR shall disclose,
upon request, Protected Information to the Sponsor for Plan Administration
Functions and to designated Sponsor employees (or designated Business
Associates of the Plan) who are working for or on behalf of the Plan for purposes
of Payment and Health Care Operations (including claims assistance activities)
consistent with 45 CFR § 164.506(c)(1). Notwithstanding the foregoing,
CONTRACTOR shall not disclose Protected Information in any manner that
violates the Privacy Rule, or that would violate the Privacy Rule if so, disclosed by
the Plan (except for the purposes specified under 45 CFR § 164.504(e)(2)(i)(A)
and (B)).
(c)
Minimum Necessary. To the extent required by the Privacy Rule, CONTRACTOR
shall only request, use, and/or disclose the minimum amount of Protected
Information necessary to accomplish the purpose of the request, use, and/or
disclosure. For this purpose, the determination of what constitutes the minimum
necessary amount of Protected Information shall be determined in accordance with
Section 164.502(b) of the Privacy Rule.
(d)
Direct Application of Privacy Rules. CONTRACTOR shall not use and/or disclose
Protected Information or provide any Services that require the use and/or
disclosure of Protected Information unless such use and/or disclosure directly
complies with this Section 2.2 and Sections 164.502(a)(3) and 164.504(e) of the
Privacy Rule.
(e)
GINA Provisions. Notwithstanding subsections (a) through (c) above,
CONTRACTOR shall not use and/or disclose Protected Information that is genetic
information for underwriting purposes, as set forth in 45 CFR § 164.502(a)(5).
2.3
Safeguards. CONTRACTOR shall maintain and use appropriate and commercially
reasonable safeguards to prevent use and/or disclosure of Protected Information other
than as permitted or required in this Agreement.
2.4
Reports of Prohibited Disclosures. If CONTRACTOR becomes aware of a disclosure of an
Individual’s Protected Information by CONTRACTOR and the disclosure violated the
provisions of this Agreement, CONTRACTOR must inform the Privacy Official regarding
the prohibited disclosure of the Individual’s Protected Information. To the extent that a
disclosure described in this Section 2.4 also constitutes a Breach of Unsecured PHI, the
SERIAL 230056-RFP
provisions of this Section 2.4 shall not apply, but rather the provisions of Section 2.8 shall
apply.
2.5
Agents and Subcontractors. CONTRACTOR shall require each of its authorized
representatives, agents, and entities (collectively, “Agents”) to whom CONTRACTOR
provides Protected Information on behalf of the Plan to agree to observe the restrictions
on use and disclosure of the Protected Information imposed upon CONTRACTOR by this
Agreement and the Privacy Rule. In addition, CONTRACTOR shall enter into a business
associate agreement with each of its Subcontractors which meets the requirements of the
Privacy Rule, including the requirements set forth in 45 CFR § 164.504(e).
2.6
Access by Secretary. CONTRACTOR shall make available to the Secretary
CONTRACTOR’s internal practices, books, and records (including its policies and
procedures) relating to CONTRACTOR’s use and disclosure of Protected Information for
the purpose of enabling the Secretary to assess the Plan’s and/or CONTRACTOR’s
compliance with HIPAA. CONTRACTOR shall inform the Privacy Official of any request
sent by the Secretary on behalf of the Plan that is received by CONTRACTOR, unless it is
prohibited by applicable law from doing so.
2.7
Mitigation. CONTRACTOR agrees to mitigate, to the extent practicable, any harmful effect
that is known to CONTRACTOR of a use or disclosure of Protected Information by
CONTRACTOR in violation of the requirements of this Agreement and provide any notice
and remediation that either CONTRACTOR or the Plan is required to provide by any
applicable law in connection with such actual or suspected Breach. Where a Breach
involves PHI data elements that reasonably could lead to identity theft, CONTRACTOR
shall provide credit monitoring or other commercially reasonable identity theft mitigation
service for the affected individuals for one year.
2.8
Notice of Breach of Unsecured PHI.
(a)
CONTRACTOR Requirements. Upon CONTRACTOR’s discovery of a Breach of
Unsecured PHI by CONTRACTOR, CONTRACTOR shall –
(1)
Pursuant to the requirements set forth in subsection (c) below, provide
written notice of the Breach to the Privacy Official, as soon as
administratively practicable, but no later than 10 business days after the
Breach is discovered, and
(2)
Pursuant to the requirements set forth in subsection (b) below, provide
written notice of the Breach, on behalf of the Plan, without unreasonable
delay and in no case later than 60 calendar days after discovery of a
Breach as authorized under 45 CFR § 164.404 or such later date as is
authorized under 45 CFR § 164.412 to:
(i)
each Individual whose Unsecured PHI has been, or is
reasonably believed by CONTRACTOR to have been,
accessed, acquired, used or disclosed as a result of the
Breach;
(ii)
the media to the extent required under 45 CFR § 164.406;
and
(iii)
the Secretary to the extent required under 45 CFR §
164.408 (unless the Plan has elected to provide this
notification and has informed CONTRACTOR); and
(3)
If the Breach involves less than 500 individuals, maintain a log or other
documentation of the Breach which contains such information as would
be required to be included if the log were maintained by the Plan
SERIAL 230056-RFP
pursuant to 45 CFR § 164.408, and provide such log to the Plan within
five business days of the Plan’s written request.
(b)
Notice Requirements. This subsection (b) provides the following special rules that
shall each be applicable to the provisions of Section 2.8(a)(2) –
(1)
The date that a Breach is discovered shall be determined by
CONTRACTOR, in its sole discretion, in accordance with the Breach
Notification Rule.
(2)
The content, form, and delivery of each of the notices required by
Section 2.8(a)(2) shall comply in all respects with the breach notification
provisions applicable to the Plan, as set forth in the Breach Notification
Rule.
(3)
CONTRACTOR shall send the notices described in Section 2.8(a)(2)(i)
to each Individual using the address on file with CONTRACTOR (or as
may be otherwise provided by the Plan). If the notice to any Individual is
returned as undeliverable, CONTRACTOR shall make one additional
attempt to deliver the notice to the Individual using such information as
is reasonably available to it or shall take other action required by the
Breach Notification Rule.
(4)
With respect to notices required under Section 2.8(a)(2)(i) and (ii),
CONTRACTOR and the Privacy Official shall cooperate in all respects
regarding the drafting and the content of the notices. To that end, before
sending any notice to any Individual or the media under Section
2.8(a)(2)(i) or (ii), CONTRACTOR shall first provide a draft of the notice
to the Privacy Official. The Privacy Official shall have 10 business days
(plus any reasonable extensions) to either approve CONTRACTOR’s
draft of the notice or revise the language of the notice. Alternatively, the
Privacy Official may elect to draft the notice for review by
CONTRACTOR. Once CONTRACTOR and the Privacy Official agree
on the final content of the notice, CONTRACTOR shall send the notice
to the Individuals and/or the media based on the requirements of the
Breach Notification Rule.
(c)
Privacy Official Notice. The notice to the Privacy Official pursuant to Section
2.8(a)(1) shall include any information available to CONTRACTOR that is required
to be included in a notification to an Individual under 45 CFR § 164.404(c). To the
extent that CONTRACTOR does not have the information to be provided in the
prior sentence when it is required to notify the Privacy Official, CONTRACTOR
shall provide such information as soon as administratively practicable after such
information becomes available. Upon the Plan’s written request, CONTRACTOR
shall provide such additional information regarding the Breach as may be
reasonably requested from time-to-time by the Plan.
(d)
Notice Fees. CONTRACTOR reserves the right to charge reasonable, cost-based
fees for sending the notices required by this Section 2.8 should a Breach be due
to actions on the part of the Sponsor, the Plan or any other entity (other than
CONTRACTOR, its Agents or Subcontractors).
(e)
Remuneration. CONTRACTOR shall not directly or indirectly receive any
remuneration in exchange for PHI or Use or Disclose PHI for marketing or
fundraising purposes.
SERIAL 230056-RFP
ARTICLE 3 INDIVIDUAL RIGHTS REQUIREMENTS
3.1
Designated Record Sets.
(a)
General. CONTRACTOR agrees to maintain a Designated Record Set for the Plan
in a manner and form that will allow the Plan to provide access and amendment
rights to an Individual with respect to the Individual's Protected Information in
conformance with 45 CFR §§ 164.524 and 164.526.
(b)
Access to Protected Information. Upon request from the Plan, CONTRACTOR
shall process and respond to a request by an Individual for access to an
Individual’s Protected Information that is maintained by CONTRACTOR in a
Designated Record Set pursuant to 45 CFR § 164.524 (an “Access Request”).
CONTRACTOR shall respond to such Access Request by furnishing such
Protected Information to the Plan within a timeframe that reasonably allows the
Plan to satisfy the timeframes required by 45 CFR § 164.524. If the Protected
Information that is requested is maintained electronically and the Individual
requests an electronic copy of such information, CONTRACTOR will provide
access to the information in an electronic format that complies with 45 CFR §
164.524(c)(2)(ii). Thereafter, the Plan will be responsible for sending such
information to the Individual.
(c)
Amendment
to
Protected
Information.
Upon
request
from
the
Plan,
CONTRACTOR shall process a request by an Individual for amendment to an
Individual’s Protected Information that is maintained by CONTRACTOR in a
Designated Record Set pursuant to 45 CFR § 164.526 (an Amendment Request).
CONTRACTOR shall process such Amendment Request within a timeframe that
reasonably allows the Plan to satisfy the timeframes required by 45 CFR §
164.526.
(d)
Coordination with Privacy Official. CONTRACTOR shall coordinate and cooperate
with the Privacy Official (or any other person designated by the Plan Administrator
for this purpose) regarding all processing, recordkeeping, and documentation
issues relating to Access Requests and Amendment Requests. Notwithstanding
the foregoing, CONTRACTOR shall not be obligated to coordinate with the Privacy
Official if an Individual files an Access Request or an Amendment Request with
CONTRACTOR and such request is directed solely to CONTRACTOR.
3.2
Accounting of Disclosures of Protected Information.
(a)
Documentation of Disclosures. CONTRACTOR agrees to document and maintain
a log of any and all disclosures from and after the date or dates required by 45
CFR § 164.528 made by CONTRACTOR of Protected Information in a manner and
form that will allow the Plan to provide to an Individual an accounting of disclosures
or other applicable report of the Individual's Protected Information in compliance
with and based on the requirements of 45 CFR § 164.528.
(b)
Accounting Requests. Upon request from the Plan, CONTRACTOR shall process
and respond to a request by an Individual for an accounting of disclosures or other
applicable report of an Individual’s Protected Information pursuant to the
requirements of 45 CFR § 164.528 (an “Accounting Request”). CONTRACTOR
shall furnish such accounting relating to the Accounting Request to the Plan within
a timeframe that reasonably allows the Plan to satisfy the timeframes required by
45 CFR § 164.528. Thereafter, the Plan will be responsible for sending such
information to the Individual.
(c)
Coordination with Privacy Official. CONTRACTOR shall coordinate and cooperate
with the Privacy Official (or any other person designated by the Plan Administrator
for this purpose) regarding all processing, recordkeeping, and documentation
SERIAL 230056-RFP
issues relating to Accounting Requests. Notwithstanding the foregoing,
CONTRACTOR shall not be obligated to coordinate with the Privacy Official if an
Individual files an Accounting Request with CONTRACTOR and such request is
directed solely to CONTRACTOR.
3.3
Privacy Protection Requests.
(a)
Restriction Requests on Uses and Disclosures. The Plan and CONTRACTOR on
behalf of the Plan shall not agree to a restriction on the use or disclosure of
Protected Information pursuant to 45 CFR § 164.522(a) without first consulting with
the other party. CONTRACTOR is not obligated to implement any restriction, if
such restriction would hinder Health Care Operations or the Services
CONTRACTOR provides to the Plan, unless such restriction would otherwise be
required by 45 CFR § 164.522(a).
(b)
Confidential Communication Requests. CONTRACTOR shall implement any
reasonable requests by Individuals relating to a request to receive communications
of Protected Information by alternative means or at alternative locations to the
extent required by 45 CFR § 164.522(b).
(c)
Coordination with Privacy Official. CONTRACTOR shall coordinate and cooperate
with the Privacy Official (or any other person designated by the Plan Administrator
for this purpose) regarding all processing, recordkeeping, and documentation
issues relating to requests under this Section 3.3.
ARTICLE 4 ELECTRONIC TRANSACTION RULE
4.1
Business Associate Requirements. CONTRACTOR acknowledges that it is a Business
Associate of the Plan for purposes of the Electronic Transaction Rule. CONTRACTOR
agrees that it shall comply with all Electronic Transaction Rule requirements that may be
applicable to CONTRACTOR with respect to the Services it provides to and on behalf of
the Plan. CONTRACTOR shall also require each of its Agents and Subcontractors to whom
CONTRACTOR provides Protected Information that is received from or created or received
by CONTRACTOR on behalf of the Plan, to provide assurances, in writing, that they will
comply with the applicable requirements of the Electronic Transaction Rule.
4.2
Sponsor Transmissions. The Sponsor hereby represents and warrants that all electronic
transmissions with respect to the Plan between the Sponsor (either directly or through its
designated agent) and CONTRACTOR relating to enrollment and disenrollment
information and premium payment information as each are covered by the Electronic
Transaction Rule are sent or received by the Sponsor (either directly or through its
designated agent) in the Sponsor’s capacity as an employer and are not sent or received
by the Plan or are not subject to HIPAA for other reasons, such as that the information is
an employment record and not PHI.
ARTICLE 5 OBLIGATIONS OF PLAN
5.1
Privacy Notice. Upon request, the Plan will provide CONTRACTOR with a copy of its notice
of privacy practices pursuant to 45 CFR § 164.520.
5.2
Authorizations. The Plan will notify CONTRACTOR of any changes in or revocations of
Individual authorizations for use or disclosure of Protected Information to the extent that
such changes or revocations may affect CONTRACTOR’s use or disclosure of Protected
Information.
5.3
Officials. The Plan will notify CONTRACTOR of the current name and contact information
of the Plan Administrator, the Privacy Official, and any other person that has the authority
to act on behalf of the Plan with respect to the provisions contained in this Agreement.
SERIAL 230056-RFP
5.4
Plan. Sponsor represents that its Plan documents include specific provisions to restrict the
use or disclosure of PHI and to ensure adequate procedural safeguards and accounting
mechanisms for such uses or disclosures, in accordance with the Privacy Rule.
5.5
Standard Requirements for Group Health Plans. The Plan represents and warrants that:
(a) its plan documents, in accordance with 45 CFR § 164.504(f), allow the Plan to receive
Protected Information; (b) it has received a certification from the Sponsor in accordance
with 45 CFR § 164.504(f)(2)(ii) and will provide a copy of such certification to
CONTRACTOR upon request; (c) the plan document amendments permit the Plan to
receive Protected Information (including detailed invoices, reports, and statements from
CONTRACTOR); and (d) the Plan has determined, through its own policies and procedures
and in compliance with 45 CFR § 164.502(b), that the Protected Information that it receives
from CONTRACTOR (including the detailed invoices, reports, and statements) contains
the minimum information necessary for the Plan to carry out its Payment and Health Care
Operations activities.
5.6
Sponsor agrees and understands that the Plan is independently responsible for the security
of all PHI in its possession (electronic or otherwise), including all PHI that it receives from
outside sources including the Business Associate.
ARTICLE 6 AMENDMENT AND TERMINATION
6.1
Amendment. No change, modification or attempted waiver of any of the provisions of this
Agreement shall be binding upon any party hereto unless reduced to writing and signed by
both parties. CONTRACTOR agrees to take such action as is necessary to amend this
Agreement from time to time as the Plan reasonably determines necessary to comply with
HIPAA, or any other applicable law, rule or regulation.
6.2
Term. The Term of this Agreement shall be effective on the Effective Date (unless
otherwise noted herein) and shall terminate when all of the Protected Information received
from the Plan or created or received by CONTRACTOR on behalf of the Plan, is destroyed
in accordance with the Plan’s authorization or is returned to the Plan (or its designated
agents) pursuant to Section 6.4.
6.3
Termination. If one party to this Agreement (“Non-Breaching Party”) has knowledge of a
material violation of this Agreement by the other party to this Agreement (“Breaching
Party”), as determined in good faith by the Non-Breaching Party, the Non-Breaching Party
must promptly:
(a)
Provide an opportunity for the Breaching Party to end and to cure the material
violation within a reasonable time specified by the Non-Breaching Party, and if the
Breaching Party does not end and cure the material violation within such time
(including reasonable extensions that the Non-Breaching Party determines are
necessary) to the satisfaction of the Non-Breaching Party, the Non-Breaching
Party shall immediately terminate the Services rendered by CONTRACTOR and
any agreement or contract related thereto; or
(b)
If a cure is not possible as determined by the Non-Breaching Party in its sole
discretion, the Non-Breaching Party shall immediately terminate the Services
rendered by CONTRACTOR and any agreement or contract related thereto.
6.4
Effect of Termination. Upon termination pursuant to Section 6.3, the Plan within a
reasonable time thereafter must inform CONTRACTOR to either destroy or return to the
Plan (or any agents designated by the Plan) the Protected Information that CONTRACTOR
and its Agents and Subcontractors maintain in any form, and CONTRACTOR and its
Agents and Subcontractors shall retain no copies of the Protected Information.
SERIAL 230056-RFP
However, in many situations’ CONTRACTOR maintains one or more backup copies of Protected
Information for auditing, data management, and other related purposes and CONTRACTOR has
determined that destruction of all copies of Protected Information that it maintains is infeasible.
Therefore, after termination of the Services and pursuant to 45 CFR § 164.504(e)(2)(ii)(J), this Agreement
shall remain in effect, and CONTRACTOR shall continue to observe and shall ensure that its Agents and
Subcontractors continue to observe its obligations under this Agreement to the extent copies of the
Protected Information are retained by CONTRACTOR and shall limit further uses and disclosures of
Protected Information to the purposes that make its return or destruction infeasible and that are consistent
with the Privacy Rule.
ARTICLE 7 ELECTRONIC SECURITY STANDARDS
7.1
Definitions. When used in this Article, the following terms shall have the meanings set forth
as follows:
(a)
“Electronic Media” shall have the meaning given to it in 45 CFR § 160.103.
(b)
“Electronic Protected Information” shall mean Protected Information received from
the Plan or created, received, maintained or transmitted by CONTRACTOR on
behalf of the Plan that is transmitted by Electronic Media or maintained in
Electronic Media.
(c)
“Security Incident” shall have the meaning given to it in 45 CFR § 164.304.
7.2
Requirements. Pursuant to 45 CFR § 164.314(a)(2)(i), CONTRACTOR shall:
(a)
Comply with the applicable requirements of the Security Rule, including the
requirement
that
CONTRACTOR
implement,
maintain
and
document
administrative, physical, and technical safeguards that reasonably and
appropriately protect the confidentiality, integrity, and availability of Electronic
Protected Information to the extent required by the Security Rule;
(b)
Report (pursuant to the terms and conditions of Section 7.3) to the Privacy Official
(or such other person designated for this purpose) any Security Incident of which
CONTRACTOR becomes aware and which occurred during the applicable
reporting period;
(c)
Require each of its Agents to whom CONTRACTOR provides Electronic Protected
Information to agree to implement administrative, physical, and technical
safeguards that reasonably and appropriately protect the confidentiality, integrity,
and availability of the Electronic Protected Information that is provided to the Agent
to the extent required by the Security Rule; and
(d)
Enter into a contract or other arrangement with each of its Subcontractors that
create, receive, maintain or transmit Electronic Protected Information on behalf of
CONTRACTOR pursuant to which the Subcontractor agrees to comply with the
applicable requirements of the Security Rule.
7.3
Reporting Protocols. All reports required by Section 7.2(b) shall be provided pursuant to
the terms and conditions specified in this section.
(a)
Attempted Security Incidents. Reporting for any Security Incident involving the
attempted unauthorized access, use, disclosure, modification or destruction of
Electronic Protected Information (collectively, an “Attempted Security Incident”)
shall be provided pursuant to the standard reporting protocols of CONTRACTOR
(as determined by CONTRACTOR).
SERIAL 230056-RFP
(b)
Successful Security Incident. Reporting for any Security Incident involving the
successful unauthorized access, use, disclosure, modification or destruction of
Electronic Protected Information (collectively, a “Successful Security Incident”)
shall be provided to the Plan pursuant to the standard reporting protocols of
CONTRACTOR (as determined by CONTRACTOR), provided that: (i) the reports
shall at a minimum include the date of the incident, the parties involved (if known,
including the names of Individuals affected), a description of the Successful
Security Incident, a description of the Electronic Protected Information involved in
the incident, and any action taken to mitigate the impact of the Successful Security
Incident and/or prevent its future recurrence; and (ii) the reports shall satisfy the
minimum requirements for Security Incident reporting that may be required from
time to time by the Secretary. In addition, Successful Security Incidents shall be
reported to the Plan as soon as administratively practicable after the occurrence
of the incident taking into account the severity and nature of the incident.
Notwithstanding the foregoing, the Plan may request details about one or more
Successful Security Incidents, and CONTRACTOR shall have 30 days thereafter
to furnish the requested information.
(c)
Breach of Unsecured PHI. To the extent that a Security Incident described in this
Section 7.3 also constitutes a Breach of Unsecured PHI, the provisions of this
Section 7.3 shall not apply, but rather the provisions of Section 2.8 shall apply.
7.4
Mitigation. CONTRACTOR agrees to mitigate, to the extent practicable, any harmful effect
that is known to CONTRACTOR relating to any Successful Security Incident and provide
any notice and remediation that either CONTRACTOR or the Plan is required to provide
by any applicable law in connection with such Security Incident. Where the Security
Incident involves data elements that reasonably could lead to identity theft, CONTRACTOR
shall provide credit monitoring or other commercially reasonable identity theft mitigation
service for the affected individuals for one year.
7.5
Access by Secretary. CONTRACTOR shall make available to the Secretary
CONTRACTOR’s internal practices, books and records (including its policies and
procedures) relating to the safeguards established by CONTRACTOR with respect to
Electronic Protected Information for the purpose of enabling the Secretary to assess
CONTRACTOR and/or the Plan’s compliance with the Security Rule. CONTRACTOR shall
inform the Privacy Official of any request sent by the Secretary on behalf of the Plan that
is received by CONTRACTOR, unless CONTRACTOR is prevented by applicable law from
doing so.
ARTICLE 8 GENERAL
8.1
Other Agreements. The Plan and CONTRACTOR acknowledge and affirm that this
Agreement is in no way intended to address or cover all aspects of the relationship of the
Plan and CONTRACTOR and of the Services that are rendered by CONTRACTOR to and
on behalf of the Plan. Rather, this Agreement deals only with those matters that are
specifically addressed herein. Further, this Agreement supersedes any prior business
associate agreements entered into by CONTRACTOR and the Plan (or any predecessor
to the Plan) and shall apply to all Protected Information existing as of the effective date of
this Agreement or created or received thereafter while this Agreement is in effect.
8.2
Indemnification. Any indemnification relating to violations of this Agreement by
CONTRACTOR or the Plan (or the Sponsor on behalf of the Plan) shall be addressed to
the extent applicable by the Master Services Agreement.
8.3
Severability. The provisions of this Agreement shall be severable, and the invalidity or
unenforceability of any provision (or part thereof) of this Agreement shall in no way affect
the validity or enforceability of any other provisions (or remaining part thereof). If any part
of any provision contained in this Agreement is determined by a court of competent
jurisdiction, or by any administrative tribunal, to be invalid, illegal or incapable of being
SERIAL 230056-RFP
enforced, then the court or tribunal shall interpret such provisions in a manner so as to
enforce them to the fullest extent of the law.
8.4
Interpretation. The provisions of this Agreement shall be interpreted in a manner intended
to achieve compliance with HIPAA. Whenever the Agreement uses the term “including”
followed by a specific item or items, or there is a passage having a similar effect, such
passages of the Agreement shall be construed as if the phrase “without limitation” followed
such term (or otherwise applied to such passage in a manner that avoids limitations on its
breadth of application). Where the term “and/or” is used in this Agreement, the provision
that includes the term shall have the meaning the provision would have if “and” replaced
“and/or,” but it shall also have the meaning the provision would have if “or” replaced
“and/or.” Any reference to a section or provision of HIPAA shall include any amendment or
clarification of such section or provision contained in the HIPAA Omnibus Rule and any
regulation, rule or guidance issued by the Secretary following the effective date of this
Agreement.
8.5
Binding Effect. The provisions of this Agreement shall be binding upon and shall inure to
the benefit of the parties hereto and their heirs, assigns and successors in interest. The
Plan shall have the right to assign this Agreement to any successor or surviving health
plan, and all covenants and agreements hereunder shall inure to the benefit of and be
enforceable by any such assignee.
8.6
No Third-Party Beneficiaries. Nothing express or implied in this Agreement is intended to
confer, and nothing herein shall confer, upon any person other than the parties hereto any
rights, remedies, obligations or liabilities whatsoever.
8.7
Applicable Law and Disputes. The provisions of this Agreement shall be construed and
administered to, and its validity and enforceability determined under HIPAA. To the extent
that HIPAA is not applicable in a particular circumstance, the provisions of this Agreement
shall be construed and administered to, and its validity and enforceability determined under
the Employee Retirement Income Security Act of 1974, as amended (ERISA). In the event
that HIPAA and ERISA do not preempt state law in a particular circumstance, the laws of
the State of North Dakota shall govern. In the event of any conflict of state laws, the laws
of the State of Arizona shall prevail. The parties agree that any claim or action arising from
this Agreement can only be brought in the United States District Court for the District of
Arizona, and both parties’ consent to such jurisdiction and venue. Any disputes between
the parties arising under this Agreement shall be resolved in accordance with the dispute
resolution procedures, if any, set forth in the Master Services Agreement.
8.8
State Privacy and Security Laws.
(a)
General. Pursuant to 45 CFR § 160.203, CONTRACTOR and the Plan
acknowledge that HIPAA only preempts state laws which are contrary to a HIPAA
standard, requirement or implementation specification, provided that state laws
which relate to the privacy of Protected Information and are more stringent than
the Privacy Rule are not preempted. Accordingly, the parties acknowledge that
certain State Privacy Laws affecting the privacy and/or security of personally
identifiable information (e.g., name, address, age, and social security number)
relating to a Plan participant or beneficiary (“Privacy Restricted Data”) may apply
to the Services provided by CONTRACTOR to the extent such State Privacy Laws
are not preempted by HIPAA. For purposes of this Section 8.8, “State Privacy
Laws” shall mean any applicable state and local privacy laws governing the
creation, collection, storage, maintenance, access, modification, transmission, use
or disclosure of Privacy Restricted Data.
(b)
State Privacy Laws. All Privacy Restricted Data created, collected, received or
obtained by or on behalf of CONTRACTOR in the course of performing its Services
shall be created, collected, received, obtained, stored, maintained, accessed,
modified, transmitted, used, and disclosed in accordance with any and all
SERIAL 230056-RFP
applicable State Privacy Laws. CONTRACTOR shall at all times perform the
Services in accordance with the State Privacy Laws and as not to cause the
Sponsor or the Plan to be in violation of the State Privacy Laws. CONTRACTOR
shall be fully responsible for any creation, collection, receipt, access, storage,
maintenance, modification, transmission, use, and disclosure of Privacy Restricted
Data performed by or on behalf of CONTRACTOR that is in violation of any State
Privacy Laws. CONTRACTOR shall remedy and mitigate the damages of any
breach of privacy, security, integrity or confidentiality with respect to the
unauthorized creation, collection, receipt, storage, maintenance, access,
modification, transmission, use or disclosure (a “State Breach”) of Privacy
Restricted Data that is or may be in violation of any State Privacy Laws.
(c)
Notification. CONTRACTOR shall notify the Privacy Official (using the procedures
that apply to Breaches of Unsecured PHI under Section 2.8(c)) of any State
Breaches by or on behalf of CONTRACTOR of Privacy Restricted Data that is or
may be in violation of any State Privacy Laws. In addition, CONTRACTOR shall
also notify the affected Plan participants and beneficiaries (using the procedures
that apply to Breaches of Unsecured PHI under Section 2.8(b)) of any State
Breaches by or on behalf of CONTRACTOR of Privacy Restricted Data that is in
violation of any State Privacy Laws and any state or local governmental agencies,
authorities or other entities, but only to the extent required by such State Privacy
Laws.
(d)
HIPAA Coordination. The parties acknowledge that in certain situations the
provisions of both Section 2.8 and this Section 8.8 shall apply. If both Sections 2.8
and 8.8 apply in a given situation, CONTRACTOR shall comply with both Sections
2.8 and 8.8 to the extent applicable.
Obligation of Plan and CONTRACTOR. To the extent that CONTRACTOR carries out the HIPAA
obligations of the Plan (including the obligations set forth in Section 2.8 and Article 3), CONTRACTOR shall
comply with the applicable requirements of HIPAA as they apply to the Plan in the performance of such
obligations on behalf of the Plan.
SERIAL 230056-RFP
Exhibit F – Fusion EULA
This End User License Agreement (EULA) and its terms (the “Terms”) govern your usage of the software
and services (collectively, the “Software”) provided to you (the “Licensee”) by and through Fusion Capital
Management, LLC d/b/a Fusion Health (the “Licensor”), for use pursuant to and subject to the terms and
conditions herein.
BY DOWNLOADING, INSTALLING, OR USING THE SOFTWARE YOU: (i) REPRESENT THAT YOU ARE
DULY AUTHORIZED BY LICENSOR TO ACCESS AND USE THE SOFTWARE; AND (ii) ACCEPT THESE
AUTHORIZED USER TERMS AND AGREE THAT YOU ARE LEGALLY BOUND BY THEM. IF YOU DO
NOT AGREE TO THESE TERMS, DO NOT DOWNLOAD, INSTALL, OR USE THE SOFTWARE AND YOU
WILL HAVE NO LICENSE TO, AND MUST NOT ACCESS OR USE, THE SOFTWARE.
Definitions. For purposes of these Terms, the following terms have the following meanings:
“Authorized Users” means individual persons identified to use the Software pursuant to the
license granted under these Terms, the quantity and type of user will be set forth on the Invoice, or Licensor
equivalent Documentation.
“Documentation’ means user manuals, technical materials, and any other materials provided by
Licensor, in printed, electronic, or other form, that describe the installation, operation, use, or technical
specifications of the Software. All Documentation is subject to change from time to time, with or without
notice.
“Go-Live” means the activation of Software by Licensor for production use by Licensee at
designated Installation Site.
“Intellectual Property Rights” means an and all registered and unregistered rights granted,
applied for, or otherwise now or hereafter in existence under or related to any patent, copyright trademark,
trade secret, database protection, or other intellectual property rights laws, and all similar or equivalent
rights or forms of protection, in any part of the world.
“Installation Site” means the designated and defined location(s) where the Software will be
installed by Licensor as set forth in separate documentation, and as may be mutually updated from time to
time by Licensor and Licensee.
“Invoice” means the invoice sent to Licensee documenting the Software, License and Support
Fees, of which these Terms are incorporate herein by reference.
“License and Support Fees” means the fees, including all taxes thereon, paid or required to be
paid by Licensee for the license and ongoing support as provided for under these Terms.
“Person” means an individual, corporation, partnership, joint venture, limited liability company,
governmental authority, unincorporated organization, trust, association, or other entity.
“Software” means the software programs for which Licensee is purchasing a subscription or
license, as expressly set forth on the Invoice.
“Third-Party” means any Person other than Licensor or Licensee.
License Grant. Subject to your strict compliance with these Terms, Licensor hereby grants you a non-
exclusive, non-transferable, non- sublicensable, limited license to use the Software solely in accordance
with the Documentation, as installed on the equipment provided by Licensee and for Licensee's internal
business purposes. The foregoing license will terminate immediately on the earlier to occur of:
a)
the expiration or earlier termination of the related software license agreement between Licensor and
Licensee, if any; or
b)
your ceasing to be authorized by Licensor to use the Software.
Third-Party Materials. The Software may include software, content, data, or other materials, including
related documentation, that are owned by Persons other than Licensor and that are provided to Licensee
on third-party terms and conditions that are in addition to and/or different from those contained herein
(“Third-Party Terms”). Licensee is bound and shall comply with all Third-Party Terms and agrees to any
pass-through terms as set by Third-Party Terms. Any breach by Licensee or any of its Authorized Users of
any Third-Party Terms is also a breach of these Terms.
SERIAL 230056-RFP
Responsibility for Use of Software. Licensee is responsible and liable for all uses of the Software and
Documentation through access thereto provided by Licensee, directly or indirectly to its Authorized Users
at designated Installation Sites. Specifically, and without limiting the generality of the foregoing, Licensee
is responsible and liable for all actions and failures to take required actions with respect to the Software
and Documentation by its Authorized Users or by any other Person to whom Licensee or an Authorized
User may provide access to or use of the Software and/or Documentation, whether such access or use is
permitted by or in violation of these Terms.
Use Restrictions. You shall not, directly, or indirectly:
a)
copy the Software or Documentation, in whole or in part;
b)
modify, translate, adapt, or otherwise create derivative works or improvements, whether or not
patentable, of the Software or any part thereof;
c)
combine the Software or any part thereof with, or incorporate the Software or any part thereof in, any
other programs;
d)
reverse engineer, disassemble, decompile, decode, or otherwise attempt to derive or gain access to
the source code of the Software or any part thereof;
e)
remove, delete, alter, or obscure any trademarks or any copyright, trademark, patent, or other
intellectual property or proprietary rights notices included on or in the Software or Documentation, including
any copy thereof;
f)
rent, lease, lend, sell, sublicense, assign, distribute, publish, transfer, or otherwise provide any access
to or use of the Software or any features or functionality of the Software, for any reason, to any other person
or entity, including any subcontractor, independent contractor, affiliate, or service provider of Licensee,
whether or not over a network and whether or not on a hosted basis, including in connection with the internet,
web hosting, wide area network (WAN), virtual private network (VPN), virtualization, time-sharing, service
bureau, software as a service, cloud, or other technology or service;
g)
use the Software or Documentation in, or in association with, the design, construction, maintenance,
or operation of any hazardous environments or systems, including but not limited to safety- critical
applications such as medical or life-support systems, vehicle operation applications, or any police, fire, or
other safety response systems; and
h)
use the Software or Documentation in violation of any law, regulation, or rule;
i)
or use the Software or Documentation for purposes of competitive analysis of the Software, the
development of a competing software product or service, or any other purpose that is to Licensor’s
commercial disadvantage.
Compliance Measures. The Software may contain technological copy protection or other security
features designed to prevent unauthorized use of the Software, including features to protect against use
of the Software outside the acceptable use of these Terms. You shall not, and shall not attempt to, remove,
disable, circumvent, or otherwise create or implement any workaround to, any such copy protection or
security features.
Maintenance and Support. Maintenance and Support is a required service component for production
access to Software (the “Maintenance and Support”). Licensor shall provide Licensee with support
services for Software purchased, provided that Licensee purchases and keeps current support payments
for any and all purchased Software. Licensor will make available to Licensee, a scope of support document
(the “Scope of Support”) which shall detail what is covered and not covered under support; which is
incorporated herein by reference, which may be amended by Licensor from time to time.
Collection and Use of Information.
a)
Licensor may, directly or indirectly through the services of others, collect and store information
regarding use of the Software and about equipment on which the Software is installed or through which it
otherwise is accessed and used, by means of (i) providing maintenance and support services and (ii)
security measures included in the Software as described in Section 3.
b)
You agree that Licensor may use such information for any purpose related to any use of the Software
by you, including but not limited to: (i) improving the performance of the Software or developing updates;
and verifying compliance with the Terms and enforcing Licensor's rights, including all intellectual property
SERIAL 230056-RFP
rights in and to the Software.
Payment. All License and Support Fees are payable in advance in the manner set forth on the Invoice and
are non-refundable, except as may be expressly set forth herein. Any renewals hereunder shall not be
effective until the fees for such renewal have been paid in full. Maintenance and Support fees are due and
payable upon Go-Live of the Software at the applicable Installation Site of Licensee.
Term and Termination.
a)
The term of these Terms as applied to you shall be as follows:
If you purchased a subscription to the Software, the term of these Terms shall commence upon access to
the Software and continue for twelve (12) months thereafter and shall automatically renew, unless a multi-
year, or other, agreement is otherwise agreed upon in an Invoice or corresponding Purchase Order. If you
purchased a license to the Software, the term of these Terms shall commence upon delivery of the Software
and remain in effect until Software is no longer in use by Licensee or until terminated as defined herein
(collectively, the “Term").
b)
Maintenance and Support services for Software shall start upon Go-Live of the Software and shall
continue for the one-year period following delivery. Thereafter, it shall automatically renew, at the then-
current and then-applicable annual maintenance fee, for subsequent one-year periods.
c)
Licensor may terminate these Terms, effective upon written notice to Licensee, if Licensee breaches
these Terms and such breach: (i) is incapable of cure; or (ii) being capable of cure, remains uncured for
thirty (30) days after Licensor provides written notice thereof.
d)
Upon expiration or earlier termination of these Terms, the license granted hereunder shall also
terminate, and Licensee shall cease using and destroy all copies of the Software and Documentation. No
expiration or termination shall affect Licensee’s obligation to pay all License and Support Fees that may
have become due before such expiration or termination, or entitle Licensee to any refund, in each case,
except as may be otherwise set forth herein.
Intellectual Property Rights. You acknowledge that the Software is provided under license, and not sold,
to you. You do not acquire any ownership interest in the Software under these Terms, or any other rights
to the Software other than to use the Software in accordance with the license granted under these Terms,
subject to all terms, conditions, and restrictions. Licensor and its licensors and service providers reserve(s)
and shall retain its/their entire right, title, and interest in and to the Software and all intellectual property
rights arising out of or relating to the Software, subject to the license expressly granted to the Licensee
under these Terms. You shall use commercially reasonable efforts to safeguard all Software (including all
copies thereof) from infringement, misappropriation, theft, misuse, or unauthorized access.
Limited Warranties, Exclusive Remedy, and Disclaimer/Warranty Disclaimer.
a)
Solely with respect to Software for which Licensor receives payment in full, Licensor warrants that,
for a period of thirty (30) days following the Go-Live date of Software, the Software when properly installed
and operated in accordance with the Documentation, will materially conform in accordance therewith (the
“Limited Warranty”).
b)
The warranties set forth herein will not apply and will become null and void if Licensee breaches
any material provision of these Terms, including but not limited to, those terms under “Use Restrictions”.
c)
EXCEPT FOR THE LIMITED WARRANTY SET FORTH HEREIN, THE SOFTWARE AND
DOCUMENTATION ARE PROVIDED TO LICENSEE “AS IS” AND WITH ALL FAULTS AND DEFECTS
WITHOUT WARRANTY OF ANY KIND. TO THE MAXIMUM EXTENT PERMITTED UNDER
APPLICABLE LAW, LICENSOR, ON ITS OWN BEHALF AND ON BEHALF OF ITS AFFILIATES AND
ITS AND THEIR RESPECTIVE LICENSORS AND SERVICE PROVIDORS, EXPRESSLY DISCLAIMS
ALL WARRANTIES, WHETHER EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE, WITH
RESPECT TO THE SOFTWARE AND DOCUMENTATION, INCLUDING ALL IMPLIED WARRANTIES
OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TTLE, AND NON-
INFRINGEMENT, AND WARRANTIES THAT MAY ARISE OUT OF COURSE OF DEALING, COURSE
OF PERFORMANCE, USAGE, OR TRADE PRACTICE. WITHOUT LIMITATION TO THE FOREGOING,
LICENSOR PROVIDES NO WARRANTY OR UNDERTAKING, AND MAKES NO REPRESENTATION
OF ANYKIND THAT THE LICENSED SOFTWARE WILL MEET THE LICENSEE’S REQUIREMENTS,
ACHIEVE ANY INTENDED RESULTS, BE COMPATIBLE, OR WORK WITH ANY OTHER SOFTWARE,
APPLICATIONS, SYSTEMS, OR SERVICES, OPERATE WITHOUT INTERRUPTION, MEET ANY
SERIAL 230056-RFP
PERFORMANCE OR RELIABILITY STANDARDS OR BE ERROR FREE, OR THAT ANY ERRORS OR
DEFECTS CAN OR WILL BE CORRECTED. THE FOREGOING WARRANTIES DO NOT APPLY, AND
LICENSOR STRICTLY DISCLAIMS ALL WARRANTIES, WITH RESPECT TO ANY THIRD-PARTY
MATERIALS.
d)
If the Software, or any part of the Software, is, or in Licensor's opinion is likely to be, claimed to
infringe, misappropriate, approaching end of life, or otherwise violate any third-party intellectual property
right, or if Licensee's use of the Software is enjoined or threatened to be enjoined, Licensor may, at its
sole option, modify or replace the Software, in whole or in part, while providing equivalent features and
functionality, and such modified or replacement software will constitute Software under these Terms; or if,
none of those remedies is reasonably available to Licensor, terminate the Software, in its entirety or with
respect to the affected part or feature of the Software, effective immediately on written notice to Licensee.
Disclaimer of Liability. IN NO EVENT WILL LICENSOR OR ITS AFFILIATES, OR ANY OF ITS OR
THEIR RESPECTIVE LICENSORS OR SERVICE PROVIDERS, BE LIABLE TO YOU FOR ANY USE,
INTERRUPTION, DELAY, OR INABILITY TO USE THE SOFTWARE. YOU ARE PROVIDED THE
SOFTWARE PURSUANT TO THESE TERMS, SOLELY FOR THE BENEFIT OF LICENSEE AND AT
LICENSEE'S DISCRETION. YOU ACKNOWLEDGE THAT YOU HAVE NO RIGHTS UNDER THAT
AGREEMENT INCLUDING ANY RIGHTS TO ENFORCE ANY OF ITS TERMS. ANY OBLIGATION OR
LIABILITY OF LICENSOR OR ITS AFFILIATES, OR ANY OF ITS OR THEIR LICENSORS OR SERVICE
PROVIDERS, MAY HAVE WITH RESPECT TO YOUR USE OR INABILITY TO USE THE SOFTWARE
SHALL BE SOLELY TO LICENSEE PURSUANT TO THAT AGREEMENT AND SUBJECT TO ALL
LIMITATIONS OF LIABILITY SET FORTH THEREIN.
Miscellaneous.
a)
Software will be provided in accordance with a Statement of Work (SOW) for each designated
Installation Site as mutually agreed upon in writing between the parties. Software is based upon
information furnished to Licensor by Licensee. Licensee is responsible for modifications, if any, to the
configuration due to inaccuracies or incompleteness of the information furnished to Licensor by Licensee,
changes Licensee’s needs or requirements, or for other reasons attributable to Licensee.
b)
Licensor will not be responsible or liable to Licensee, or deemed in default or breach hereunder by
reason of any failure or delay in the performance of its obligations hereunder where such failure or delay
is due to strikes, labor disputes, civil disturbances, riot, rebellion, invasion, epidemic, hostilities, war,
terrorist attack, embargo, natural disaster, acts of God, flood, fire, sabotage, fluctuations or non-availability
of electrical power, heat, light, air conditioning, or Licensee’s equipment, loss and destruction of property,
or any other circumstances or causes beyond Licensor's reasonable control.
c)
Purchasing Agent acknowledges and agrees that Licensor has the right, in our sole discretion, to
modify these Terms from time to time, and that modified terms become effective on posting. You will be
notified of modifications through notifications or posts where applicable. You are responsible for reviewing
and becoming familiar with any such modifications. Your continued use of the Software after the effective
date of the modifications will be deemed acceptance of the modified terms.
d)
Licensee acknowledges and agrees that all clinical and medical treatment, diagnostic decisions and
billing decisions are the responsibility of Authorized Users and its professional healthcare providers,
including but not limited to general clinical staff, nurses, nurse practitioners, physicians (including
psychiatrists). Software does not make clinical or other decisions (such as narrative conditions, coded
diagnosis, submission of claims) and is not a substitute for competent, properly trained and knowledgeable
staff who bring professional judgment to the information presented by the Software. Although Licensor and
its third-party vendors have used reasonable care in obtaining information from sources believed to be
reliable, Licensee acknowledges that it is Licensee’s obligation to be informed about any and all medical
best practices, regulations, clinical information, and guidelines that may not be reflected in the Software.
The absence of an alert or warning for without limitation, a given course of treatment, drug or drug
combination should not be construed to indicate that the treatment, drug or drug combination is safe,
appropriate or effective for any given patient.
e)
Licensee shall not assign or otherwise transfer any of its rights, or delegate or otherwise transfer
any of its obligations or performance, under these Terms, in each case whether voluntarily, involuntarily,
by operation of law, or otherwise, without Licensor's prior written consent, which consent Licensor may
give or withhold in its sole discretion.
f)
Licensee grants Licensor the right to review and use de-identifiable prescription data processed
SERIAL 230056-RFP
through Software for purposes of research, development, analytics, third-party claims processing, and
similar purposes, subject to terms and conditions of use where applicable.
g)
These Terms are for the sole benefit of the parties hereto and their respective successors and
permitted assigns and nothing herein, express or implied, is intended to or shall confer on another Person
any legal or equitable right, benefit, or remedy of any nature whatsoever under or by reason of these
Terms.
h)
The relationship between the parties is that of independent contractors. Nothing contained in these
Terms shall be construed as creating any agency, partnership, joint venture or other form of joint
enterprise, employment or fiduciary relationship between the parties, and neither party shall have authority
to contract for or bind the other party in any manner whatsoever.
i)
These Terms are governed by and construed in accordance with the internal laws of the State of
New Jersey without giving effect to any choice or conflict of law provision or rule that would require or
permit the application of the laws of any jurisdiction other than those of the State of New Jersey. Any legal
suit, action, or proceeding arising out of or related to these Terms or the licenses granted hereunder will
be instituted exclusively in the federal courts of the United States or the courts of the State of New Jersey,
and each Party irrevocably submits to the exclusive jurisdiction of such courts in any such suit, action, or
proceeding.
j)
If any of the terms contained herein are invalid, illegal, or unenforceable in any jurisdiction, such
invalidity, illegality, or unenforceability shall not affect any other term or provision of these Terms or
invalidate or render unenforceable such term or provision in any other jurisdiction.
Section
Requirement Description
Explanation
2.1
COMPLIANCE: The proposed EHR system shall meet the following compliance requirements as listed in the section below.
Compliance
Non-Compliance
Provide detailed information in narrative format to support the compliance rating and identify any corresponding attachments.
2.1.1
Health Level Seven (HL7) standards: https://www.hl7.org/implement/standards
Mandatory
X
FusionEHR offers powerful interoperability and imports and exports data through its robust interface engine. HL7-compliant inbound and
outbound data exchange interfaces are built directly into FusionEHR. Numerous correctional settings utilize FusionEHR to exchange data in real
time through direct database connection using secure VPN tunnels, through FTP/SFTP as well as numerous other delivery methods. FusionEHR
was also one of the first adopters of the HL7 FHIR API.
2.1.2
Health Insurance Portability and Accountability Act (HIPAA) rules and regulatory standards: https://www.hhs.gov/hipaa/for-professionals/index.html
Mandatory
X
Fusion stores all data in SSAE-18 audited data centers that are FedRAMP, FIPS, NIST, CJIS, ISO, SOC-2, and HIPAA compliant.
2.1.3
Health Information Technology for Economic and Clinical Health (HITECH) Act Enforcement Interim Final Rule: https://www.hhs.gov/hipaa/for-professionals/special-topics/hitech-
act-enforcement-interim-final-rule/index.html
Mandatory
X
As a CCHIT Certified solution, FusionEHR ensures compliance with applicable auditing standards of the Health Information Technology for
Economic and Clinical Health Act (HITECH).
2.1.4
Health IT Certification Criteria (2015 Edition) Final Rule: https://www.healthit.gov/topic/certification-ehrs/2015-edition
Mandatory
X
Fusion is 2015 certified, which can be found on the Certified Health IT Product List (CHPL) which attests our commitment to healthcare IT
excellence.
2.1.5
Certified Health IT Product List (CHPL): https://www.healthit.gov/topic/certified-health-it-products-list-chpl
Mandatory
X
Fusion is 2015 certified, which can be found on the Certified Health IT Product List (CHPL) which attests our commitment to healthcare IT
excellence.
2.1.6
National Commission on Correctional Healthcare (NCCHC) standards: https://www.ncchc.org/standards/
Mandatory
X
As a correctional specific EHR, Fusion meets correctional health industry standards such as NCCHC and ACA standards and guidelines.
2.1.7
Criminal Justice Information System (CJIS) security policy: https://www.fbi.gov/services/cjis
Mandatory
X
Fusion stores all data in SSAE-18 audited data centers that are FedRAMP, FIPS, NIST, CJIS, ISO, SOC-2, and HIPAA compliant.
2.1.8
Arizona Criminal Justice Information System (ACJIS) guidelines: https://www.azdps.gov/organization/tsd/cjs
Mandatory
X
Fusion has reviewed ACJIS guidleines and is confident that we are compliant with the requirements set forth.
2.1.9
Centers for Medicare and Medicaid (CMS's) e-prescribing criteria: https://www.cms.gov/Medicare/E-Health/Eprescribing/Adopted-Standard-and-Transactions
Preferred
X
In Fusion's newest release of our CPOE functionaility, through our certification by Drummond we will meet all CMS and DEA standards for
ePrescibing and EPCS. It is expected to be live in 2024.
2.1.10
Drug Enforcement Agency (DEA) Interim Final Rule for controlled substances certification: https://www.deadiversion.usdoj.gov/fed_regs/rules/2020/fr0421_3.htm
Preferred
X
In Fusion's newest release of our CPOE functionaility, through our certification by Drummond we will meet all CMS and DEA standards for
ePrescibing and EPCS. It is expected to be live in 2024.
2.1.11
Electronic Prescribing for Controlled Substances (EPCS) Certified Solution: https://www.deadiversion.usdoj.gov/ecomm/e_rx/
Preferred
X
In Fusion's newest release of our CPOE functionaility, through our certification by Drummond we will meet all CMS and DEA standards for
ePrescibing and EPCS. It is expected to be live in 2024.
System Requirements
Vendor Responses
Rate the proposed EHR system by placing
an “X” in the appropriate category:
Mandator
y -OR -
Preferred
Exhibit G – Fusion Functional Response Matrix
SERIAL 230056-RFP
Section
2.4
PLATFORM
STAKEHOLDER
DESCRIPTION
STANDARD(S)
TYPE
FREQUENCY
Already Exists
Needs Developed
2.4.1
PreBooking
Maricopa County Sheriff’s Office (MCSO)
PreBooking Information
Extensible Markup Language (XML)
Bi-directional
Real Time
Mandatory
X
Inmate demographics such as first and last name, date of birth, gender, and an identifying
number will be pulled from our interface to create the initial health record. It is our intent to
maintain an ongoing integration with the JMS to serve as the basis of inmate chart creation
when an individual completes CHS intake. Data sharing between the systems will allow
FusionEHR to automatically create an inmate chart and populate critical data fields of the
inmate banner bar. Although Fusion does not have an existing interface with MCSO's
PreBooking system, gathering patient demographic information is standard for all of Fusion's
clients.
During the negotions, Fusion would request the expected data points that will need to be
shared between the systems to ensure each data point can be met.
18,000.00
$
2.4.2
Sheriff’s Inmate Electronic Data (SHIELD) Maricopa County Sheriff’s Office (MCSO)
Offender Management
Extensible Markup Language (XML)
Bi-directional
Real Time and
Daily Batch
Mandatory
X
In addition to receiving inmate demographics from MCSO's PreBooking, Fusion will integrate
with MCSO SHIELD to maintain additional Inmate demographics, inmate location and
movement. sAlthough Fusion does not have an existing interface with MCSO's PreBooking
system, gathering patient demographic information is standard for all of Fusion's clients.
During the negotions, Fusion would request the expected data points that will need to be
shared between the systems to ensure each data point can be met.
46,500.00
$
2.4.3
Diamond
Diamond Pharmacy Services
Pharmacy
Health Level Seven (HL7)
Bi-directional
Real Time
Mandatory
X
With Diamond Pharmacy, we guarantee full integration between FusionEHR and the
CIPS pharmacy management software, which is utilized by Diamond. CIPS is a Fusion
product that can easily support the high volume of pharmaceutical care that CHS
provides, and we’re confident that it’s the most cost- and time-efficient pharmacy
integration solution available. CHS can maintain their current pharmacy operational
workflows while enhancing them with FusionEHR. Data sharing between our
applications will improve efficiency and the accuracy of your clinical services.
Formularies will be imported from CIPS, and it will allow our eMAR to enable barcode
verification functionalities amongst others. The integration of FusionEHR with Fusion’s
CIPS that is already in use by Diamond will create a true closed-loop medication
management process.
10,000.00
$
2.4.4
CareEvolve
Garcia Labs
Laboratory
Health Level Seven (HL7)
Bi-directional
Real Time
Mandatory
X
FusionEHR will be integrated bi-directional with Garcia Laboratory in a complete and cost-
effective manner while increasing the ease of use for your clinicians. CHS end-users will be
able to electronically send lab orders, print paper requisitions and specimen labels and map
LOINC codes to OBS terms. FusionEHR provides laboratory results directly in the patients
chart. Users can be notified of messages requiring responses and tasks they need to
complete, all through secure connections and HIPAA-complaint data exchanges. Fusion
actively works with Garcia and currently has an active interface with Garcia at multiple
facilities.
9,000.00
$
2.4.5
TD Synergy
Public Health
Laboratory
Health Level Seven (HL7)
Bi-directional
Real Time
Mandatory
X
FusionEHR will be integrated bi-directional with the Public Health's TD Synergy Laboratory in
the same fashion as we will integrate with Garcia Labs. Fusion does not currently work with
the Public Healths Laboratory but is confidfent that we will be able to have a bi-directional
and real time interface as we do with multiple laboratory vendors.
9,000.00
$
2.4.6
Viztek Opal-RAD
Opal Picture Archiving and Communication Systems
(PACS)
Radiology
Health Level Seven (HL7); Digital
Imaging and Communications in
Medicine (DICOM)
Bi-directional
Real Time
Mandatory
X
FusionEHR’s radiology interfacing capabilities will include data sharing of all results, including
interpretation reports, as text or separate documents. Images are available as files easily
accessed within the inmate record or can be available as hyperlinks in the file to a remote
image location. FusionEHR features dedicated radiology orders and order sets that can easily
be searched and navigated so the user can be sure they are picking the right order.
9,000.00
$
2.4.7
TridentCare
Rely Radiology
Radiology
Health Level Seven (HL7)
Inbound
Real Time
Mandatory
X
FusionEHR’s radiology interfacing capabilities will include data sharing of all results, including
interpretation reports, as text or separate documents. Images are available as files easily
accessed within the inmate record or can be available as hyperlinks in the file to a remote
image location. FusionEHR features dedicated radiology orders and order sets that can easily
be searched and navigated so the user can be sure they are picking the right order.
9,000.00
$
2.4.8
Arizona Health Care Cost Containment
System (AHCCCS)
Arizona Health Care Cost Containment System
(AHCCCS)
Health Plans
Extensible Markup Language (XML)
Inbound
Real Time
Mandatory
X
To date, Fusion has not integrated with a Health Care Cost Containment System. With our
experience in receiving information via XML format, Fusion will successfully integrate with
AHCCCS.
During the negotions, Fusion would request the expected data points that will need to be
shared between the systems to ensure each data point can be met.
22,500.00
$
Provide an estimate of the
associated cost for the
development of each
interface.
Vendor Responses
Mandatory -
OR - Preferred
Describe the capability for interfacing narrative and/or diagrammatic description format
and identify any corresponding attachments.
Requirement Description
System Requirements
Rate the proposed EHR system by placing an
“X” in the appropriate category:
The proposed EHR system shall seamlessly interface with numerous platforms associated with internal and external stakeholders as listed in EXHIBIT 5: CORRECTIONAL HEALTH SERVICES’ INTERFACES.
2.4.9
Mercy Care
Mercy Maricopa
Regional Behavioral Health Authorities
(RBHA)
Health Level Seven (HL7)
Bi-directional
Real Time and
Daily Batch
Mandatory
X
Continuity of care will be assured through HIE integration and allow CHS to electronically
send a patients health records wherever they go upon discharge. Your staff will be able to
import and export Continuity of Care Document (CCD) transcripts, eliminating the need for
offsite providers to scan and send off-site paperwork to the CHS. Fusion’s CCD Import-Export
Package is a preconfigured interface that automates the export of CCD data from EHR and
transmits it securely to the HIE. It also includes a preconfigured interface that allows CCD
documents to be received by the EHR. The CCD Import-Export Package includes logic to
standardize the CCD output from the EHR and ensure it is complete and properly formatted
before submission to the HIE.
In addition, our interface with the HIE will allow problems, medications, and allergies that
are part of any CCD document to be reconciled as discrete data into the detainee’s chart. In
addition to being able to reconcile documents imported to EHR, this package enables other
reconciliation workflows, such as the ability to query an HIE or other EHR system on-demand
for a CCD document to be reconciled.
32,000.00
$
2.4.10
Mirth Connect (Clinical Data Repository)
Health Current, a Contexture Company
Health Information Exchange (HIE)
Continuity of Care Document (CCD)
Outbound
Real Time
Mandatory
X
Continuity of care will be assured through HIE integration and allow CHS to electronically
send a patients health records wherever they go upon discharge. Your staff will be able to
import and export Continuity of Care Document (CCD) transcripts, eliminating the need for
offsite providers to scan and send off-site paperwork to the CHS. Fusion’s CCD Import-Export
Package is a preconfigured interface that automates the export of CCD data from EHR and
transmits it securely to the HIE. It also includes a preconfigured interface that allows CCD
documents to be received by the EHR. The CCD Import-Export Package includes logic to
standardize the CCD output from the EHR and ensure it is complete and properly formatted
before submission to the HIE.
In addition, our interface with the HIE will allow problems, medications, and allergies that
are part of any CCD document to be reconciled as discrete data into the detainee’s chart. In
addition to being able to reconcile documents imported to EHR, this package enables other
reconciliation workflows, such as the ability to query an HIE or other EHR system on-demand
for a CCD document to be reconciled.
The price for the Mrth Connect interface located in item 2.4.14 includes both inbound and
outbound integration. If the County elects to have the bi-directional interface the Price in 14L
will be irrelevant.
35,000.00
$
2.4.11
Arizona Department of Health Services
(ADHS)
Arizona State Immunization Information System
(ASIIS)
Immunizations
Health Level Seven (HL7)
Bi-directional
Real Time
Mandatory
X
Fusion has developed interfaces between FusionEHR and state immunization registries for
numerous clients and we are prepared to do the same for CHS through a bi-directional
interface. The COVID-19 pandemic has acutely affected the correctional world, and we
recognize the importance of collecting and sharing immunization records across the state.
30,000.00
$
2.4.12
Global Tel Link (GTL)/ViaPath
Global Tel Link (GTL)/ViaPath/Maricopa County
Sherriff’s Office (MCSO)
Health Needs Requests/Grievances
Extensible Markup Language (XML)
Inbound
Real Time
Preferred
X
FusionEHR integrates with tablet devices and kiosks to allow individuals in custody access to
their clinical information. We understand that CHS partners with ViaPath for the provision of
tablets and kiosks: As a partner of ViaPath, we have already held discussions with their
leadership team surrounding CHS’ request for electronic sick call request functionality and
are confident that we can deliver this feature. Fusion will work with CHS in good faith to
determine functionality, project scoping, and additional costs as needed.
20,000.00
$
2.4.13
Arizona Department of Health Services
(ADHS)
ASU Bio/Create Survivors, Reduce Victims (CSRV)
Consulting/Point-N-Click Solutions
COVID-19 Test Results
Health Level Seven (HL7); Comma-
Separated Values (CSV)
Bi-directional
Daily Batch
Preferred
X
Similiarly to the state immunization registry, Fusion will provide a bi-directional interface for
COVID-19 Results. The COVID-19 pandemic has acutely affected the correctional world, and
we recognize the importance of collecting and sharing immunization records across the
state.
20,000.00
$
Describe the capability for full participation via a bi-directional interface with the regional
Health Information Exchange (HIE) by having the ability to separate the 42 Code of Federal
Regulations (CFR) Part 2 data from other data (e.g., physical health, general behavioral
health data):
2.4.14
Mirth Connect (Clinical Data Repository)
Health Current, a Contexture Company
Health Information Exchange (HIE)
Continuity of Care Document (CCD)
Bi-directional
Real Time
Preferred
X
Continuity of care will be assured through HIE integration and allow CHS to electronically
send a patients health records wherever they go upon discharge. Your staff will be able to
import and export Continuity of Care Document (CCD) transcripts, eliminating the need for
offsite providers to scan and send off-site paperwork to the CHS. Fusion’s CCD Import-Export
Package is a preconfigured interface that automates the export of CCD data from EHR and
transmits it securely to the HIE. It also includes a preconfigured interface that allows CCD
documents to be received by the EHR. The CCD Import-Export Package includes logic to
standardize the CCD output from the EHR and ensure it is complete and properly formatted
before submission to the HIE.
In addition, our interface with the HIE will allow problems, medications, and allergies that
are part of any CCD document to be reconciled as discrete data into the detainee’s chart. In
addition to being able to reconcile documents imported to EHR, this package enables other
reconciliation workflows, such as the ability to query an HIE or other EHR system on-demand
for a CCD document to be reconciled.
45,000.00
$
Section
Requirement Description
2.3
SYSTEM REQUIREMENTS: The proposed EHR system shall include the functionalities and supporting software modules as listed in the section below.
Out of the Box
With
Configuration:
setting values
and options in
existing tables
With
Programming:
modifying the
code
Future
Release
With Third
Party Vendor
Cannot Meet
Provide detailed information in narrative format to
support the rating (e.g. what functionality is available out
of the box; what configuration is needed to meet the
requirement; what programming is needed to meet the
requirement; or when and what functionality will be
released to meet the requirement.)
Provide detailed information in
narrative and/or diagrammatic
description format and identify any
corresponding attachments.
2.3.1
2.3.1.1
The system must capture specific demographic information as part of the EMPI.
Mandatory
X
FusionEHR will capture specific demographic data from
MCSO's SHIELD JMS solution. This will include information
such as EMPI unique identifiers, and patient demographic
information.
2.3.1.2
The system must provide the matching logic and method for the EMPI.
Mandatory
X
To ensure that a patients EMPI is matched, FusionEHR
leverages the demographic integration from MCSO's
SHIELD. Specifically, we utilize certain key identifiers such
as Name, DOB, ExternalID (from SHIELD), and more. To
correctly match patients with their charts from previous
stays, Fusion utilizes an algorithm requiring certain
specific fields to match.
2.3.1.3
The system must provide a reconciliation process for the EMPI, i.e., a detailed explanation of the records merging process used when a duplicate
record is identified.
Mandatory
X
The following steps must be followed to merge two
duplicate charts within FusionEHR. Only certain specified
users will have the ability to merge records.
1. Find and open the patient chart you wish to merge with
another chart.
2. Select More > Merge Patient Chart from the Chart
group on the Home Tab.
3. On the Merge Patient window, in the Destination
Patient field, select a patient or click the binoculars to
search for the patient chart you want to merge the source
chart into and click OK.
4. Confirm that the Source Chart is correct. It will become
obsolete and the information moved to the Destination
Chart.
5. Confirm that the Destination chart is correct.
6. Click Merge and then OK to confirm.
2.3.2
2.3.2.1
The preferred system uses biometric technology for patient identification.
Preferred
X
Biometric technology has been used with FusionEHR and
the system can be configured to leverage this
functionality.
2.3.2.2
The preferred system is compatible with different types of biometric/handheld devices.
Preferred
X
More information is needed to ensure compatibility with
FusionEHR. Providing the specific devices that will need to
be campatible will allow Fusion to test and ensure the
compatibility.
2.3.2.3
The preferred system automatically receives data from biometric/handheld devices.
Preferred
X
More information is needed to ensure compatibility with
FusionEHR. We will need to determine what data will
need to be transmitted to ensure that we can meet this
requirement.
2.3.3
2.3.3.1
The system must provide an initial screening process, including a questionnaire that is customizable by the department.
Mandatory
X
Fusion possesses a clincial content repository which
consists of clinical content that adheres to NCCHC
standards. Some examples consists of the following:
1) Receiving Screening J-E-02
2) Transfer Screening J-E-03
3) Initial Heatlh Assessment J-E-04
4)Mental Health Screening and Evaluation J-E-05
5) Discharge Planning J-E-10
6) Nursing Assessment Protocols and Procedures
7) Oral Care J-E-06
The forms can be customized or be built to the client's
specifications which will require some system
configuration.
Enterprise Master Patient Index ("EMPI") also known as a “unique identifier,” to facilitate continuity of care across bookings for patients who return to custody:
Initial Screening:
Compatible Biometric Technology:
Explanations
Specify
the
module:
Vendor Responses
System Requirements
Mandatory -
OR - Preferred
Rate the proposed EHR system by placing an “X” in the appropriate category:
2.3.3.2
The system must provide comprehensive and designated fields for all collected vital signs.
Mandatory
X
The vital signs form contains the following fields:
1) Patient refused Vital signs checkbox
2) Weight and Height fields
3) Automatic BMI Calculator
4) Blood Pressure position that allows for documentation
of systolic and diastolic blood pressures in the standing,
sitting and standing positions
5) Temperature in Fahrenheit and Temperature site
6) Pulse Rate and Pulse rhythm if known
7) Finger stick (blood sugar) and finger stick (INR)
8) Respirations and Respiration type
9) Peak Flow and Expected Peak Flow
10) Pulse OX%
11) Room Air
12) Oxygen Liters per minute
13) Fetal heart tones
14) Skin turgor
*** Many fields are hidden from the end user view unless
specific programmed conditions are met***
2.3.3.3
The system must provide the ability to capture, review, and manage clinical history, risk/social factors, substance use, etcetera.
Mandatory
X
FusionEHR allows the capture of clinical data via an array
of input options within form components. All clinical
content forms consists of Radio buttons, Edit fields (single
line free text field, Multiline edit fields (Multiple line free
text), Checkboxes, Listboxes, Dropdowns and data display
fields. These fields allow for the enduser to input clincial
hisotry, social factors, document substance abuse, Suicide
risk factors, Prea, Discharge planning and so forth.
2.3.3.4
The system must provide special attention queues incorporated within the intake/booking process.
Mandatory
X
The form comopnents found in the receiving screening
(Intake/booking process) can be configured to place
automatic orders and or send flags that mark the patient's
chart to place them in specific Queues. These items are
tailored and discussed in detail during the implementation
process to ensure that the workflow functions as intended
for the client
2.3.4
2.3.4.1
The system must provide an Admission, Discharge, and Transfer (ADT) notification process.
Mandatory
X
The Admission, Discharge, and Transfer (ADT) form
components have built in Flags that can be sent to a
specific user or users, make a pop up alert once the
patient's chart is opened, or have a unique order be
placed. This is also discussed in detail during the
implementation process to determine what is best for the
client.
2.3.4.2
The system must provide customized patient tracking and reminder capabilities.
Mandatory
X
Patient tracking and reminder capabilities are done with
the use of SSRS reports, alerts and flags, and orders. The
specific configuration requested will dictate what would
be the best option for the client.
2.3.4.3
The system must provide customized categorization of patients via the use of flags as determined by the department.
Mandatory
X
Patients are best categorized using orders in FusionEHR as
opposed to flags. However, flags can be used but is not
preferred.
2.3.4.4
The system must log automated and user-defined alerts.
Mandatory
X
Flags and care alerts can be converted into documents
within a patient's chart.
2.3.4.5
The system must track responses to alerts.
Mandatory
X
Responses to alerts are tracked. An alert specifically a care
alert. Care alerts are always tied to a patient chart. Care
Alerts and flags can be managed from the users desktop
or from the patient's chart. A flag or alert can be
converted into a chart note by selecting the convert
button.
2.3.4.6
The system must provide discharge/transfer/release summaries for continuity of care.
Mandatory
X
Discharge, Transfer or release of summaries for continuity
of care are is accessed and can be printed using the
transition of care document. The transition of care
document provides a consolidated clinical document
architecture where compliant documents are viewable in
an easy to read and cofigured format withint he patient
chart. With the transition of care document, there exist
the functionality of choosing the section or section that
are relevant for your facility.
2.3.5
Patient Search:
Patient Management:
2.3.5.1
The system must provide extensive criteria to search for patients.
Mandatory
X
FusionEHR's find patient modules allows end users to
search for patient using the following filters:
1) Search by:
External ID, Name, Birthdae, Home phone, SSN, Patient ID,
MRN, External ID
2) Search Method:
Beginning with, Containing, Ending with
3) Search Population
4) Search Location:
Locations are specified and set up under the client's
guidance
*** The external ID, patient ID can be configured to use
the clients Jail ID. The search criterias used can also be
saved to your preference to save time the next the end
user needs to search for a patient. ***
2.3.5.2
The preferred system is capable of storing recent, user-defined, search criteria for frequent queries.
Preferred
X
FusionEHR's find patient module has a checkbox labeled
"Save settings as my preference" that stores the previous
values selected by the end user.
2.3.5.3
The preferred system is capable of creating customizable, user-defined patient rosters, including the ability to save and recall frequently used rosters.
Preferred
X
Patient Rosters can be sorted by patient last name, birth
date, contact method, responsible provider, problem
code, or medication generic name. This information is
obtained via a clinic management report that is accessed
by going to Chart reports module. Chart reports can be
printed and or previewed for ease of access.
2.3.5.4
The preferred system is capable of storing and linking historical information related to a specific diagnosis for a patient, e.g., if a patient has
Hypertension, filter the information in the health record to allow easy access to review the previous documentation and actions taken related to that
diagnosis.
Preferred
X
The Patient Roster mentioned above can be sorted by
problem code to get a list of patients with the defined
parameter.
The system also stores documents based on Document
type. Document types are programmed and is how the
system stores all documents to make it easier for end
users to find previous documentation on a pertinent item.
For example, if you want to see all chronic care documents
that have been completed by any user, they will be able to
select the document type from the document view to
filter all the documents tied to the designated document
type.
Examples of document types currently used by clients,
consists of Receiving Screening, Transfer summary,
Nursing Assesment and protocols, Provider Intake, MH
provider intake, Provider Chronic Care, Sick Call etc.
2.3.6
2.3.6.1
The system must provide the entry and tracking of sick call appointments for patients.
Mandatory
X
Sick calls are documented in the system via encounters
which are attached to a document type. Sick Call
appointments are created using an Order for sick call to
kick off and schedule the sick call workflow.
Fusion uses the Order manager app for scheduling orders/
appointments.
2.3.6.2
The system must track and maintain detailed information for both onsite and off-site referrals.
Mandatory
X
On site and Offsite referrals are documented using
Referral specific orders and the order manager web app.
2.3.7
2.3.7.1
The system must provide preloaded problem lists.
Mandatory
X
FusionEHR uses the International Classification of
Diseases, Tenth Revision, Clinical Modification for all
diagnoses. The ICD 10 codes are kept up to date on a
monthly basis. Every month there is knowledgebase
update that includes diagnoses and medication updates.
2.3.7.1
The system must provide modules for the management of patients with shared problems, diagnoses, and chronic diseases.
Mandatory
X
Fusion Order Manager, Patient Rosters and inquiries can
all be used to assist the management of patients with
shared diagnoses and problems. All of these features
come inherent with FusionEHR
2.3.8
2.3.8.1
The system must provide a comprehensive list of all order templates within the ordering module(s).
Mandatory
X
Fusion EHR contains the medication tool that allows
providers enter medications based off of a formulary or a
reference list. The Medication tool allows for the creation
of Medication custom lists that saves times for providers
where Instructions, route of administration, stop and end
date, dosage, quanity, refill are all prefilled to the
providers specifications. These can always be modified at
anytime.
Computerized Physician Order Entry (CPOE):
Problem Lists and Chronic Disease Management:
Scheduling Appointments and Electronic Referrals (E-Referrals):
2.3.8.2
The system must provide Electronic Prescribing (E-Prescribing), including order entry, medication lists, allergies, drug
interactions/reactions/contraindications, and refills.
Mandatory
X
FusionEHR is EPCS ready and will be configured based on
your agency and your State's requirements. Drug
interaction preferences come inherent with the system
and can be modified depending on the client's choosing.
The drug interaction preferences are configured by system
administrators under the guidance of the client. In order
to modify the drug interaction preferences. A system
administrator or analyst will need to go to Administration
module and select System>User and Resource
Management> Users> Preferences> User Preferences >
Patient Charts > Drug interactions.
Drug interaction preferences levels consists of the
following: Established, Probable, Suspected, possible,
Doubtful, and None
Contraindications indicates a condition which makes a
particular treatment or procedure inadvisable and can be
configured to a specific threshold. Contraindications check
medications, allergies or adverse reactions and the levels
that exist are Absolute, Potential, Use with Caution, and
None
2.3.8.3
The system must support diagnostic codes, e.g.: International Classification of Diseases (ICD), Current Procedural Terminology (CPT), Diagnostic and
Statistical Manual (DSM), etcetera.
Mandatory
X
FusionEHR uses ICD, DSM and CPT codes.
2.3.8.4
The system must support formularies, either as supplied by the department -OR - from Medicare/Medicaid and other managed care regulatory
agencies, e.g., Arizona Health Care Cost Containment System (AHCCCS).
Mandatory
X
FusionEHR uses formularies that are provided by the
client. More than one formulary can be used however,
only one formulary can be the default. In the medication
module, the prescribing provider will be able to search the
default formulary or select a specific formulary.
Fusion also has a Formulary Manager application that
allows users to modify and or add formularies.
2.3.9
2.3.9.1
The system must provide medication administration at point of care.
Mandatory
X
FusionEHR's eMAR application that allows for both online
and offline medication administration documentation. The
eMAR can also be used to provide bulk administrations to
multiple people by location and medication types as well
as allow the administration of medication to be
documented individually
2.3.9.2
The system must provide tracking and documentation of medication administration.
Mandatory
X
Fusion's eMAR records all administrations and refusals of
administration with a time stamp and user signature.
Reports can also be run based on the data avaialble in
Fusion's eMAR.
2.3.10
2.3.10.1
The system must provide a dental module.
Mandatory
X
FusionEHR comes with an odontogram and other dental
related clinicla content such as periodontal screening and
recording.
2.3.10.2
The system must provide a referral/off-site management module.
Mandatory
X
To manage referrals and offsite management, Fusion
leverages Orders along with the Fusion Order Manager
tool which allows users to to manage and schedule onsite
and offsite referrals
2.3.10.3 The system must provide a pharmacy module.
Mandatory
X
FusionEHR Integrates with CIPS (Correctiona Institution
Pharmacy Software) which is utilized by CHS' pharmacy
provider Diamond. As part of this project, Fusion will be
integrated with Pharmacy, Radiology and Laboratory and
more. Additionally, CIPS is a product owned by Fusion
which will allow the agency the most advanced EHR< >
pharmacy integration.
2.3.10.4 The system must provide a laboratory module.
Mandatory
X
Labs are ordered within the Orders module. All labs will be
added depending on what is on the client's compendium.
All orders are added to a specific Order Category name
and can later be placed into order sets and custom lists to
help providers identify and select the most commonly
ordered labs. Through the integration with CMS'
Laboratory Vendors outlined in Section 2.2 Interfaces, this
process will be fully automated from Lab Orders to Lab
Results Review.
2.3.10.5 The system must provide a radiology module.
Mandatory
X
Radiology tests are ordered within the Orders module. All
radiology orders available on the clients compendium will
be added to a specific order category name. The radiology
orders can then be placed into order sets and custom lists
to help providers idenfity and select the most commonly
ordered radiological tests. Through the integration with
CMS' Radiology Vendors outlined in Section 2.2 Interfaces,
this process will be fully automated from Rad Orders to
Rad Results Review.
Ancillary Services Management:
Electronic Medication Administration Record (EMAR):
2.3.10.6 The system must provide an obstetrics module.
Mandatory
X
Obstetrics and Gynecology content is accessed via
encounters that are tied to specific document types. The
providers will be able to document any screening
questions, SOAP notes, and plans where medications and
procedures specific to OB/GYN can be ordered or placed.
2.3.10.7 The preferred system offers additional multidisciplinary or specialty modules.
Preferred
X
Data captured within form components in encounters can
be used to push pertinant data to other encounters and
form components allowing different disciplines to view
pertinent data. These are configured and usually discusses
with the client to ensure that pertinent data is flowing to
the right encounters/documents for better clinical
decision making and documentation.
2.3.11
2.3.11.1 The system must support multiple clinical documentation categories e.g., order-related, incident, progress, emergent event, admission, ancillary
services, etcetera.
Mandatory
X
The system supports multiple documentation categories
by the user of encounters and document types. In
FusionEHR all documentation is done via an encounter.
Encounters are comprised of three core elements which
are Document types, Document Templates and form
components.
Form components are individual forms that are specific
and contain data entry fields such as Listboxes, Check
boxes, Edit fields, Multiline edit fields, Radio buttons,
flowsheet views and dropdowns.
Document template consists of grouping one or more
form components (data capturing elements) that are
organized based on the client's workflows.
Document Type is the data element that the system uses
to store and file the data. Document types are what is
seen in your document views so that you can see all
previous documents that were created for say a sick call,
chronic care visit, Nurse Receiving Screening, CIWA, PREA,
General Note, Medical progress note, MH progress note,
Dental provider note, Dental hygeinist note, emergency
event etc.
2.3.11.2
The system must provide various form templates, e.g., consent to treat, healthcare refusal, immunization, receiving screening, health assessment,
etcetera.
Mandatory
X
Fusion contains a form repository that spans all common
medical, mental health and dental disciplines.
For example the receiving screening workflow can be
comprised of a single form or multiple forms. The form
components that are available from our repository will be
analyzed and compared to the forms and workflows
provided by the client using a GAP Analysis. The form
components will be uploaded and shown to the client
during the implementation process.
Other items such as cosents are typically client specific
since they may have some legal language that needs to be
included and varies by state. FusionEHR contains an eSign
web application which allows endusers and patients to
electronically sign a consent and or refusal form.
2.3.11.3 The system must provide a robust clinical documentation module to capture multidisciplinary Subjective/Objective/Assessment/Plan/Education
(SOAPE) notes.
Mandatory
X
Clinical documentation for all disciplines is the same
where a new document is created via encounters which
consists of single or multiple form components. The data
entered within encounters can be used to push or pull
information from one encounter to another (one
discipline to another) to assist and streamline workflows.
2.3.11.4 The system must provide the ability to create, review, update, and amend objective and subjective health data regarding the patient’s current health
status.
Mandatory
X
FusionEHR contains an append feature that is viewable
when looking at documents. Signed documents cannot be
changed or modified. If an error was made then the
document will need to be "filed in error." In the event that
an update or a document needs to be updated, the
append button which can be accessed by left clicking on
the desired document or the append button readily
available from the document view tool bar allows the user
to do a full update or type in a general note. Appended
documents have a default document type of APPEND.
Visit ID and Summary are all inherited from the master
document and can be changed if needed.
2.3.11.5 The system must provide various modes for clinical documentation, e.g., text, checkboxes/selections, radio buttons, dropdown menus, etcetera.
Mandatory
X
All new documents use encounters which is comprised of
a single or multiple form component.Form components all
contain data entry fields in the form of edit fields (single
line free text), multiline edit field (Multiple line free text),
Radio button, Check box, List Boxes, and dropdowns.
2.3.11.6 The system must provide the capability to document telemedicine and telephonic consultation.
Mandatory
X
Telemedicine and Telephonic consultations are
documented using specific encounters and form
components
Clinical Documentation:
2.3.11.7 The system must provide Clinical Decision Support (CDS) tools.
Mandatory
X
FusionEHR uses IBM Micromedex solutions for provider
reference that is available for diagnostic and medication
information. For patient information/education, the EHR
uses IBM Micromedex Care Notes.
If the client prefers to use an additonal decision support
tool such as Up to Date, it can be added however,
configuration and further discussion will be needed.
2.3.11.8 The preferred system supports evidence-based Clinical Practice Guidelines (CPGs) published and maintained by nationally recognized authoritative
sources, e.g., U.S. Preventive Services Task Force (USPSTF) or others.
Preferred
X
Clients determine which guidelines they would like to
adhere. USPSTF guidelines can be added to the protcols
and be built into the form components being used.
At times, some disciplines may want to follow the
guidelines from NCCHC, ACA, AMA, ADA, and or AHA to
name a few. Which guidlines need to be implemented will
be determined based on the client's needs.
2.3.11.9 The preferred system supports integration with dictation/talk to text software applications.
Preferred
X
Dragon dictation and other talk to text software can be
used with FusionEHR.
2.3.11.10 The preferred system offers users the ability to save draft entries before submitting the final documentation.
Preferred
X
Documents (encounters) can be placed on hold with data
previously entered.
2.3.11.11 The preferred system provides user-defined templates that are customizable.
Preferred
X
Form Components are customizable where additional data
entry fields can be added, removed, or renamed.
Additional coding can be added to form compnents to add
and place orders when certain conditions are met or
display specific previous data if needed. Fields can also
have prompts to ensure that users answer specific
questions or fields to further enhance report writing.
2.3.12
2.3.12.1 The system must provide standard, built-in clinical reports for queries of aggregate patient numbers.
Mandatory
X
FusionEHR currently contains standard out of the box
reports. NCCHC and ACA reports are currently being
worked on to include as OOB for the future.
2.3.12.2 The system must provide the ability to create and save customized queries to comply with NCCHC reporting standards, e.g.:
Mandatory
X
Inquiries are requests that can be formulated to find
records in the database that match specific criteria.
Inquiries can be saved and modified as needed by end
users who have access to the chart reports section.
2.3.12.2.1
Patients with Receiving Screenings/Health Assessments completed within the specified timeframe.
Mandatory
X
An inquiry or an SSRS report can be built to provide the
data needed for all patients who have had a receiving
screening or heatlh assessment from a specified time
frame.
2.3.12.2.2 Patients who have been in-custody for at least one year require an annual oral/dental exam.
Mandatory
X
Annual or dental exams are typically scheduled during the
intake process. An order for an Annual Dental Exam is
used to schedule the dental exam visit and a report or
inquiry can be used to verify all patients who have had a
completed annual dental order. Another report can be
built to look for any document type that is specific for
annual dental visits tied to the order completion for a
more accurate report.
2.3.12.2.3 Patients with Chronic Care conditions.
Mandatory
X
Inquiries are requests that can be formulated to find
records in the database that match specific criteria.
Inquiries can be saved and modified as needed by end
users who have access to the chart reports section.
SSRS reports or inquiries could also look for key words
such as diabetes or so forth. Best method to make sure
the reports are as accurate as possible is to discuss the
needs with the client as well as where the information will
be coming from.
2.3.12.2.4 Peer review by user.
Mandatory
X
End users are able to view other users documents and
flags.
2.3.12.3 The system must have a customizable reporting module/dashboard to run ad hoc data queries.
Mandatory
X
Inquiries are FusionEHR's ad hoc module.
2.3.12.4 The system must have associated databases to build reporting tools.
Mandatory
X
Select individuals will have access associated database for
data reporting purposes
2.3.12.5 The system must define how parameters are specified for reporting.
Mandatory
X
Specific parameters need to be provided by CHS. The data
captured in either edit fields, checkboxes, listboxes,
dropdowns, or multiline edit fields can be reported on.
2.3.12.6 The system must specify the relationship between the database tables and structures.
Mandatory
X
Database documentation will be provided for individuals
that have the appropriate permissions to access and run
database SQL queries.
2.3.12.7 The system must facilitate historical data/“snapshot” reporting.
Mandatory
X
Reportable fields in the system are also referred to as
clinical list changes and include Observation terms,
Diagnoses, Medications, Orders, Advanced directives and
allergies. Observation terms are unique items that are tied
to specific fields within form components to be able to
pull data from for reports or queries.
2.3.12.8 The preferred system includes a customizable performance metrics dashboard that can be filtered by specific clinic locations.
Preferred
X
A dashboard can be used by using SSRS reports or Power
BI.
2.3.12.9 The preferred system allows users with specific access roles to create categories and set customizable metrics to monitor productivity.
Preferred
X
Specific users can have access to SSRS and Power BI.
2.3.12.10 The preferred system provides the capability for designated users to access the backend database for the main production and test servers for ad hoc
reporting.
Preferred
X
Users can be set with specific permissions for access to
the EHR and the database
2.3.12.11 The preferred system provides the capability for users to independently create and run reports via Structured Query Language (SQL) Server Reporting
Services (SSRS), Crystal reports, or similar tools.
Preferred
X
SSRS is preferred over crystal reports given that crystal
reports has more limitations with writing reports.
Reports:
2.3.12.12 The preferred system supports Microsoft Power BI, or a similar business analytics tool for dashboards and reporting.
Preferred
X
The system can leverage Microsoft Power BI
2.3.12.13 The preferred system continually updates the data dictionary.
Preferred
X
The data dictionary is updated with each future release.
2.3.13
2.3.13.1 The system must provide various form templates, such as: Release of Information (ROI) and Request for Information (RFI).
Mandatory
X
Fusion has a repository for clinical content that includes
Release of information and request for information forms.
These items are typically tailored to the client
specifications given that legal language differs from state
to state. These items can also be used in the e-Sign web
application that allows for the end users as well as the
patient to electronically sign.
2.3.13.2 The system must be capable of importing and exporting health records in Consolidated-Clinical Document Architecture (C-CDA) format.
Mandatory
X
FusionEHR uses C-CDA (HL7) for use with HIE
2.3.13.3 The system must be capable of attaching and exporting records in Portable Document File (PDF) format.
Mandatory
X
Documents can be imported and exported in PDF format.
2.3.13.4
The system must be capable of attaching images in PNG, JPG, and DICOM formats.
Mandatory
X
Images can be attached to chart documents and store
them in the application database. The following image
formats are supported: BMP, JPG, or .TIFF formats.
External reference links to images can be added for
unsupported formats. If a chart attachment that is in an
unsupported format is open, then the application
launches the program on your workstation that is
associated with the unsupported format such as a
browser, a graphics software application, or another
image viewer.
Adding images to chart notes is a two part process:
1) Acquire and attach the image (from a camera, scanner,
file system, or software application)
2) Insert a link to the image into the note. This puts image
links in the text where you want them to appear with
other clnical informaiton or notes and adds the image to
the inserted list.
2.3.13.5
The system must be capable of importing existing health records stored in electronic format from the current EHR system.
Mandatory
X
FusionEHR uses LinkLogic that allows for efficient and
intelligent sharing of data among the application and a
variety of external systems, such as practice management,
transcription, laboratory, hospital information, and clinical
data repositories. LinkLogic uses interfaces to share data.
LinkLogic Import functions consists of Demographics,
Documents, Images, Lab Results and Appointments.
2.3.13.6
The system must support document management, including the ability to scan, store, and index images and information.
Mandatory
X
FusionEHR uses Indexing Client for document
management. Other third party vendors such as
Docubatch can also be used for scanning, storing, and
indexing data.
2.3.13.7 The preferred system is capable of exporting all disclosable records as determined by the department.
Preferred
X
Specific documents can be selected for printing or
exporting.
2.3.13.8
The preferred system is capable of automatically deleting health records for patients who have not been seen for the last six or more years.
Preferred
X
Health records can be deleted. Arizona law requires health
care providers to keep medical records of adult patients
for at least 6 years after the date the patienc received
medical care from their provider.
Patient files can be programmed to be inactivated or
deleted within a specific time period.
2.3.13.9
The preferred system is capable of performing Electronic Discovery (E-Discovery) for litigation holds and tracking the holds moving forward.
Preferred
X
There are different types of eDiscovery which looks for
emails, documents, databases, Web sites etc. In
FusionEHR, individuals will have access to the database to
assist with any information needed for any legal
proceedings.
2.3.14
2.3.14.1 The system must manage user access.
Mandatory
X
FusionEHR uses application user management that allows
for the separation of human entities into tow distinct
groups: application users and non application users.
Managing application users is the gateway to creating and
maintaining responsible providers, mid levels, and any
other person who require accest to chart.
Furthermore, users need to be set up in Active Directory
along with the location of care.
2.3.14.2 The system must support Role-Based Access Control (RBAC).
Mandatory
X
FusionEHR uses the manage application users to set up
security groups. Security groups allow for administrators
to grant or deny access rights to one or more permissions
to groups of users, rather than assigtning rights on an
individual basis. To manage security groups, an
administrator will need to go to the following:
Administration> System > User and Resource
Management > Users > Security > Security groups.
2.3.14.3 The system must provide unique credentials for each authorized user.
Mandatory
X
Credentials are unique for each authorized user
User Access:
Records Management:
2.3.14.4
The system must support a process for password recovery.
Mandatory
X
FusionEHR uses Rdweb which allows users to individually
change their passwords. User Management is also carried
out by the client. Fusion can assist with setting up Rdweb
utility or an ADSelfService.
2.3.14.5 The system must support County password policy requirements, such as minimum length, mixed case, numerals, and non-alphanumeric characters and
forced expiration.
Mandatory
X
Policy requirements are determined by the client. The
client have access to AD and will be able to set any
password to set their policy requirements
2.3.14.5 The system must support session time-outs.
Mandatory
X
Idle user timeout is a set period of inactivity after which
the users ia automatically logged off. Any mouse or
keyboard action can reset the timeout countdown. Long
running tasks, such as inqiuries, reports, printing, faxing,
and LinkLogic import or export postpone the timeout
countdown until the task is completed.
Idle user timeout is modified by going to the following:
Administration>System> Idle Timeout and Password
Management.
For idle user timeout set the number of minutes that must
pass before the application automatically logs off the user.
The recommended setting is 15 minutes.
2.3.14.6 The system must log failed login attempts and support the ability to disable or lock out user accounts after a designate number of failed login
attempts.
Mandatory
X
FusionEHR logs and creates an audit trail for all failed and
successful login attempts.
2.3.14.7 The preferred system supports a self-service process for password recovery.
Preferred
X
FusionEHR uses Rdweb which allows users to individually
change their passwords. User Management is also carried
out by the client. Fusion can assist with setting up Rdweb
utility or an ADSelfService.
2.3.14.7 The preferred system supports multi-factor authentication.
Preferred
X
FusionEHR next feature release will unclude MFA
functionality.
2.3.14.8 The preferred system supports Security Assertion Markup Language (SAML) or Single Sign On (SSO) capabilities.
Preferred
X
FusionEHR next feature release will include SSO
functionality.
2.3.15
2.3.15.1 The system must provide comprehensive audit trails for all user activity.
Mandatory
X
FusionEHR automatically monitors and logs many user
activities, including user and workstation IDs, user actions,
date and time, charts accessed, and other information,
such as report or document names, clinical values changed
and actual value changes. When all auditing options are
enabled, database storage requirements increase
significantly. To save space, clients can choose not to track
certain activities such as viewing, previewing, printing, or
faxing of documents with a confidentiality type of Normal.
By Default, the application logs only HIPAA events. To
access system auditing, follow the this path:
Administration > System > Auditing.
2.3.15.2 The system must log all material user actions and activities completed under that profile at each session.
Mandatory
X
FusionEHR automatically monitors and logs many user
activities, including user and workstation IDs, user actions,
date and time, charts accessed, and other information,
such as report or document names, clinical values changed
and actual value changes. When all audting options are
enabled, database storage requirements increase
significantly. To save space, clients can choose not to track
certain activities such as viewing, previewing, printing, or
faxing of documents with a confidentiality type of Normal.
2.3.15.3 The system must log all material administrator actions, including but not limited to, user creation, user deleting, password resets, and privilege level
changes.
Mandatory
X
The system logs administrator actions.
2.3.15.4 The system must have functionality for audit trails to identify errors and opportunities for process improvement.
Mandatory
X
The system has multiple items that are automatically
logged.
2.3.16
2.3.16.1 The preferred system provides a mainstream Relational Database Management System (RDBMS) e.g., Microsoft Structured Query Language (SQL)
server.
Preferred
X
FusionEHR Runs off of a Microsoft SQL Server backend.
2.3.16.2 The preferred system is a web-based (thin client) user interface that meets Hypertext Markup Language (HTML)5 standards.
Preferred
X
FusionEHR next feature release will be a web-based (thin
Client) solution.
2.3.16.3 The preferred system supports multiple handheld and mobile device screen adaptations and portable form factor, etcetera.
Preferred
X
FusionEHR is capable with working on Laptops, tablets,
and phones. Laptops and tablets are the recommended
devices utilized.
2.3.16.4 The preferred system supports imbedded pictures within core package functions.
Preferred
X
Pictures can be added and imbedded within form
components of encounters.
Technical Specifications:
Audit Trails:
Syste
m
Requi
reme
nts
Vendor
Respons
es
Section
Requirement Description
Mandator
y -OR -
Preferred
Rate the
proposed EHR
system by
placing an “X”
Explanation
2.4
QUICK RESPONSES: The proposed EHR system shall include the functionalities as listed below.
Yes
No
Provide detailed information in narrative format only for “No” responses and identify any corresponding attachments.
2.4.1
Alerts:
2.4.1.1
Does the system provide alerts if two patients have same name at same location, house, pod, clinic, etcetera?
Mandator
y
X
A user will be notified if two patients have the same name at the same location, house, pod, clinic, etc. The patients will clearly all be listed for
the user to see. In the process of looking up an offender within the electronic medical record (EMR) via the Fusion search there are a number of
criteria in which the search can be set: by patient ID, name, birthdate, medical record number. Search method contains: beginning with,
containing, ending with. Populations set: all patients, Location set: all authorized locations. Most customers search by patient ID. Once the search
is run: the name, birthdate, SSN, home location, patient ID, and MRN. Should there be two patients who are similar or the same, both will present
to the end-user. The process is to locate the patient ID and birthday date. Should these two still be similar upon selection and opening of the
patient medical record, an alert can present to the user informing of similar names. On the patient ID banner at the top of the patient medical
record there can be an alert that displays informing any users that patient has a same or similar name. There is a picture from the offender
management system that displays on every patient medical record upon entry of the medical record.
2.4.1.2
Does the system route, manage, and present current and historical test results to appropriate clinical personnel for review?
y
X
2.4.1.3
Does the system evaluate results against normal values and notify the provider abnormal results?
y
X
When results are abnormal, the following options are available: Automatically Sign - Route for review, Automatically Sign - Route for final
2.4.1.4
Does the system alert the provider if results are not viewed?
y
X
2.4.1.5
Does the system provide automatic abnormal and panic value alerts?
y
X
2.4.1.6
Does the system provide the ability to forward the alert to specific provider or other authorized users via a secure message module?
y
X
2.4.1.7
Does the system provide the ability for the department to customize the timing, location, frequency of alerts?
Preferred
X
2.4.1.8
Does the system support alerts to follow up and close any open issues i.e., dental, labs, specialists, etcetera?
Preferred
X
2.4.2
Assessment and Treatment Planning:
2.4.2.1
Does the system update other portions of the record with captured vital signs?
y
X
This is a feature included in the solution. Workflow discussion will be needed to build the form components to the client's needs.
2.4.2.2
Does the system provide screening tools and a clinical risk assessment calculator for medical, mental health, and substance abuse, etcetera?
y
X
2.4.2.3
Does the system provide screening tools and a clinical risk assessment calculator that has the ability to generate templated notes or similar documentation?
y
X
2.4.2.4
Does the system support building specific assessment templates, i.e. speech and language, self-care, cognitive functioning, abnormal involuntary movements, etcetera?
y
X
2.4.2.5
Does the system provide the department with the ability to create and modify assessments in a table or menu with unlimited text values?
Mandator
y
X
Assessments can be tailored to each department's needs. These items are addressed during workflow discussions, however, tables is not an item
that is used within form components. Flowsheets are available as a standard component.
2.4.2.6
Does the system provide the ability to create and modify assessments in a table or menu with unlimited text values to comply with medical and mental health standards?
Preferred
X
Tables are not a feature in the system. A combination of edit fields and a flowsheet view can be used to display the information needed.
2.4.2.7
Does the system provide treatment planning or the tools to build a Special Needs Treatment Plan (SNTP)?
Preferred
X
2.4.2.8
Does the system provide the ability to create, review, and modify long/short term goals and objectives as part of treatment planning?
Preferred
X
2.4.3
Clinical Decision Support (CDS) and Clinical Practice Guidelines (CPGs):
2.4.3.1
Does the system provide real-time Clincial Decision Support (CDS) to the provider at the time of order entry and clinical documentation?
Preferred
X
2.4.3.2
Does the system support dual-diagnosis decision matrix?
Preferred
X
2.4.3.3
Does the system support both medical and mental health diagnosis decision matrix that addresses continuity of interventions in treatment planning?
Preferred
X
2.4.3.4
Does the system allow initial authoring and revising of Clinical Practice Guidelines (CPGs)?
Preferred
X
2.4.3.5
Does the system allow linkages from Clinical Practice Guidelines (CPGs) to Clinical Decision Support (CDS) modules?
Preferred
X
2.4.3.6
Does the system allow providers and other authorized users to override any or all parts of the Clinical Practice Guidelines (CPGs)?
Preferred
X
2.4.3.7
Does the system provide recommendation prompts for preventative interventions?
Preferred
X
Preventive prompts can be added in the form of notes, action buttons and pop ups. However, this is disucssed during workflow discussions.
2.4.4
Clinical Documentation:
2.4.4.1
Does the system support on-demand completion of a form for any given patient?
y
X
2.4.4.2
Does the system automatically trigger the completion of a specific form based upon a clinical event?
Mandator
y
X
More informaiton is needed to understand this question. Encounters are completed upon an individual signing the document.
Certain tools such as Fusion's inpatient BedBoard, can be configured to automatically create an admission and discharge document for patients in
the infirmary.
2.4.4.3
Does the system require all mandatory fields to be completed for a patient encounter before documentation is completed?
y
X
Hard stops or soft stops can be used.
2.4.4.4
Does the system capture prescription medications in a progress notes?
y
X
Medications can be added during a progress note and will get stored with a date and time stamp.
2.4.4.5
Does the system automatically update other sections of the record with data entered in progress notes?
y
X
Information can be displayed on other encounters to enhance workflows, however, this will require discussion on the workflows to ensure that
2.4.4.6
Does the system support spell checking of clinical documentation entries?
Mandator
y
X
Spellcheck is included on the 'Text' version of the encounter. Adding spell check to all textboxes is a feature that is being added in a future
release.
2.4.4.7
Does the system allow progress notes to be sorted and viewed in chronological or reverse chronological order by encounter date?
y
X
2.4.4.8
Does the system support documenting segregation checks using parameters defined by the department?
y
X
2.4.4.9
Does the system support dual verification by authorized individuals for specific entries requiring co-signatures?
y
X
The system allows for co-signing but does not currently have dual authentication.
2.4.4.10
Does the system support both standardized and customizable flow sheets i.e. HIV, Coumadin, Neuro, Diabetic, growth charts, maternal care, etcetera?
y
X
2.4.4.11
Does the system support secure form handling to prevent unauthorized revisions?
y
X
2.4.4.12
Does the system support users with the proper permissions to amend entries?
y
X
2.4.4.13
If entries can be amended, does the system maintain both original and amended entries?
y
X
2.4.4.14
Does the system provide fields for entering performed and planned procedures in a progress note template?
y
X
2.4.4.15
Does the system capture performed and planned laboratory procedures in a progress note?
y
X
2.4.4.16
Does the system support a variety of different input methods, such as: voice recognition, touch screen pen, mouse, keyboard, etcetera?
Preferred
X
2.4.4.17
Does the system incorporate Living Will/Power of Attorney (POA), next of kin, dependents, and code status?
Preferred
X
2.4.5
Communicable Diseases:
2.4.5.1
Does the system support contact investigations for communicable disease populations, e.g., varicella, tuberculosis?
y
X
2.4.5.2
Does the system support the compilation of all current and historical information regarding a patient's communicable disease history onto one screen for review?
y
X
2.4.5.3
Does the system allow for the notifying of relevant electronic laboratory results for reportable conditions to appropriate public health authorities and released patients?
y
X
2.4.5.4
Does the system automatically trigger an alert based on the documentation of a diagnoses or event as defined by the department that requires reporting to public health authorities?
Preferred
X
This can be configured with a form. Automatic triggers can be added depending on what is needed and if certain conditions are met. A workflow
2.4.6
Discharge, Transfer, and Release:
2.4.6.1
Does the system cancel all orders, appointments, medications, when patient is released from custody?
Preferred
X
2.4.6.2
Can the system be customized by the department to not auto-cancel certain types of appointments, queue entries, etcetera, when patient is released from custody?
Preferred
X
2.4.6.3
Does the system generate an automated discharge summary when the patient is released from custody?
Preferred
X
2.4.6.4
Does the system prompt the need for follow-up care, discharge prescriptions, and discharge planning, before the patient's release?
Preferred
X
2.4.7
Displays and Functions:
2.4.7.1
Does the system display updates and changes in real-time?
y
X
2.4.7.2
Does the system use a standardized screen design and navigation flow that is similar from screen-to-screen?
y
X
2.4.7.3
Does the system provide consistent formatting for users to find information?
y
X
2.4.7.4
Does the system display patient data as defined by the department (demographics, allergies, diagnoses) on every screen to avoid redundancy?
y
X
All this information is viewable on the patient's banner. The patient banner is always displayed and available for view.
2.4.7.5
Does the system provide key data as defined by the user (e.g., allergies, problem list) to be viewed on a single main screen?
y
X
2.4.7.6
Does the system have standardized naming conventions throughout the application?
y
X
2.4.7.7
Does the system interface with web-based Structured Query Language (SQL) servers?
Preferred
X
2.4.7.8
Does the system support remote monitoring technology?
Preferred
X
2.4.7.9
Does the system have the ability to process deactivations from the active directory and automatically turn off access for terminated personnel?
Preferred
X
2.4.8
Intake Screening:
2.4.8.1
Does the system support the storage of receiving screening information if patient is not accepted for booking?
y
X
2.4.8.2
Does the system trigger relevant actions based on the intake screening answers (e.g., queue entries, flags, additional form pop-ups)?
y
X
Pop up alerts and text can appear to remind users that another task needs to be done or provide additional information when certain triggers are
2.4.8.3
Does the system use any algorithms to speed up the intake screening process?
Preferred
X
2.4.8.4
Does the system formally admit patients to specialty care units, such as: the Infirmary or the Mental Health Unit?
Preferred
X
2.4.9
Medication Administration:
2.4.9.1
Does the system display routine medications separately from Pro Re Nata (PRN)/"as needed" medications?
y
X
2.4.9.2
Does the system have a fail-safe mechanism to prevent double-dosing of medications when medications are administered in an off-line mode?
y
X
2.4.9.3
Does the system log patient releases and housing moves to enable the nurse to remove medication from carts for redeployment?
y
X
2.4.9.4
Does the system require the nurse to run a reconciliation report at the end of each pass to confirm all medications were given and documented if missed or refused?
y
X
2.4.9.5
Does the system support the preparation of a medication pass list in the event of a server outage/off-line mode?
y
X
2.4.9.6
Does the system provide a mechanism for re-entering the actual date and time of the medication administration following a medication pass during a server outage/off-line mode?
y
X
2.4.9.7
Does the system notify the clinical staff of a list of patients who have missed medication within the first 24 hours after booking?
Mandator
y
X
Upon administering medications, nursing staff has clear access to the patients compliance levels regarding medication admin. Including
compliance on the last three admins for the patient.
2.4.9.8
Does the system's medication administration module include access to the National Drug Classification (NDC) database?
y
X
2.4.9.9
Does the system store common prescriptions/immunizations for quick entry?
y
X
2.4.9.10
Does the system store prescription data for retrieval by all of the following: Drug name, National Drug Classification (NDC) code number, dosage prescribed, route, time, etcetera?
y
X
2.4.9.11
Does the system allow printing a patient's Electronic Medication Administration Record ("EMAR") for a specific date range?
y
X
2.4.9.12
Does the system identify the individual by personnel number who administered each dose on the printed EMAR?
y
X
2.4.9.13
Does the system check that appropriate laboratory monitoring or other pre-administering conditions are met?
Preferred
X
This is being worked on for a future release, however, the labs will not be placed automatically but instead be recommended to the provider to
2.4.9.14
Does the system maintain a history of all medications including those prescribed elsewhere?
Preferred
X
The EHR shows all medications that are active and inactive throughout the patient's history. For medications documented elsewhere, then the
medications can be added as historical if the information is available (Manually entered). If there is a Health Exchange Interface medications can
also be added from there. Fusion also has the ability to search the SureScripts network to pull medication information.
2.4.9.15
Does the system support a mechanism for nurses to document wasted medications for both controlled and non-controlled medications?
Preferred
X
2.4.9.16
Does the system's EMAR support offsite pharmacy orders and tracking?
Preferred
X
Medications will be displayed in the EHR as long as they are entered in the medications module. The interface will need to ensure that the meds
2.4.9.17
Does the system's EMAR allow tracking of medication inventories at different clinics?
Preferred
X
Not currently, but this feature is being planned and scoped for a future release.
2.4.9.18
Does the system display medications/immunizations prescribed both before and after the patient encounter?
Preferred
X
2.4.9.19
Does the system allow providers to document the effectiveness or ineffectiveness of the medication?
Preferred
X
2.4.9.20
Does the system require the nurse to reconcile the medication pass prior to leaving a housing location to ensure there are no missed doses of medication?
Preferred
X
2.4.10
Medication Administration - Documentation:
2.4.10.1
Does the system allow for documenting the actual time of medication administration?
y
X
2.4.10.2
Does the system allow for multiple clinic-specific medication pass times?
y
X
2.4.10.3
Does the system ensure medication administration times are adjusted when the patient is transferred to a different housing unit?
y
X
2.4.10.4
Does the system allow for distinct medication administration times different from routine medication passes, i.e. insulin administration?
y
X
2.4.10.5
Does the system allow for customization of medication administration codes, i.e. given, refused, held, no-show?
y
X
2.4.10.6
Does the system provide a field to document why a medication was refused or why a medication was held?
y
X
2.4.10.7
Does the system support scheduled and unscheduled medication administration in a jail setting?
y
X
2.4.11
Medication Administration - Special:
2.4.11.1
Does the system support patient-specific special administration instructions to the nurse for each medication pass, e.g., watch for cheeking, crush all medications, etcetera?
y
X
In the eMAR, when selecting administered or not administered there are multiple choices that can be added along with a comment note.
2.4.11.2
Does the system alert the nurse of medical parameters to be met before administration, i.e. blood sugar, blood pressure, pulse?
y
X
These items can be added to the Patient banner.
2.4.11.3
Does the system prevent the nurse from documenting the medication as administered until the medical parameter is entered and meets requirements?
Mandator
y
X
The medications will not appear on the eMAR unless, all the appropriate fields such as dose, quantity, refill, route, end and start dates, authorizing
provider (with an NPI) have been entered.
2.4.11.4
Does the system automatically flag medications that can cause heat sensitivity?
y
X
This is an item that can be scoped to add to the pharmacy interface.
2.4.11.5
Does the system require the medical director’s or designee's approval before ordering non-formulary medication?
y
X
Non formulary manager is the tool used for a chief medical director or other equivalent individuals to approve or deny non formulary
2.4.11.6
Does the system alert the medical director or designee when a non-formulary medication is ordered by any provider with a reason?
y
X
2.4.11.7
Does the system allow for medication administration documentation before the assignment of a unique identifier at pre-intake prior to booking?
Preferred
X
Medications (charting) can be added to a patient's chart once the chart has been created. If the patient is in the JMS/OMS then a chart is created
and allows users to view and begin documenting on the patient's chart.
2.4.11.8
Does the system support a single click to document "education provided" for medications causing heat sensitivity?
Preferred
X
Patient education is available for each medication at all times. A provider entering the order can search for the education which comes in multiple
languages and print it out from there. If the patient needs a refresher than a user can select the active medication from the chart and choose the i
button to access the patient information again for that specific medication. If the client has specific instructions and or education that can be
added as a handout. In that case, a button can be added to a form component to print out the client specific patient education handout.
2.4.11.9
Does the system support a visible flag during each medication pass and during routine medical care for medications causing heat sensitivity?
Preferred
X
The system does not place automatic flags for medications that has heat sensitivity out of the box. However it is something that can be scoped
and possibly added via the pharmacy interface.
2.4.11.10 Does the system support tracking Court Order Treatment (COT) start and end dates?
Preferred
X
2.4.12
Medication - Controlled Substances:
2.4.12.1
Does the system apply the correct controlled substance ordering restrictions for physician assistants and nurse practitioners?
y
X
2.4.12.2
When Schedule II medications are ordered, does the system automatically print a hard-copy prescription for provider signature?
y
X
EPCS does not print the prescription automatically, however it can be added.
2.4.12.3
Does the system require the provider to electronically validate the order of controlled substance stock medication?
y
X
For controlled substance EPCS requires multifactor authentication for the prescriber to approve a prescription entry and sign the prescription.
2.4.12.4
Does the system support a mechanism for a provider and a nurse to authorize the order of Schedule II stock medication?
y
X
Yes, as long as the medication is part of your formulary and the authorizing provider posseses an NPI and a DEA number the medication can be
2.4.13
Medication - Ordering:
2.4.13.1
Does the system allow the provider to enter required medical parameters when ordering medication?
y
X
2.4.13.2
Does the system limit the duration of a medication order?
Mandator
y
X
The system allows the end user to add any duration. However, no pharmacy will dispense a medication with an order duration of over a year. The
interface checks and notifies the pharmacy. The pharmacy can send a flag to the end user or may end up calling the end user directly.
2.4.13.3
Does the system add the Patient Identification Number (PIN) to printed prescriptions for both narcotic and non-narcotic medications?
y
X
2.4.13.4
Does the system support the nurse taking telephone orders?
y
X
2.4.13.5
Does the system support provider review/approval (co-sign) process?
y
X
2.4.13.6
Does the system support medications ordered to be administered at a designated frequency, i.e. weekly, monthly, every three months?
y
X
2.4.13.7
Does the system support clinic-specific provider verification of a verbal order rather than verification by the ordering provider who may be located at another clinic?
y
X
2.4.13.8
Upon attestation of a medication order, does the system allow for the creation of a medication adjustment note to indicate the reason for the medication change?
y
X
2.4.13.9
Does the system support ordering of Statim (STAT)/"immediate" and stock medications?
y
X
2.4.13.10 Does the system include a pull down list of all ordering departments to enable multiple orders, such as: Medical, Mental Health, Dental, etcetera?
Mandator
y
X
The orders module allows you to select any order as long as the order exists in the EHR. Order Custom lists are essential to allow users from
different departments to find the orders that they need quickly. The recommendation is that each department have their own custom lists with
the most common items ordered which include but not limited to radiology, laboratory, diet, adaptive equipment, off site and on site referrals
etc.
2.4.13.11 Does the system alert providers to potential medication ordering and administration issues, such as: incorrect patient, incorrect dose, incorrect route, and incorrect time?
Mandator
y
X
Fusion's eMAR was strategically developed and layed out to have all patient and medication information right at your fingertips. For instance, the
patients banner with their Picture and Demographic information is located just above the medications to be administered. Each medication will
include Med Name, Dose, Route, Instructions, Time and more.
When ordering medications, Fusion provides Dosing calculators and mongraphs to ensure that the medication is ordered correctly. The agency
can also have medication lists preset to ensure the meds are ordered in the manner set forth by the County.
2.4.13.12 Does the system support clinic-specific orders under defined Nursing Assessment Protocols (NAP)?
y
X
2.4.13.13 Does the system allow for customized provider protocol orders, such as for Librium, steroid tapers, emergency medications?
y
X
2.4.13.14 Does the system allow for the nurse to edit a prescription from Keep on Person (KOP) to Directly Observed Therapy (DOT) status?
y
X
2.4.13.15 Does the system require justification for overriding and cancelling orders?
y
X
2.4.13.16 Does the system detect and display duplicate orders by issuing warnings and allow the user to override it by entering justification?
Mandator
y
X
Multiple orders can be added and removed as needed. In the Orders module, you can look at all active orders however, the system will not
prompt you to let you know that mulitple orders for the same item have been placed. Logic can be built within form components to ensure that
duplicate orders are not added or to check for Active orders.
2.4.13.17 Does the system automatically record the date, time, and user who enters an order correction?
y
X
2.4.13.18 Does the system allow providers to modify/create the most commonly used orders to assist in order placement?
Preferred
X
2.4.13.19 Does the system allow providers view medication history both online and off-line?
Preferred
X
When in the eMAR (whether online or offline) you will see all active medications for the patient. Additionally, you are able to see the Medpass
Dashboard which includes information such as medications ending soon (72 Hours), and recently Discontinued Medications (last 72 hours). Fusion
will consider adding Medication history in future releases.
2.4.13.20 Does the system have a process to manage orders for emergency medications that are not kept in stock?
Preferred
X
The medications that are not kept in stock will still be ordered through the same Medication order module.
2.4.14
Medication Queues/Notifications:
2.4.14.1
Does the system offer provider medication queues for new orders, reorder, refill, and approval?
y
X
2.4.14.2
Does the system support notifications to the provider in the clinic where the patient is housed, regardless if this is the ordering provider?
y
X
2.4.14.3
Does the system support automatic "refill due" or "reorder" notification to provider?
y
X
2.4.14.4
Does the system support a queue that would allow for the refill or reorder of one or more medication(s) for multiple patients simultaneously?
y
X
Multiple medications order can be done simultaneously for a single patient.
2.4.14.5
Does the system notify the provider of which medications the patient missed based on departmental policy for number of missed doses?
y
X
There is a compliance indicator in the eMAR. It's also color coded to assist and let the provider know that the patient is or not in compliance with
2.4.14.6
Does the system provide a mechanism for the provider to review refusals?
y
X
Documents that are signed can be viewed and appended. Refusals are typically require a patient signature and is generally an e-sign document.
2.4.14.7
Does the system provide a note section for the nurse to flag a patient question or issue regarding medications or general medical inquiries?
y
X
All encounter are comprised of one or multiple form components. Most form components contain multiline edit fields for additional comments
2.4.14.8
Does the system offer a provider dashboard?
Mandator
y
X
Rosters can be set up for the providers as well as a user specific task list within Fusion's Order Manager.
2.4.14.9
Does the system provide queues to assist clinical staff in tracking and managing daily activities?
y
X
Orders Manager is used to to track and set up work queues for staff. Global task list or Personal task lists can be created.
2.4.14.10 Does the system provide an alert to the nurse regarding patients with new medications and changes in medications?
Preferred
X
Prior to administering medications, the nurse has the ability to view the locations administrative dashboard. The Dashboard includes information
such as new patients in the last 72 hours, medications expiring in 24 hours as well as any location changes.
2.4.14.11 Does the system provide a refusal report in a sortable format based on date range, provider, clinic, etcetera?
Preferred
X
A report can be run with the parameters dictated by the client.
2.4.14.12 Does the system provide a customized task list to assist user to manage unscheduled tasks and clinical events?
Preferred
X
2.4.14.13 Does the system provide any queue for providers to track and manage priorities?
Preferred
X
2.4.15
Orders:
2.4.15.1
Does the system designate order priority i.e. routine, Statim (STAT)/"immediate," today, timed, discharge, involuntary administration?
y
X
Orders have a priority of: Normal, Urgent, Stat
2.4.15.2
Does the system identify specific orders that need approval/verification prior to becoming active orders?
y
X
This requires workflow discussion. Form components can be used to assist in the approval process for orders.
2.4.15.3
Does the system provide an acknowledgement of acceptance of order?
y
X
2.4.15.4
Does the system allow authorized users to override order conflicts?
y
X
2.4.15.5
Does the system allow entering narrative information regarding the reason for any specific order?
y
X
2.4.15.6
Does the system display an alert to identify any missing data in the order?
y
X
Form components can be programmed to have order data be mandatory fields and provide pop ups for the user to complete and answer specific
2.4.15.7
In addition to medication orders, does the system support provider notification of any continuing order with an upcoming expiration date?
y
X
Form components can be programmed to show order that have not been completed.
2.4.15.8
Does the system support sorting/viewing orders for any given patient(s) in multiple formats, i.e. active, discontinued, problem, diagnosis, provider, location, etcetera?
y
X
2.4.15.9
Does the system provide for the ability to assign and display an order number for active, hold, and pending orders?
y
X
2.4.15.10 Does the system provide the ability to select orders as recurring?
y
X
Form componenets can be programmed to add new orders after the encounter/document has been completed
2.4.15.11 Does the system provide order inquiry functionality to allow user to inquire on the details of the order?
y
X
2.4.15.12 Does the system display an alert if an order varies from guidelines, rules, or presents safety issues?
Preferred
X
Guidelines can be set within form components in the encounter but not the individual order.
2.4.15.13 Does the system allow the backdating of order times and dates in the event of a server outage/off-line mode?
Preferred
X
2.4.15.14 Does the system allow for the tracking of all orders through completion?
Preferred
X
2.4.15.16 Does the system document an order as completed when all order parameters have been met?
Preferred
X
An order needs to be manually completed. End users need to select the order or orders for completion.
2.4.15.17 Does the system have the capability to generate multiple orders from one request to all appropriate responsible parties?
Preferred
X
2.4.15.18 If an order is cancelled, does the system prompt the user to re-verify the cancellation?
Preferred
X
2.4.15.19 If an order is accidentally cancelled, does the system support a simplified mechanism to reinstate it?
Preferred
X
Once an order is removed/cancelled. A new order will need to be added into the EHR.
2.4.15.20 When a patient is admitted Infirmary or Mental Health Unit, does the system flag all existing orders for review by the licensed nurse and receiving provider?
Preferred
X
This is a functionality that can be programmed. It's best to discuss these items when discussing workflows to avoid flag and alert fatigue.
2.4.15.21 Does the system display all the data associated with one order, including: demographics, order parameters, and order status on one display screen?
Preferred
X
2.4.15.22 Does the system provide a mechanism to select orders via alpha listing, user-defined order sets, and high-frequency use?
Preferred
X
2.4.15.23 Does the system provide a visual alert when a high-priority order is received?
Preferred
X
2.4.15.24 Does the system forbid the user from bypassing order menus to directly type order information?
Preferred
X
2.4.16
Patient Identification:
2.4.16.1
Does the system allow the authorized users to update identification photos of patients when needed?
y
X
2.4.16.2
Does the system complete an internal Patient Identification Number (PIN) clean-up process before go-live?
Preferred
X
Patient identification numbers come from the Jail or offender management systems. Prior to Go live this information is going to need to be
verified for accuracy.
2.4.16.3
Does the system capture the patient's home address?
Preferred
X
2.4.16.4
Does the system trigger any action if an interpreter is needed for patient care?
Preferred
X
Flags and alerts can be programmed to generate when a user requires a translator. The interpreter needed can also be displayed at the top in the
patient banner for all endusers to see. A pop up alert can be configured for anytime the patients chart is accessed requesting an interpreter.
2.4.17
Patient Instructions and Education:
2.4.17.1
Does the system require the pharmacy to produce patient direction labels in patient's native language for Keep on Person (KOP) medication?
y
X
2.4.17.2
Does the system support printed patient instructions in patient's native language?
y
X
2.4.17.3
Does the system link specific patient education materials to the individualized problem list?
Preferred
X
End users will always have access to the patient education for diagnosis/problems by highlighting the diagnosis and selecting the "i" button.
2.4.17.4
Does the system print relevant education materials on demand or automatically at the end of the encounter?
Preferred
X
Users are able to select patient education materials in multiple languages. Patient education materials come from IBM Micromedex CareNotes.
2.4.17.5
Does the system provide patient specific instructions related to both pre and post-procedural care?
Preferred
X
2.4.18
Patient Location:
2.4.18.1
Does the system provide a patient's real-time location with facility name, level, house pod, cell and bed?
y
X
2.4.18.2
Does the system allow providers to view all patients at all sites?
y
X
2.4.18.3
Does the system support the identification of patients at intake and in various holding areas when there is no bed assignment?
y
X
2.4.18.4
Does the system support sorting patients by top tier within a housing unit?
y
X
2.4.18.5
Does the system capture historical housing locations with dates?
y
X
2.4.18.6
Does the system produce an alert when a patient moves into or out of a segregated status?
y
X
2.4.19
Problem Lists:
2.4.19.1
Does the system track the status of each problem for each encounter?
y
X
2.4.19.2
Does the system link problems with forms, orders, results, and referrals, related to the problem?
y
X
2.4.19.3
Does the system expand the problem list summary when required?
y
X
2.4.19.4
Does the system provide a status for each problem shown: active versus inactive?
y
X
2.4.19.5
Does the system capture the diagnosis, severity of illness, and problem identification date?
y
X
2.4.19.6
Does the system organize applicable patient data into a comprehensive problem summary list?
Preferred
X
2.4.19.7
Does the system allow authorized users to maintain a problem list in a table or dropdown menu format?
Preferred
X
2.4.20
Referrals:
2.4.20.1
Does the system designate referrals that need approval as defined the department?
y
X
2.4.20.2
Does the system indicate the referral disposition, i.e. approved, scheduled, completed, no-show, or refusal?
y
X
2.4.20.3
Does the system capture admission and discharge dates for all types of hospitalizations?
y
X
2.4.20.4
Does the system capture admitting diagnoses and procedures performed on the patient?
y
X
2.4.21
Reports:
2.4.21.1
Does the system produce a report of user's activity per sign-on for productivity tracking?
y
X
2.4.21.2
Does the system provide a report of user credentials not used for a certain timeframe as specified by the department?
y
X
2.4.21.3
Does the system provide a report identifying all personnel who have accessed a specific patient's record?
y
X
2.4.21.4
Does the system allow the automatic transmission of predetermined reports at a scheduled timeframe to authorized entities?
y
X
2.4.21.5
Does the system generate a report for all chronic clinic visits, specifying which visits were on time or overdue?
y
X
2.4.21.6
Does the system provide a list of patients with the date of the most recent Purified Protein Derivative (PPD) test and the results in millimeters?
y
X
2.4.21.7
Does the system provide a list of patients with the date of the last annual physical specifying if it was on time or overdue?
y
X
2.4.21.8
Does the system generate a report of all of the Health Needs Requests (HNR) specifying if responded to within 24 hours or not?
Preferred
X
A report can be created using SSRS to provide the data needed.
2.4.22
Scheduling:
2.4.22.1
Does the system provide space to document reasons for initiating, canceling, rescheduling, and completing appointments?
y
X
2.4.22.2
Does the system provide reminders for follow-up appointments via queues?
Preferred
X
2.4.22.3
Does the system allow for the automatic scheduling of tests requiring more than one session for completion?
Preferred
X
Vendor Responses
Section
Requirement Description
Explanations
2.6
PLAN PROGRESS CHARTS: The proposed EHR system must include the plan progress charts as listed in the section below.
Provide the project approach including Work Breakdown Structure (WBS), resourcing, and Gant charts that reflect the proposed schedule and all major milestones and identify any corresponding attachments.
2.6.1
Specify an estimate of the current monthly implementation capacity.
Fusion's core implementation teams are staffed sufficiently to perform as many as 6 full scale EHR implementations simultaneously. To ensure all of those client projects get the attention necessary to ensure success, Fusion uses a comprehensive resource
planning program across our portfolio that assesses both capacity and demand. This program ensures we proactively align our expertise and resources to major project deliverables and milestones.
2.6.2
Specify the number of active and planned implementations in progress.
As of December 2022, Fusion has three full scale EHR implementations implementations in progress.
2.6.3
Specify the number of pending implementations based on the availability of company resources.
Fusion's core implementation teams are staffed sufficiently to perform the three current full scale EHR implementations that are pending as well as dedicate the necessary time and expertise to a successful implementation for the County.
2.6.4
Specify if any subcontractors or consultants are used to fill this capacity.
Fusion has access to highly qualified EHR specialists on a contract basis. Our core implementation teams are staffed by Fusion employed team members, but if necessary to meet certain client needs, we engage these resources with consistent success.
System Requirements
Vendor Responses
Section
Requirement Description
Explanations
2.7
TRAINING PLAN: The proposed EHR system must include a comprehensive training plan as listed in the section below.
Provide detailed information in narrative and/or diagrammatic description format and identify any corresponding attachments.
2.7.1
Identify the attached Training Guide. The Training Guide must be modifiable by the department. The department must be licensed to reproduce the Training Guide as needed for the life of the contract.
Fusion will provide the training plan and guide(s) during the EHR implementation project. Training guides include training outlines, facilitator guides, and end-user companion
guides built and structured per end-user discipline. All guides are custom tailored to include client and discipline-specific workflows. Once provided, training guides are owned by
the client and can be modified or reproduced as needed for any future training during the life of the contract.
2.7.2
Identify the attached User Guide. The User Guide must be modifiable by the department. The department must be licensed to reproduce the User Guide as needed for the life of the contract.
Fusion will provide user guides for the base EHR product and any Fusion applications installed on the client's environment. These guides will be used for training purposes and will
be provided to all end-users as referencable materials. The department will have the ability to reproduce User Guides as needed for the life of the contract.
2.7.3
Describe any pre-training assessments.
Fusion recommends completing a pre-training assessment of end-user knowledge and capabilities regarding EHR systems before each training. The pre-training assessment will
be used as a benchmark to measure training success against a post-training assessment. The pre-training assessment will vary by client but will include questions around the basic
features and functionality of the EHR, including searching for patients, reviewing patient charts and documents, prescribing medications, etc. All end-users will also have access to
the Fusion Learning Management System (LMS), which will help to provide foundational knowledge of the system before any virtual or in-person training sessions.
2.7.4
Provide an overview of the orientation training plan targeted for all users.
Each end-user will receive EHR system overview training and specialized training per discipline or type of user. EHR system overview training will be classroom style traiing and
will include the following topics at a minimum:
- Logging In and Out of the system
- Logging In: User Credentials, Location of Care
- Logging Out: Basic Log Out, Exit
Chart Desktop
- Layout, Horizontal Toolbar – Action Icons, Print, Help Menu, Vertical Toolbar – Navigation Icons, & Alerts and Flags: Communication, Patient Alerts
Documents
- Document Types, Document Status: In progress, On Hold, Unsigned, Signed, Scheduling: Select Schedule, View Schedule
Fusion Applications
- Location, Custom Commands, Set Up Links
Applications (as needed)
- Compliance Manager – Check-in recently booked patients
- Lab Manager – Create and print lab requisitions
- Order Manager – Search order task lists
- Group Notes – Create and complete group notes
- Non Formulary Manager – Approving/Denying non-formulary medications
- Formulary Manager – Upload and edit formulary lists
- eSign – Electronically sign documents
- Bedboard – Manage patients in the infirmary
P ti
t Ch
t
2.7.5
Specify the training curriculum by job category or role, please refer to "Table B. Types of Users" in Exhibit 4: CORRECTIONAL HEALTH SERVICES’ VOLUMES AND CONCURRENT USAGE.
Fusion will create and provide training materials (including guides, outlines, etc.) specific to each type of user. These training sessions and materials will include specific
workflows designed and finalized during the analysis and configuration phase of the implementation.
2.7.6
Describe the training methodology and delivery mode (e.g.: onsite, corporate, online, on-demand/self- service); include the length and scope of the training classes.
Fusion provides two options for training. Train the Trainer or Train the End User. Based on CHS' request. We will be providing the Train the Trainer approach. Please see a sample
of our Train the Trainer guide as a separate attachment labeled Fusion Health - Train the Trainer - CONFIDENTIAL . Below are some key differences and similarities the county
should expect with the train the trainer methodology.
Differences to highlight:
- For train the trainer, Fusion will provide in-depth training to a selected group of client trainers who will then be primarily responsible for training the remaining staff (super
users and end users)
- For end-user training, Fusion will provide training for all client users
Similarities:
- Fusion will always provide admin/support staff training directly
- Fusion will always provided all necessary training materials (outlines, facilitator guides, user guides, job aides, etc.) to the client. The client will be able to modify these materials
as required.
- Fusion will provide the same level of go-live support for either option.
2.7.7
Describe the training for new users in a sandbox environment before and after go live.
Users will be trained in a non-production environment setup and configured by Fusion. Users will be provided access to this environment and will follow along with the trainer(s)
during training sessions to maximize the understanding of the system and retention of knowledge. Test data is provided by Fusion, allowing users to step through various
workflows. This environment will remain available to users after the go-live to allow for additional training of existing users and onboarding training of any new users through the
life of the contract
2.7.8
Describe how the system distinguishes between test versus production libraries for screens and functions.
When loading the environment, the icon selected will clearly be labeled TRAINING, TEST, UAT, DEVELOPMENT, or the specified naming convention determined. Additionally, most
screens, and functionality will be maintained regardless of the environment type, with the exception of the integrations with third party solutions. Patient data will consist of
mocled up data for test patients.
2.7.9
Describe and itemize any additional training options that may be provided.
Fusion offers three training models;Train the trainer, train the end user, and assisted train the trainer. As per CHS' request, Fusion will provide a Train the Trainer methodology to
the County.
In addition to the training models, Fusion provides CHS with training materials, outlines, user guides/manuals, and the Fusion Learning Management System.
- LMS for life of the contract
- Training provided for any upgrades to the system
- Unlimited training post go-live at Fusion's discretion
- Additional training provided periodically via webcast
- Helpdesk access for questions, concerns, issues or training requests
System Requirements
Vendor Responses
Section
Requirement Description
Explanations
2.8
SUPPORT AND MAINTENANCE AGREEMENT: The proposed EHR system must include support and maintenance services as listed in the section below.
Provide detailed information in narrative and/or diagrammatic description format and identify any corresponding attachments.
2.8.1
Identify the attached Support and Maintenance Agreement.
Please reference Fusion's standard Support and Maintenance as a separate attachment labeled Fusion Health - Support Maintanence SLA - CONFIDENTIAL.
2.8.2
Describe the approach for deploying support and maintenance services to 1000 total users and approximately 400 concurrent users 24 hours per day and seven days
per week.
CHS will be assigned a dedicated Client Success Manager. Your assigned Client Success Manager will serve as the single-point-of-contact for escalations after project management closure and will continue to provide
proactive product utilization advice to CHS and all health services staff. The CSM’s duties are to provide CHS with expeditious resolution with cross-functional issues and will coordinate all correspondence between the
proper support personnel and the client. The CSM will also communicate release/upgrade/product roadmaps and schedules to enable IT strategy.
Fusion provides CHS with 24x7x365 US based support. Our help desk team consists of a wide range of qualified Technical Support Engineers and Clinical Consultants, who are operating system software certified and have
expertise in our products, databases, network and other related application software products to our clients’ operations. Fusion prides itself on our support team’s experience and intimate know how of our clients’
workflows and operations.
Fusion will train all authorized technical and non-technical users on how to open a support ticket at any time via the dedicated helpdesk portal or the dedicated toll-free number. Our support staff utilize Jira as our web-
based incident tracking software to collect initial incident information and track progress and status of reported incidents. With our team’s familiarity with your organization and with the agreed upon SLAs, we will be able to
expedite the incident resolution time for all issues surrounding your agency.
2.8.3
Describe any additional support and maintenance offered.
Fusion prides ourself on our top of the line support we provide all clients. Our support and maintance is standard across our clientele, which is an indication of the excellent support all Fusion clients receive.
2.8.4
Specify the level of system design and build that is required from and accessible to the department (e.g.: menus, user security, order and documentation templates,
code set/dictionaries, alerts).
System configuration is completed during the project implementation. Some of the common areas that will be configured by Fusion and/or CHS includes: Forms/Encounters, Reports, System Security,Patient locations,
MedPass times, Order Sets, Medication Formularies, etc.
2.8.5
Provide the hours of operations for support, including adjustments for the Mountain Standard Time (MST) zone via all contact methods.
As a correctional EHR vendor, Fusion understands the need for 24/7/365 operations for support. Additionally, Fusion has an office located on the east coast with its standard operating hours being 8-5 EST and an office in
Central timezone that’s standard operating hours are 8-5 CST.
2.8.6
Specify the frequency of the proposed EHR system’s updates for major release levels.
Major releases and new versions typically are available every 12-18 months.
2.8.7
Specify the frequency of the proposed EHR system’s updates for minor release levels.
Minor releases are supplied approximately every 6 months
2.8.8
Specify the frequency of the proposed EHR system’s updates for hot patch fixes and emergency release levels.
Hot patches and fixes are completed as needed based on the urgency of the fix. Fusion will typically provide a monthly patching for non-urgent fixes.
2.8.9
Describe the version control process: e.g., rollbacks in scenarios where changes need to be reverted.
Fusion does have the capability to rollback versions of new releases in the event that it must be reverted. Due to Fusion's thorough testing of all new features and fuctions, through our pilot site methodology, we have not
had the need to rollback software in many occasions with our clients.
2.8.10
Describe the support process for reporting issues and requesting services.
Through the utilization of Jira Helpdesk, users can update and escalate the severity of a tcket. Additionally, if the agency needs to escalate an issue, the client will contact the agencies dedicated support staff that will
upgrade the priority level of the request at hand.
2.8.11
Describe the issue escalation process or procedure.
Through the utilization of Jira Helpdesk, users can update and escalate the severity of a tcket. Additionally, if the agency needs to escalate an issue, the client will contact the agencies dedicated support staff that will
upgrade the priority level of the request at hand.
2.8.12
Describe the method and tools to contact the support team: e.g.: phone, e-mail, web-based portal, etcetera.
Two main methods to contact support: Jira Helpdesk Ticketing System and through a toll free number. Additionally, certain staff will have direct access to our client manager.
2.8.13
Specify if the support line is answered by a human or is automated.
Suppport line is answered by a human.
2.8.14
Identify all the attached associated Service Level Agreements (SLAs).
Incident Response
To help us manage your support issues, Fusion’s Support Services use a three-tiered priority system to log application support service requests. To help manage technical support issues, clients are asked to identify the
priority of the issue according to the following guidelines. Fusion encourages clients to report Emergency and High issues by telephone because of the escalated response time. Fusion’s average percentage of first-call
resolutions is at 95%. It is important to note that while many Fusion team members help with behind-the-scenes troubleshooting, CHS will maintain contact with a designated team member throughout the incident process.
Incident Level 3 – Immediate Initial Response
Contact Methods: Fusion Support Line & Fusion Help Desk Portal (24x7)
1. FusionEHR client will not launch for all users.
2. FusionEHR applications will not load for all users and the user has the appropriate security permissions to access the applications
3. An incident where patient care may be affected that was triaged by facility superusers and/or IT.
* For the fastest resolution, it is recommended that CHS open a helpdesk ticket with the appropriate issue type as well as a call to our support line.
Incident Level 2 – Immediate to 12-hour initial response
Contact Method: Fusion Help Desk Portal (24x7)
1. Interface-related issues such as demographics not importing, lab results not importing, or pharmacy message errors.
2. Defects relating to clinical content (FusionEHR encounters/forms).
3. Component of the system not functioning as designed.
Incident Level 1– Immediate to 24 business hour response.
Contact Method: Fusion Help Desk Portal (24x7)
1. Functionality questions.
2. Clinical content or report enhancements.
3. Component of the system not functioning as expected.
2.8.15
Describe which upgrades are included within the software maintenance contract.
All upgrades are included within the software maintenance of the contract for the entirety of the contract.
2.8.16
Describe the process model for enhancement requests to customize the EHR for both pre-implementation and post-implementation.
Fusion’s pre-planned roadmap, we provide numerous ways for clients to submit suggestions for product enhancements and work closely with our clients in implementing suggested improvements and features in future
releases. Through the duration of our partnership, all suggestions and system improvement ideas will be discussed and submitted to our team. Prior to each development cycle all enhancement requests are pulled into a
report, and ranked by how often they have been requested, and this forms the basis of the initial list of enhancements to be considered. This is true for pre and post implementation.
2.8.17
Describe how formal user groups and online community forums are facilitated.
Our user community is very active in sharing creative solutions among themselves, at their own discretion, which is especially useful since templates can be exported by one group and imported by another through Fusion.
Fusion places no restrictions on this activity and works to promote it since users often create extremely useful solutions that many other groups could benefit from. However, a customization or configuration that is created
for a client may remain proprietary to them if they so wish.
Fusion also holds user group at annual conferences for the NCCHC and ACA. Fusion is always promoting collaboration between users and user groups.
2.8.18
Specify the tools available today to support a user community, such as: Frequently Asked Questions (FAQs).
FusionEHR has two options to cover FAQ's and Help. On any screen within the EHR, we have a Help section that allows users to walk through commonly asked tasks and workflows within the EHR. Additionally, when a user
needs to put in a ticket, Fusion provides predictive and commonly asked questions to try and assist the user.
2.8.19
Describe the services offered for optimization of the system post-implementation.
Fusion’s ongoing maintenance of FusionEHR will include performance optimization, database management, software and tools (e.g., patches, upgrades, and replacement to include testing), interface, report, and
correspondence changes, and making corrections or changes to maintain the integrity of the system or the data within it.
2.8.20
Specify if monitoring tools for technical support applications include access to viewing the end-user’s screen.
Fusion's monitoring tools currently do not access viewing end-user's screens unless a formal screen share is initiated.
2.8.21
Describe how current code bases are maintained, e.g.: International Classification of Diseases (ICD), Current Procedural Terminology (CPT), Diagnostic and Statistical
Manual (DSM), etcetera.
Code based are maintaned and updated through a regular knowledge based update.
2.8.22
Specify the process by which clinical content (e.g.: evidence-based tools, drug interactions) and patient education materials are updated.
Drug interactions, patient education are maintaned and updated through a monthly knowledge based update.
2.8.23
Describe any included network products and/or services that the department will receive.
Maricopa County will receive access to the solution. Fusion leverages multiple products and tools to help monitor and support the solution. Including SentinelOne for antivirus and malware detection, Rapid7 for penetration
vulnerabilities, SolarWinds for patch management and deploymnet and availability alerts.
2.8.24
Describe other network products and/or services.
All network products and services will be included have been listed in 2.8.23.
2.8.25
Specify the required staff support from the department.
Department support staff will manage and monitor user accounts and local networking issues.
System Requirements
Vendor Responses
Section
Requirement Description
Explanations
2.9
BUSINESS CONTINUITY; DISASTER RECOVERY; DATA BACKUP and RESTORE; ARCHIVE, RETENTION and DISPOSAL PRACTICES: The proposed EHR system must include the
mandatory requirements as listed in the section below.
Provide detailed information in narrative and/or diagrammatic description format and identify any corresponding attachments.
2.9.1
Describe the current and proposed business continuity practices and approaches as they relate to the daily operation and possible interruptions of service (outages). This should include
a description of the data configuration model and the redundancy capabilities including, but not limited to: telecommunications, geographic isolation of the data centers. The response
must include a graphical representation of the process and the location(s) of backup data centers.
Fusion’s Standard Disaster Recovery
Fusion provides you with a robust, client-specific Disaster Recovery plan that is designed to mitigate short-term outages and provides solutions quickly. Our disaster recovery plan is
reviewed annually, refreshed as needed, and promotes optimal performance and usage of FusionEHR throughout the enterprise providing CHS with:
• Minimized interruptions to normal operations.
• Limited disruption and damage.
• Minimized economic impact of the interruption.
• Established alternative means of operation in advance.
• Trained personnel with emergency procedures.
• Smooth and rapid restoration of service.
Fusion’s Disaster Recovery plan follows a 5-step process starting with disaster readiness ending with CHS returning to normal operations.
Disaster Readiness, Risk Assessment, Communication Process, Failover, Backup and Disaster Recovery, and Disaster Retrospective.
As stated in the response, Fusion leverages Microsoft Azure Governement for our data centers. Due to the counties location we will leverage data centers located in the Central and
Western regions of the US.
2.9.2
Describe the current and proposed data backup and restore practices. This response must include an explanation of the standards, procedures, methods, cycles, turnover, retention
periods, and off-site capabilities. The response must specify the encryption used for backups and describe any relevant key management practices.
FusionEHR leverages Microsoft Server, Microsoft SQL, to support industry-standard High Availability, DR strategies, tools, process, and procedures that secure industrial internet
solutions. Fusion will develop a customized and rigorous DR Plan for CHS. Fusion adheres to many of the industry best practices for Disaster Recovery, making Fusion overly prepared in
the case of a disaster.
FusionEHR offers full backups at block level every 15 minutes with adjustable frequency to the tolerance level of PDOC’s desire and performance configuration of the server array. Time
to restore will be a function of the volume of data being restored and the performance of the storage area environment. Offsite backups and log shipping are available to the extent of
CHS’ needs and the scope of the project.
Hot backups are conducted daily with snapshots of the database taken as well. The database backup is then archived for up to 28 days to allow for full restoration. In addition,
transaction logs are also created consistently which allow for rapid recovery should the event arise.
Recovery procedures are tested to ensure restoration procedures are operational. Also, testing will be conducted with CHS’ testing environment to ensure that both the backups work as
designed as well as to ensure recent test data is available. Should system modification be performed between the scheduled recovery tests, it will be conducted immediately before the
planned update/upgrade as well as following the commitment of the updates to the system.
For enhanced 24/7/365 monitoring, Fusion utilizes industry-leading monitoring systems to observe system activity and prevent and detect intrusion, hacking, unusual activity, or system
compromise. Rapid7, Solarwinds MSP, and SentinelOne are antivirus and intrusion protection software solutions that support the entire vulnerability management lifecycle, including
discovery, detection, verification, risk classification, impact analysis, reporting, and mitigation. Fusion’s use and constant monitoring of our Hosting Centers allow us to avoid threats
before they occur.
2.9.3
An industry-recognized backup methodology must be employed, including the use of off-site storage. The contractor must make backup procedures and logs available at any time upon
request from the County.
As stated in the above response, Fusion has a proven backup and recovery methodology that includes offsite storage and transaction logs. These can be provided to the county upon
request.
2.9.4
Describe the current and proposed disaster recovery procedures and standards. The response must explain how the system implementation will cover any disruptions in service
(outages) and minimize any downtime.
Back up procedures will be defined by Fusion, our scalable and highly redundant load balanced architecture ensures high availability, business continuity, and disaster recovery. In the
event of disaster recovery, which includes full loss of all resources, we can entirely rebuild the system(s) (to fully functional) in a very short amount of time since we back up the file
systems and databases to an encrypted private cloud system archived for up to 28 days. The recovery time is based on data size.
During any outage, Fusion will devote all resources to recovery. We will work diligently and expeditiously to re-establish a stable connection to your production environment. Once
restored, Fusion will work with all parties to discover the root cause of the problem and work towards preventative measures. Along the way, we will be in constant contact with CHS to
advise you of the situation, guide aspects of FusionEHR that will be affected, and provide timelines for a full recovery.
2.9.5
Describe how the system will meet the Federal, State, and local Public Record Retention requirements for the effective and efficient archive, retention, and disposal of the electronic
data that is entered, stored, handled, and/or distributed by the proposed system, including compliance with Health Insurance Portability and Accountability Act (HIPAA) rules and
regulatory standards, as well as Health Information Technology for Economic and Clinical Health (HITECH) regulations.
Our business continuity plan is dependent on the hosting architecture selected by CHS. For this project, we have proposed that FusionEHR be cloud hosted utilizing Microsoft s Azure
Government platform. This means we can provide to you a Tier 4 hosting environment built on best-in-class technology. The data centers all are SSAE-18 audited and are FedRAMP, FIPS,
NIST, CJIS, ISO, SOC-2, and HIPAA compliant.
Azure Government has earned a P-ATO at the High Impact Level from the Joint Authorization Board, the highest bar for FedRAMP accreditation, which authorizes the use of Azure
Government to process highly sensitive data. The FedRAMP audit of Azure Government included the information security management system that encompasses infrastructure,
development, operations, management, and support of in-scope services.
System Requirements
Vendor Responses
Section
Requirement Description
Explanations
2.10
HOSTING REQUIREMENTS: The proposed EHR system must include the hosting requirements as listed in the section below.
Provide detailed information in narrative and/or diagrammatic description format and identify any corresponding attachments.
2.10.1
Identify the attached copies of any security policies, procedures, or standards relevant to the hosted solution. The contractor shall make their information security incident response
policy and procedure available to the County upon request.
Please reference Fusion's standard Support and Maintenance as a separate attachment labeled Fusion Health - Access Control Policy - CONFIDENTIAL.
2.10.2
The data center required for proper functionality of the proposed EHR system shall achieve a minimum 99.6% monthly uptime. Uptime measurements must be met for all servers and
their connectivity to the Internet or dedicated connection to the County, whichever is applicable. Specify the minimum monthly uptime.
The proposed data center for the EHR system meets and exceeds the minimum of 99.6% uptime.
2.10.3
The application response time (defined as the time it takes to completely render the user interface after a user action) shall not be less than the established time limits for other similar
users of the application in the data center: probably less than one (1) second under normal circumstances. Unacceptable response times shall be considered to make the program
unavailable and will count against the 99.9% uptime metric. Specify application response time.
Application response time includes multiple factors such as internet speed and availability. If in an appropriate area in the facility with standard internet speed and bandwidth Fusion will
meet the agencies applications response time under normal circumstances.
2.10.4
The EHR system must be housed using one of the following options: 1) Fully internet available Software as a Service (SaaS) solution with other access controls, such as: Internet Protocol
(IP) address restrictions and device certifications; 2) The contractor’s own servers; 3) A third-party hosting site that would be accessed via high speed private or dedicated leased lines and
connecting to the County’s Virtual Private Network (VPN) via the Internet. Specify which hosting location the system will use.
Fusion offers multiple options for the County.
1. The solution can be public facing, meaning it is accessible from any network and device.
2. The solution can be IP filtered (Private Facing), only devices within your facilities would be able to access the solution.
3. Maricopa Hosts the solution yourself.
2.10.5
If applicable based on the response to the question above, the location of servers is discretionary but must be within the continental United States, preferably in non-earthquake, non-
hurricane, and non-flood zone areas. Describe recommendations for location of both the main servers and back-up servers, based on the dynamics of the integration model, while
considering efficiency, cost, and security. Mixed-model solutions will also be considered.
Microsoft Azure Government has their data centers strategically in each region of the US. They are strategically located in non-earthquake, non-hurricane, and non- fllood zone areas.
Due to Maricopa County being located in Arizona, Fusion will likely leverage the Central and Western Regions.
2.10.6
Where applicable, contractor connectivity will use a commercial Internet Service Provider (ISP) with Virtual Private Networking (VPN), or similar tunneling. The County shall not be
financially responsible for networking equipment at the contractor's site.
If Fusion is hosting, the County will incur no additional costs. If the County is hosting, you will need to provide VPN seats for the County access.
System Requirements
Section
Requirement Description
Explanation
2.11
DATA SECURITY: The proposed EHR system must comply with the data security requirements as listed in the section below.
Compliance
Non-Compliance
Provide detailed information in narrative format to support the compliance rating and identify any corresponding attachments.
2.11.1
Contractor shall bear the sole responsibility and total cost of any security breach and/or data loss for which the County has no control.
X
Fusion agree to bear the sole responsibility and total cost of any security breach and/or data loss for which the County has no control.
2.11.2
Contractor shall be required to report all suspected security breaches within 24 hours of detection in writing to the County and be obligated to fully cooperate in
investigations of said security breach(es).
X
Fusion shall report all suspected security breaches within 24 hours of detection in writing to the County and be obligated to fully cooperate in
investigations of said security breach(es).
2.11.3
At no time can County data be transmitted, transferred, or stored to any site or company outside the United States.
X
Fusion agrees that at no time County data be transmitted, transferred, or stored to any site or company outside the United States.
2.11.4
Transfer of patient or confidential data to a third-party requires first obtaining prior written approval from the County.
X
Fusion agrees that we will obtain written approval from the county prior to transfering patient or confidential data to a third-parties.
2.11.5
Data and database must be secured/encrypted using the Advanced Encryption Standard (AES) with a minimum of a 128-bit key at all times.
X
Fusion ensure that the data is encrypted in transit and at rest. SSL in transit and AES at rest.
2.11.6
Contractor must provide a third-party security assessment report (SOC 2) on an annual basis -OR - agree to allow a security assessment to be performed by Maricopa County
or authorized subcontractor of Maricopa County. Describe how often risk assessments of the environment are performed by external parties and indicate agreement to
provide the results upon request.
X
Microsoft Azure Governement provides all users with the ability to review their SOC 2 Report as well as others reports. These reports are updated on a
regular basis. If the Microsoft Azure SOC2 report is insufficient, Fusion will discuss an alternate plan with Maricopa County.
2.11.7
Contractor must agree to all terms set forth in Exhibit 7: CORRECTIONAL HEALTH SERVICES’ BUSINESS ASSOCIATES AGREEMENT. The Business Associate Agreement must be
maintained for the life of the contract.
X
Fusion agrees to the terms in Exhibit 7 Correctional Health Service's BAA.
2.11.8
Backups to removable media must be encrypted using the Advanced Encryption Standard (AES) with a minimum of a 128-bit key. At no time shall the key be stored on the
backup media in clear text, including but not limited to table labels. The contractor must make backup procedures and logs available at any time upon request from the
County.
X
All data stored by Fusion is encrypted (SSL in transit and AES at Rest) . Fusion will make backup procedures and logs available at any time upon request
from the County.
2.11.9
Hosted applications must support encrypted protocols for sensitive data. Preferred encryption protocols are Transport Layer Security (TLS) or Internet Protocol Security
(IPsec). Encryption ciphers must use at least a 128-bit key length. Hashing algorithms used must be of the Secure Hash Algorithm (SHA) family. The minimum acceptable
algorithm shall be SHA-2.
X
All data within FusionEHR is encrypted with Advanced Encryption Standard (AES) encryption with a SHA2/SHA-256 hash Algorithm. SQL Server has built-
in encryption capabilities for PHI data and can encrypt both at rest and data in motion via AES and SSL. CEHR provides encrypted passwords and
encryption at the VPN level, Internet, Intranets, and wireless networks and devices. User account access can be reviewed by CHS as necessary, and
should any responsibilities change within the organization CHS can modify/disable said roles appropriately. Any unneeded hardware, software, and
licenses can be decommissioned as needed.
2.11.10
The contractor must maintain a Non-Disclosure Agreement (NDA) with the County. All employees of the contractor must maintain an NDA with the contractor.
X
Since Fusion is hosting the EHR solution, it is not standard protocol to have an individual level NDA for each Fusion employee accessing the County
Data. If this is required Fusion will agree although in our experience a company NDA should suffice.
2.11.11
All employees of the contractor must pass a federal, state, and local criminal background check. Any employee who fails the background check shall not have any access to
County data unless specifically authorized by Maricopa County in writing. The contractor shall make personnel and background check procedures available for inspection at
any time upon request from the County.
X
Fusion agrees that all employees must pass a federal, state, and local criminal background check. Fusion shall make personnel and background check
procedures available for inspection at any time upon request from the County.
2.11.12
Breach notification requirements shall be determined by all applicable laws and contracts including, but not limited to, requirements as detailed in section 2.1: COMPLIANCE.
X
Fusion agrees to the breach notification requirements detailed in section 2.1: COMPLIANCE.
2.11.13
Contractor must comply with all applicable laws, regulations, and requirements as detailed in section 2.1: COMPLIANCE.
X
Fusion complies with all applicable laws, regulations, and requirements as detailed in section 2.1: COMPLIANCE.
2.11.14
Contractor must make compliance reports, audit findings, and third-party attestations available to the County upon request.
X
Fusion shall make compliance reports, audit findings, and third-party attestations available to the County upon request.
2.11.15
Contractor must notify the County, in writing, within 24 hours of a confirmed violation of the compliance requirement. The notification must include any information
provided by the regulatory body.
X
Fusion shall notify the County, in writing, within 24 hours of a confirmed violation of the compliance requirement. The notification must include any
information provided by the regulatory body.
2.11.16
Contractor shall destroy all offline copies of County data at the time it ceases to be useful. Destruction procedures must be made available to the County upon request.
X
Fusion shall destroy all offline copies of County data at the time it ceases to be useful. Fusion shall provide our destruction procedures upon request.
2.11.17
At the conclusion of the contract, all Maricopa County data and working papers must be returned to the County and all contractor copies destroyed. Contractor must
confirm in writing to the County that all data was destroyed in accordance with this agreement and state the methodology used.
X
At the conclusion of the contract, Fusion agrees to return all Maricopa County data and working papers to the County and all contractor copies
destroyed. Fusion shall confirm in writing to the County that all data was destroyed in accordance with this agreement and state the methodology used.
Vendor Responses
Rate the proposed EHR system by placing an “X” in
the appropriate category:
System Requirements
Explanation
ID
Standard
National Institute of Standards and Technology (NIST) Questionnaire
Yes
No
Provide comments and identify any corresponding attachments.
S.1
NIST SP 800-53 Access Control
Do you have a procedure for restricting employees from accessing our information? (Can only authorized personnel on your staff access
information and/or resources which are owned by Maricopa County, and can you demonstrate how you control such access)?
X
Fusion maintains an access control policy/procedure that is reviewed regularly. Our access control policy outlines our
procedures restricting users from accessing client information unless authorized. Fusion monitors internal resources to
ensure that only the appropriate resources are accessing client information.
S.2
NIST SP 800-53 Awareness and Training
Do you provide security training and awareness to members of your staff who will have access to Maricopa County information and resources?
(Can you provide Maricopa County with the content that you use to train members of your staff)?
X
Each of Fusion's employees are trained during their onboard with respects to their specific role and the controls which
they must fulfill. Each staff member also undergoes annual retraining. Fusion considers its security policies and
procedures documents confidential, however we would be willing to share this document during contracting if
requested.
S.3
NIST SP 800-53 Audit and Accountability
Do you log and record transactions initiated by members of your staff who have access to Maricopa County information and operated resources
(Can you provide us with a sample of logs which show user transactions)?
X
Yes, Fusion logs all activities that are happening within the EHR solution. Regardless if it is Maricopa staff or Fusion staff,
users audit logs will be maintained and are viewable by administrative users.
S.4
NIST SP 800-53 Configuration Management
Do you maintain secure baseline security configurations on your computer information systems which house Maricopa County data (for example
do you configure your systems in accordance with NIST FDCC standards or DISA Security Technical Implementation Guidelines)?
X
Yes all Fusion Data Centers are SSAE-18 audited and are FedRAMP, FIPS, NIST, CJIS, ISO, SOC-2, and HIPAA compliant.
S.5
NIST SP 800-53 Security Assessment and Authorization
Do you pay a third party to at least annually conduct a security assessment of your computing environment, including penetration testing and an
evaluation of your security policies, processes and procedures (Can you provide Maricopa County with evidence that demonstrates that such an
assessment was accomplished including the results)?
X
Fusion provides third party audits on a per client basis. If Microsoft Azure Governments audit by an AICPA accredited CPA
firm is not sufficient, Fusion is willing to work with a CPA firm to accomadate this request.
S.6
NIST SP 800-53 Contingency Planning
Do you maintain a contingency plan which outlines how you will backup and restore Maricopa County data that you might hold on site (Can you
provide Maricopa County with a copy of your contingency plan)?
X
Yes, Fusion will work with Maricopa County to develop a client specific contingency plan. Our standard parameters can
be found in Section 2.9 Contingency Plan.
S.7
NIST SP 800-53 Contingency Planning
Do you perform Disaster Recovery testing?
X
Fusion test our Business Continuity andd Disaster Recovery Plan annually.
S.8
NIST SP 800-53 Identification and Authentication
Do you require all members of your staff who will have access to Maricopa County information and resources to have unique identifiers and to use
authentication practices that meet best practices and standards (For example do all users have unique user IDs and are all user passwords required
to be at least 8 characters in length, require a mix of uppercase, lowercase, special character, and numbers and can you provide us with a sample
list of users and their associated user IDs matched to their names, in addition to your internal password policy as a screenshot from your domain,
workstation or server policy)?
X
Yes, Fusion requres all staff members to have unique identifiers and to use authentication practices that meet bedt
practice standards. An example of our required security standards are seen below:
- Enforce Password History - 5 Passwords Remembered
- Maximum Password Age - 90 Days
- Minimum Password Age - 1 Day
- Minimum Password Length - 7 Characters
- Password must meet complexity Requirements - Enabled
S.9
NIST SP 800-53 Incident Response
Does your organization have a defined level of incident that triggers reporting to Maricopa County? If so, please describe what characterizes this
reporting level. Can you provide your incident response policy?
X
Yes, Fusion has defined levels of incident reporting. We utilizes Rapid7 and SolarWinds to monitor system activity and
prevent and detect intrusion, hacking, unusual activity, or system compromise. Rapid 7 allows for enhanced security
incident reporting and mitigation mechanisms. Fusion will preserve and report specified audit data if security violations
are detected and mitigated.
S.10
NIST SP 800-53 Incident Response
Do you maintain a process that is documented, including workflows which illustrate how you identify cyber security incidents, how you notify
affected parties of incidents, procedures to contain identified incidents, eradication strategies for incidents and how you would recover from
incidents (Can you provide Maricopa County with an example of how you have tested and executed your incident response plan)?
X
For enhanced 24/7/365 monitoring, Fusion utilizes industry-leading monitoring systems to observe system activity and
prevent and detect intrusion, hacking, unusual activity, or system compromise. Rapid7, Solarwinds MSP, and SentinelOne
are antivirus and intrusion protection software solutions that support the entire vulnerability management lifecycle,
including discovery, detection, verification, risk classification, impact analysis, reporting, and mitigation. Fusion’s use and
constant monitoring of our Hosting Centers allow us to avoid threats before they occur. Additional information regarding
our monitoring tools and our incident response plan have been provided within Fusion Health's Proposal.
S.11
NIST SP 800-53 Maintenance
Do you allow third parties (for example vendors, consultants, etc.) external to your organization to access Maricopa County information and
resources; including systems containing our data at your facility (Can you tell us what your security processes are for managing maintenance
personnel access)?
X
Fusion does not allow any third parties.
S.12
NIST SP 800-53 Media Protection
Do you store Maricopa County data on any media and if you do, is the media non-portable (for example, Maricopa County data is not stored on
CDROMs, USB Drives, etc.) and is Maricopa County data encrypted in storage (Can you provide us with a description of how you will store our data
and evidence which demonstrates that it will never be moved to mobile media)?
X
The software can be either public or private facing. The data is encrypted in transit and at rest. SSL in transit and AES at
rest.
S.13
NIST SP 800-53 Physical and Environmental Protection
Do you pay a third party to at least annually conduct a physical and environmental security assessment of your computing environment (i.e. data
center) including where members of your staff will access Maricopa County information and resources (Can you provide us with the results of any
physical security assessments which have been conducted)?
X
Azure government takes a layered approach to physical security, Access request and approval, Facility’s perimeter.
Building entrance. Inside building security. Datacenter floor security.
Periodically, Microsoft Azure conducts physical security reviews of the facilities, to ensure the datacenters properly
address Azure security requirements. The datacenter hosting provider personnel do not provide Azure service
management. Personnel can't sign in to Azure systems and don't have physical access to the Azure collocation room and
cages.
S.14
NIST SP 800-53 Planning
Do you maintain a Security Program Plan which documents how you manage security within your environment (Can you provide us with a copy of
your security program plan)?
X
Please reference Fusion's standard Support and Maintenance as a separate attachment labeled Fusion Health - Access
Control Policy - CONFIDENTIAL.
S.15
NIST SP 800-53 Personnel Security
Do you require all members of your staff with access to Maricopa County information and resources to undergo a background investigation which
includes verification of their social security numbers, as well as a criminal history check, and do you have adjudication procedures which are used
to deny or accept employment based on the results of the criminal history check and social security number verification (Can you provide us with a
copy of your adjudication criteria)?
X
Fusion leverages a credible third party vendor to perform all background checks on our employees. The following items
are included in all employee background searches: County Criminal Court Search, Federal Criminal Court Search, Motor
Vehicle Records Search, Nationwide Criminal Database Search, Social Security Number Trace, and Sex Offender Registry
Search.
S.16
NIST SP 800-53 Risk Assessment
Do you conduct internal risk assessments of the systems that you will be using to house Maricopa County information and resources? (Can you
provide us with your risk assessment methodology as well as the results of any assessments conducted for assets you own which you plan to use to
connect to our resources)?
X
Fusion conducts risk assessments associated with data governance requirements on an annual basis.
S.17
NIST SP 800-53 System and Services Acquisition
Do the systems and resources that you use to store Maricopa County information and resources meet the requirements which have been
identified in sections; SA-9, SA-10, SA-11, SA-12, and SA-13 of the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-
53? (Can you demonstrate that you have assessed the systems that you plan on using for accessing Maricopa County owned and operated
resources)?
X
Fusion leverages Microsoft Azure Government Encryption at rest, Encryption in transit,Environment isolation IETF RFC
4271. Microsoft Azure Governements 'Azure Policies' include regulatory compliance for NIST SP 800-53.
S.18
NIST SP 800-53 System Communications Protection
Do you ensure that communications between your site and Maricopa County maintain proper communications protections which would prevent;
eavesdropping, man in the middle attacks or any other attack which could be used to access Maricopa County data (Can you provide us with an
illustration on how you protect communications between each site, for example an diagram of how your sites VPN solution is set up or a network
topology diagram)?
X
We will work with your IT to establish a proper IP filter tunnel during kickoff of the implementation. This tunnel will be
isolated to only Maricopa devices and networks.
S.19
NIST SP 800-53 System and Information Integrity
Do you maintain integrity protections on systems that you will use to access Maricopa County information and resources (For example do you
maintain anti-virus and patch management on all systems that you will use to access Maricopa County information and resources and can you tell
us specifically which Antivirus programs you use to accomplish this as well as your process for patching)?
X
Fusion leverages Rapid7 , which is an aggressive antivirus and intrusion protection software which aims to support the
entire vulnerability management lifecycle, including discovery, detection, verification, risk classification, impact analysis,
reporting and mitigation.
S.20
NIST SP 800-53 Access Control
Is the product capable of restricting access to defined assets and networks?
X
Fusion maintains a whitelist only approach as to what applications are authorized for installation on any of its servers and
computers. Access to install applications are given only to administrative level staff to prevent installation of
unauthorized applications. A daily log is generated of applications installed on each device on Fusion's network.
S.21
NIST SP 800-53 External Information System Services
Do you have a method for providing ongoing visibility of SLA performance?
X
All tickets are tracked and timestamped to allow for visibility and tracking ability to ensure they are meeting SLA's.
P.1
NIST SP 800-53 Access Control
Does the product support the creation of unique user identifiers and associated authentication features that can be integrated using lightweight
access directory protocol and secure lightweight directory access protocol (LDAP)?
X
Yes, FusionEHR supports the creation of unique user identifiers and associated authentication features that can be
integrated using lightweight access directory protocol and secure lightweight directory access protocol (LDAP)
P.2
NIST SP 800-53 Access Control
Does the product allow configuration of access control groups for unique user identifiers?
X
Yes, FusionEHR allows configuration of access control groups for unique user identifiers
P.3
NIST SP 800-53 Access Control
Is the product capable of demonstrating approval of unique user identifiers by an authorizing party (e.g., super user/administrator)?
X
Yes, FusionEHR is capable of demonstrating approval of unique user identifiers by an authorizing party (e.g., super
user/administrator)
P.4
NIST SP 800-53 Access Control
Does the product support access restrictions based on group assignments including unique identifiers or groups which can read, write and execute
files, commands or code associated with commands?
X
Yes, this is standard system security within FusionEHR.
P.5
NIST SP 800-53 Access Control
Does the product allow unique user identifiers to be activated, deactivated, and/or deleted?
X
Yes, Fusion permits CHS to have the ability to activate, deactivate, and/or delte users identifiers, logins etc.
P.6
NIST SP 800-53 Access Control
Does the product support the ability to automatically disable access based on a preset period of time established by Maricopa County?
X
Modification of User Access will be controlled by agencies administrative users through Active Directory Administrive
Center.
P.7
NIST SP 800-53 Access Control
Does the product support audit logging and email notification in the event of account creation, modification, disabling and termination actions?
X
Modification of User Access will be controlled by agencies administrative users through Active Directory Administrive
Center.
P.8
NIST SP 800-53 Access Control
Does the product support automatic logout in the event of inactivity from unique user identifiers?
X
Yes, inactivity peremeters can be set to auto log out users due to inactivity.
P.9
NIST SP 800-53 Access Control
Does the product allow monitoring and reporting (e.g., email) of system account usage?
X
All audit reports provided by FusionEHR can be run automatical and sent to specified staff.
P.10
NIST SP 800-53 Access Control
Does the product support automated alerts in the event that a unique user identifier or system account is used outside of a preset period of time
as determined by Maricopa County?
X
Yes, FusionEHR supports automated alerts in the event that a unique user identifier or system account is used outside of
a preset period of time as determined by Maricopa County
P.11
NIST SP 800-53 Access Control
Does the product allow reporting on atypical usage of unique user identifier or system accounts via electronic mail?
X
Additional information would be needed to define atypical usage. Our audit reports are robust.
P.12
NIST SP 800-53 Access Control
Does the product support reporting on user privileges via electronic mail (e.g., can it generate a report on user access permissions or assignments)?
X
FusionEHR has a system security area that can be accessed by administrative users. This section allows users to see users
and user groups security levels and access.
P.13
NIST SP 800-53 Access Control
Is the product capable of tracking and monitoring the assignment of privileged roles (privileged roles are defined as unique user identifiers or
system accounts with read, write and execute permissions) via electronic mail?
X
FusionEHR has a system security area that can be accessed by administrative users. This section allows users to see users
and user groups security levels and access. Including who has read, write, and admin privelages.
P.14
NIST SP 800-53 Access Control
Does the product support the ability to restrict access to it by Internet Protocol Address?
X
Yes. Fusion can WhiteList IP Addresses.
P.15
NIST SP 800-53 Access Control
Does the product support assignment of discretionary or mandatory access control?
X
DAC
P.16
NIST SP 800-53 Access Control
Is the product capable of preventing encrypted data from bypassing content-checking mechanisms?
X
Yes.
P.17
NIST SP 800-53 Access Control
Does the product allow configuration of unique user identifiers and system accounts with different access permissions separating key functions
based on user or group (i.e., separation of duties)?
X
Yes.
P.18
NIST SP 800-53 Access Control
Is the product capable of restricting access based on role or group (e.g., group account policy)?
X
Yes.
P.19
NIST SP 800-53 Access Control
Is the product capable of logging unsuccessful logon attempts and automatically disabling unique user identifiers or system accounts based on a
present number of unsuccessful attempts as defined by Maricopa County?
X
Yes.
P.20
NIST SP 800-53 Access Control
Does the product support configuration of a logon banner prior to permitting access that has content defined by Maricopa County?
X
The logon banner is standard across our clientele. It includes User Name, User Password, and User Location.
P.21
NIST SP 800-53 Access Control
Does the product support logging of last successful and unsuccessful logon attempt for unique identifiers?
X
Yes.
P.22
NIST SP 800-53 Access Control
Is the product capable of restricting the number of sessions that are allowed to be established as defined by Maricopa County?
X
Yes.
P.23
NIST SP 800-53 Access Control
Is the product capable of locking a session automatically after a preset period of time as defined by Maricopa County?
X
Yes.
P.24
NIST SP 800-53 Access Control
Is the product capable of requiring all transactions have an associated unique user identifier or system account prior to transaction initiation?
X
Yes, a user will not be able to access the system unless the identifier and password.
P.25
NIST SP 800-53 Access Control
Is the product capable of tagging information with access permission rights, so that the information can only be viewed with proper credentials
regardless of where it is stored?
X
Yes. As an example, certain patients can be tagged confidential which shall limit the specific users that can access the
patients chart.
P.26
NIST SP 800-53 Access Control
Is the product capable of restricting remote access except through approved Maricopa County mediums such as the Virtual Private Networking
(VPN) infrastructure?
X
Yes.
P.27
NIST SP 800-53 Access Control
Is the product capable of restricting unique user identifiers' access to other unique user identifiers' information, directory structure, etc. unless
otherwise permitted by a user with super user/administrative access?
X
Unique user identifiers will be managed through Active Directory, thus only AD administrators will have access.
P.28
NIST SP 800-53 Audit and Accountability
Is the product capable of logging and recording all unique user identifier activity and system account activity?
X
Yes.
P.29
NIST SP 800-53 Audit and Accountability
Is the product capable of logging and recording all changes which occur on the asset including applications, databases, network or system operating
systems?
X
Yes.
P.30
NIST SP 800-53 Audit and Accountability
Is the product capable of logging system and activity transactions including date, time and whether the event was successful?
X
Yes.
P.31
NIST SP 800-53 Audit and Accountability
Is the product capable of storing log data on a predefined amount of storage as defined by Maricopa County?
X
Yes.
P.32
NIST SP 800-53 Audit and Accountability
Is the product capable of alerting via email if log data is not successfully recorded?
X
Yes.
P.33
NIST SP 800-53 Audit and Accountability
Is the product capable of recording software / hardware errors and when storage capacity has been reached?
X
Yes.
P.34
NIST SP 800-53 Audit and Accountability
Is the product capable of logging messages using the “syslog” or “syslog-ng” protocol in compliance with FC 3164?
X
System can log Syslog-ng and syslog messages.
P.35
NIST SP 800-53 Audit and Accountability
Does the product support filtering capabilities for all specified log types that are captured by the asset (e.g., application, database, network or
system operating systems)?
X
Yes.
P.36
NIST SP 800-53 Audit and Accountability
Does the product support time stamps of transactions and events for purposes of logging?
X
Yes, FusionEHR supports time stamps of transactions for the purposes of logging.
P.37
NIST SP 800-53 Audit and Accountability
Does the product support data storage using encryption algorithms that exceed the strength of 256-bit advanced encryption standard?
X
Yes, Fusion encrypts all data with a SHA2/SHA-256 hash Algorithm
P.38
NIST SP 800-53 Audit and Accountability
Does the product support utilization of hashing and/or generally accepted digital signature-based technology to provide non-repudiation of logs
stored or transmitted from the asset including applications, database, network or system operating systems?
X
Yes, Fusion encrypts all data with a SHA2/SHA-256 hash Algorithm. The solution is secured through an issued TLS SSL
certificate.
P.39
NIST SP 800-53 Audit and Accountability
Does the product support the retention of log data for a preset period of time (in storage) as defined by Maricopa County?
X
Fusion can retain log data for a preset time period. Fusion will discuss with the County the requested time period to
confirm this can be accomadated
P.40
NIST SP 800-53 Identification and Authorization
Does the product require unique user identification before access is granted to an asset including applications, databases, network or system
operating platforms?
X
Yes, unique identification is required before accessing any asset.
P.41
NIST SP 800-53 Identification and Authorization
Does the product require unique system identification before system-to-system access is allowed?
X
Yes.
P.42
NIST SP 800-53 Identification and Authorization
Is the product capable of establishing user accounts based on unique attributes such as last names, initials, etc. at the discretion of Maricopa
County?
X
Yes.
P.43
NIST SP 800-53 Identification and Authorization
Is the product capable of restricting the permanent use of a unique user identifier that has already been used?
X
Yes.
P.44
NIST SP 800-53 Identification and Authorization
Does the product require the authentication of a unique user identifier prior to permitting access to the requested resource?
X
Yes.
P.45
NIST SP 800-53 Identification and Authorization
Is the product capable of supporting password strings of at least 15 characters during password authentication?
X
Yes.
P.46
NIST SP 800-53 Identification and Authorization
Is the product capable of enforcing password complexity which requires the use of at least 1 uppercase, 1 lowercase, 1 special character, and 1
number?
X
Yes.
P.47
NIST SP 800-53 Identification and Authorization
Is the product capable of enforcing that new passwords for unique user identifiers cannot use previous password sequences where at least 6
characters are being reused?
X
Yes.
P.48
NIST SP 800-53 Identification and Authorization
Does the product support password storage use at least 256-bit advanced encryption standard?
X
Yes.
P.49
NIST SP 800-53 Identification and Authorization
Is the product capable of expiring passwords and requiring unique user identifiers to change their password after a preset period of time not to
exceed 365 days and at the discretion of Maricopa County?
X
Yes.
P.50
NIST SP 800-53 Identification and Authorization
Does the product support the use of Public Key infrastructure (PKI) including validation of certificates through the construction of certification
paths with status information to an accepted trust anchor?
X
Fusion has a unique wildcard SSL for encryption. That is specifically used for your agency.
P.51
NIST 800-53 System and Communications Protection
Do you have a key management system?
X
Yes.
P.52
NIST SP 800-53 Identification and Authorization
Does the product support the use of PKI including enforcement of authorized access to the corresponding private keys? (auditing/tracking of
private storage)
X
Fusion has a unique wildcard SSL for encryption. That is specifically used for your agency.
P.53
NIST SP 800-53 Identification and Authorization
Does the product support the use of PKI maps authenticated identities to unique user identifiers? (need to have a table mapping certificates to
users)
X
Fusion has a unique wildcard SSL for encryption. That is specifically used for your agency.
P.54
NIST SP 800-53 Identification and Authorization
Is the product capable of masking passwords during system entry? (i.e., shows passwords as ******).
X
Yes.
P.55
NIST SP 800-53 Identification and Authorization
Does the product support cryptographic authentication schemes which are at a minimum in compliance with FIPS 140-2 (i.e. 256-bit AES for
example is acceptable)?
X
Fusion's compliance controls include the capability for FIPS 140-2.
P.56
NIST SP 800-53 System and Communications Protection
Is the product capable of separating the administration of the asset from the use of the asset (i.e., Application Partitioning) including applications,
databases, network or system operating platforms?
X
Yes.
P.57
NIST SP 800-53 System and Communications Protection
Is the product capable of requiring unique user identification and authentication to shared resources, and all activity and use of the resource is
logged, recorded and reported?
X
Yes.
P.58
NIST SP 800-53 System and Communications Protection
Is the product capable of restricting access from specific sources using specific protocols?
X
Yes.
P.59
NIST SP 800-53 System and Communications Protection
Is the product capable of prioritizing services as determined by Maricopa County to enhance performance (generally only applied to operating
platforms)?
X
Yes.
P.60
NIST SP 800-53 System and Communications Protection
Is this product capable of preventing access via Internet Protocol, Service and Port?
X
Yes.
P.61
NIST SP 800-53 System and Communications Protection
Does this product support checksums and hash values to maintain the integrity of information?
X
Yes.
Vendor Responses
Rate the proposed EHR system by placing an “X” in
the appropriate category:
System Requirements
Requirement Description
P.62
NIST SP 800-53 System and Communications Protection
Is this product capable of encrypting data in transit to protect it from unauthorized disclosure?
X
Yes, SSL is leveraged for data in motion.
P.63
NIST SP 800-53 System and Communications Protection
Is this product capable of terminating communications when sessions are completed?
X
Yes.
P.64
NIST SP 800-53 System and Communications Protection
Can the product be configured to communicate only with specific assets?
X
Yes.
P.65
NIST SP 800-53 System and Communications Protection
Is the product capable of utilizing only FIPS 140-2 compliant encryption algorithms (e.g., 256-bit AES)?
X
Fusion's compliance controls include the capability for FIPS 140-2.
P.66
NIST SP 800-53 System and Communications Protection
Does the product support the ability to use acceptable mobile code such as JavaScript and PDF?
X
Yes.
P.67
NIST SP 800-53 System and Communications Protection
Does the product support session authenticity during initialization of sessions (e.g., SSL)?
X
AES encryption can be used for data at rest. SSL can be used for data in motion that is transferred between client
workstations and the database server.
P.68
NIST SP 800-53 System and Information Integrity
Does the product support the ability to have vendor’s correct flaws (e.g., security vulnerabilities) including applications, databases, network and
system operating platforms?
X
Yes, FusionEHR allows for the vendor to correct security vulnerabilities including applications, databases, network and
system operating platforms.
P.69
NIST SP 800-53 System and Information Integrity
Is the product capable of being scanned using well-known antivirus systems for malicious code?
X
For anti-virus and anti-malware Fusion leverages SentinalOne and SEM.
P.70
NIST SP 800-53 System and Information Integrity
Is the product capable of restricting personnel from entering data in the asset based on access control (e.g., role-based access)?
X
Yes, role based and end user secutity permissions can be created to block users from entering certain data.
P.71
NIST SP 800-53 System and Information Integrity
Does the product have the ability to determine whether or not inputs are valid?
X
Yes, FusionEHR can determine if inputs are valid or not. Such as a data entry option requiring only numbers for a patients
age.
P.72
NIST SP 800-53 Access Control
Do you provide tenants with strong Multi-Factor Authentication options for users?
X
Our 2023 release will include SSO options using industry standard protocols (oAuth and SAML).
P.73
NIST SP 800-53 Access Control
Does your solution provide for Security Assertion Markup Language (SAML) authentication?
X
Our 2023 release will include SSO options using industry standard protocols (oAuth and SAML).
P.74
NIST SP 800-53 System and Services Acquisition
Do you and your software suppliers adhere to industry standards for software development lifecycle security?
X
Yes, Fusion adheres to industry standards for software development lifecycle security.
P.75
NIST SP 800-53 Access Control
Do you maintain a data destruction policy for customer termination? If so, can you provide your data destruction policy?
X
Please reference Fusion's standard Support and Maintenance as a separate attachment labeled Fusion Health - Data
Destruction and Sanitation Policy - CONFIDENTIAL .
P.76
NIST SP 800-53 Incident Response
Do you have a breach policy? Please attach a policy including your definition of a breach.
X
Please reference Fusion's standard Support and Maintenance as a separate attachment labeled Fusion Health - Breach
Policy - CONFIDENTIAL .
P.77
NIST SP 800-53 Access Control
If Application Programming Interfaces (APIs) are in place, are there methods for authenticating to the APIs? Please attach a description of these
authentication measures or describe them in the comment box.
X
Each interface will be managed via Interface Control Documents (ICD) which will provide appropriate application and
system operations documentation. In addition to the ICD, Fusion will provide the following tasks associated with
interface development:
• Interface requirements gathering/define standard and custom interfaces required and complete the Interface
Requirements Document (IRD).
• Work with vendors to develop interfaces.
• Create cross-reference file(s) as needed.
• Define parameters for fault tolerance interfaces.
• Test the interfaces and data for format and content.
• Perform data integrity checks for all interfaces (clinical staff).
• Train system managers to process files and manage interfaces (if applicable).
Vendor Responses
Section
Requirement Description
Explanations
2.13
PRODUCT HISTORY: The proposed EHR system must include the product history as listed in the section below.
Provide detailed information in narrative and/or diagrammatic description format and identify any corresponding attachments.
2.13.1
Specify the if the products are native with the company or added to the respondent’s product line through acquisitions. If acquired, specify the name of the previous owner and the internal
systems integrated with the EHR.
All products being offered by Fusion for the purposes of this proposal are native products of Fusion.
In addition to FusionEHR, Fusion owns CIPS - Pharmacy Management System that we had acquired from Kalos, INC in 2020. CIPS is not directly part of this contract but is the Pharmacy
Management Software leveraged by the counties pharmacy vendor, Diamond.
2.13.2
Specify the date of first installation.
Essex County Jail, New Jersey - 2012
2.13.3
Specify the number of de-installations in the last three years and reason(s) for de-installations. Please include the name and contact information for these customers.
Over the last three years, FusionEHR has only been de-installed at a single location. Fusion had partnered with Centurion Health Service to provide our EHR solution for Pima County, AZ. Due to
the County replacing Centurion, Fusion's software and services was no longer needed. Since Fusion was not contracted with the County, we do not have any contacts from the county. If
required, we can provide a contact from Centurion.
2.13.4
Specify the frequency of updates, e.g.: major releases, minor releases.
Fusion's support includes software upgrades and patches that are supplied approximately every 6 months, while new versions are available every 12 – 18 months. There are also regularly
scheduled bi-monthly updates to the system. Fusion will coordinate all version upgrades or system maintenance activities with CHS and will schedule these events accordingly to minimize
disruption to your operations. Should a major release require modifications to the system, forms, or reports, this will be communicated with the stakeholders and appropriate actions will be
taken.
2.13.5
Based on the planned general availability dates for releases, describe your on-time delivery of scheduled releases, e.g.: frequency for on-time delivery, frequency for delayed delivery,
rescheduling or movement of planned release dates, duration of delays before a release is delivered, etcetera.
Upon any new software updates or new releases, Fusion develops a thorough plan to ensure that timelines can be met. As part of these releases Fusion plans for testing, bug fixes, pilot
programs, and deployment time for each client. Fusion has agood track record of meeting timelines for availability of releases. Upon any delays that may unintentionally occur, Fusion ensure
communication and updates to all clients.
2.13.6
Describe any major issues with previous releases.
Fusion is always planning ahead and our approach to new releases is no different. We are methodical and thorough in our testing and quality assurance programs. We strategically release new
innovations to a small subset of our client’s so that they may test it in the real world and provide valuable feedback. We progress slowly, but deliberately so that when released our full client
base all innovations are proven and ready full production use. As per any new software releases, Fusion does come across the occasional bugs to the system that our team patches and
resloves in an expedited timeframe.
2.13.7
Describe if any releases had to be called/rolled back or general availability dates delayed to the customer due to issues experienced with alpha, beta and/or pilot sites.
To date, Fusion has not had to rollback any new releases at alpha, beta, or pilot sites. Due to us including time for patching and bug fixes between all levels, Fusion has been able to maintain
general release dates.
2.13.8
Describe if releases in general production experienced patient care or safety issues.
To date, no new releases in general production have experienced patient care or safety issues.
2.13.9
Describe if releases in general production experienced functionality that did not work as designed.
No major functionalities in our general releases have had issues in their functionality as they were designed. Minor features have had to be tweaked through bug fixes.
2.13.10
Describe if releases in general production experienced system performance issues, e.g., system slowness, printing problems, system hanging, freezes, etcetera.
No performance issues have been notified to Fusion regarding new releases to general production.
2.13.11
Describe if releases in general production experienced system availability issues with scheduled or unscheduled downtime.
To date, any new releases that needed any bug fixes while in general production have been able to have been completed while system was functioning or during pre-scheduled downtime.
System Requirements