Request for Proposals Statewide Two Factor Authentication Solution

Size: px
Start display at page:

Download "Request for Proposals Statewide Two Factor Authentication Solution"

Transcription

1 Request for Proposals Statewide Two Factor Authentication Solution Issued: September 17, 2012 Proposals Due: October 18, 2012 A Letter of Intent to Respond (LOI) to this RFP is required (See Section 4.1) NYeC RFP Two Factor Authentication Page 1 of 20

2 Contents 1. Purpose of Request for Proposals (RFP) Background on NYeC Current State of Systems that may Access SHIN-NY Data Terms used within the RFP 5 2. RFP Scope Statement Two Factor Authentication Use Cases In Scope Items (Visual) Proposal Instructions Proposal Contents Submission Details Timeline Submission Method Proposal Evaluation Criteria 17 Attachment A: Letter of Intent to Respond (LOI) 19 Attachment B: NYeC Master Services Agreement 20 NYeC RFP Two Factor Authentication Page 2 of 20

3 1. Purpose of Request for Proposals (RFP) As New York State (NYS) Regional Health Information Organizations (RHIOs) continue to grow, so does the need to keep pace with security controls and patient privacy concerns to protect the integrity, confidentiality, and availability of Protected Health Information (PHI) as it is transferred over the NYS Health Information Exchange (HIE). New penalties for confidentiality breaches in violation of the Health Insurance Portability and Accountability Act (HIPAA), as amended, as well as strict federal regulations governing e-prescribing of controlled substances, are driving the need for improved e-authentication capabilities across the Statewide Health Information Network for New York (SHIN-NY). New York ehealth Collaborative (NYeC) is seeking a vendor for the implementation of a Statewide Two Factor Authentication (TFA) Solution. In addition to the specific requirements for the solution in this RFP, NYeC would like proposers to consider the following: The solution must comply with the National Institute of Standards and Technology Special Publication (NIST SP) Level 3 requirements. The solution should increase the ability to share information across the SHIN-NY while keeping the number of authentication tokens used by an individual to a minimum. NYeC understands that while necessary in several instances, hard tokens present an added inconvenience to the end users and is seeking a solution that can provide suitable soft token options. NYeC understands that when constructing such a system, the workflow, processes and humanacceptance factor are just as important as the technical authentication solution deployed. Since large centralized and federated authentication solutions can be challenging to implement, vendor responses should consider how their approach can balance security with adoption and overcome implementation obstacles, such as solution acceptance, integration within the variety of systems that will access SHIN- NY data (such as RHIO Clinical Viewers, EMRs, etc.). 1.1 Background on NYeC NYeC ( is a public-private partnership that serves as a focal point for health care stakeholders to build consensus on state health Information Technology (IT) policy priorities and to collaborate on state and regional health IT implementation efforts. Working collaboratively with the New York State Department of Health and other key constituents, NYeC is developing the Statewide Health Information Network for New York (SHIN-NY), a statewide network of health information technology to allow providers to share patient health information in a timely and secure manner, which will lead to improved health care quality and reduced health care costs. Founded in 2006 by healthcare leaders, NYeC receives funding from state and federal grants to serve as the focal point for HIT in New York State. NYeC facilitates an interoperable health information exchange through the SHIN-NY, supporting the establishment of health information policies, standards and technical approaches and aiding stakeholders at the regional and local levels to implement such policies and standards. NYeC s goal is for patients and their healthcare providers, wherever they need and provide treatment in New York State, to be able to obtain fast, secure, accurate, and accessible information. The SHIN-NY will enable the health information exchange. As more providers adopt HIT, there is a greater opportunity for sharing patient data between those entrusted with patient care. The creation, expansion, security and management of this network is an important undertaking for New York State; a connected HIT system in New York will offer better, safer, and faster treatment for all patients. As healthcare technology adoption grows, new policies must be written and technology expanded. An essential undertaking of NYeC is to develop and improve policies, set standards, and insure complete NYeC RFP Two Factor Authentication Page 3 of 20

4 patient privacy and security. A key element in support of these goals is the creation of a Statewide TFA Solution. 1.2 Current State of Systems that may Access SHIN-NY Data Regional Health Information Organizations (RHIOs) All RHIOs will be accessing SHIN-NY data either via a Service or Connect Model. Currently, NYS RHIOs are at various stages of implementation of TFA solutions and single factor token solutions in accordance with NIST SP While some RHIOs have implemented TFA solutions, the majority of RHIOs have not. Several RHIOs are currently exploring two factor technologies that can satisfy security needs while at the same time meet user acceptance needs. The following chart illustrates the average level of implementation of TFA solutions and compliance with NIST SP requirements across the eleven (11) NYS RHIOs. The chart lists NIST implementation criteria on the vertical axis and the average level of implementation on the horizontal axis. NYeC RFP Two Factor Authentication Page 4 of 20

5 Current State of EHR Environment The selected Statewide TFA Solution must have the capability to integrate and interact with existing EMR and EHR solutions. In their response, proposers must state if their solution is supported for each EHR/EMR vendor listed below and provide any necessary details (see section 3.1 D.4 for details). The following list identifies the known EHR and EMR solutions in place across the NYS RHIOs: Vendor Name AdvantaChart Allscripts Amazing Charts Aprima Athenahealth Cerner ChartLogic Inc ComChart CompuGroup Medical Connexin CPSI (Computer Programs and System Inc.) Criterions CureMD Corporation Data Strategies, Inc. DigiChart DOC-TOR.com eclinicalworks EHR Clinical Solution e-mds EncounterPro Healthcare Resources Inc Epic escribehost GE Glenwood Systems Greenway Medical Technologies Inc Vendor Name Infor*Med Corporation MacPractice Inc McKesson MCS - Medical Communication Systems, Inc. MDLand International Med A-Z MedcomSoft MEDENT Medical Office Online Meditab MEDITECH NCG Medical Systems NextGen Healthcare Information Systems Inc OptumInsight Practice Fusion Prime Clinical Systems Quest Diagnostics SequelMed SOAPware Inc Spring Medical Systems SRSsoft STI Computer Services Inc SuiteMed LLC Universal EHR Solutions 1.3 Terms used within the RFP Term Clinical Viewer E-prescribing Definition A web-based portal for access to RHIO clinical data. The RHIO members log in to the portal for access to patient data, available patient documents, consent details, medication details, alerts, messages, etc. The Clinical Viewer allows RHIO members to access patient information available across all the participating hospital and provider locations. Defined by the ehealth Initiative as "the use of computing devices to enter, modify, review, and output or communicate drug prescriptions." Although the term e-prescribing implies the use of a computer for any type of prescribing action, there are a wide range of NYeC RFP Two Factor Authentication Page 5 of 20

6 Term Definition e-prescribing activities with varying levels of sophistication. Electronic Medical/Health Records (EMR/EHR) Federated Identity Management Health Information Exchange (HIE) Health Information Technology (HIT) Identity and Access Management (IAM) Meaningful Use The electronic systems providers use to store patients' health information. These have replaced the paper records that providers traditionally used. An EMR/EHR contains data gathered from a variety of clinical services, including laboratory data, pharmacy data, patient registration data, radiology data, surgical procedures, clinic and inpatient notes, preventive care delivery, emergency department visits, billing information, and so on. The linking of a person s electronic identity and attributes across multiple distinct identity management systems. The sharing of clinical and administrative data across the boundaries of healthcare institutions and other health data repositories. Many stakeholder groups (payers, patients, providers, and others) realize that if such data are shared healthcare processes would improve with respect to safety, quality, cost, and other indicators. The use of computers and computer programs to store, protect, retrieve, and transfer clinical, administrative, and financial information electronically within healthcare settings. A framework that includes business processes and technical solutions that facilitate the management of electronic identities from creation to removal. IAM includes: identity verification, onboarding processes, account management, access controls and auditing. The American Recovery and Reinvestment Act of 2009 specifies three main components of Meaningful Use: 1. The use of a certified EHR in a meaningful manner, such as e-prescribing. 2. The use of certified EHR technology for electronic exchange of health information to improve quality of health care. 3. The use of certified EHR technology to submit clinical quality and other measures. Multi-Factor Token Protected Health Information (PHI) Regional Health Information Organization (RHIO) A token that uses two or more factors to achieve authentication. For example, a private key on a smart card that is activated via PIN is a multi-factor token. The smart card is something you have, and something you know (the PIN) is required to activate the token. Any information about health status, provision of healthcare, or payment for healthcare that can be linked to a specific individual. This is interpreted rather broadly and includes any part of a patient's medical record or payment history. A non-governmental organization that exists as a New York State not-for-profit corporation to enable interoperable health information exchange via a common Statewide Health Information Network for New York (SHIN-NY). RHIOs participate in setting information policies through a statewide policy framework and governance process, implementing policies and ensuring adherence to such policies with a mission of governing its use in the public s interest and for the public good to improve healthcare quality and safety and reduce costs. To fulfill this mission, RHIOs require commitment from multiple healthcare stakeholders in a geographic region, including physicians, hospitals, long term care and home care providers, patients, insurers, purchasers and government. RHIOs are responsible for enabling interoperability through which individual NYeC RFP Two Factor Authentication Page 6 of 20

7 Term Definition stakeholders are linked together both organizationally and technically through the SHIN- NY in a coordinated manner for health information exchange and quality and population health reporting. Clinicians and other entities wishing to access data from outside their organization connect to a local RHIO to enable data exchange. The RHIOs across New York State will be connected to each other via the SHIN-NY technical infrastructure. Service RHIO Connect RHIO Single Factor Token Statewide Health Information Network for New York (SHIN-NY) Statewide Two Factor Authentication Solution Two Factor Authentication (TFA) A RHIO whose technical infrastructure is managed by NYeC. NYeC is responsible for all technology associated with RHIO activities and manages upgrades and software enhancements. A RHIO whose technical infrastructure is managed by the RHIO itself. It is connected to the SHIN-NY and is able to send data to and receive data from other RHIOs but its systems are individually managed. A token that uses one of the three factors to achieve authentication. For example, a password is something you know. There are no additional factors required to activate the token. A statewide health information exchange that allows for data sharing between clinicians and other entities within and across regions of New York State using standard interoperability protocols. The technical infrastructure will connect both Connect and Service RHIOs in order to allow clinicians and consumers to make timely, fact-based decisions that will reduce medical errors and redundant tests and improve care coordination and the quality of care. Participating organizations connected to the RHIOs include medical facilities, ambulatory care centers, physician offices, labs, long term care centers and nursing homes. A TFA mechanism that will allow individuals to authenticate in order to access SHIN-NY data. The statewide solution will be provided to those who do not have a valid two factor solution implemented within their own system but who require access to SHIN-NY data. Those with valid TFA mechanisms in place will not be required to use the solution provided by the state. The statewide solution will include identity management including identity proofing, certificate management and token distribution. An authentication method that requires the user to present at least two factors to verify their identity. Acceptable authentication factors fall into three categories: knowledge (something that the user knows), possession (something the user has) and inherence (something the user is). A valid two factor solution will require factors from two of the three categories. NYeC RFP Two Factor Authentication Page 7 of 20

8 2. RFP Scope Statement NYeC is seeking to make available for the participating RHIOs, providers, and patients a Statewide TFA Solution used to validate the identity of individuals prior to accessing SHIN-NY data via the RHIO Clinical Viewer, a connected EMR/EHR, or a connected third party application (such as a mobile device). NYeC also intends for the Statewide TFA Solution to be utilized for the I-STOP legislation which will Require practitioners to review a patient's controlled substance prescription history on the system prior to prescribing (for details see: This service will be provided as a single statewide shared service that provides a standard TFA solution which will support and easily integrate into the existing applications accessing SHIN-NY data. (Note: the Statewide TFA Solution will NOT need to integrate or interact with systems and solutions that have a native TFA option and can pass a SAML assertion to NYeC.) Key components of the authentication solution are the provision of Identity and Access Management (IAM) related services and components such as the issuance of certificates, identity proofing, token management, governance, and other outsourced IAM services and how they integrate with the vendor s two factor solution. In addition to serving authentication needs of users accessing SHIN-NY data, the Statewide TFA Solution may be utilized for the following additional purposes: Patients requesting to electronically download PHI into a Personal Health Record Patients accessing their PHI via a Patient Portal Providers writing e-prescriptions including the dispensing of controlled substances Access to Medicaid data for Health Homes Access to e-molst or Advanced Directive documentation for both patients and providers Patients providing electronic consent The need for an enterprise-level well-designed and capable Statewide TFA Solution is critical to the success of many other NYeC and HIE goals, such as: Security efficiency ability to minimize the time, costs and resources necessary to implement and support the IAM needs of the SHIN-NY and its users Security effectiveness ability to meet all legal and regulatory needs Security acceptance ability to balance strong security controls with usability and acceptance and adoption of the solution Mitigation of risks to breaches of PHI Enablement of: Broader sharing of EHRs across RHIOs and across the SHIN-NY Secure growth of patient portals NYeC RFP Two Factor Authentication Page 8 of 20

9 2.1 Two Factor Authentication Use Cases The Statewide TFA Solution will be required when a user attempts to access data from the SHIN-NY as well as the possibility of using the Statewide TFA Solution when a user attempts to use other functionality such as: e-prescribing, e-molst or Advanced Directives, and Medicaid data for Health Homes. A user must first be identity proofed and issued credentials and access tokens before access to the system can be granted. Specific workflow and implementation steps will be dependent on the organization and systems involved. All users will be required to be authenticated using a NIST SP Level 3 compatible authentication mechanism. Once the user has been authenticated, a SAML assertion must be passed for interoperability operation. Proposers should detail their ability to provide solutions for the following three (3) categories of access methods. (Note: The Statewide TFA Solution will NOT need to integrate or interact with systems and solutions that have a native TFA option and can pass a SAML assertion to NYeC. The use cases below apply only to those implementations where SHIN-NY is being accessed by a system that does not have a TFA solution that meets NIST Level 3 standards.) 1. User accesses the SHIN-NY through a system (EHR or other - such as a hospital information system, HIE, a Connect RHIO Clinical Viewer, etc.) that allows access to the SHIN-NY. The EHR or other system vendor should be able to work with the selected Statewide TFA Solution vendor to implement a solution within the EHR system as needed. The selected Statewide TFA Solution vendor will provide widgets for EHR vendor integration and the EHR (or other system) vendor will be required to integrate the TFA solution. 2. User accesses the SHIN-NY through a Service RHIO Clinical Viewer. The selected vendor will work with NYeC to implement the Statewide TFA Solution within the Service RHIO that the user is connected through. NYeC will be responsible for needed changes to Service RHIO systems for solution implementation. 3. User accesses the SHIN-NY through a third party application (through smart phones, tablets, etc.). The application vendor should be able to work with the selected Statewide TFA Solution vendor to implement a solution within the EHR system as needed. The selected Statewide TFA Solution vendor will provide widgets for EHR vendor integration and the application vendor will be required to integrate the TFA solution. SAML Validation will be a functional service of the NYeC system for all passed SAML assertions. NYeC RFP Two Factor Authentication Page 9 of 20

10 2.2 In Scope Items (Visual) The following diagram details the needed components and structure for the TFA solution for access to SHIN-NY data. Proposers must detail their solution for components presented in blue. Identity Proofing Certificate Assignment and Management Token Assignment and Management Identity Access Management User requests SHINY data through system utilizing the Statewide NIST level 3 compatible TFA Solution EHR/Hospital / Connect QE Clinical Viewer/System App Service QE Clinical Viewer Statewide Two Factor Authentication System SAML Assertion passed for interoperability operation SAML Validation SHINY User Directory: User Roles and Permissions Patient Directory: User Roles and Permissions Key: In Scope Out of Scope Descriptive NYeC RFP Two Factor Authentication Page 10 of 20

11 3. Proposal Instructions Proposers must respond to ALL items contained in section 3.1 below (A-L and sub-sections thereof), as well as adhere to the page limits. Every page in the proposal, including all appendices, exhibits and attachments, must be numbered consecutively. Each section must be clearly labeled with the title, letter and number of the section. Proposals should be single-spaced, contain one-inch margins, and be typed in Times New Roman 12-point font. 3.1 Proposal Contents The proposal contents must be organized in the following order: A. Cover Letter and Company Overview (1-page limit) a brief overview of the vendor s organization and contact information to direct future inquiries regarding the proposal. The cover letter must be signed by an officer authorized to bind the vendor to the terms of the proposal. B. Executive Summary (3-page limit) - a brief narrative that demonstrates the vendor s understanding of the services requested by this RFP and the scale and complexity of this initiative. The Executive Summary should demonstrate the strengths of the vendor s proposed approach, the key features that distinguish its proposed solution to meet the requirements and the major benefits it offers. C. Experience (2-page limit) an overview of the vendor s and any proposed subcontractors relevant experience. If subcontractors will be used, identify instances where the vendor has worked with the proposed subcontractors. D. Approach for TFA Solution Implementation (20-page limit) a detailed description of the approach the vendor proposes to use to implement its TFA solution, including detailed descriptions of all solution components that will be outsourced and of any proposed subcontractors. 1. Provide details on how the proposed TFA solution will integrate and work with existing systems that do not have a built-in TFA solution. The details must cover the use cases and systems described in section 2.1 Two Factor Authentication Use Cases above: a) Include specifics on the methods (such as web services, Application Programming Interfaces (APIs), etc.) that will be provided by the TFA vendor to integrate the TFA solution with existing RHIO Clinical Viewers, EMR vendors, and connected third party applications (such as a mobile device). b) State specifically how well industry standards (OATH, RADIUS, LDAP, PAM, etc.) are used for 2 nd factor integration interfaces with systems. Preference will be given to vendors who incorporate industry standards within their solution. 2. Identify the integration utilized between the various application components of all response partners that allow it to operate as a seamless cohesive solution. Identify the relationship between the primary respondent and its partners. 3. Detail the types of tokens accepted by the proposed TFA solution. Proposed solutions should encompass at minimum one hard and one soft token. Preference will be given to proposed solutions with flexible token requirements. NYeC RFP Two Factor Authentication Page 11 of 20

12 4. Identify and provide the necessary details on the EHRs/EMRs that are currently supported by the proposed solution from the list provided in Section 1.2, and any others that are not included in the list. Vendors must identify all EHRs/EMRs that have implemented the proposed TFA solution and how it was implemented. E. Identity and Access Management (IAM) Services (5-page limit) Describe the IAM services, specifically: 1. Ability to support Level 3 basis for issuing credentials for in-person and remote use cases. 2. Ability to support Registration Authority actions at Level 3 for in-person and remote-use cases. 3. Ability to support Level 3 Credential Lifetime, Status or Revocations requirements. 4. Ability to implement token and credential revocation and destruction processes. 5. Ability to provide a complete enterprise IAM service for establishing and maintaining identities as per NIST Describe your recommended IAM Governance model and structure. 7. Ability to support an IAM solution that will be expandable to include new forms of identity verification, assertion and authentication approaches. 8. Details on integration of needed third party solutions with the proposed IAM capabilities. Include details on the agreement between the TFA vendor and the third party vendor as needed. F. Architecture (2-page limit) provide a diagram (along with the necessary descriptions) of the proposed architecture for the overall TFA solution. This should incorporate all the in-scope items identified in Section 2.2 above. G. Hardware Requirements (2-page limit) identify the hardware needed to support the TFA solution. Use the user count table in the Business and Pricing section below to provide details on the incremental hardware needs based on the number of users being supported via the TFA solution. H. Team (5-page limit) detailed overview of the vendor s and proposed subcontractors team members who will staff the project if vendor is selected. This section should identify all key team members by name and role (NYeC may at its discretion choose to interview some or all key team members during the selection process). Note: The team size and makeup should consider a strong desire at NYeC to complete the implementation by the end of Organization Chart. In addition to identifying all of the vendor team members (including subcontractors) by their names (for key members) and roles, the chart should identify all roles, teams and governance groups that the vendor expects NYeC to provide for the implementation. 2. Name, role and brief experience of the key members of the team (this should also include key subcontractor positions). 3. Descriptions for ALL roles identified within the Organization Chart. 4. Resumes of all key members (to be included as an Appendix the 5-page limit for this section does not include resumes). I. Other Services (5-page limit) identify and provide details for other supporting services that will be provided for the overall implementation and maintenance. These include: NYeC RFP Two Factor Authentication Page 12 of 20

13 1. Help Desk Services 2. Knowledge Transfer Services 3. Service Level Agreements (include standard SLA documents as an appendix) 4. Token replacement, addition, and termination as well as password recovery 5. Software Support (including upgrades and maintenance) J. Project Implementation Timeline (5-page limit) provide a timeline for the overall implementation of the Statewide TFA Solution that includes the IAM implementation as well as the implementation of the use cases defined in section 2.1 above. Identify the key tasks, milestones and deliverables within the timeline. Any assumptions used in developing the timeline should be identified in this section. If there are specific tasks that NYeC will be responsible for, they should be identified clearly within the timeline. (Assume a January 7, 2013 start date) Note: The Project Implementation Timeline should consider a strong desire at NYeC to complete the implementation by the end of K. Two Factor Authentication Solution Requirements (10-page limit) proposers must address all the requirements detailed in the table below. Two Factor Authentication Solution Requirement 1. Confirm that the proposed TFA solution complies with NIST SP at Level Ability to support a variety of TFA types such as those defined in NIST SP that may be permitted for HIE access as well as the more restricted subset of two factor solutions that are required by DEA for e- Prescriptions for Controlled Substances. State how your solution can support two factor solutions for both business needs. HIE access may allow Out of Band two factor solutions while the DEA allows only FIPS validated hard cryptographic tokens. 3. Ability for TFA solution to comply with NIST Special Publication , Electronic Authentication Guideline, December 2011 Authentication Guideline, (NIST SP ). 4. Ability to protect long-term shared secrets as per NIST SP requirements. 5. Ability to support Single factor (SF) One-Time Password (OTP) Device as defined by NIST in SP Ability to support Single factor (SF) Cryptographic Device as defined by NIST in SP Ability to support Multi-factor (MF) Software Cryptographic Token Cryptographic Token as defined by NIST in SP Ability to support Multi-factor (MF) One-Time Password (OTP) Device as defined by NIST in SP Ability to support Multi-factor (MF) Cryptographic Devices as defined by NIST in SP Ability to support Memorized Secret Token as defined by NIST in SP Ability to support Pre-registered Knowledge Token as defined by NIST in SP Ability to support Look-up Secret Token as defined by NIST in SP Ability to support Out of Band Token as defined by NIST in SP Ability to support TFA for patients across a variety of patient portal instances. Please state which web platforms and PHR systems your solution works with or is certified to work with. 15. Ability to comply with the New York State Personal Privacy Protection Law ( 16. Provide two-factor system performance information for deployments of 100, 10K, 100K, 200K, 1M, and 10M users. 17. Ability to support multiple browser types. Describe any restrictions on browsers when integrating your solution. 18. Ability to support centralized accumulation and management of audit data. NYeC RFP Two Factor Authentication Page 13 of 20

14 Two Factor Authentication Solution Requirement 19. Ability to provide granular controls to manage the length of time that an authentication assertion is valid for. Can the solution support various identity assertion lifetimes for various applications and roles within the SHIN-NY? 20. Ability to operate across data centers that are geographically spread out across the state. Address any network or other technical related requirements for your proposed solution. 21. Ability to support records retention requirements. 22. Meets the DEA Requirements for Electronic Orders and Prescriptions (e-cfr Title 21: Food and Drugs, Part 1311 Requirements for Electronic Orders and Prescriptions). State and discuss any compliance capabilities or experience with integrating your solution with e-prescription services including support for controlled substances. NYeC RFP Two Factor Authentication Page 14 of 20

15 L. Business Model and Pricing 1. Pricing model: explain the possible pricing model(s) available and provide component prices and volume discounts. Available Enterprise Pricing Options including but not limited to adoption by NYeC of the vendor's proposed solution as a statewide solution for all connected systems that lack the required functionality should be explained here. 2. Vendors must indicate if their proposed solution requires collaboration with any other entities not included as subcontractors and must clearly state if these are ongoing or new relationships. 3. Costs for all required components (including services, software, hardware, and any other costs) must be included using the pricing table below. All areas are required to be addressed. If an area is non-applicable a reason must be provided as to why there is no price. If a cost for an area is included within other costs please mark the item as included and specify in the Comments column where the cost is covered. Vendors may add additional rows within the table as required. This includes adding subcomponents to an existing line to provide a more detailed breakdown of a cost or adding new rows to identify a cost component not identified in the table. Please be sure to indicate the creation of a new sub-component or row within the Comments column and to provide an explanation for why it was included. Solution Costs: Licensing Costs Third Party License Fees (please specify third party organization as applicable) Identity Proofing Costs Certificate Management Costs Implementation Costs Help Desk Costs Training Costs Knowledge Transfer Costs Maintenance (24x7 Support) Professional Services Costs Custom Development Costs Hardware and Server Costs Administrative Costs Other: Please Specify Acquisition or recurring Cost (if recurring, state frequency) K Per User Costs: Number of Users 10K 100K 100K 200K 200k- 1M 1M- 10M 10M+ COMMENTS NYeC RFP Two Factor Authentication Page 15 of 20

16 Token Purchase and Management Costs: Token Type 1 (please specify) Acquisition or recurring Cost (if recurring, state frequency) K Per User Costs: Number of Users 10K 100K 100K 200K 200k- 1M 1M- 10M 10M+ COMMENTS Token Type 2 (please specify) Token Type 3 (please specify) Token Type 4 (please specify) (Add additional lines as necessary) External Costs: Cost Details Anticipated costs to third party (EHR and Application) vendors for integration services and support. Please specify costs that vary by integration type. Costs to EHR vendors Costs to application developers Hospital/practice incurred costs 4. Financial Report- Due to the breadth and scope of the project, the proposer is required to submit its most recent audited financial statement and management letter. In the event that the proposer is a wholly owned subsidiary or is otherwise a subordinate of another entity, the most recent audited financial statement and management letter of the proposing company is expected- not that of the parent company. 5. In-Kind Service details: Any In-Kind services and the value of those services should be noted in this section. In-kind services are those services provided at no cost yet have an intrinsic value or worth. Descriptions of what is included in the cost including support model and hours of coverage must be noted. If your cost excludes certain fees or charges, you must provide a detailed list of the exclusions with a complete explanation of the nature of those fees. While In-Kind services are not a requirement of the RFP, proposers are encouraged to include them since they demonstrate to NYeC the proposers commitment to providing the highest value for the public funds being used for this effort. NYeC RFP Two Factor Authentication Page 16 of 20

17 4. Submission Details All communication regarding this RFP must be in writing and addressed to: The subject line of all communications must include: TFA Proposal and your company name Timeline RFP Issued: September 17, 2012 Letter of Intent to Respond due: September 24, 2012; 11:59pm EDT Written Questions due: September 24, 2012; 11:59pm EDT Q&A Vendors Conference Call: October 2, 2012; 3:00 5:00 pm EDT Written Responses to Q&A Available no later than: October 5, 2012 Proposals Due: October 18, 2012; 11:59pm EDT Requested Vendor Demonstrations/Presentations Held: November 16, 2012 Award Notification: November 30, 2012 Anticipated Contract Start Date: January 7, 2013 In order to effectively manage the process, NYeC is requiring all interested vendors to submit a Letter of Intent to Respond (LOI) to RFPContact@nyehealth.org no later than 11:59pm EDT on September 24, LOIs must contain the address of the vendor s contact person. Submitting an LOI will not bind a vendor to submitting a proposal, but will be used to notify the vendor of any changes, including the Q&A Vendor Conference Call number, changes to the above timeline, and any additional information related to this RFP. (See Attachment A - Letter of Intent to Respond). All questions must also be submitted via to RFPContact@nyehealth.org and must be received by 11:59pm EDT on September 24, Responses to questions received by this deadline are expected to be posted on the NYeC website no later than October 5, Proposers are advised that the Authorized Contact Person for all matters concerning this RFP is the RFP Contact address. Proposers may not contact any NYeC staff, NYeC board members, the NYS Department of Health staff, NYC Department of Health and Mental Hygiene staff, or any other stakeholder regarding this project in the period between the issue of this RFP and the notice of award. Any oral communication will be considered unofficial and non-binding with regard to this RFP and subsequent award. 4.2 Submission Method Proposal submission method ( ) to: RFPContact@nyehealth.org Include TFA Proposal and your company name in the subject line Format: PDF and MS Word 4.3 Proposal Evaluation Criteria Proposals will be evaluated based on the following criteria: Use of Industry Standard Integration methods Logging, auditing, and reporting capabilities The ability to support multiple authentication solutions NYeC RFP Two Factor Authentication Page 17 of 20

18 Demonstrated ability to provide a successful pilot of the vendor s proposed solution with key EMR/EHR systems Experience and skill sets of the proposed team Financial strength of the company Cost and In-Kind Services NYeC RFP Two Factor Authentication Page 18 of 20

19 Attachment A: Letter of Intent to Respond (LOI) Instructions The LOI form must be completed and returned to notify NYeC that you intend to respond to this Request for Proposals (RFP). Any information relating to this RFP will be ed to the person designated as the point of contact (POC) on this form. the completed form to Letter of Intent to Respond Our organization intends to respond to the NYeC Request for Proposals for the Statewide Two Factor Authentication Solution. Organization Name: Address: POC Name: POC Title: POC POC Telephone: NYeC RFP Two Factor Authentication Page 19 of 20

20 Attachment B: NYeC Master Services Agreement The selected vendor will be required to execute the NYeC Master Services Agreement (MSA) provided separately with this RFP. The contents of the MSA are non-negotiable. Vendors have a responsibility to review the requirements carefully. NYeC RFP Two Factor Authentication Page 20 of 20

Request for Proposals. Statewide Two Factor Authentication Solution. Addendum #2 October 5, 2012. Questions and Responses

Request for Proposals. Statewide Two Factor Authentication Solution. Addendum #2 October 5, 2012. Questions and Responses Request for Proposals Statewide Two Factor Authentication Solution Addendum #2 October 5, 2012 Questions and Responses NOTE: NYeC responses to the questions are in red. Licensing Entity 1. Will the Licensing

More information

VASCO: Compliant Digital Identity Protection for Healthcare

VASCO: Compliant Digital Identity Protection for Healthcare VASCO: Compliant Digital Identity Protection for Healthcare Compliant Digital Identity Protection for Healthcare The proliferation of digital patient information and a surge in government regulations are

More information

Request for Proposal (RFP) Supporting Efficient Care Coordination for New Yorkers: Bulk Purchase of EHR Interfaces for Health Information

Request for Proposal (RFP) Supporting Efficient Care Coordination for New Yorkers: Bulk Purchase of EHR Interfaces for Health Information Request for Proposal (RFP) Supporting Efficient Care Coordination for New Yorkers: Bulk Purchase of EHR Interfaces for Health Information ISSUE DATE: April 10, 2013 RESPONSE DUE DATE: May 3, 2013 Region:

More information

Request for Proposal Implementation Agents of Health Information Technology: Behavioral Health, Primary Care, and other Specialty Healthcare Providers

Request for Proposal Implementation Agents of Health Information Technology: Behavioral Health, Primary Care, and other Specialty Healthcare Providers Request for Proposal Implementation Agents of Health Information Technology: Behavioral Health, Primary Care, and other Specialty Healthcare Providers ISSUE DATE: April 26 th, 2013 RESPONSE DUE DATE: May

More information

HIE Services & Pricing

HIE Services & Pricing Services Available at No Cost Health Information Exchange Services & Pricing Package Effective: December 11, 2015 0 Interface Connection Details Services Available at No Cost HealthlinkNY Web Portal The

More information

HIE Services & Pricing

HIE Services & Pricing Services Available at No Cost Health Information Exchange Services & Pricing Package Services Available at No Cost Services Available at No Cost HealthlinkNY Web Portal The HealthlinkNY Web Portal is available

More information

YOU MAY PURCHASE THE COMPLETE 268 PAGE REPORT AT AMAZON.COM IN THE BLACK BOOK MARKET RESEARCH STORE

YOU MAY PURCHASE THE COMPLETE 268 PAGE REPORT AT AMAZON.COM IN THE BLACK BOOK MARKET RESEARCH STORE THE FOLLOWING DATA IS AN EXCERPT FROM BLACK BOOK S PROPRIETARY RESEARCH REPORT STATE OF THE EHR REPLACEMENT MARKET PLACE: 2013 CONDITIONS & TOP PERFORMING VENDORS DO NOT COPY, DUPLICATE, DISTRIBUTE OR

More information

Report Information. EMR/EHR Market in the US 2015-2019

Report Information. EMR/EHR Market in the US 2015-2019 Report Information EMR/EHR Market in the US 2015-2019 Report / Search Code: WGR55090 Publish Date: 13 May, 2015 Report Price: 1-user PDF : $ 2500.0 1-5 User PDF : $ 3000.0 Site PDF : $ 4000.0 Enterprise

More information

An Overview of THINC s Health Information Exchange Initiatives

An Overview of THINC s Health Information Exchange Initiatives An Overview of THINC s Health Information Exchange Initiatives Susan Stuard, Executive Director June 22, 2011 THINC Goals THINC s Goals: 1. HIT Adoption both implementation of EHRs and standing up a health

More information

CHAPTER THREE: EMERGING TRENDS Meaningful Use Economic Stimulus Package

CHAPTER THREE: EMERGING TRENDS Meaningful Use Economic Stimulus Package CHAPTER ONE: EXECUTIVE SUMMARY Industry at a Glance Physician Use of EMR Hospital Use of EMR Size and Growth of the Market Key Issues and Trends Affecting the Market Leading Market Participants Conclusions

More information

New From Kalorama Information: EMR 2012: The Market for Electronic Medical Record Systems KLI3804306 Current Physician Usage of EMR

New From Kalorama Information: EMR 2012: The Market for Electronic Medical Record Systems KLI3804306 Current Physician Usage of EMR New From Kalorama Information: EMR 2012: The Market for Electronic Medical Record Systems KLI3804306 Paperless medicine is a key goal of healthcare systems. Kalorama Information has continued to track

More information

Health Home Implementation Series: Vendor Selection. 24 January 2012

Health Home Implementation Series: Vendor Selection. 24 January 2012 Health Home Implementation Series: Vendor Selection 24 January 2012 Agenda Background on the New York ehealth Collaborative (NYeC) What is a Health Home? Key steps to Effective Vendor Selection Resources

More information

EMR 2014: The Market for Electronic Medical Records

EMR 2014: The Market for Electronic Medical Records Brochure More information from http://www.researchandmarkets.com/reports/2832991/ EMR 2014: The Market for Electronic Medical Records Description: The EMR Industry Standard Kalorama has continuously examined

More information

SAML for EPCS (Electronic Prescription of Controlled Substances)

SAML for EPCS (Electronic Prescription of Controlled Substances) SAML for EPCS (Electronic Prescription of Controlled Substances) Discussion Slides for review in the OASIS Security Services (SAML) TC August, 2014 DEA Regulation Compliance with New York s istop law-

More information

Request for Proposals Data Warehouse/Data Analytics

Request for Proposals Data Warehouse/Data Analytics Request for Proposals Data Warehouse/Data Analytics Issued: November 9, 2012 Proposals Due: January 7, 2013 A Letter of Intent to Respond (LOI) to this RFP is required (See Section 4.1) NYeC RFP - Data

More information

New York ehealth Collaborative. Health Information Exchange and Interoperability April 2012

New York ehealth Collaborative. Health Information Exchange and Interoperability April 2012 New York ehealth Collaborative Health Information Exchange and Interoperability April 2012 1 Introductions Information exchange patient, information, care team How is Health information exchanged Value

More information

SURVEY QUESTIONNAIRE 2013 AHA ANNUAL SURVEY INFORMATION TECHNOLOGY SUPPLEMENT

SURVEY QUESTIONNAIRE 2013 AHA ANNUAL SURVEY INFORMATION TECHNOLOGY SUPPLEMENT 2013 AHA ANNUAL SURVEY INFORMATION TECHNOLOGY SUPPLEMENT SURVEY QUESTIONNAIRE This survey instrument can be used to facilitate sales, planning and marketing activities. For example, consider current and

More information

2013 NYeC / HealtheConnections Spring Summit

2013 NYeC / HealtheConnections Spring Summit 2013 NYeC / HealtheConnections Spring Summit Rob Hack Executive Director 109 S. Warren Street Suite 500, State Tower Building Syracuse, NY 13202 315-671-2241 x100 rhack@healtheconnections.org Agenda Welcome

More information

Identity: The Key to the Future of Healthcare

Identity: The Key to the Future of Healthcare Identity: The Key to the Future of Healthcare Chief Medical Officer Anakam Identity Services July 14, 2011 Why is Health Information Technology Critical? Avoids medical errors. Up to 98,000 avoidable hospital

More information

HEAL NY Phase 5 Health IT RGA Section 7.1: HEAL NY Phase 5 Health IT Candidate Use Cases Interoperable EHR Use Case for Medicaid

HEAL NY Phase 5 Health IT RGA Section 7.1: HEAL NY Phase 5 Health IT Candidate Use Cases Interoperable EHR Use Case for Medicaid HEAL NY Phase 5 Health IT RGA Section 7.1: HEAL NY Phase 5 Health IT Candidate Use Cases Interoperable EHR Use Case for Medicaid Interoperable Electronic Health Records (EHRs) Use Case for Medicaid (Medication

More information

Qualified Entity (QE) Member Facing Services Requirements

Qualified Entity (QE) Member Facing Services Requirements Qualified Entity (QE) Member Facing Services Requirements Version 1.2 REVISED June 2014 AS DEVELOPED THROUGH THE STATEWIDE HEALTH INFORMATION NETWORK OF NEW YORK (SHIN-NY) POLICY STANDARDS Table of Contents

More information

Request for Applications for CareAccord s Electronic Health Record (EHR) Direct Secure Messaging Integration Pilot

Request for Applications for CareAccord s Electronic Health Record (EHR) Direct Secure Messaging Integration Pilot Request for Applications for CareAccord s Electronic Health Record (EHR) Direct Secure Messaging Integration Pilot Key Applicant Dates: June 30: Request for Application Release Date July 7: Informational

More information

Statewide Health Information Network of New York. Darryl Hollar Director, Product Management

Statewide Health Information Network of New York. Darryl Hollar Director, Product Management Statewide Health Information Network of New York Darryl Hollar Director, Product Management 40 New York ehealth Collaborative Overview NYeC is a not-for-profit organization, working to improve healthcare

More information

2014 AHA Annual Survey Information Technology Supplement Health Forum, L.L.C.

2014 AHA Annual Survey Information Technology Supplement Health Forum, L.L.C. 2014 AHA Annual Survey Information Technology Supplement Health Forum, L.L.C. Please return to: AHA Annual Survey Information Technology Supplement 155 N. Wacker Chicago, IL 60606 Please Note: This year

More information

ARRA HITECH Programs and Goals Where is Nevada?

ARRA HITECH Programs and Goals Where is Nevada? ARRA HITECH Programs and Goals Where is Nevada? Regional Extension Center HealthInsight NV and UT $7,151,783 awarded, 50% to NV or $3,575,892 Feb. 2010 Feb. 2014 Approx. 700 NV providers enrolled out of

More information

EMR/EHR Market in the US 2015-2019

EMR/EHR Market in the US 2015-2019 Brochure More information from http://www.researchandmarkets.com/reports/3238438/ EMR/EHR Market in the US 2015-2019 Description: About EMR/EHR An EMR/EHR is defined is a digital version of the traditional

More information

Medical Society of the State of New Physician Practice Support Organization Initiative

Medical Society of the State of New Physician Practice Support Organization Initiative Medical Society of the State of New Physician Practice Support Organization Initiative Introduction The Medical Society of the State of New York (MSSNY) has been retained by the New York State Department

More information

AHAdatainfo@healthforum.com 866-375-3633. 2012 AHA Annual Survey Information Technology Supplement. Healthcare IT Database Download and Data Licensing

AHAdatainfo@healthforum.com 866-375-3633. 2012 AHA Annual Survey Information Technology Supplement. Healthcare IT Database Download and Data Licensing 2012 AHA Annual Survey Information Technology Supplement Survey Questionnaire This survey instrument can be used to facilitate sales, planning and marketing activities. For example, consider current and

More information

Briefly describe the #1 problem you have encountered with implementing Multi-Factor Authentication.

Briefly describe the #1 problem you have encountered with implementing Multi-Factor Authentication. Polling Question Briefly describe the #1 problem you have encountered with implementing Multi-Factor Authentication. Please type in your response. This poll will close promptly at 1:00 pm CDT Getting the

More information

Use Cases for Argonaut Project. Version 1.1

Use Cases for Argonaut Project. Version 1.1 Page 1 Use Cases for Argonaut Project Version 1.1 July 31, 2015 Page 2 Revision History Date Version Number Summary of Changes 7/31/15 V 1.1 Modifications to use case 5, responsive to needs for clarification

More information

Connecting EHRs to HIEs: A Collaboration of States and Vendors Driving Toward Common Adoption HIE Specifications

Connecting EHRs to HIEs: A Collaboration of States and Vendors Driving Toward Common Adoption HIE Specifications Connecting EHRs to HIEs: A Collaboration of States and Vendors Driving Toward Common Adoption HIE Specifications Anuj Desai, MBA Director of Business Development New York ehealth Collaborative 1/12/2012

More information

Top Inpatient Electronic Health Records Vendors

Top Inpatient Electronic Health Records Vendors Part One: Aggregate Black Book EHR Survey Findings 0 Top Inpatient Electronic Health Records Vendors Part One: Aggregate Black Book Survey Findings Part Two: Comparative Performance Result Set of Top EHR

More information

ELECTRONIC HEALTH RECORDS. Nonfederal Efforts to Help Achieve Health Information Interoperability

ELECTRONIC HEALTH RECORDS. Nonfederal Efforts to Help Achieve Health Information Interoperability United States Government Accountability Office Report to Congressional Requesters September 2015 ELECTRONIC HEALTH RECORDS Nonfederal Efforts to Help Achieve Health Information Interoperability GAO-15-817

More information

New York ehealth Collaborative

New York ehealth Collaborative New York ehealth Collaborative Policy and Governance Structure January 2012 0 Table of Contents Executive Summary 2-4 Introduction 5-6 Achieving Statewide Interoperability Goals 7-8 SHIN-NY Governance

More information

NYS Landscape. 9 RHIOs cover state. RHIOs will be interconnected by State Health Information Network of NY (SHIN-NY) - funded by state and CMS

NYS Landscape. 9 RHIOs cover state. RHIOs will be interconnected by State Health Information Network of NY (SHIN-NY) - funded by state and CMS NYS Landscape 9 RHIOs cover state RHIOs will be interconnected by State Health Information Network of NY (SHIN-NY) - funded by state and CMS SHIN-NY will enable each RHIO to access records of any other

More information

How To Improve Health Information Exchange

How To Improve Health Information Exchange Health Information Exchange Strategic and Operational Plan Profile Overview Hawai i is comprised of eight main islands, seven of which are inhabited. With a population of approximately 1.3 million, Hawai

More information

WHAT IS THE SHIN-NY?

WHAT IS THE SHIN-NY? WHAT IS THE SHIN-NY? Table of Contents Executive Summary... 2 What is the SHIN-NY?... 3 Statewide Health Information Network of New York (SHIN-NY) at a Glance... 4 How Will the SHIN-NY Benefit Patients

More information

Request for Proposal. Integration System

Request for Proposal. Integration System Request for Proposal Integration System July 8, 2015 Introduction and Executive Summary The Hawai i Health Information Exchange (Hawai i HIE) is a 501(c)(3) non- profit established in 2006 by leading health

More information

November 22, 2013. Dear Ms. Tavenner:

November 22, 2013. Dear Ms. Tavenner: 33 W. Monroe, Suite 1700 Chicago, IL 60603 Phone: 312-915-9582 Fax: 312-915-9511 E-mail: himssehra@himss.org AllMeds, Inc. Allscripts Healthcare Solutions Amazing Charts Aprima Medical Software, Inc. athenahealth,

More information

Electronic Medical Record (EMR) Request for Proposal (RFP)

Electronic Medical Record (EMR) Request for Proposal (RFP) Electronic Medical Record (EMR) Request for Proposal (RFP) SAMPLE Proposal Due: [INSERT DESIRED DUE DATE] Table of Contents SECTION 1 RFP INFORMATION... 2 I. Introduction... 2 A. Purpose and Background...

More information

HIE, RHIOs and EHR Interoperability The Journey to Meaningful Use, Interoperable Health Care Delivery and Improved Quality of Care

HIE, RHIOs and EHR Interoperability The Journey to Meaningful Use, Interoperable Health Care Delivery and Improved Quality of Care HIE, RHIOs and EHR Interoperability The Journey to Meaningful Use, Interoperable Health Care Delivery and Improved Quality of Care Christina Galanis Executive Director, Southern Tier HealthLink Topics

More information

Achieving meaningful use of healthcare information technology

Achieving meaningful use of healthcare information technology IBM Software Information Management Achieving meaningful use of healthcare information technology A patient registry is key to adoption of EHR 2 Achieving meaningful use of healthcare information technology

More information

December 2014. Federal Employees Health Benefits (FEHB) Program Report on Health Information Technology (HIT) and Transparency

December 2014. Federal Employees Health Benefits (FEHB) Program Report on Health Information Technology (HIT) and Transparency December 2014 Federal Employees Health Benefits (FEHB) Program Report on Health Information Technology (HIT) and Transparency I. Background Federal Employees Health Benefits (FEHB) Program Report on Health

More information

Inpatient EHR. Solution Snapshot. The right choice for your patients, your practitioners, and your bottom line SOLUTIONS DESIGNED TO FIT

Inpatient EHR. Solution Snapshot. The right choice for your patients, your practitioners, and your bottom line SOLUTIONS DESIGNED TO FIT Inpatient EHR The right choice for your patients, your practitioners, and your bottom line SOLUTIONS DESIGNED TO FIT Our customers do more than save lives. They re helping their communities to thrive.

More information

Achieving HIPAA and HITECH Compliance. with Enterprise Single Sign-On

Achieving HIPAA and HITECH Compliance. with Enterprise Single Sign-On Achieving HIPAA and HITECH Compliance with Enterprise Single Sign-On Achieving HIPAA and HITECH Compliance with Enterprise Single Sign-On 1 TABLE OF CONTENTS The Challenges of HIPAA and HITECH Compliance

More information

Presenters: Laura Zaremba, ILHIE Acting Executive Director Ivan Handler, Chief Technology Officer Kevin Ferriter, InterSystems Corp, Program Manager

Presenters: Laura Zaremba, ILHIE Acting Executive Director Ivan Handler, Chief Technology Officer Kevin Ferriter, InterSystems Corp, Program Manager Presenters: Laura Zaremba, ILHIE Acting Executive Director Ivan Handler, Chief Technology Officer Kevin Ferriter, InterSystems Corp, Program Manager June 21, 2012 Every provider in Illinois has at least

More information

Health Information Technology: A tool for optimizing health

Health Information Technology: A tool for optimizing health Health Information Technology: A tool for optimizing health December 2014 Susan Otter, Director of Health Information Technology, OHA Gina Bianco, Executive Director, Jefferson Health Information Exchange

More information

Applying Lessons Learned in the New Frontier

Applying Lessons Learned in the New Frontier Applying Lessons Learned in the New Frontier Better Communication for Better Healthcare National Health Policy Forum January 14, 2010 Washington, DC Gina B. Perez, MPA DHIN Executive Director Advances

More information

americanehr.com A Report by AmericanEHR Partners October 2011

americanehr.com A Report by AmericanEHR Partners October 2011 Market Share and Top 10 Rated Ambulatory EHR Products by Practice Size A Report by AmericanEHR Partners October 2011 americanehr.com Copyright AmericanEHR Partners 2011 Market Share and Top 10 Rated Ambulatory

More information

July 10, 2014. Dear Dr. DeSalvo and Ms. Tavenner:

July 10, 2014. Dear Dr. DeSalvo and Ms. Tavenner: 33 W. Monroe, Suite 1700 Chicago, IL 60603 Phone: 312-915-9582 Fax: 312-915-9511 E-mail: himssehra@himss.org AllMeds, Inc. Allscripts Healthcare Solutions Amazing Charts Aprima Medical Software, Inc. Cerner

More information

Health Information Exchange in NYS

Health Information Exchange in NYS Health Information Exchange in NYS Roy Gomes, RHIT, CHPS Implementation Project Manager 1 Who is NYeC? 2 Agenda NYeC Background Overview and programs Assist providers transitioning from paper to electronic

More information

Vendor Assessment: The Industry Short List of Electronic Health and Medical Records for Large Ambulatory Practices

Vendor Assessment: The Industry Short List of Electronic Health and Medical Records for Large Ambulatory Practices Vendor Assessment: The Industry Short List of Electronic Health and Medical Records for Large Ambulatory Practices Global Headquarters: 5 Speen Street Framingham, MA 01701 USA P.508.935.4445 F.508.988.7881

More information

EMR 2015: The Market for Electronic Medical Records

EMR 2015: The Market for Electronic Medical Records Brochure More information from http://www.researchandmarkets.com/reports/3328963/ EMR 2015: The Market for Electronic Medical Records Description: For Eight Editions, The Industry Standard for Analysis

More information

October 12, 2010. Dear Health Care Provider:

October 12, 2010. Dear Health Care Provider: DEPARTMENT OF SOCIAL SERVICES DIVISION OF MEDICAL SERVICES 700 GOVERNORS DRIVE PIERRE, SD 57501-2291 PHONE: 605-773-3495 FAX: 605-773-5246 WEB: dss.sd.gov October 12, 2010 Dear Health Care Provider: We

More information

Understanding EHRs: Common Features and Strategic Approaches for Medicaid/SCHIP

Understanding EHRs: Common Features and Strategic Approaches for Medicaid/SCHIP Understanding EHRs: Common Features and Strategic Approaches for Medicaid/SCHIP Presented by: Karen M. Bell MD, MMS, Director, HIT Adoption W. David Patterson PhD, Deputy Chief, Health and Demographics

More information

Health Record Banking Alliance White Paper

Health Record Banking Alliance White Paper Health Record Banking Alliance White Paper A Proposed National Infrastructure for HIE Using Personally Controlled Records January 4, 2013 Table of Contents Executive Summary...3 I. Overview...5 II. Architectural

More information

2013 State of the Ambulatory Electronic Health Records Replacement Market

2013 State of the Ambulatory Electronic Health Records Replacement Market LICENSED COPY: BLACK BOOK RANKINGS 2013 SURVEY RESULTS 2013 State of the Ambulatory Electronic Health Records Replacement Market Executive Summary: Client Experience/Customer Survey Results Top Ranked

More information

Electronic Prescribing of Controlled Substances

Electronic Prescribing of Controlled Substances Electronic Prescribing of Controlled Substances (EPCS) This document, as well as the software described in it, is provided under a software license agreement with STI Computer Services, Inc. Use of this

More information

Consumer Engagement with Health Information Technology Summary of NeHC Survey Results

Consumer Engagement with Health Information Technology Summary of NeHC Survey Results Consumer Engagement with Health Information Technology Summary of NeHC Survey Results Background In June 2012, National ehealth Collaborative (NeHC) distributed a survey on consumer engagement with health

More information

Health Homes Implementation Series: NYeC Privacy and Security Toolkit. 16 February 2012

Health Homes Implementation Series: NYeC Privacy and Security Toolkit. 16 February 2012 Health Homes Implementation Series: NYeC Privacy and Security Toolkit 16 February 2012 1 Agenda What are the New York ehealth Collaborative (NYeC) and the Regional Extension Center? What are Health Homes?

More information

EHR Glossary of Terms

EHR Glossary of Terms EHR Glossary of Terms American Recovery and Reinvestment Act of 2009 (ARRA): budget bill enacted by Congress and signed by President Obama on February 17, 2009 that was designed to provide an economic

More information

Custom Report Data Elements: 2012 IT Database Fields. Source: American Hospital Association IT Survey

Custom Report Data Elements: 2012 IT Database Fields. Source: American Hospital Association IT Survey Custom Report Data Elements: 2012 IT Database Fields Source: American Hospital Association IT Survey COMPUTERIZED SYSTEM IMPLEMENTATION 3 Bar Coding 3 Computerized Provider Order Entry 3 Decision Support

More information

etools for Health Homes: Overview of NYS DOH OHITT Programs

etools for Health Homes: Overview of NYS DOH OHITT Programs 00111 etools for Health Homes: Overview of NYS DOH OHITT Programs June 16, 2013 Marni Ehrlich TechLeaders Consulting mehrlich@jemsconsult.com 631-757-6363 1 GOAL OF THE NYS CARE MANAGEMENT TRAINING ETOOLS

More information

Following are our comments and recommendations:

Following are our comments and recommendations: 230 E. Ohio Street Suite 500 Chicago, IL 60611 Phone: 252-946-3546 Fax: 734-973-6996 E-mail: himssehra@himss.org AllMeds, Inc. Allscripts Healthcare Solutions Amazing Charts Aprima Medical Software, Inc.

More information

California State Board of Pharmacy and Medical Board of California

California State Board of Pharmacy and Medical Board of California California State Board of Pharmacy and Medical Board of California Transmission and Receipt of Electronic Controlled Substance Prescriptions Pursuant to DEA Interim Final Rule (IFR): Electronic Prescriptions

More information

Status of Electronic Health Records in Missouri Hospitals HIDI SPECIAL REPORT JULY 2012

Status of Electronic Health Records in Missouri Hospitals HIDI SPECIAL REPORT JULY 2012 Status of Electronic Health Records in Missouri Hospitals HIDI SPECIAL REPORT JULY 2012 HIDI SPECIAL REPORT INTRODUCTION The steady progress that Missouri hospitals continue to demonstrate in their adoption

More information

State of the State Health IT

State of the State Health IT State of the State Health IT Susan Otter Director of Health Information Technology November 10, 2015 HIT: Opportunity and Challenges HIT impacts nearly every aspect of coordinated care New tools are needed

More information

Health Information Technology in Healthcare: Frequently Asked Questions (FAQ) 1

Health Information Technology in Healthcare: Frequently Asked Questions (FAQ) 1 Health Information Technology in Healthcare: Frequently Asked Questions (FAQ) 1 1. What is an Electronic Health Record (EHR), an Electronic Medical Record (EMR), a Personal Health Record (PHR) and e-prescribing?

More information

Table of Contents. Page 1

Table of Contents. Page 1 Table of Contents Executive Summary... 2 1 CPSA Interests and Roles in ehealth... 4 1.1 CPSA Endorsement of ehealth... 4 1.2 CPSA Vision for ehealth... 5 1.3 Dependencies... 5 2 ehealth Policies and Trends...

More information

Clinics: Adoption and Use of EHRs and Exchange of Health Information, 2015

Clinics: Adoption and Use of EHRs and Exchange of Health Information, 2015 Minnesota e-health Report Clinics: Adoption and Use of EHRs and Exchange of Health Information, 2015 August 2015 Prepared by: Minnesota Department of Health Office of Health Information Technology http://www.health.state.mn.us/e-health

More information

New York State All Payer Database Request for Information

New York State All Payer Database Request for Information New York State All Payer Database Request for Information July 26, 2012 RFI 1205180104 Schedule of Events: Milestone APD RFI Released July 26, 2012 Date and Time Deadline Date for Questions Deadline for

More information

Open Platform. Clinical Portal. Provider Mobile. Orion Health. Rhapsody Integration Engine. RAD LAB PAYER Rx

Open Platform. Clinical Portal. Provider Mobile. Orion Health. Rhapsody Integration Engine. RAD LAB PAYER Rx Open Platform Provider Mobile Clinical Portal Engage Portal Allegro PRIVACY EMR Connect Amadeus Big Data Engine Data Processing Pipeline PAYER CLINICAL CONSUMER CUSTOM Open APIs EMPI TERMINOLOGY SERVICES

More information

AT&T Healthcare Community Online - Enabling Greater Access with Stronger Security

AT&T Healthcare Community Online - Enabling Greater Access with Stronger Security AT&T Healthcare Community Online: Enabling Greater Access with Stronger Security Overview/Executive Summary With a nationwide move to electronic health record (EHR) systems, healthcare organizations and

More information

How to Optimize Epic Clinical Workflows with Imprivata

How to Optimize Epic Clinical Workflows with Imprivata How to Optimize Epic Clinical Workflows with Imprivata Imprivata OneSign gives care providers fast, secure access to patient information by combining single sign-on with strong authentication enabling

More information

How to Use the NYeC Privacy and Security Toolkit V 1.1

How to Use the NYeC Privacy and Security Toolkit V 1.1 How to Use the NYeC Privacy and Security Toolkit V 1.1 Scope of the Privacy and Security Toolkit The tools included in the Privacy and Security Toolkit serve as guidance for educating stakeholders about

More information

Data Analytics Update. Health IT Standards Committee Meeting November 13, 2013

Data Analytics Update. Health IT Standards Committee Meeting November 13, 2013 Data Analytics Update Health IT Standards Committee Meeting November 13, 2013 2014 Edition EHR certification update 2014 EDITION HER CERTIFICATION UPDATE 1 Hospitals attested to stage 1 MU by 84% of EHs

More information

Ron Wyden Senate Finance Committee Chairman 221 Dirksen Senate Office Building. Dear Chairman Wyden and Senator Grassley:

Ron Wyden Senate Finance Committee Chairman 221 Dirksen Senate Office Building. Dear Chairman Wyden and Senator Grassley: 33 W. Monroe, Suite 1700 Chicago, IL 60603 Phone: 312-915-9582 Fax: 312-915-9511 E-mail: himssehra@himss.org AllMeds, Inc. Allscripts Healthcare Solutions Amazing Charts Aprima Medical Software, Inc. Cerner

More information

Vendor Assessment: The Industry Short List of Electronic Health and Medical Records for Small and Midsize Ambulatory Practices

Vendor Assessment: The Industry Short List of Electronic Health and Medical Records for Small and Midsize Ambulatory Practices Global Headquarters: 5 Speen Street Framingham, MA 01701 USA P.508.935.4445 F.508.988.7881 www.healthindustry-insights.com Vendor Assessment: The Industry Short List of Electronic Health and Medical Records

More information

PARTICIPATION AGREEMENT For ELECTRONIC HEALTH RECORD TECHNICAL ASSISTANCE

PARTICIPATION AGREEMENT For ELECTRONIC HEALTH RECORD TECHNICAL ASSISTANCE PARTICIPATION AGREEMENT For ELECTRONIC HEALTH RECORD TECHNICAL ASSISTANCE THIS AGREEMENT, effective, 2011, is between ( Provider Organization ), on behalf of itself and its participating providers ( Providers

More information

Authentication Tokens

Authentication Tokens State Capitol P.O. Box 2062 Albany, NY 12220-0062 www.its.ny.gov New York State Information Technology Standard IT Standard: Authentication Tokens No: NYS-S14-006 Updated: 05/15/2015 Issued By: NYS ITS

More information

MEDICAL ASSISTANCE BULLETIN

MEDICAL ASSISTANCE BULLETIN ISSUE DATE April 8, 2011 EFFECTIVE DATE April 8, 2011 MEDICAL ASSISTANCE BULLETIN NUMBER 03-11-01, 09-11-02, 14-11-01, 18-11-01 24-11-03, 27-11-02, 31-11-02, 33-11-02 SUBJECT Electronic Prescribing Internet-based

More information

Request for Service. Business and Technical Consulting Services Senior Business Analyst OntarioMD EMR Physician Dashboard

Request for Service. Business and Technical Consulting Services Senior Business Analyst OntarioMD EMR Physician Dashboard Request for Service Business and Technical Consulting Services Senior Business Analyst OntarioMD EMR Physician Dashboard RFS Number: 2015-11 Issued: October 29, 2015 Closing Date: November 12, 2015 at

More information

Fund for Public Health in New York 291 Broadway, 17th Floor, New York, NY 10007 Phone: (212) 266-7821 Fax: (212) 693-1856 www.fphny.

Fund for Public Health in New York 291 Broadway, 17th Floor, New York, NY 10007 Phone: (212) 266-7821 Fax: (212) 693-1856 www.fphny. Fund for Public Health in New York 291 Broadway, 17th Floor, New York, NY 10007 Phone: (212) 266-7821 Fax: (212) 693-1856 www.fphny.org Medical Billing and Coding Training Program Request for Proposals

More information

Four rights can t be wrong: why now is the right time to implement an EHR

Four rights can t be wrong: why now is the right time to implement an EHR White Paper Four rights can t be wrong: why now is the right time to implement an EHR OptumInsight www.optum.com Page 1 White Paper EHRs and small to mid-size physician practices: Finding the right fit

More information

Presented by: DV-NJ HIMSS Fall Event 10/22/2009. Colleen Woods, Chief Information Officer, State of NJ Department of Human Services

Presented by: DV-NJ HIMSS Fall Event 10/22/2009. Colleen Woods, Chief Information Officer, State of NJ Department of Human Services Overcoming the interoperability challenges between a health plan and a provider as payers have been reluctant to participate in traditional clinical exchanges DV-NJ HIMSS Fall Event 10/22/2009 Presented

More information

The Best Electronic Health Record Systems

The Best Electronic Health Record Systems The Best Electronic Health Record Systems There are 500 or more electronic health record software options. That s a lot to choose from. The EHR software vendors make the case that their system is the best.

More information

Request for Information (RFI): Electronic Health Record (EHR) systems For New York State Designated Home and Community Based Services (HCBS) Providers

Request for Information (RFI): Electronic Health Record (EHR) systems For New York State Designated Home and Community Based Services (HCBS) Providers Request for Information (RFI): Electronic Health Record (EHR) systems For New York State Designated Home and Community Based Services (HCBS) Providers Behavioral Health Information Technology (BHIT) Grant

More information

A Planning Guide for Electronic Prescriptions for Controlled Substances (EPCS)

A Planning Guide for Electronic Prescriptions for Controlled Substances (EPCS) A Planning Guide for Electronic Prescriptions for Controlled Substances (EPCS) The Federal Drug Enforcement Administration (DEA) regulates prescriptions of controlled substances that have risks for abuse.

More information

Introduction. Joe Fontenot, Manager Business Development Michael Justice, President

Introduction. Joe Fontenot, Manager Business Development Michael Justice, President Introduction Joe Fontenot, Manager Business Development Michael Justice, President About Us Founded to address the unique IS needs of Ambulatory Healthcare, especially in the age of ACO s and corporate

More information

EHR Optimization Study For Hospitality Practice

EHR Optimization Study For Hospitality Practice Brochure More information from http://www.researchandmarkets.com/reports/3453519/ US Ambulatory Electronic Health Record Market: 2015-2020 Description: This study analyzes trends in the US ambulatory electronic

More information

Health Information Technology

Health Information Technology Health Information Technology chartbook volume II Maine Hospitals Survey 2010 UNIVERSITY OF SOUTHERN MAINE Health Information Technology Maine Hospitals Survey Volume II Authors Martha Elbaum Williamson,

More information

Health: Electronic Health Records

Health: Electronic Health Records Performance Audits 2 Electronic Health Records Summary Nova Scotia is working towards the development of a provincial electronic health record system known as SHARE. The province is participating in and

More information

2015 RBC Capital Markets Global Healthcare Conference February 2015

2015 RBC Capital Markets Global Healthcare Conference February 2015 2015 RBC Capital Markets Global Healthcare Conference February 2015 1 Safe Harbor Provisions SAFE HARBOR PROVISIONS FOR FORWARD-LOOKING STATEMENTS: This news release may contain forward-looking statements

More information

How To Help Your Health Care Provider With A Health Care Information Technology Bill

How To Help Your Health Care Provider With A Health Care Information Technology Bill 875 Greentree Road Pittsburgh, PA 15220 QuestDiagnostics.com Quest Diagnostics Statement on the Pennsylvania Health Information Technology Act (Senate Bill 8) to the Senate Communications & Technology

More information

Global Electronic Health Records (EHR) Market is Projected to Reach US$30.28 bn by 2023

Global Electronic Health Records (EHR) Market is Projected to Reach US$30.28 bn by 2023 www.gosreports.com http://www.gosreports.com Global Electronic Health Records (EHR) Market is Projected to Reach US$30.28 bn by 2023 Global EHR market was valued at US$18.93 bn in 2014 and is expected

More information

E-Prescribing of Controlled Substances (EPCS) New York State Board for Podiatry

E-Prescribing of Controlled Substances (EPCS) New York State Board for Podiatry E-Prescribing of Controlled Substances (EPCS) As of March 27, 2015 it will be mandatory for practitioners, excluding veterinarians, to issue electronic prescriptions for controlled and non-controlled substances.

More information

Custom Report Data Elements: IT Database Fields. Source: American Hospital Association IT Survey

Custom Report Data Elements: IT Database Fields. Source: American Hospital Association IT Survey Custom Report Data Elements: IT Database Fields Source: American Hospital Association IT Survey TABLE OF CONTENTS COMPUTERIZED SYSTEM IMPLEMENTATION... 4 Bar Coding... 4 Computerized Provider Order Entry...

More information

HIPAA for HIT and EHRs. Latest on Meaningful Use and EHR Certification: For Privacy and Security Professionals

HIPAA for HIT and EHRs. Latest on Meaningful Use and EHR Certification: For Privacy and Security Professionals HIPAA for HIT and EHRs Latest on Meaningful Use and EHR Certification: For Privacy and Security Professionals Donald Bechtel, CHP Siemens Health Services Patient Privacy Officer Fair Information Practices

More information

Use Case Summary NAME OF UC: SINGLE SIGN ON FOR HEALTHCARE PROVIDERS AND PATIENTS. Sponsor(s): Michigan Department of Health and Human Services

Use Case Summary NAME OF UC: SINGLE SIGN ON FOR HEALTHCARE PROVIDERS AND PATIENTS. Sponsor(s): Michigan Department of Health and Human Services Use Case Summary NAME OF UC: SINGLE SIGN ON FOR HEALTHCARE PROVIDERS AND PATIENTS Sponsor(s): Michigan Department of Health and Human Services Date: 02 03 16 The purpose of this Use Case Summary is to

More information

Health Information Exchange in Minnesota & North Dakota

Health Information Exchange in Minnesota & North Dakota Health Information Exchange in Minnesota & North Dakota April 16, 2014 Objectives Learn basic HIE concepts Understand key success factors for HIE Gain an understanding of Minnesota and North Dakota s approach

More information