Exym
بواسطة Exym, LLC
The typical implementation process for Exym’s Behavioral Health EHR:
Phase 1: Administrative Setup: Begins with a kickoff meeting to outline milestones, define agency locations, payers, and create admin accounts for early access.
Phase 2: Billing Configuration: Exym configures billing programs, sets up service activities, rates, modifiers, and rule codes in line with county and payer requirements.
Phase 3: Clinical Workflow Setup: Clinical roles, workflows, and system configurations (referrals, client statuses, reminders) are tailored to agency operations.
Phase 4: Review and Finalize Notes: Custom note templates created previously are reviewed, edited, and finalized before data import.
Phases 5–6: Data Import: Client and service data are imported to ensure all records are available by the go-live date, enabling immediate billing operations.
Phase 7: Training: Role-specific training sessions for clinicians, billing users, and administrators ensure teams are fully prepared before launch.
Exym can indeed be customized extensively to fit specific business needs. Here are multiple data points highlighting its customization capabilities:
Custom Workflows: Exym allows agencies to create custom workflows tailored to their specific client treatment stages and processes. It automates paperwork generation based on client status changes, ensuring regulator info is recorded, internal tracking is efficient, and deadlines/triggers can notify staff of overdue tasks, which improves compliance and reduces administrative burden.
Custom Notes & Documentation: Clinicians can create and automate custom notes, forms, and documentation templates tailored to their clinical and billing needs. The system links notes to activities, ensures continuity of client info, and supports electronic signatures and custom client forms.
Custom Dashboards & Reports: Exym provides configurable dashboards and reporting tools, allowing agencies to create reports and visualize clinical, billing, and compliance data to meet agency-specific data needs.
Custom Permissions & Security: Permissions can be customized for different roles (e.g., clinicians, supervisors, interns) to control data access and safeguard private health info, supporting HIPAA and FERPA compliance.
Custom Setup & Implementation: During onboarding, Exym works with agencies to identify pain points and tailor system setup, including forms, workflows, billing rules, and reporting to meet unique program goals.
Modular Software for Specialized Programs: Exym includes modules that support specific behavioral health programs (e.g., foster care, residential treatment, substance use), allowing agencies to store all data within a single system while meeting specialized requirements.
Exym provides extensive training and robust customer support to ensure behavioral health agencies can fully leverage its EHR software. The approach combines personalized onboarding, role-based training, and ongoing education supported by expert teams.
Role-Specific Training: During implementation, Exym provides distinct training programs for clinicians, billing users, and administrators to ensure each team understands their part in operations and workflows.
Ongoing Education: Users have continuing access to learning materials through webinars, virtual user groups, on-demand sessions via KCare Academy, and periodic in-person regional events.
Annual User Conferences: Exym hosts user conferences offering training sessions, platform updates, and networking opportunities to help agencies stay informed about the latest features and best practices.
Leadership and Specialist Expertise: Many trainers and implementation specialists at Exym come from behavioral health backgrounds, offering contextual, real-world insights into billing, analytics, and telehealth.
Dedicated Customer Success Manager: Each agency is assigned a customer success manager who ensures smooth system usage and provides proactive engagement about new features or regulatory changes.
Responsive Helpdesk: Exym’s support team resolves 90–95% of tickets within 1 hour, providing fast and highly rated service. Agencies can also communicate with specialized teams for billing, reporting, or telehealth support needs.
Continuous Updates: Clients receive regular newsletters, system updates, and invitations to beta testing groups for new features and compliance changes.
Exym employs a multi-layered approach to data protection designed for compliance with healthcare privacy laws like HIPAA, HITECH, and FERPA. Its security architecture combines technical, administrative, and physical safeguards to ensure the confidentiality and integrity of sensitive health records.
HIPAA & HITECH Compliance: Exym’s platform and telehealth modules maintain full compliance with HIPAA and HITECH standards, ensuring all data processing and storage meet healthcare regulatory requirements.
256-Bit Data Encryption: All client data is protected using AES 256-bit encryption both at rest and in transit, offering one of the highest levels of commercial cryptographic security available.
Secure U.S.-Based Data Centers: Data is housed exclusively in SOC 2–compliant data centers within the United States, offering advanced physical security, 24/7 monitoring, redundant backups, and disaster recovery systems.
Zero Trust Access Model: Exym applies a Zero Trust security framework, enforcing identity verification for all users and devices to limit exposure and protect telehealth records.
Strict Access Controls & Permissions: Administrators can configure user-specific access rights (e.g., clinician, supervisor, intern), ensuring that staff access only the data necessary for their roles — essential for both HIPAA and FERPA compliance.
Frequent Penetration & Vulnerability Testing: Exym partners with GreyCastle Security, a national cybersecurity firm, for continuous penetration testing and security audits to identify and mitigate vulnerabilities.
Regular Staff Security Training: All Exym personnel undergo mandatory cybersecurity training and refresher sessions to meet evolving compliance standards and reduce human error risks.
Third-Party Vendor Compliance (BAAs): Exym holds Business Associate Agreements (BAAs) with all vendors, including Zoom and Zendesk, to ensure all integrations maintain HIPAA compliance.
FERPA Alignment for Educational Clients: For schools and agencies handling student mental health data, Exym aligns with FERPA standards, safeguarding student records and confidentiality through encryption and access controls.
Exym releases updates on a regular, structured schedule to ensure its EHR system remains compliant, secure, and aligned with user and regulatory needs. The approach emphasizes stability, user feedback integration, and smooth deployment management.
Quarterly Major Releases: Exym typically issues major platform updates every quarter, introducing new features for clinical documentation, billing automation, telehealth, reporting, and compliance enhancements such as CalAIM or Medi-Cal revisions.
Monthly Minor Updates: Between these, Exym rolls out minor releases and patches monthly to address smaller feature improvements, user experience upgrades, and integration refinements with third-party services (e.g., Zoom, Eleos Health, or Medi-Cal systems).
Security and Regulatory Updates: Security patches, compliance framework updates, and regulatory alignment adjustments (e.g., HIPAA or CalAIM mandates) are delivered as needed, independently of the normal release cycle, ensuring uninterrupted compliance.
Automated Cloud Delivery: All updates are automatically deployed via Exym’s secure cloud infrastructure, ensuring no downtime or manual installation is required by agencies.
Advance Notification and Training: Exym informs users before major releases through release notes, helpdesk announcements, and KCare webinars. Training sessions accompany major feature changes, helping users adapt efficiently.
Beta Testing and User Feedback Loops: Selected client agencies participate in beta testing before rollout, ensuring stability and real-world usability of new features.
Exym’s policy on data ownership and portability is structured around transparency, user control, and compliance with HIPAA and federal data access regulations. The company ensures that agencies retain full ownership of their clinical and billing data, while facilitating secure portability when needed.
Agency-Owned Data: Exym explicitly states that all client and agency data — including clinical notes, billing details, attachments, and outcome measures — remains the property of the agency using the software. Exym acts only as the data custodian, providing secure storage and management infrastructure.
No Vendor Lock-In: Agencies retain the right to retrieve or move their data at any time. Exym does not restrict users from exporting data if they choose to discontinue service or migrate to another EHR platform.
Data Retention and Continuity: Exym retains customer data only for the duration of the contractual relationship and removes it following termination in accordance with HIPAA and recordkeeping laws. Before deletion, agencies are allowed to export their full dataset.
Structured Data Export: Agencies can export records in standard file formats (CSV, XML, or PDF) to ensure compatibility with other healthcare systems and county/state reporting requirements like Medi-Cal and CalAIM.
Compliance with the CURES Act: Exym’s system supports the CURES Act data-sharing standards, enabling agencies to provide patients with access to their own electronic health information and to transfer it securely to other health providers if requested.
Automated Reports and API Integration: Exym allows agencies to automatically sync or download data from analytics dashboards, billing records, and claims modules — ensuring ongoing interoperability with external systems and funding programs.
Data Exchange Support: The platform integrates easily with Medi-Cal, county systems, and third-party applications through compliant data interfaces and secure APIs, facilitating seamless exchange of client information.
Exym’s contract renewal and cancellation policies for its Behavioral Health EHR software are structured for flexibility, transparency, and compliance with healthcare vendor standards. While exact terms can vary by agency size and service configuration, available documentation and EHR industry standards outline consistent core conditions.
Typical Contract Term: Exym contracts commonly range between one to three years, depending on the agency’s service scope and customization level.
Automatic Renewal (“Evergreen”) Clauses: Most Exym agreements automatically renew for successive 12-month terms unless either party opts out. Agencies must typically notify Exym 30–60 days before the renewal date to prevent automatic extension.
Price Escalation on Renewal: Renewal terms may include a minimal cost adjustment or escalation rate tied to inflation or software improvement factors. Long-term contracts generally secure lower pricing compared to short-term agreements.
Notice Period: Agencies may cancel services by providing written notice (30–60 days) prior to contract renewal. Early termination outside of these periods may incur prorated service or data extraction fees.
Termination for Cause: Either party may terminate the contract immediately for breach of terms, including issues like nonpayment, misuse of the system, or failure to uphold data security obligations.
Transition Support Upon Cancellation: When an agency discontinues its Exym subscription, the vendor supports secure data export in nonproprietary formats (e.g., HL7, CSV, or XML) and ensures full data recovery before termination. This prevents data loss and eases migration to other EHR systems.
Customer Data Retention: Following contract termination, Exym retains customer data only for a defined period—usually 30–90 days—to allow secure retrieval. Data is then permanently purged from Exym systems, complying with HIPAA and HITECH requirements.
Assistance for Migration: Exym assists agencies in transferring data to a new EHR system at the end of a contract term, maintaining compliance with CURES Act data portability and state-level interoperability obligations.
Transparent Renewal Communication: Exym provides advance notifications before renewal periods, allowing agencies to review updated service terms, features, or pricing adjustments.
Exym’s Behavioral Health EHR software meets a wide range of federal and state compliance standards designed to protect patient privacy, ensure secure data management, and maintain billing and documentation accuracy. These standards cover HIPAA, HITECH, SOC 2, CalAIM, Medi-Cal, and FERPA regulations.
HIPAA (Health Insurance Portability and Accountability Act): Exym is fully HIPAA-compliant, ensuring the confidentiality and integrity of Protected Health Information (PHI) across all modules — including clinical documentation, billing, and telehealth. Both Exym’s EHR and integrated platforms (Zoom and Zendesk) operate under Business Associate Agreements (BAAs) to guarantee privacy during data exchange.
HITECH Act Compliance: Exym aligns with the HITECH Act by applying robust data protection controls, encryption, and breach notification procedures. The platform utilizes a risk-based Information Security Program that aligns with NIST (National Institute of Standards and Technology) frameworks.
SOC 2 Certified Data Centers: All Exym data is hosted in SOC 2–2-compliant U.S.-based data centers, ensuring independent validation of its privacy, security, availability, and processing integrity controls.
CalAIM and Medi-Cal Compliance: Exym is tailored for behavioral health providers operating in California, offering compliance-ready modules for CalAIM (California Advancing and Innovating Medi-Cal) and Medi-Cal billing. Features include customizable billing templates, audit-ready reporting, and integration with county and state funding systems.
FERPA (Family Educational Rights and Privacy Act): For organizations serving school-based programs, Exym enforces FERPA data handling standards, protecting student mental health records and educational data privacy through encryption and controlled access.
BAA-Compliant Vendor Relationships: Every third-party integration—including cloud infrastructure, chat, and telehealth—operates under HIPAA-compliant Business Associate Agreements.
Secure Development Lifecycle (SDLC): Exym follows a secure software development lifecycle, incorporating penetration testing, static and dynamic code analysis, and vulnerability management.
Comprehensive Audit Trails: The EHR automatically logs all user activity and records changes, supporting transparency and compliance with Medi-Cal and DMH (Department of Mental Health) auditing requirements.