The typical implementation process for DivvyCloud software involves several key steps designed to ensure effective integration and optimal performance within an organization's cloud environment. Initially, the process begins with planning and assessment, where stakeholders identify their specific security needs, compliance requirements, and the cloud environments in use (e.g., AWS, Azure, Google Cloud). Following this, configuration takes place, which includes setting up the platform to align with existing infrastructure and defining security policies tailored to the organization's requirements.Next, integration occurs, allowing DivvyCloud to connect with existing tools and workflows, particularly within CI/CD pipelines to enhance security during the development process. The platform's real-time monitoring capabilities are then activated to continuously assess cloud configurations against defined policies. This step is crucial for identifying misconfigurations or policy violations as they occur.Training sessions for relevant personnel are typically conducted to familiarize them with the platform's features and functionalities. The entire implementation process can vary in duration depending on the organization's size and complexity but generally takes between two weeks to a few months. This timeframe allows for thorough testing and adjustments to ensure that DivvyCloud operates effectively within the organization's cloud ecosystem while achieving desired security outcomes. Overall, DivvyCloud aims to provide a seamless transition that enhances cloud security posture management across multi-cloud environments.
Customisation
While specific details about its customization capabilities are not extensively documented, the software offers several features that suggest a degree of adaptability to meet specific business needs:
Patient Records Management: DOCISS allows for the creation, updating, and organization of comprehensive patient records, including demographics, medical history, medications, allergies, and test results. This flexibility enables healthcare providers to tailor patient information management to their specific requirements.
Appointment Scheduling: The software offers an appointment scheduling system that enables efficient management of patient appointments. It allows for easy appointment creation, rescheduling, and cancellation, with options to set reminders and notifications, facilitating customization to fit the workflow of different practices.
Medical Billing and Insurance Claims: DOCISS includes features for medical billing and insurance claims processing, allowing for the generation of invoices and billing statements, as well as the submission of insurance claims electronically. This functionality can be adapted to align with the financial processes of various healthcare facilities.
Prescription Management: The software provides tools for managing prescriptions, allowing doctors to create and track medication orders for their patients. It supports electronic prescribing, drug interaction checking, and medication history tracking, which can be customized to meet the prescribing practices of different medical professionals.
Clinical Documentation: DOCISS offers comprehensive clinical documentation capabilities, providing templates and forms for various medical specialties. This feature enables accurate documentation of diagnoses, treatments, and follow-up plans, allowing customization to fit the documentation needs of different specialties.
Additional Costs
DivvyCloud's pricing structure primarily revolves around an annual subscription model. However, there may be additional costs associated with the implementation and ongoing use of the software. These can include:
Setup Fees: While specific setup fees are not detailed in the available information, organizations should anticipate potential costs related to initial configuration and deployment, especially for larger or more complex environments. This may involve professional services or consulting fees if external assistance is required.
Maintenance Costs: Ongoing maintenance costs are typically included within the subscription model; however, organizations may incur additional expenses if they require extensive support or customizations that go beyond standard offerings.
Support Charges: DivvyCloud offers various levels of support, which may come with additional charges depending on the service level agreement (SLA) selected. Enhanced support options may include prioritized response times or dedicated support resources, which could result in higher costs.
Custom Development: If businesses need specific features or integrations that are not part of the standard offering, this could lead to additional development costs, particularly if custom solutions are required.
Training
Implementing a new Electronic Medical Records (EMR) system like DOCISS requires comprehensive training and support to ensure a smooth transition and effective utilization. While specific details about DOCISS's training and support offerings are not publicly available, it's common for EMR providers to offer the following services to new users:
Onboarding Training: This initial phase includes comprehensive sessions covering system navigation, data entry, appointment scheduling, and other fundamental functionalities. Training can be conducted on-site or virtually, depending on the provider's capabilities and the client's preferences.
Role-Based Training: Tailored training modules are designed for different user roles within the practice, such as physicians, nurses, administrative staff, and billing personnel. This approach ensures that each team member receives relevant instruction pertinent to their responsibilities.
User Manuals and Documentation: Providers typically supply detailed user manuals, quick reference guides, and online resources to assist users in navigating the system and troubleshooting common issues.
Ongoing Support: Post-implementation support is crucial for addressing any challenges that arise during daily operations. Support services may include:
Help Desk Support: Access to a dedicated support team via phone, email, or chat to resolve technical issues and answer user queries.
System Updates and Maintenance: Regular updates to enhance system functionality, address security concerns, and introduce new features.
Advanced Training Sessions: Periodic training opportunities to help users stay updated with new features and best practices.
Customization Assistance: Support in tailoring the EMR system to align with the specific workflows and requirements of the practice, ensuring optimal efficiency and user satisfaction.
Security Measures
DivvyCloud implements a robust set of security measures to protect data across its cloud security platform. These measures encompass various aspects of data protection, including access control, encryption, and monitoring.
Access Control: DivvyCloud employs strict access controls to ensure that only authorized personnel can access sensitive data. This includes role-based access control (RBAC), where users are granted permissions based on their job functions, limiting access to only the data necessary for their roles. Additionally, multi-factor authentication (MFA) is utilized to add an extra layer of security during the login process, requiring users to provide multiple forms of verification before gaining access.
Data Encryption: All sensitive data is encrypted both at rest and in transit. This means that data stored on servers is protected from unauthorized access, and any data transmitted over networks is secured using protocols such as SSL/TLS. This encryption helps safeguard against potential breaches and ensures that even if data is intercepted, it remains unreadable without the appropriate decryption keys.
Monitoring and Logging: Continuous monitoring is a key component of DivvyCloud's security strategy. The platform logs all user activities and system changes, enabling real-time detection of suspicious behavior or unauthorized access attempts. This logging capability allows for thorough audits and helps organizations maintain compliance with regulatory requirements.
Automated Remediation: DivvyCloud features automated remediation capabilities that can identify and correct misconfigurations or policy violations in real time. This proactive approach minimizes the risk of security incidents by ensuring that any vulnerabilities are addressed promptly.
Data Backups: Regular backups are conducted to protect against data loss due to accidental deletion or corruption. These backups are stored securely and can be restored quickly in the event of a data loss incident, ensuring business continuity.
Network Security: The platform is protected by firewalls and intrusion detection systems that monitor incoming and outgoing traffic for malicious activity. These security measures help prevent unauthorized access to cloud environments and protect sensitive data from external threats.
Compliance with Standards: DivvyCloud adheres to industry standards and regulations related to data protection, such as GDPR and HIPAA, ensuring that its security practices meet the necessary legal requirements for handling sensitive information.
Updates
Specific information regarding the frequency and management of software updates for DOCISS is not publicly available. However, in the healthcare software industry, it is common for EMR systems to receive regular updates to enhance functionality, address security vulnerabilities, and comply with evolving healthcare regulations.
Data Ownership and Portability
DivvyCloud's policy on data ownership and portability emphasizes that all data created or stored by users within the platform remains the property of the users. This policy is designed to ensure that organizations retain full control over their data while utilizing DivvyCloud's services. Key aspects of this policy include:
Data Ownership: Users maintain ownership of all documents, databases, and other types of data they create, amend, or store using DivvyCloud. The company does not claim any ownership rights over this data, reinforcing the notion that users are the rightful owners.
Access Control: DivvyCloud restricts access to user data to only those individuals nominated by the user and its technical support team when necessary for assistance. This ensures that sensitive information is only accessible to authorized personnel.
Data Portability: Users can request the return of their data at any time, including upon termination of their account. DivvyCloud commits to returning user data promptly, although there may be a nominal fee associated with this process. This facilitates easy migration or transfer of data as needed.
Data Deletion: After account termination, any remaining user data on DivvyCloud's systems is deleted within 30 days unless it has been returned to the user. This policy helps ensure that organizations can manage their data lifecycle effectively and securely.
Scaling Up / Down
Specific details regarding DOCISS's policies on scaling the software to accommodate changing organizational needs are not publicly available. However, in the context of Electronic Medical Records (EMR) systems, scalability is a crucial factor that allows healthcare organizations to adjust their software capabilities in response to growth or downsizing.
The terms & conditions for contract renewal and cancellation
DivvyCloud's terms and conditions for contract renewal and cancellation are structured to provide clarity and flexibility for users. Here are the key points regarding these terms:
Contract Renewal
Automatic Renewal: DivvyCloud's subscription agreements automatically renew for an additional one-year term unless otherwise specified on the order form. Either party can opt out of renewal by providing written notice at least 30 days prior to the anniversary date of the contract.
Rate Changes: Upon renewal, the subscription will be invoiced at the prevailing list price for the applicable tier at that time, unless a different rate is specified in the order form. Rapid7 reserves the right to change rates and introduce new charges for subsequent subscription terms, provided that customers receive written notice at least 60 days prior to the end of the current term.
Contract Cancellation
Notice Requirement: To cancel a subscription, users must provide 20 days' notice before their annual contract renewal date. This ensures that both parties have adequate time to process the cancellation.
Termination by DivvyCloud: DivvyCloud retains the right to terminate a user's account with 10 days' advance notice if payment is not received on time or if there is a violation of the terms of service. Additionally, either party may terminate the agreement immediately in cases of material breach or bankruptcy proceedings against either party.
No Refunds for Early Cancellation: If a user cancels their subscription before the end of an annual term, they will not receive any refunds for unused months or partial months. Users are responsible for paying all fees that have accrued up to the point of cancellation.
Data Management upon Termination: Upon termination, users are responsible for backing up their data, as DivvyCloud does not guarantee data retention post-cancellation. After account termination, any remaining user data will be deleted within 30 days unless it has been returned to the user.
Obligations upon Termination: Termination of the contract does not relieve users from their obligation to pay any outstanding fees that have accrued prior to termination. Users must cease using the service immediately upon termination and certify that they have destroyed or returned all copies of the software.
Compliance
Specific details regarding the compliance standards met by DOCISS are not publicly available. However, in the context of EMR systems, adherence to certain compliance standards is crucial to ensure data security, patient privacy, and interoperability.
Common Compliance Standards for EMR Systems:
Health Insurance Portability and Accountability Act (HIPAA): In the United States, HIPAA sets the standard for protecting sensitive patient information. EMR systems compliant with HIPAA ensure that patient data is securely stored and transmitted.
General Data Protection Regulation (GDPR): In the European Union, GDPR regulates data protection and privacy. EMR systems adhering to GDPR standards ensure that patient data is handled with the utmost care and in compliance with EU regulations.
Health Level Seven International (HL7): HL7 is a set of international standards for the transfer of clinical and administrative data between software applications used by various healthcare providers. EMR systems compliant with HL7 standards facilitate interoperability between different healthcare systems.
International Organization for Standardization (ISO) 27001: This standard specifies the requirements for establishing, implementing, maintaining, and continually improving an information security management system. EMR systems compliant with ISO 27001 demonstrate a commitment to information security.
Recommendations:
Consult with the Provider: Engage with Purple Brains to understand the specific compliance standards that DOCISS meets, ensuring that the system aligns with your organization's regulatory requirements.
Review Documentation: Request detailed documentation outlining the compliance certifications and standards adhered to by DOCISS.
Seek Legal Advice: Consult with legal professionals to ensure that the EMR system complies with relevant data protection and privacy laws applicable to your region.