Typical duration: 1–3 weeks, depending on organization size and complexity.
2) Solution design and customization planning
Activities: Map current processes to BestNotes features, design new workflows, determine templates (note types, forms, progress notes), create role-based access controls, plan data migration strategy.
Deliverables: Solution design document, integration map, data migration plan, security/compliance plan, test scenarios.
Fine-grained permissions for clinicians, admins, billers, and supervisors.
Data fields and migrations:
Custom patient data fields; handling of legacy data mapping; field-level validation rules.
Reporting and analytics:
Custom dashboards and ad-hoc reports; export formats (CSV/PDF); scheduled reports.
Security and compliance:
Custom encryption settings, audit logs, user activity monitoring, HIPAA/HITECH alignment.
Integrations:
Custom integrations with practice management, billing systems, e-prescribing, lab systems, and patient portals; API access if available.
Branding and UI:
Custom branding elements (logos, color schemes) and localized language/terminology if supported.
Additional Costs
Software licensing / subscription:
Per-user, per-month or per-provider model.
Different tiers by feature set (core EMR, enhanced analytics, patient portal, telehealth, etc.).
Implementation/setup fees:
One-time activation/implementation fee often covering project management, initial configuration, data migration planning, and onboarding support.
Data migration costs:
Based on data volume, complexity, and the number of sources; sometimes included in the implementation fee, sometimes billed separately.
Customization charges:
If you require significant tailoring (templates, workflows, custom fields, specific dashboards), there may be a one-time development fee or ongoing maintenance fees.
Training fees:
Costs for administrator/trainer sessions; may be included in onboarding or charged separately.
Integrations and API access:
Fees for connecting to third-party systems; may include one-time integration development and ongoing maintenance.
Support and maintenance:
Tiered support plans (basic, standard, premium) with varying response times, hours of coverage, and SLAs.
Possible annual maintenance or renewal fees; sometimes included in the subscription.
Data storage and backups:
Additional charges for extended data retention, backups, or archival storage, if not included.
Telehealth or portal fees:
If applicable, separate fees for patient portal access, telehealth modules, or secure messaging.
Training
Administrator onboarding: Comprehensive sessions for super users and system admins covering configuration, user provisioning, security roles, and core workflows.
Clinician and staff training: Role-specific training for clinicians, front-d desk staff, billers, and portal users. May cover note templates, scheduling, charting, and billing workflows.
Live training sessions: Real-time webinars or on-site training (where applicable) led by a trainer.
Self-paced resources: Access to a library of recorded trainings, quick reference guides, how-to articles, and best-practice checklists.
Sandbox/testing environment: A safe space to practice configurations, note templates, and workflows before going live.
Train-the-trainer options: Empowering internal “super users” to train their teams, reducing go-live friction.
Playbooks and templates: Standard operating procedures, sample workflows, and macro templates to accelerate adoption.
Security Measures
Data encryption:
In transit: TLS/SSL for all data exchanged between clients and servers.
At rest: Encryption for databases and storage.
Access control:
Role-based access control (RBAC) with least-privilege permissions.
Multi-factor authentication (MFA) options for user logins.
Audit logging and monitoring:
Detailed logs of user activity, access to PHI/PII, and configuration changes.
Regular review processes and alerting for unusual or unauthorized activity.
Data residency and backups:
Regular backups, with defined retention periods and disaster recovery procedures.
Options for data export and portability for business continuity.
Security standards and compliance:
Alignment with HIPAA/HITECH requirements.
Business Associate Agreement (BAA) availability.
End-user device security guidance and encryption where applicable.
Privacy and data handling:
Data minimization practices, access reviews, and incident response planning.
Procedures for data subject requests and data de-identification where relevant.
Updates
Regular release cycles: Vendors commonly publish updates quarterly or semi-annually, with interim patches as needed.
Major versions vs. minor patches: Major versions may introduce new features and UI changes; patches typically address bugs, security fixes, and small enhancements.
Impact assessment: Pre-release testing to assess compatibility with existing configurations and data.
Staged rollout:
Sandbox/pre-production environments for validation.
Pilot groups (optional) to test before broad deployment.
Broad deployment to all users after successful testing.
Communication: Release notes detailing new features, changes, deprecations, and any required user action.
Training alignments: Optional quick-start guides or short trainings when significant changes affect workflows.
Backout plan: Contingency steps if an update introduces issues, including rollback options.
Data Ownership and Portability
Vendor role: The vendor typically acts as a data processor/controller on behalf of the practice and is responsible for secure storage, access controls, and processing in line with the contract and applicable laws.
Data usage rights: Vendors usually reserve rights to use aggregated, de-identified data for analytics, product improvement, or benchmarking, but should not use identifiable PHI for other purposes without explicit consent or contractual allowances.
BAA requirements: Ensure a Business Associate Agreement (BAA) is in place that defines responsibilities for safeguarding PHI, incident response, breach notification, and subcontractor controls.
Export capability: Request the ability to export full patient records, scheduling data, billing histories, and metadata in a machine-readable format (e.g., CSV, JSON, CDA/HL7 FHIR if applicable).
Archiving and retention: Confirm data retention periods post-termination and any obligations for archived data formats and retrieval.
Migration assistance: Verify whether the vendor provides data export tooling, migration support, and guidance to transition to another system with minimal downtime.
Scaling Up / Down
Scaling model: Clarify whether scaling is purely usage-based (per-user, per-provider) or location-based, and how add-ons (telehealth, portal, analytics) affect pricing.
Cohort changes: Understand how rapidly you can add or remove users, locations, or modules, and whether there are minimums or penalties.
Data and performance impact: Inquire about performance guarantees as data volume grows (e.g., response times, backup windows, API rate limits).
The terms & conditions for contract renewal and cancellation
Term length: Common terms are 1-year or multi-year contracts; some offerings use evergreen terms with annual renewals.
Price protection: Look for caps on annual price increases, renewal rate locks, or grandfathered pricing for existing users.
Inclusion of features in renewal: Clarify if feature sets or modules can be removed or added at renewal, and how that affects price.
Termination for convenience vs. for cause: Determine if you can terminate for convenience at certain notice periods, or only for specific breaches.
Notice period: Typical 30–90 days for renewal termination; ensure clear language on end-of-term notices.
Data handover post-termination: Requirements and timelines for data export, format, and delivery after termination.
Transition support: Availability of transitional assistance (e.g., continued access for a grace period, support during data migration to another system) and any associated costs.
Early termination penalties: Check for early termination fees or unrecovered implementation costs.
Compliance
HIPAA/HITECH: Most EMR vendors provide safeguards consistent with HIPAA/HITECH, including administrative, physical, and technical safeguards.
BAA availability: A signed BAA outlining responsibilities for PHI, breach notification, and subcontractor oversight.
Security certifications: Look for independent attestations or certifications (e.g., SOC 2 Type II, ISO 27001) if available; vendors may share the latest audit reports upon request.
Data privacy laws: Compliance considerations for regional laws (e.g., GDPR if you operate in the EU, state privacy laws in the US). Confirm data processing agreements reflect applicable regulations.
Audit and logging: Detailed access logs, change logs, and monitoring practices for PHI access and system activity.
Incident response: Documented incident response plan with timelines for breach notifications and remediation steps.