Estimated duration: 2–6 weeks depending on practice size and complexity.
System design and configuration
Workflow mapping: tailor templates, orders, visit types, and point-of-care documentation paths to match your clinics.
Data migration planning: determine which data (patient demographics, active/remedial charts, historical encounters) moves to Nexus and how it maps to fields.
Security & compliance setup: user roles, access controls, audit trails, HIPAA/PHI safeguards, and disaster recovery plans.
Interface design: setup of interfaces with labs, imaging, pharmacies, payers, and any legacy EHRs or practice management systems.
Estimated duration: 2–8 weeks (could be longer for multi-site or complex integrations).
Data migration and testing
Migration execution: transfer of patient data, encounters, allergies, medications, problem lists, and billing data.
Quality assurance: test patient records, charting workflows, order sets, templates, and reporting.
User acceptance testing (UAT): clinicians and admins validate day-to-day tasks in a sandbox.
Estimated duration: 2–6 weeks (depends on data volume and cleansing needs).
Training and change management
Role-based training: physicians, nurses, medical assistants, billers, schedulers, and IT staff.
Super-user program: develop internal champions to support peers.
Training materials: manuals, quick reference guides, video tutorials, and go-live checklists.
Security and roles: granular access controls, audit reporting, and role-based dashboards.
Data migration rules: field mappings, de-duplication rules, historical data cleansing.
Reporting and analytics: custom dashboards, ad-hoc reports, and scheduled report distribution.
UI/UX tweaks: color schemes, navigation tweaks, and clinician-friendly layouts.
Additional Costs
Setup/implementation fees: one-time charges for project planning, configuration, data migration, interfaces, and initial training.
Software licensing or subscription: ongoing per-user or per-provider fees; may vary by module and site count.
Hosting and infrastructure: if cloud-based, monthly hosting fees; if on-prem, hardware, backups, and maintenance.
Data migration costs: cleansing, mapping, and migration services (may be separate from standard implementation).
Interfaces and integrations: lab, imaging, pharmacy, payer portals, and any legacy EHR interfaces often incur setup and ongoing maintenance fees.
Training costs: initial training (on-site or virtual) and ongoing education sessions; sometimes bundled with implementation.
Support and maintenance: annual or monthly fees for support, software updates, and access to priority support; may include a tiered support structure.
Upgrades and customization maintenance: fees for maintaining customizations after software upgrades (some vendors charge annual maintenance for customizations).
Training
Initial training programs
Role-based onboarding: tailored sessions for physicians, nurses, medical assistants, billers, schedulers, and IT staff.
Hands-on training: live or virtual sessions using a sandbox environment to practice common workflows (documentation, orders, e-prescribing, scheduling, billing).
Training materials: user manuals, quick reference guides, video tutorials, and job aids.
Super-user program: designation of internal champions who receive deeper training to help peers post go-live.
Go-live support
Hypercare or go-live window: intensified support for the first days to weeks after launch, with rapid issue resolution and escalation paths.
Typical duration: 2–8 weeks of elevated support, depending on practice size and complexity.
Ongoing support options
Tiered support plans: standard, enhanced, and premium support with defined service levels (response times, issue severities).
Knowledge base: searchable articles, FAQs, and self-service troubleshooting.
Refresher training: periodic training sessions, annual or semi-annual updates aligned with new releases or process changes.
User feedback and governance: channels for clinics to propose improvements or report systemic pain points; periodic product feedback sessions.
Training for upgrades
When updates introduce new features or UI changes, vendors typically offer (a) upgrade-focused training modules, (b) release notes and webinars, and (c) optional “what’s new” clinics to minimize disruption.
Security Measures
Access control and identity management
Role-based access control (RBAC): granular permissions by user role, with the ability to restrict data access (PHI) by user.
Multi-factor authentication (MFA): optional or required for added login security.
Data encryption
In transit: TLS/SSL encryption for all data exchanged between clients and servers.
At rest: encryption for database files, backups, and object storage where protected data resides.
Audit and monitoring
Audit trails: comprehensive activity logging for user access, data changes, and system events.
Monitoring: security information and event management (SIEM) integrations or built-in monitoring for anomalous activity.
Data integrity and backups
Regular backups: automated, encrypted backups with defined RPO/RTO targets.
Disaster recovery: documented DR plans with recovery objectives and failover procedures.
Compliance
HIPAA/PHI safeguards: standard controls to meet U.S. healthcare privacy and security regulations. Business Associate Agreement (BAA): provided or negotiated as part of customer agreement.
Updates
Update cadence
Regular release cycles: many EHR vendors deploy minor updates quarterly, with major releases annually or semi-annually. Some deployments may offer continuous delivery for cloud environments.
Frequency: typical pattern ranges from monthly security patches to quarterly feature updates.
Delivery model
Cloud (SaaS): updates are applied by the vendor with minimal downtime; customers receive release notes and may have a preview window.
On-premises or hosted, but customer-managed: updates require scheduled maintenance windows, with potential data migration or compatibility testing.
Change management
Announcement and planning: advance notice of upcoming changes, with release notes detailing new features, bug fixes, and potential impact.
Backward compatibility and deprecation: guidance on deprecated features and timelines for sunset.
Upgrade assistance: documentation, upgrade checklists, and optional professional services to assist with migrations, data mappings, and testing.
Testing and validation
Pre-production/testing environments: sandbox or staging environments to validate new releases before production deployment.
User acceptance testing (UAT): optional or recommended for major releases, especially if workflows or templates change.
Support considerations around updates
Impact assessment: guidance on any required reconfiguration of templates, macros, order sets, or interfaces after an update.
Training materials: updated user guides and quick reference sheets aligned with changes in the release.
Data Ownership and Portability
Data ownership
Patient data ownership: In most Nexus EHR agreements, the customer retains ownership of all patient data that you input into the system.
Vendor position typically: Nexus EHR acts as a data processor or service provider with responsibilities to protect and securely store data on behalf of the customer (data controller remains the customer).
Data access and control
Access rights: Customer typically retains rights to access, extract, and export data.
Portability rights: Vendors commonly provide data export capabilities in standard formats (e.g., CSV, JSON, or HL7/FHIR bundles) to facilitate migration or archiving.
Data formats and exports
Standard export options: Demographics, encounters, encounter diagnoses, medications, immunizations, lab results, billing data, attachments, and metadata.
Migration tooling: Some agreements include data migration/assist services or advisory support to ensure clean extraction.
Data retention and deletion
Retention policies: Defined in the contract; may specify minimum retention periods and orderly deletion upon user request or contract termination.
De-identification: Options may exist for de-identified data extracts for analytics, subject to consent and regulatory requirements.
Pseudonymization and PHI handling
PHI safeguards: Standard protections during export, transmission, and storage; secure transfer mechanisms for data extracts.
Data circulation after termination
Transition assistance: Could include a data export package, assistance with data reconciliation, and a defined post-termination access window (sometimes limited) to retrieve data before complete deactivation.
Return or destruction of data: Usually specified, with process for securely deleting customer data after termination, subject to regulatory data retention obligations.
Scaling Up / Down
Scaling options
Consumption-based or tiered licensing: Some contracts scale by number of providers, locations, or user seats; pricing adjusts accordingly.
Volume discounts or tier adjustments: Possible for growing organizations.
Change control
Formal change requests: Any expansion or contraction typically requires a change order, updated SOW, and amended pricing.
Data and performance considerations
Performance SLAs: Ensure that scaling resources (compute, storage, and interfaces) maintain response times and uptime.
Migration/archival guidance: For downsizing, recommendations for archiving older data or adjusting data retention settings.
Implementation effort
Timeline impact: Adding sites or providers may require additional training, interface provisioning, and data migrations; likewise, downsizing may entail data export, reconfiguration, and decommissioning tasks.
The terms & conditions for contract renewal and cancellation
Renewal structure
Term length: Commonly 1–3 years; auto-renewal is often standard unless notice of non-renewal is provided.
Price adjustments: Potential annual increases or CPI-based adjustments; may be capped or negotiated.
Cancellation and termination
Termination for convenience vs. for cause:
For cause: breach of material terms, failure to meet SLAs, or non-payment; usually with a cure period.
For convenience: fewer vendors offer, but some may allow with notice and potential wind-down periods.
Notice period: Requirement to provide written notice within a defined window (e.g., 90–180 days) prior to renewal.
Transition obligations on termination:
Data export/return
Deletion of data within a defined period
Continued access to data for a short wind-down period, if applicable
Fees at termination
Outstanding charges: Payment for services incurred but not yet billed; termination fees (if any) per contract.
Data migration costs post-termination: Possible charges for data extraction or assistance during transition.
Post-termination support
Limited support window: Some vendors offer limited support after termination for a defined period; often at an additional cost.
Compliance
HIPAA / PHI safeguards
Generally required for U.S. healthcare customers; BAAs (Business Associate Agreements) are typically provided and negotiated.
Security frameworks and certifications (common in the industry)
SOC 2 Type II or Type I
ISO 27001 (information security management)
ISO 27701 (privacy information management)
HITRUST CSF alignment or certification (where applicable)
Data privacy regulations
Compliance considerations for regional data protection laws (e.g., GDPR for EU data, CCPA/CPRA for California residents) depending on data residency and customer location.
Audit and oversight
Regular security assessments, vulnerability scans, and penetration testing disclosures; access to audit reports or summaries may be provided to customers under NDA.
Business continuity and disaster recovery
Documented DR plans with defined RPO/RTO targets; annual testing sometimes required.
Interoperability standards
Support for HL7, FHIR, and other standard healthcare data exchange formats; secure API access and token-based authentication.