Understanding the client’s needs, existing infrastructure, and defining scope.
Design & Customization (4-8 weeks):
Configuring the system, integrating workflows, and customizing interfaces to match business requirements.
Development & Setup (2-6 weeks):
Data migration, setting up access controls, and testing integrations.
Training & Pilot Testing (2-4 weeks):
Conducting user training, resolve initial issues, and refine configurations.
Go-Live & Support (1-2 weeks):
Full deployment, monitoring, and final adjustments.
Customisation
Customization points include: workflow design, data reporting, user interface, access controls, and integration with existing systems (e.g., SAP, other clinical tools).
Extent of customization: Usually flexible, with some vendor support for custom modules or features.
Additional data points:
Custom scripting or automation for specific data handling.
Role-based access customization.
Integration with external databases or third-party APIs.
Additional Costs
Setup Fees: Often a one-time fee for deployment and initial configuration—ranging from a few thousand to tens of thousands USD depending on scope.
Maintenance & Support:
Annual support and maintenance typically costs around 15-20% of the licensing fee.
Could include updates, bug fixes, and access to support staff.
Training Costs: May be included or billed separately, especially for large user bases.
Additional Modules: Custom features, additional integrations, or advanced analytics might incur extra charges.
Training
Training options:
On-site or virtual training sessions.
Self-paced e-learning modules.
Documentation and user manuals.
Support Services:
Helpdesk assistance (available 24/7 or business hours).
Dedicated customer success managers
Regular updates and system health checks.
Security Measures
Data Encryption:
Data at rest is encrypted using standards like AES-256.
Data in transit is protected via SSL/TLS protocols.
Access Controls:
Role-based access management ensures users only see what they’re authorized to.
Multi-factor authentication (MFA) may be employed.
Audit Trails:
Detailed logging of user activities for accountability and compliance.
Compliance Standards:
Often aligned with HIPAA, GDPR, and other relevant regulations depending on jurisdiction.
Regular security assessments and vulnerability testing.
Network Security:
Firewalls, intrusion detection systems, and secure VPN access for remote users.
Data Backup & Recovery
Regular, encrypted backups with disaster recovery plans.
Updates
Release Schedule:
Encapsia typically releases updates quarterly or biannually, though it can vary.
Update Management:
Updates are managed through a structured deployment process, often with test environments for beta testing before production rollout.
Major updates may require scheduled downtime, with notifications provided in advance.
Features & Security Patches:
Critical security patches are applied as needed, often immediately, to mitigate vulnerabilities.
Data Ownership and Portability
Ownership Policy:
The client retains ownership of their data.
Encapsia acts as a custodian, managing data securely but not owning or controlling the data content
Data Portability:
Usually, the platform supports exporting data in standard formats (like CSV, XML, or JSON) for external use.
Data extraction procedures are often outlined in the service agreement, ensuring clients can retrieve their data at any time.
Compliance & Rights:
The policy aligns with GDPR, HIPAA, or other applicable standards, protecting client rights to data access, correction, and deletion.
Scaling Up / Down
Flexibility:
Most contracts include provisions to adjust user licenses or modules as organizational needs evolve.
Additions or reductions can often be handled with short-notice updates, subject to agreement.
Process:
Usually involves formal request and approval from the vendor’s account manager.
Scaling may include costs or discounts depending on volume changes.
Lead Time:
Scaling adjustments are often manageable with 30-90 days’ notice, but exact timelines vary.
The terms & conditions for contract renewal and cancellation
Renewal Terms:
Typically annual, with auto-renewal clauses unless canceled by the client ahead of the renewal date.
Renewal notices are usually required 30-60 days prior to expiration.
Cancellation Terms:
Can usually be done with advance notice (e.g., 30-90 days).
Some contracts may have penalties or fees for early termination, depending on upfront payments or customization.
Data & Transition:
Upon cancellation, clients are generally entitled to export their data.
Transition support may be provided to facilitate data migration out of the platform.
Renegotiation:
Contract terms can often be renegotiated upon renewal, including pricing, scope, or service levels.
Compliance
HIPAA (Health Insurance Portability and Accountability Act):
For healthcare data privacy and security compliance in the US.
GDPR (General Data Protection Regulation):
For data handling in the European Union, ensuring privacy rights.
ISO 27001:
Information security management standards, if certified.
21 CFR Part 11:
Electronic records and signatures compliance for regulated environments.
Other Standards:
Depending on the deployment scope, it might also meet standards like SOC 2, HITRUST, or relevant regional regulations.