Building or replacing a custom EHR system is a multi-year commitment, and the wrong partner choice compounds every year after go-live — through interoperability gaps, failed audits, or clinicians who abandon the workflows entirely. This RFP template focuses on the questions that predict whether a build will actually work in production: interoperability depth, HIPAA architecture, and certification readiness.
Who this is for: health system CIOs, clinical informatics leads, and digital health founders evaluating vendors for a custom EHR build, module, or major EHR integration project.
Before You Send the RFP
- [ ] Decide your scope: a full custom EHR platform, a specific module (e-prescribing, scheduling, billing), or an integration layer connecting to Epic, Cerner, or athenahealth
- [ ] Confirm whether you need ONC 2015 Edition Cures Update certification, and by when
- [ ] Document every existing system that will need to exchange data with the new platform
- [ ] Set a realistic timeline — a focused module typically runs 4–6 months; a full custom platform with certification prep runs 9–18 months
- [ ] Identify clinical, IT, compliance, and billing stakeholders who need sign-off
Interoperability Questions
- Which FHIR R4 resources does your platform or integration support natively, with read/write/search capability for each?
- Which HL7 v2 message types and versions do you support (ADT, ORM, ORU, SIU, MDM, DFT)?
- Do you have direct experience integrating with our existing EHR (Epic, Cerner, athenahealth, or other)?
- How do you handle USCDI data class support for ONC certification purposes?
- Is your platform FHIR-native, or does it translate between an internal format and FHIR at the edges — and what does that mean for integration speed and cost?
HIPAA & Security Architecture Questions
| Safeguard type | What to ask |
|---|---|
| Technical | How do you implement encryption at rest and in transit, audit logging, and role-based access control? |
| Administrative | What's your process for HIPAA risk assessments and workforce security training during the build? |
| Physical | If cloud-hosted, what physical and infrastructure safeguards does your hosting provider maintain? |
| Audit logs | Are access and change logs immutable and retained for the required period? |
| Breach response | What's your documented process if a security incident occurs during or after development? |
ONC Certification & Compliance Questions
- [ ] Have you taken a system through ONC 2015 Edition Cures Update certification before?
- [ ] How do you architect for the 21st Century Cures Act's information-blocking provisions?
- [ ] What's your approach to patient access APIs and standardized data exchange requirements?
- [ ] Who owns certification maintenance and renewal after launch — us or you?
Process & Delivery Questions
- What does your six-stage (or equivalent) development process look like, and where does compliance architecture get designed in — early or late?
- How do you validate workflows with actual clinicians before and during the build, not just at the end?
- What's your QA and testing process for a system handling PHI?
- What post-launch support and SLA do you offer for a clinical system where downtime has real consequences?
- How do you handle change requests once clinical workflows start surfacing gaps in production?
Vendor Scorecard
| Criteria | Weight | Vendor A | Vendor B | Vendor C |
|---|---|---|---|---|
| HL7/FHIR interoperability depth | ||||
| HIPAA safeguard architecture | ||||
| ONC certification experience | ||||
| EHR integration track record (Epic/Cerner/etc.) | ||||
| Clinical workflow validation process | ||||
| Post-launch support & SLA |
Red Flags to Watch For
- Vague answers on which specific FHIR resources or HL7 message types are supported
- No prior experience integrating with major EHR platforms relevant to your environment
- Treats HIPAA compliance as something bolted on at the end rather than designed in from discovery
- No clear answer on who owns ONC certification maintenance post-launch
- No plan for validating workflows with actual clinical staff before go-live
How to Use This
Send this RFP to every vendor under consideration and require specific, written answers to the FHIR/HL7 questions — vague answers here are the clearest early signal of shallow interoperability experience. Loop in a clinical stakeholder on workflow validation questions specifically; a technically sound system that clinicians won't use is a failed project regardless of how clean the architecture is.