13.07.2015 Views

Part 4 - Iowa Medicaid Enterprise

Part 4 - Iowa Medicaid Enterprise

Part 4 - Iowa Medicaid Enterprise

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

RFP MED-12-001 | Technical Proposal<strong>Iowa</strong> <strong>Medicaid</strong> <strong>Enterprise</strong> System Service Procurement | MMIS and Core MMIS Operations• Contractor Voice and Data Telecommunications Equipment. Team Noridian will documentexpectations for our own voice and data needs.• Uninterruptible Power Source (UPS). Team Noridian's standard is to allow a minimum of 30minutes of run time for all systems. For alternate power sources in Team Noridian's data centers, theuse of generators provides the minimum of 24 hours of run time.Our DRP will address the continued processing of transactions in the case of a disaster. This will includedocumenting backup procedures and support in case of loss of connectivity. The DRP contains detailedfile backup plans and procedures. Those files will be stored at an offsite facility that is responsible forsecuring the data against unauthorized access or disclosure, as well as fire, sabotage, and environmentalconsiderations. Maintenance of system documentation and source code will also be stored at the offsitefacility. Finally, the DRP will contain all backup processing capabilities at remote sites to assist in day-todayoperations of the IME in case of a disaster.Maintenance of the Disaster Recovery PlanRFP Section 6.3.1.2, Requirements x.2.v and y.8Our DRP planning process is cyclical, and we will leverage existing plans and start with an updated riskimpact analysis. All deliverables from the risk impact analysis process are updated to reflect systemtechnology, as well as changes in some of the operational processes. The deliverables from the riskimpact analysis are inputs to the development and updating of the DRP. All applicable state and federalstatutes and laws will also be reviewed to make sure the plans are compliant with contract requirements.Reviews will occur and are documented according to a pre-determined schedule, which is at leastannually. In addition, a number of other events will require a review, which may invoke another planningcycle. Examples where reviews will be conducted include:• Risk Assessment. The plans should be reviewed every time a risk assessment is completed for theorganization. This can happen when there are significant changes to the system, regulatory changes,and other events that impact the plans.• Health Care Industry Trends. Major health care industry initiatives should initiate a plan review.Examples could include patient consent laws, interoperability standards for Health InformationExchanges (HIE), and general trends in business continuity planning techniques.• Regulatory Requirements. New federal and state regulatory requirements may require a reviewof the plans.• Event Occurrence. A review is performed following a response to an event, whether or not theCrises Management, Business Continuity, or Disaster Recovery Plan was executed. If the plans wereactivated, the review should take into account the history of the plan itself, how it worked, and why itwas activated. If the plans were not activated, the review should examine why and whether this wasan appropriate decision.• Test/Execution Results. The plans are modified, as needed, based on test results or plan executionresults.• Changes to Crisis Management Plan or Business Continuity Plan. Related plans that may affecteach other when they are updated include the Crisis Management Plan, BCP, and DRP.The DRP and backup plan will be submitted to the Department for approval each time a plan change ismade, and initially, prior to implementation. Annual test results reports are also submitted to the Departmentfor review and approval. Approved copies of the DRP will be made available to the Department.8.3.1.2.8 Configuration Management PlanRFP Section 6.3.1.2, Requirements z and ccThe essence of change control and management of application development is configuration management.Configuration management requires controlling data items through change management processes and8 | 101

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!