Business Continuity and HIPAA Business Continuity Management in the Health Care Environment [Electronic resources] نسخه متنی

اینجــــا یک کتابخانه دیجیتالی است

با بیش از 100000 منبع الکترونیکی رایگان به زبان فارسی ، عربی و انگلیسی

Business Continuity and HIPAA Business Continuity Management in the Health Care Environment [Electronic resources] - نسخه متنی

Jim Barnes

| نمايش فراداده ، افزودن یک نقد و بررسی
افزودن به کتابخانه شخصی
ارسال به دوستان
جستجو در متن کتاب
بیشتر
تنظیمات قلم

فونت

اندازه قلم

+ - پیش فرض

حالت نمایش

روز نیمروز شب
جستجو در لغت نامه
بیشتر
لیست موضوعات
توضیحات
افزودن یادداشت جدید







section III, Vendor Instructions:

Item 7, Proposed Recovery Configuration

Item 8, Prime Contractor

Item 9, Single Site/Single Source



Vendor Profile



Vendor Corporate Profile

This section must provide a brief overview of vendor's company and services, including discussion of:



History



Customer Service Approach



Healthcare organizational and Corporate Synergy



Prior 12 Months' Investment into Business Continuity Services



Mission Statement





Local Vendor Support

Please provide a brief overview of where the support of ABCD will originate and list any facilities owned or operated by your company within 100 miles. List support available before a disaster, during a disaster, while operating at the hot site and work area site and while operating at the cold site.



Experience



How many customer declarations has vendor supported to date?



How many non-customer declarations has vendor supported to date?



How many customer declarations has vendor supported to date where the recovered configuration was equal to or greater than ABCD's required configuration?



How many successful customer tests has vendor supported to date?





References

Vendor must provide three references of customers currently under subscription for a recovery configuration equal to or greater than ABCD's requirements. The references must include at least one customer who has used vendor's services to recover from an actual disaster; the remainder should have conducted at least one test.



Financial Data

This section should contain information describing the current financial condition of vendor's company. Include the latest annual report.





Subscriber Data



At present, how many subscribers does vendor support?



How many of these subscribers have a recovery configuration equal to or greater than that of ABCD?



How many of these subscribers utilize the same primary recovery facility as being proposed to ABCD?



How many of these subscribers which utilize the same primary recovery facility as being proposed to ABCD are within a 50 mile radius of ABCD's facility?





Vendor Policies



Subscriber Risk Limitations



How does vendor limit the number of subscribers allowed per facility?



Will vendor contractually agree to limit the number of subscribers?



How does vendor plan to manage the risk of simultaneous declarations from multiple subscribers of the same configuration size as ABCD?



How does vendor assure that frivolous disaster declarations are not made?





Vendor Integrity



Will vendor allow a non-subscriber to declare and subsequently recover at vendor's recovery facility?



If yes, provide details of the recovery.



If no, does vendor contractually agree to not grant access to non-subscribers for the purposes of testing or business continuity?





Sharing of Recovery Facility



What is vendor's policy on handling the recovery of multiple subscribers when both are using the same recovery hardware, i.e., CPU sharing?



Does vendor allow sharing by more than one subscriber at the same recovery facility? If yes, how will vendor protect the confidentiality of ABCD's data?





Preemptive Access Rights

Will vendor allow any subscriber to have preemptive access rights over ABCD? If yes, please describe the circumstances.



Multiple/Regional Disaster Support



What is vendor's policy on regional disasters or multiple, simultaneous disasters when more than one subscriber invokes a disaster declaration?



Can vendor provide access to additional hardware at time of disaster? What rights to access are granted to ABCD?



If ABCD is required to access a facility other than the primary recovery facility, how will ABCD's telecommunications requirements be supported?





Disaster Alert and Declaration



Define vendor's disaster alert and declaration procedure.



Does vendor require a fee be paid when placing a disaster declaration or alert?



Does vendor require subscribers to place a disaster declaration in order to "reserve" a recovery facility?



How does vendor assign a recovery facility when a subscriber places a disaster declaration?





Disaster Avoidance

What is vendor's methodology and capability to provide disaster avoidance support? Provide examples of proactive involvement by vendor to avert customer disasters.



Internal Business Continuity Plan

Attach a copy of the vendor's plan to respond to a disaster occurring at the proposed recovery site.



Testing Methodology and Support



Provide a summary of vendor's testing methodology and standard support provided during tests.



What type of support does vendor provide before, during and after a test? What type of fee is associated with this support?



Does vendor support remote testing?



Does vendor provide turnkey testing services? If yes, detail the extent of services provided

d. What additional fees will subscriber incur during testing (i.e., telephone expense, etc.?





Facility Audit

Will vendor allow a representative of ABCD or an independent third party not under contract with vendor to audit the proposed recovery facility?



Internal Quality Program

Describe vendor's internal service quality control and continuous improvement program.



Vendor Commitment



How much investment has vendor made in technology in the past 12 months?



What is vendor's policy for providing services for new technologies?



Has vendor ever closed a recovery facility? Please provide the details, including the customers' ramifications surrounding the closures.



How much investment in technology does the vendor plan on making in the next 12 months?







Recovery Facility Specifications



Location(s) Available



Provide a list of all vendor recovery facility location(s). Indicate the proposed primary and alternate(s) facilities capable of supporting ABCD's required configuration. (Also refer to Item 7, Proposed Recovery Configuration, under Section III, Vendor Instructions).



Provide a list of all hot site and work office site facilities. Indicate if the proposed hot site is co-located with the primary work area site.



Provide a summary of vendor's local remote testing recovery facility and local work area (end user) recovery capability.





Telecommunications



Describe the local telephone company and inter-exchange carrier access installed at your proposed recovery site suitable for recovering ABCD's netw

Discuss the following:



Access methods, standard telephone company and alternate access vendors, if any



Capacity



Diversity



Carrier services available on a subscription basis





Describe above parameters at your alternate recovery site(s) in the event the primary recovery site is not available.



Describe how you can/will reroute ABCD's network and communications to the primary or alternate recovery site(s).

Describe the following:



Use of standard carrier services



Use of your dedicated business continuity network





Describe any pertinent network recovery expertise and capabilities.





Remote Testing

Please outline vendor's capabilities for testing primary configuration from ABCD's home site and/or any alternate site.



Facility Control



Of the recovery facilities identified above, indicate which ones are owned by the vendor, which ones are leased by vendor and which ones are multi-tenant.



If multi-tenant, what are the zoning codes for the area in which the facility is located?



Identify any tenants that may be located within vendor's recovery facility and the nature of their business.



If any recovery facility is utilized for anything else besides business continuity, indicate the location of the recovery facility and its use.





Access/Occupancy



ABCD requires immediate access after a disaster declaration.



ABCD requires a minimum of 4 weeks of occupancy in the hot site following a disaster declaration.





Fire Detection/Suppression System

Detail the fire detection and suppression system of the proposed recovery facility.



Security System

Detail the security system and security staff provided at the proposed recovery facility. Identify any logical security software which ABCD will be required to run under. If the customer can use their own security software, please note this.



Environmental Equipment

Detail the environmental support equipment of the proposed recovery facility:



Power Conditioning



HVAC



Chiller



UPS



Diesel Generator



Indicate whether the proposed recovery facility has redundant capabilities for the above environmental support equipment.



Utility Vendors



Detail which utility (electrical and communications) vendors service the proposed recovery facility.



Indicate redundant capabilities for electrical and communications utilities in the event of an outage.





Customer Equipment

Describe provision for subscriber's placement of critical equipment at the recovery facility.



Maintenance Procedures

What are the maintenance procedures for the recovery facility, hardware and environmental support equipment at the proposed recovery facility?



Geographical Location

What is the geographical location (i.e., urban or suburban) of the proposed recovery facility and its proximity to a local airport?



Transportation

Provide detail regarding number of daily flights from ABCD's location to the proposed recovery facility; average flight time; and average commute from local airport to recovery facility.



Lodging/Restaurants

How many hotels and restaurants are available within a five-mile radius of the proposed recovery facility? Do the local area hotels offer corporate discounts to vendor's customers?



Backup Recovery Sites

Repeat information in items 6 through 14 for backup recovery sites.









RECOVERY CONFIGURATION

Vendor shall detail the proposed hot site and work area site recovery configuration as indicated below. Vendor shall provide a line-by-line comparison between the required recovery Section I, Introduction, Paragraph C, Recovery Configuration Specifications and their proposed configuration. Vendor shall indicate the recovery configurations proposed for both the primary and alternate site(s) being proposed.

If a specific requirement cannot be met, vendor shall explain why and, if applicable, offer an alternate solution. Vendor shall also provide detail regarding optional services available. This section of the proposal shall not contain any cost data. All cost data should be included under Paragraph F, Proposed Pricing.



Hot Site and Work Area Site



Hardware



Operating System



Communications



Testing



Work Space



Office equipment (i.e. Copiers, fax machines, etc.)





Cold Site



Location of Proposed Cold Site



Square Footage

3. Optional Services





Mobile Recovery Facility



Other Optional Services







PROPOSED PRICING

Vendor shall provide pricing for 1, 3 and 5 year term(s) for the proposed recovery configuration. Vendor shall also include pricing for all optional services proposed. Pricing shall include the monthly subscription fee, disaster declaration fee, daily usage fees, and any other associated fees (including one-time fees).


1 Year, 3 Years, 5 Years




IBM RS/6000



Monthly Subscription



Disaster Declaration



Daily Usage



Optional Services



Associated Fees





LAN



Monthly Subscription



Disaster Declaration



Daily Usage



Optional Services



Associated Fees





Workstations



Monthly Subscription



Disaster Declaration



Daily Usage



Optional Services



Associated Fees





Work Area Site



Monthly Subscription



Disaster Declaration



Daily Usage



Optional Services



Associated Fees





Any additional standard and/or incremental configuration charges related to this specific recovery installation

(Please specify below)

Fee




















$


_____


______________________


______


$


_____


______________________


______


$


_____


______________________


______


$


_____


______________________


______


$


_____


______________________


______




Optional Services (Not Included Above) Fee




















$


_____


______________________


______


$


_____


______________________


______


$


_____


______________________


______


$


_____


______________________


______


$


_____


______________________


______






STAFF AND SERVICES



Support Staff Availability



Indicate the number of support staff personnel (and their position) on site during testing and business continuity.



Indicate the amount of experience your support staff has as it relates to testing and business continuity.





Support Area

Describe the support area available with a hot site and cold site subscription for ABCD personnel. Is this area shared with other subscribers?



Work Area

Describe what support facilities, including office space and equipment (FAX, photocopying, microcomputers, voice communications, desks, chairs, terminals, etc.), are provided for ongoing user assistance.



Support Services

Describe what types of support services the vendor provides as part of this contract and what types of support services are available at an additional fee.



Replacement Equipment Services

Describe vendor's capability to provide expedited replacement equipment for the ABCD's home configuration.



Professional Services

Describe your range of available professional services to assist us with:



Corporate Planning



Business Impact Analysis



Recovery Plan Development



Other



Please include any automated business continuity planning tools which are supported by the vlendor, and which can be made available to ABCD





TERMS AND CONDITIONS



Priority Access



Provide vendor's policy for preempting ABCD's right of access to the primary recovery configuration by another subscriber



In the event of a multiple disaster will resources be shared or limited to ABCD?





Upgrades

Provide vendor's provisions for upgrading ABCD's recovery configuration during the term of the contract



Automatic Renewal



What is the length of term of the automatic renewal?



How much notice does the vendor customarily provide if it is not going to renew?



Describe the vendor's policy regarding annual price escalation







ADDITIONAL INFORMATION

Vendor should include any additional information that they feel would aid ABCD in their review process. This information should be limited to information the vendor feels is pertinent to this response which was not specifically asked for in the RFP (i.e., marketing structure, additional support provided, optional services, etc.). Vendor should be selective in the material to be included in this section



The above is an example of the types of things that should be included in an RFP. However, this should give you a better understanding of the categories of information that should be included.

/ 90