On behalf of the OHA, MD+A Health Solutions and iSecurity have prepared the following resources to support hospitals in their efforts to explore and evaluate the Qualtrics XM platform.
The Privacy Impact Assessment (PIA) assesses the privacy impact and risks associated with hospitals' use of the Qualtrics XM Platform for digital patient experience measurement in Ontario. The analysis addresses governance and accountability, consent, information management, privacy operations, and risk management. To minimize some of the risks within the PIA, the OHA has prepared a series of Recommended Qualtrics XM Platform Privacy Settings, which will be applied by the implementation support partner as a default setting.
The Threat Risk Assessment (TRA) was conducted by iSecurity as part of their cybersecurity risk management program. This assessment addresses the confidentiality, integrity, and availability (CIA) of the systems and assets respecting the management and operation of the Qualtrics XM platform and integrated applications.
Step 3: Submit an RFQ to the DIVA VOR Vendors to obtain quotes
The OHA has simplified Supply Chain Ontario's template for hospitals to request quotes from DIVA 20569 VOR vendors for a Qualtrics XM license and/or implementation support services to configure the Qualtrics XM platform for hospital use. Please see the FAQ for guidance.
Hospitals will need to submit the completed Request for Quote (RFQ) template to the contacts listed on page of the template to obtain quotes.
Step 4: Contract with the vendor
The OHA has developed two templates to assist hospitals with the contracting process and reaching appropriate terms and conditions to procure the VOR-enabled patient experience measurement platform. It is expected that hospitals will conduct their own due diligence review of all terms and conditions prior to entering into agreements.
The VOR Vendor Cover Agreement Template supports the signatories to execute a contract with one of the DIVA VOR vendors. Once the RFQ has been awarded, hospitals will receive an order form that specifies the contractual scope of work which will be attached as one of the appendices to the contract.
The Peer-Hospital Negotiated Qualtrics General and Privacy Terms Template reflects the terms initially negotiated by the OHA, and further amended by Trillium Health Partners (THP) and Shared Services West (SSW). THP and SSW have generously shared their final agreement terms to benefit their peers. These terms are compliant with the Personal Health Information Protection Act (PHIPA), reflect Qualtrics' role as an Electronic Services Provider (ESP), and include general terms and conditions that will meet hospitals' expectations using the DIVA VOR template agreement as the starting point for contract negotiations.