ASSESSMENTS:
You might already have policies and procedures in place. You might be adding new products and services that require specific regulatory compliance. You might be starting from scratch. We can help you analyze your quality program as a whole, or determine applicability and compliance status for any or all of the following:
- Quality Program status
- Policy and Procedure scope and effectiveness
- Computer System Validation applicability
- Testing needs
- Audit preparedness
- HIPAA
- GAMP
- GxP
- FDA – 21 CFR Part 11
- FDA – 21 CFR Part 820
- ISO 13485
Based on the results of your analyses, we can then determine what policies and procedures you need to establish, what tasks you need to perform, and what deliverables you need to produce. We then use or vast template collection to meet those needs.
TEMPLATES:
In the world of healthcare compliance, there is one rule above all else: “If it isn’t documented, it didn’t happen.” Polices and procedures must be approved and in place. Training must be established and tracked. A document management system or method must be utilized. Record retention must be defined. Technical solutions must be thoroughly documented and validated. Data must be secured. Access to facilities, documents, systems, data, and repositories must be monitored. Changes must be managed. Purchasing and vendor management must be handled with consistency.
Depending on your organization’s needs, these elements can vary in scope and extent. We have developed a comprehensive set of versatile, easy-to-use templates for:
- Policies and Procedures
- Computer System Validation
- Audit Tools
- Testing and Qualification Protocols
- Assessments
- Project Management Tools
Most Quality Programs include elements that are common for all, such as record retention, change management, document management, training, access monitoring, etc. We have basic template packages that we offer at a base price and then customize based on your own unique roadmap. This is how we can offer significant time and money savings.
QUALITY PROGRAM:
Careful organization and maintenance of this documented approach is essential; compliance is impossible without it. HCS can build a Quality Program for you or improve what you already have in place.
A little history lesson: when 21 CFR Part 11 (See the code here)was formally introduced in 1997, there was much confusion about how to securely manage systems and data with consistency. The use of technology, specifically for electronic records and documents, was new to the healthcare industry, so the common mindset at the time was to document everything, validate all systems, and to validate them all the same way. But time has taught the industry that this approach is inefficient, wasteful, and costly. Now compliance is managed with a risk-based approach: risks are identified, evaluated, and mitigated, and you and your organization have the freedom to justify how and to what extent you pursue quality and regulatory compliance. HCS specializes in risk identification, with the result of a perfectly sized compliance approach.
PROJECT MANAGEMENT
- Project Planning
- Project Charters
- Scope Management
- Project Risk Assessment and Planning
- Business and Use Cases
- Issue Escalations
- Communication Planning
- Request for Proposal (RFP)
- Stakeholder Analysis
- Project Team Rosters
- Project Backlogs
- Burndown Charts
- Suppliers, Inputs, Process, Outputs, Customers (SIPOC)
- Fishbone Diagrams
- Tollgate Reviews
An appropriate, right-sized project management methodology guides our efforts to make you compliant in the most efficient way possible.
COMPUTER SYSTEM VALIDATION:
HCS has been performing CSV tasks for nearly 20 years. We can help you validate new systems or perform validation remediation (“retro-validating” a system already in place) for any applicable system:
- Custom software applications
- Enterprise systems
- IT infrastructure implementations and upgrades
- Globally implemented applications used by multiple sites
- Vendor-provided applications (Commercial off-the-shelf, or COTS)
- Automated systems
- Laboratory instrumentation
- IT / technical solutions and protocols
- Document repositories or management systems
- Spreadsheets
- Databases
- Medical devices
- Mobile medical apps
Whether or not a system needs validating depends on how the system is used, what data it produces, and how it impacts your business, products, customers, and regulatory requirements. 21 CFR Part is applicable to systems that “create, modify, maintain, or transmit electronic records” and requires that the organization“shall employ procedures and controls designed to ensure the authenticity, integrity, and, when appropriate, the confidentiality of electronic records, and to ensure that the signer cannot readily repudiate the signed record as not genuine.”(See the code here) We will help you determine your validation needs based on applicability and risk.
POLICIES AND PROCEDURES:
- Quality Policy / Plan
- Document Management
- Record Retention
- Risk Management
- Project Management
- Vendor Management
- Training
- Computer System Validation (Procedure)
- Testing / Qualification
- Software Development Life Cycle
- Source Code Standards
- Configuration Management
- Change Management
- Incident / Deviation / Problem Management
- Defect Management
- Security
- Physical Security
- Logical Security
- Passwords
- Virus Protection
- System Access Management
- Backup and Restoration
- Business Continuity
- Disaster Recovery
- Periodic Review
- System Retirement
- Data Migration
- Internal Auditing
- System-specific System / User Administration
- System-specific User Manuals
We can also help with policies and procedures for IT:
- Network Management
- Server Management
- Data Center Management
- Platform Management
- Performance Management
- Asset Management
- Personal Equipment Management
- Removal Media
- Input / Output Controls
- IT Configuration Management
- Hosted Application Management
- Database Management
- Client and Peripheral Management
- Service Level Agreements / Service Contracts
- Operating System Standards
- Naming Standards
- Acceptable Use of Computing Resources
- License Management
- Cabling Standards
- Upgrade and Patch Management
- Equipment Decommissioning and Retirement
- Infrastructure Qualification
Not all organizations require all of these procedures. And most of them can be combined and streamlined. HCS is great at making a little go a long way.
TESTING AND QUALIFICATION:
AUDIT PREPAREDNESS AND GUIDANCE:
The best approach for auditing is to be ready. In conjunction with employee training, internal audits and self-assessments not only act as “practice” but can also provide documented evidence that can be offered to an auditor. For example, if a potential client asks about HIPAA compliance, you can show them your prepared, approved HIPAA Assessment document that was created using HCS’s HIPAA Assessment tool template, customized just for you.
HCS provides thorough, user-friendly assessment tools for nearly all of the regulatory oversights common to healthcare compliance. In addition, we can help you complete the assessments and address any gaps they reveal.
PERIODIC REVIEW
The best approach for auditing is to be ready. In conjunction with employee training, internal audits and self-assessments not only act as “practice” but can also provide documented evidence that can be offered to an auditor. For example, if a potential client asks about
Regular review of the Quality Program is essential for maintaining ongoing compliance. Establishing the Quality Program, putting security controls in place, validating and testing computer systems, and documenting these tasks is only the first step, and it is all for naught if the program is not monitored and maintained.
Policies and procedures must be reviewed regularly to ensure they are current and reflect the business needs. Validated system must be reviewed to ensure that changes were managed properly and that the system is still in a validated state. Security and system access must be monitored and reviewed to ensure that facilities, systems, data, and documents are secured as they should be and that only appropriate personnel have access. Vendors must be re-evaluated. Plans for business continuity and disaster recovery should also be verified as current. Processes for backup and restoration should be tested.
HCS has a suite of periodic review tools and worksheets designed to organize, execute, and document periodic reviews efficiently. We can also provide guidance during the reviews and help with any action plans that may be required as a result of the review findings; change is inevitable, and a good review will undoubtedly reveal ways to improve processes, products and services, customer satisfaction, and compliance status.
SYSTEM RETIREMENTS
HCS can help with retirement planning and execution, beginning with a retirement planning procedure.
TECHNICAL SOLUTIONS
While our focus is mainly on documenting compliance solutions, we can help you make decisions and find resources for:
- App development
- Custom code development
- Web design
- Database creation and configuration
- Hardware selection
- Networking design
- Hosting options
SYSTEM RETIREMENTS
HCS can help with retirement planning and execution, beginning with a retirement planning procedure.