Integration & Production
10 min
the following section defines related technical and support elements needed to achieve certification for moving into production, along with our integration, compliance, and certification processes integration process when a customer begins integrating a surescripts product into their application(s), they will be provided access to all the surescripts documentation pertaining to the product being implemented in addition, customers will be provided access to the staging environment to design, develop and test the product integration within their application note the time frame of the project can vary depending on the customer's resource allocation for the project meeting requirements during integration, customers will ensure their system has met all product requirements the certification testing will focus on message format, application workflow and display in accordance with surescripts documentation and the associated application certification requirements (acrs) upon successful completion of certification and, when applicable, other pre production network requirements (e g , identity proofing, attestations, dea audit), customers will be enabled in production for requirements, consider the following surescripts acrs are required to be met to achieve production status on the surescripts network and will be enforced as part of certification to ensure high quality transactions, surescripts applies additional business rules above and beyond the ncpdp schema defined requirements that will cause a message to be successful or rejected surescripts test cases do not cover all possible scenarios in production customers are responsible for testing any other applicable scenarios specific to their production environment in accordance with the customer’s legal agreement with surescripts, each customer is responsible for ensuring compliance with all applicable laws including, but not limited to, local and state laws/regulations where doing business transition to production once and the contract are complete and approved by the surescripts certification review board, the customer is ready to move into production surescripts will configure the production connection and validate successful operations with the customer prior to the transition to production, surescripts account management will work with the customer and internal surescripts teams to discuss the following production support contacts (escalation matrix) support process and training support hours surescripts terminology usage the following table outlines terminology usage for this guide term term usage must requirements that are enforced as part of the production code or by surescripts business rules some business rules reside in the element details section of this guide shall the requirements customers are required to meet in order to be certified on the surescripts network these requirements will be enforced as part of certification, not through business rules should used for guidance and best practices to produce superior results and enhance electronic messaging best practices can also be found in the best practice sections customers are encouraged, but not required, to meet best practices in order to be certified on the surescripts network communication rules please refer to the connectivity and authentication guide for details regarding communication and security protocol requirements as well as references to all links and ip addresses associated with surescripts services for the network to be reliable, there are communication rules to which all customers must adhere utc time format by using coordinated universal time (utc), the receiver of a message will know the time regardless of their time zone for example if a message was sent from boston at 5 30pm edt (eastern daylight time), the time would be sent as 21 30 utc time if this message was received in chicago cdt (central daylight time), the 21 30 utc could be converted to the local cdt time of 4 30pm refer to http //en wikipedia org/wiki/coordinated universal time http //en wikipedia org/wiki/coordinated universal time , or http //www w3 org/xml/ http //www w3 org/xml/ for more information utc time must be synchronized with nist (national institute of standards and technology) and the difference must be less than one minute drift of no more than one minute will be acceptable when sending only a date (not date and time), it should be sent in your local time zone, and the receiver should interpret it in their local time neither party should attempt to convert the date to utc all standard programming languages should have a function for generating a date in the utc time zone or displaying a date in the local time zone the format of the date/time fields in the xml schema must use the xsd\ datetime format examples of that format are ccyy mm ddthh\ mm\ ss fz, where the utc time zone may be specified as z, + 00 00, or 00 00 for example, 2013 01 01t16 09 04 5z, or 2013 01 01t16 09 04 5 00 00, or 2013 01 01t16 09 04 5+00 00, where 16 09 04 5z would be 16 hours, 09 minutes, 04 seconds, 5 fractional seconds utc time is denoted by either the “z” in the first example or the “ 00 00” in the second example, or the “+00 00” in the third example the fractional seconds is not required refer to xsd\ datetime for more information for simple date fields that do not include the time portion, the format is ccyy mm dd character set the character set contains ascii values 32 – 126, which include character type characters symbols ! " # $ % & ' ( ) + , / ; < = > ? @ \[ \ ] ^ ` { | } numerals ø to 9 letters, upper and lower case a to z, a to z utf 8 is the required character encoding for xml other encoding formats are not supported by surescripts it is recommended that customers declare their utf 8 formatting in the message header xml uses certain characters to describe the structure of the document when an element value needs to include one of the special characters, the character must be replaced its predefined entity representation when writing the xml document most xml processor libraries automatically handle the character replacement for more information see https //en wikipedia org/wiki/list of xml and html character entity references#predefined entities in xml or https //www w3 org/tr/rec xml/#sec predefined ent https //en wikipedia org/wiki/list of xml and html character entity references#predefined entities in xml or https //www w3 org/tr/rec xml/#sec predefined ent character character name received value > greater than \> < less than \< " quote \" & ampersand \& ' apostrophe \' compliance surescripts goal is efficiency and consistency across the network so all customers can meet the highest measures of patient safety, end to end reliability, and quality to ensure that customers comply with and adhere to the approved certification requirements, surescripts monitors customers in production to ensure all network customers remain in compliance with certification requirements and contractual terms initiates a remediation process for identified compliance issues to ensure network and patient safety, customer agrees to notify surescripts of any modifications through use of the surescripts recertification form upon receipt of this form, changes will be reviewed, and a determination made as to what (if any) level of certification may be required before being placed into production when changes are made to a customer’s implementation, the customer should advise their account manager the customer will be given a recertification guide to provide details regarding the changes made upon receipt of the completed document, the details will be reviewed, and a determination will be made as to what (if any) level of recertification is necessary as a reminder, surescripts conducts certification with customers to ensure the application adheres to network requirements surescripts will enforce mandatory fields as required by the standards body and surescripts guide requirements to maximize interoperability, customers are recommended to support optional fields that have been created to address gaps in discrete data needs and the many solutions that are in place for the benefit of the receiver surescripts encourages, but does not guarantee, the use of optional discrete fields to support end user workflows this guide is intended for certification on our network only and is not intended to ensure compliance with state and federal law in accordance with the customer’s legal agreement with surescripts, each customer is responsible for conducting its own due diligence to ensure compliance with all applicable laws and requirements, including, but not limited to, local and state laws and regulations in which the customer’s application is deployed and used