Integration & Production
11 min
integration process when a customer begins integrating a surescripts product into their application(s), they will be provided access to all the surescripts documentation pertaining to the product being implemented in addition, customers will be provided access to the staging environment to design, develop and test the product integration within their application note the time frame of the project can vary depending on the customer's resource allocation for the project meeting requirements during integration, customers will ensure their system has met all product requirements the certification testing will focus on message format, application workflow and display in accordance with surescripts documentation and the associated application certification requirements (acrs) upon successful completion of certification and, when applicable, other pre production network requirements (e g , identity proofing, attestations, dea audit), customers will be enabled in production for requirements, consider the following surescripts acrs are required to be met to achieve production status on the surescripts network and will be enforced as part of certification to ensure high quality transactions, surescripts applies additional business rules above and beyond the ncpdp schema defined requirements that will cause a message to be successful or rejected surescripts test cases do not cover all possible scenarios in production customers are responsible for testing any other applicable scenarios specific to their production environment in accordance with the customer’s legal agreement with surescripts, each customer is responsible for ensuring compliance with all applicable laws including, but not limited to, local and state laws/regulations where doing business surescripts terminology usage the following table outlines terminology usage for this guide term term usage must requirements that are enforced as part of the production code or surescripts business rules shall requirements customers are required to meet in order to be certified on the surescripts network these requirements will be enforced as part of certification should used for guidance and best practices customers are encouraged, but not required, to meet best practices in order to be certified on the surescripts network s ### designates an acr that is shared with other surescripts products f ### designates a formulary acr note acrs are summarized in the application certification requirements docid\ n 3misgnnmdda85mjjnui section transition to production once certification testing is complete and the contract is approved by the surescripts certification review board, the customer is ready to move into production surescripts will configure the production connection and ensure successful operations with the customer prior to the transition to production, surescripts account management will work with the customer and internal surescripts teams to discuss the following production support contacts (escalation matrix a tool that helps the customer know exactly who to contact and how issues will be escalated if initial support cannot resolve them ) support process and training support availability note the escalation matrix for use by surescripts customers can be found in the surescripts network operations guide communication rules please refer to the connectivity and authentication guide for details regarding communication and security protocol requirements as well as references to all links and ip addresses associated with surescripts services for the network to be reliable, there are communication rules to which all customers must adhere data load connectivity surescripts currently supports two data loads that require a customer to send large files to surescripts the master patient index (mpi) data load and the formulary and benefit data load are created by the pbm/payer and sent to surescripts for storage the formulary and benefit file is then ready for subsequent distribution for these data loads, surescripts supports secure ftp for file transfer between the pbm/payer and surescripts secure ftp secure ftp is supported for the transfer of master patient index (mpi) data loads and formulary and benefit data uploads using ftp over ssl, ssh with ftp and http/s surescripts supports both client to server and server to server communications with compatible client software a list of compatible software should be requested from surescripts surescripts processes do not have file naming requirements security is enforced through data encryption during transfer and user id/password customer files are isolated from other customer’s files connectivity to secure ftp can be established through an internet route or through a private virtual circuit with surescripts’ contracted mpls service provider if using the private virtual circuit, the customer must allow surescripts to install and manage two routers in their data center that connect to the customer’s extranet the customer must have dual network connectivity for redundancy security each customer must ensure that appropriate security measures are in place within its scope of operations to the extent of its interface with surescripts and surescripts’ systems and data these security measures must be designed to protect against fraud and abuse and to maintain patient confidentiality compliance surescripts goal is efficiency and consistency across the network so all customers can meet the highest measures of patient safety, end to end reliability, and quality to ensure that customers comply with and adhere to the approved certification requirements, surescripts monitors customers in production to ensure all network customers remain in compliance with certification requirements and contractual terms initiates a remediation process for identified compliance issues to ensure network and patient safety, customer agrees to notify surescripts of any modifications through use of the surescripts recertification form upon receipt of this form, changes will be reviewed, and a determination made as to what (if any) level of certification may be required before being placed into production when changes are made to a customer’s implementation, the customer should advise their account manager the customer will be given a recertification guide to provide details regarding the changes made upon receipt of the completed document, the details will be reviewed, and a determination will be made as to what (if any) level of recertification is necessary as a reminder, surescripts conducts certification with customers to ensure the application adheres to network requirements surescripts will enforce mandatory fields as required by the standards body and surescripts guide requirements to maximize interoperability, customers are recommended to support optional fields that have been created to address gaps in discrete data needs and the many solutions that are in place for the benefit of the receiver surescripts encourages, but does not guarantee, the use of optional discrete fields to support end user workflows this guide is intended for certification on our network only and is not intended to ensure compliance with state and federal law in accordance with the customer’s legal agreement with surescripts, each customer is responsible for conducting its own due diligence to ensure compliance with all applicable laws and requirements, including, but not limited to, local and state laws and regulations in which the customer’s application is deployed and used