C802 Task 2 HIM Needs Assessment and Vendor Plan Example

This C802 Task 2 example is a release of information needs assessment and vendor selection plan for a composite health system with three hospitals and twelve clinics on one electronic health record. WGU C802, Foundations in Healthcare Information Management, asks BS Health Information Management students in this task to plan a technology decision from evidence. The sample combines a four-week time study, a review of 300 sampled requests and staff interviews to describe current workflow, turns the findings into eight requirements starting with one request queue for the system, and sets out a vendor selection process from forming a team to site visits. It weights evaluation criteria with compliance first, assigns stakeholder roles and describes implementation steps such as centralizing release of information.

CourseC802 Foundations in Healthcare Information Management
TaskTask 2
Paper typeHIM needs assessment and vendor selection plan
LengthAbout 1,300 words, 3 pages
FormatAPA 7
SchoolWestern Governors University (WGU)
ProgramBS Health Information Management
UpdatedSeptember 2026

Free sample paper for C802 Task 2

1

Three Hospitals, Three Request Logs: A Release of Information Needs Assessment and Vendor Selection Plan for a Composite Health System

Student Name

Leavitt School of Health, Western Governors University

C802: Foundations in Healthcare Information Management, Task 2

Course Instructor

Month Day, Year

What this page is doingThe title names the problem in its plainest form, three separate logs for one system's requests, and the two things the paper delivers. The health system, its figures and its staff are composites.
2

Three Hospitals, Three Request Logs: A Release of Information Needs Assessment and Vendor Selection Plan for a Composite Health System

Background

Riverbend Health, a composite system, operates three hospitals and twelve outpatient clinics across two counties on a single electronic health record (EHR) that went live four years ago. Records created before go-live remain in a legacy document imaging system at each hospital. Release of information (ROI) is handled separately at each hospital by its own HIM staff, and clinics forward requests to whichever hospital is nearest. Over the past year, patient complaints about records requests have tripled, two requests were answered twice with different content, and an internal audit found that the system cannot produce an accounting of disclosures for any patient without searching three spreadsheets by hand. This paper assesses the ROI workflow, defines what a solution must do and sets out how Riverbend should select a vendor to provide it.

Needs Assessment: Current Workflow

The assessment combined three sources: a four-week time study of ROI staff at each hospital, a review of 300 randomly selected requests from the past year and interviews with ROI staff, clinic managers, the privacy officer and the legal department.

The workflow has five steps, and each has a weakness. Intake: requests arrive by mail, fax, walk-in, patient portal message and email, and are logged by hand in a spreadsheet unique to each hospital, so a patient treated at two hospitals may have two open requests that no one connects. Validation: staff check identity and authorization against a paper checklist, and 9% of sampled requests were processed without a complete authorization. Retrieval: staff search the EHR and then the legacy imaging system, which requires a separate login and a separate print queue; retrieval takes a median of 38 minutes per request. Review and redaction: sensitive records, including substance use disorder treatment notes from one hospital's program, are identified by memory rather than by a system flag. Delivery: most records leave as paper or on compact discs, even when patients ask for electronic copies.

The results are measurable. The median turnaround for patients' own requests was 19 days, and 22% exceeded the 30-day limit that 45 C.F.R. § 164.524 gives covered entities to answer a patient, with no extension letter sent in most of those cases (Office for Civil Rights, 2016). Riverbend is not unusual in this. A study that posed as patients requesting records from 83 top-ranked US hospitals found discrepancies between what hospitals' forms and their staff said about the information, formats and costs available, and found hospitals that did not provide records in the format patients requested, as federal rules require (Lye et al., 2018). The assessment concludes that the problem is not staff effort but a fragmented process with no single view of requests, records or deadlines.

What this page is doingThe needs assessment gives numbers from the organization's own data and compares them with the legal standard. That is what makes the need convincing before any product is discussed.
3

Requirements

The assessment translates into eight requirements a solution must meet. First, one request queue for the whole system, with every request logged once regardless of where it arrives. Second, intake from every channel, including portal and fax, with electronic authorization capture and identity verification. Third, direct integration with the EHR and the legacy imaging system, so records from both can be retrieved in one search. Fourth, automatic flagging of sensitive information, including substance use disorder treatment records, behavioral health and HIV results, for mandatory review before release. Fifth, redaction tools that leave an audit trail. Sixth, deadline tracking with alerts at day 20 and management dashboards showing turnaround by request type and location. Seventh, secure electronic delivery in the format the requester asks for, including portal and encrypted email, and fee calculation consistent with federal guidance. Eighth, an accounting of disclosures for any patient on demand.

Riverbend must also decide whether to purchase software and keep staff in-house, or contract with a vendor that provides both software and ROI staff. The selection process below is designed to compare both options on the same criteria.

Vendor Selection Process

Step 1, form the selection team. The team is chaired by the system HIM director and includes an ROI lead from each hospital, the privacy officer, an IT integration analyst, a representative from legal, a finance analyst and a clinic manager. A patient advisory council member reviews the patient-facing portal features.

Step 2, confirm scope and budget. The team documents the eight requirements, current volumes of about 4,100 requests a month and the budget range approved by leadership.

Step 3, market scan and request for information. The team identifies vendors serving health systems of similar size and sends a short request for information to narrow the field to four or five.

Step 4, request for proposal. The request for proposal describes Riverbend's current workflow, volumes, systems and requirements; asks each vendor to explain how it meets each requirement; requests pricing for software-only and software-plus-staffing models; and asks for security documentation and a sample business associate agreement.

Step 5, scripted demonstrations. Each shortlisted vendor demonstrates the same five scenarios using test data: a patient portal request, an attorney subpoena, a request involving substance use disorder records, a request spanning two hospitals and legacy records, and a monthly turnaround report. Scripted scenarios keep vendors from showing only their strengths, and asking every vendor to perform the same tasks is one of the most useful protections in a health IT selection (Richards, 2005).

Step 6, reference checks and site visit. The team speaks with at least two current clients of each finalist, preferably multi-hospital systems, and visits one.

Step 7, scoring and decision. Each team member scores each vendor independently against weighted criteria, and the team meets to reconcile scores.

Step 8, contract review. Legal and the privacy officer review the contract and business associate agreement, including service levels for turnaround, data ownership, breach notification and exit terms.

Evaluation Criteria

Criteria are weighted to reflect what the needs assessment found most important. Compliance and sensitive-record handling carry the greatest weight, because the current process fails there most seriously.

CriterionWeightWhat the team looks for
Compliance and sensitive-record controls25%Deadline tracking, sensitive-information flags, accounting of disclosures, audit trails
Integration20%Proven interfaces with Riverbend's EHR and legacy imaging system
Workflow and usability15%Single queue, scripted demonstration performance, staff feedback
Patient access features10%Portal requests, electronic delivery, patient status updates
Security10%Encryption, access controls, independent security assessment
Reporting5%Turnaround and volume dashboards by site and request type
Total cost of ownership10%Five-year cost including licenses, staffing, implementation and support
Vendor stability and references5%Client retention, references from similar systems, support model

Roles of Stakeholders

The HIM director owns the process and the final recommendation, because ROI is an HIM function and the department will live with the result. ROI staff contribute the most detailed knowledge of the workflow and test usability during demonstrations. The privacy officer and legal department judge compliance features and the contract. IT confirms that integration claims are realistic and that security meets system standards. Finance models the total cost of each option. Clinic managers ensure that requests arriving at clinics are captured, and the patient advisory member tests whether the portal is easy to use. Involving each group from the beginning builds support for the change and prevents a late objection from derailing the decision.

Implementation Considerations

Whichever vendor is selected, success will depend on implementation. Riverbend should consolidate ROI into a single centralized team with a presence at each hospital for walk-in requests, migrate open requests into the new queue before go-live, train staff on the sensitive-information workflow and measure turnaround monthly against a target of 95% of patient requests fulfilled within 15 days. The needs assessment's baseline figures will allow leadership to see whether the investment worked.

References

Lye, C. T., Forman, H. P., Gao, R., Daniel, J. G., Hsiao, A. L., Mann, M. K., deBronkart, D., Campos, H. O., & Krumholz, H. M. (2018). Assessment of US hospital compliance with regulations for patients' requests for medical records. JAMA Network Open, 1(6), Article e183014. https://doi.org/10.1001/jamanetworkopen.2018.3014

Office for Civil Rights, U.S. Department of Health and Human Services. (2016). Individuals' right under HIPAA to access their health information 45 CFR § 164.524. https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/access/index.html

Richards, F. (2005). Vendor selection and contract negotiation. In J. M. Walker, E. J. Bieber, & F. Richards (Eds.), Implementing an electronic health record system (pp. 15-20). Springer. https://doi.org/10.1007/1-84628-115-6_3

What the C802 Task 2 instructions ask

The second C802 task asks you to assess a health information need and plan how a solution would be selected. Most versions ask for a needs assessment of current workflow, requirements derived from it, a vendor selection process, evaluation criteria, stakeholder roles and implementation considerations. Evaluators look for a needs assessment that uses data, requirements that follow from the findings, a selection process with steps and a team, weighted criteria that reflect priorities, and roles that make sense for health information work. A plan that jumps to a product without assessing the need will not meet the assessment aspects. Many versions also ask how success will be judged after implementation.

How this C802 Task 2 example is built

The plan begins with the system's structure and the release of information problem. The needs assessment describes three data sources and what each showed, such as uneven turnaround across hospitals. Requirements are numbered and each traces to a finding. The selection process runs step by step from team to decision. Criteria are weighted and explained, with compliance and sensitive-record handling carrying the most weight. Stakeholder roles place the HIM director as owner. Implementation considerations include centralizing work and training, supported by research on patient access to records and federal access guidance. Requirements are numbered so each can be traced to a finding. Weights appear beside each criterion.

Where the C802 Task 2 rubric puts the marks

C802 Task 2 aspects are scored competent, approaching competence or not evident. A needs assessment aspect checks that current workflow is analyzed with data. A requirements aspect rewards requirements linked to findings. A selection process aspect looks for steps and a team. A criteria aspect wants weighted criteria with reasons. A stakeholder aspect asks who is involved and why. An implementation aspect looks for practical considerations. Evaluators check that compliance requirements for release of information are described accurately and expect federal guidance and research to be cited. They also look for whether the selection team includes the people who will use the system daily, and when implementation considerations address workflow as well as software. A plan that could be handed to a real selection committee is the standard.

C802 Task 2 help: what sends it back

Needs assessments come back most often when the data are thin. Use a time study, a sample of requests or interviews, and report what they show. Second, requirements do not trace to findings. Number them and link each. Third, criteria are unweighted, which hides priorities. Weight them and explain why. Fourth, stakeholders are listed without roles. Say who decides, who advises and who uses the system. Finally, implementation is an afterthought. Describe the changes in workflow and training that will determine whether any vendor succeeds. State who has the final say on the selection and on what date.

Get a C802 Task 2 example written to your instructions

Send the Task 2 instructions and rubric from your C802 course of study, plus the scenario it provides. We write a custom HIM needs assessment and vendor selection to those exact aspects and return it in 24-48h. The first custom sample is free.

More C802 papers

Other Health information sample papers

C802 Task 2 questions, answered

What is a request for proposal in C802?

It is the document the organization sends to vendors describing its requirements and asking how each would meet them. A strong paper says what the request should contain and how responses will be scored.

Does C802 Task 2 require a specific vendor?

No. The task is about the selection process. The sample describes how to choose among vendors without endorsing a product. Describe the process so any vendor could be judged fairly.

What is a request for proposal in C802?

A document that describes an organization's requirements and asks vendors to explain how they would meet them. The sample's eight requirements would form the core of one.

How are C802 vendor criteria weighted?

By the priorities the needs assessment found. The sample gives compliance and sensitive-record handling the most weight because errors there carry the highest risk. Show the weights in a table so reviewers score consistently.

Where can I find a free C802 Task 2 sample paper?

The needs assessment and vendor plan appear above with commentary. Tell us your HIM process in the C802 instructions and your first tailored plan costs nothing.