| 1 |
Define the clinical and operational problem |
Confirm that the solution addresses a documented workflow issue, patient-safety risk, access gap, or administrative burden. |
Document 3–5 measurable objectives, such as shorter wait times, fewer duplicate entries, or improved follow-up completion. |
Map the current workflow, identify affected users, and record the baseline performance before procurement. |
Percentage change from baseline for each approved objective. |
High |
| 2 |
Assess clinical fit and usability |
Evaluate whether the interface supports real clinical tasks without unnecessary clicks, duplicate documentation, or unsafe workarounds. |
At least 80% of representative users should complete priority scenarios successfully during usability testing. |
Run scenario-based testing with clinicians, administrative staff, patients, and accessibility representatives. |
Task-completion rate, average task time, error rate, and user-satisfaction score. |
High |
| 3 |
Check interoperability and data portability |
Verify support for structured data exchange, documented application programming interfaces, audit trails, and export of patient records. |
Support relevant HL7 FHIR resources where applicable, with documented interfaces and a tested export process. |
Test data exchange using realistic, de-identified records and define ownership, retention, and exit procedures. |
Interface success rate, data-mapping error rate, export completion time, and unresolved integration defects. |
High |
| 4 |
Evaluate privacy and cybersecurity controls |
Review encryption, identity management, least-privilege access, logging, vulnerability management, incident response, and data-location controls. |
Require encryption in transit and at rest, multi-factor authentication for privileged access, and a documented incident-response process. |
Complete a security risk assessment, access-role review, penetration-test review, and data-processing agreement before go-live. |
Security incidents, critical vulnerabilities overdue, privileged-access exceptions, and incident-response time. |
High |
| 5 |
Confirm accessibility and inclusion |
Check keyboard navigation, screen-reader compatibility, color contrast, readable language, captions, translation support, and low-bandwidth performance. |
Target conformance with WCAG 2.2 Level AA for applicable digital experiences. |
Conduct automated and manual accessibility testing with users who have diverse abilities and technology needs. |
Accessibility defects by severity, assisted-task completion rate, and complaints by access channel. |
High |
| 6 |
Plan implementation and change management |
Assess training needs, workflow redesign, data migration, governance, staffing, communication, and support during transition. |
Complete role-based training before launch and achieve 90% or higher completion among designated users. |
Use a phased rollout, appoint department champions, prepare downtime procedures, and provide a staffed support channel. |
Training completion, adoption rate, help-desk volume, downtime events, and time to resolve issues. |
High |
| 7 |
Test reliability, performance, and scalability |
Review availability commitments, capacity limits, response times, backup procedures, disaster recovery, and performance under peak demand. |
Set a service-availability target of at least 99.9% where clinically appropriate, with documented recovery objectives. |
Perform load testing, backup restoration testing, failover exercises, and peak-period monitoring before full deployment. |
Availability, median and 95th-percentile response time, failed transactions, recovery time, and recovery-point performance. |
High |
| 8 |
Compare total cost and value |
Include licensing, implementation, integration, migration, training, support, infrastructure, cybersecurity, and future-change costs. |
Prepare a three- to five-year total-cost-of-ownership model with documented assumptions and sensitivity scenarios. |
Compare at least three solution approaches, identify recurring and one-time costs, and calculate cost per active user or transaction. |
Actual versus planned cost, cost per completed transaction, productivity effect, and measurable benefit realization. |
Medium |
| 9 |
Review governance, compliance, and accountability |
Establish responsibility for clinical safety, data quality, configuration changes, access approvals, records retention, and regulatory reporting. |
Assign named owners for every critical process and maintain a documented change-control and audit-review schedule. |
Create a governance committee, escalation path, risk register, and decision log before production use. |
Open risks by age, audit findings, change-related incidents, data-quality exceptions, and policy-review completion. |
High |
| 10 |
Review outcomes and continuously improve |
Determine whether the solution improves patient, workforce, financial, safety, and equity outcomes after implementation. |
Conduct formal reviews at 30, 90, and 180 days, then at least annually or after major changes. |
Compare post-launch results with the baseline, collect user feedback, prioritize improvements, and reassess whether the solution remains fit for purpose. |
Outcome improvement, active-use rate, patient and staff experience, safety events, equity gaps, and return on investment. |
High |