See More RFPs

Patient Privacy Monitoring System

Overview


Cybersecurity & Data Privacy
San Francisco, California, United StatesPosted about 1 month agoDeadline: May 29th, 2026

Fit Score


Settle Intelligence

Settle helps teams find, evaluate, and respond to public RFPs. We continuously surface new opportunities, score them against your company strengths, and draft proposal responses so you can focus on the work that wins business.

SUMMARY


California is seeking a cloud-based patient privacy monitoring system integrated with Epic EHR, supporting robust security and compliance requirements.

KEY REQUIREMENTS


BUDGET

Estimate

$400,000 – $10,000,000

CONTRACT DURATION


60 months

TIMELINE


RFP Published: April 6th, 2026

Pre-Proposal Conference: April 16th, 2026

Deadline for Questions: April 30th, 2026

Estimated Q&A Addendum Posting: May 11th, 2026

Deadline to Submit Proposals: May 29th, 2026

Estimated Short-Listing Notification for Interviews: July 6th, 2026

Estimated Interviews: July 13th, 2026

Estimated Announcement of Award: July 27th, 2026

Health Commission Presentation: August 2026

Estimated Start Date: September 2026

QUESTION DEADLINE


April 30th, 2026

Issuing Agency


San Francisco Department Of Public Health

Organization overview and procurement intelligence available on paid plans.

DESCRIPTION


This Request for Proposals seeks vendors to provide a patient privacy monitoring system that integrates with the Epic Electronic Health Record (EHR) system. The proposed solution should utilize industry standards such as Health Level 7 (HL7), Fast Healthcare Interoperability Resources (FHIR) APIs, or other supported integration mechanisms. Integration with 'my Avatar' audit data is optional but may be considered.

The system must support role-based access controls, account provisioning, user administration, and Single Sign-On (SSO) authentication. It should be a secure, scalable, Software-as-a-Service (SaaS) or cloud-based system, accessible via standard web browsers without requiring local software installation. All data must be stored and processed within the continental United States, with encryption applied both in transit and at rest. Vendors are required to provide a technical architecture diagram illustrating system communication with Epic and any optional integrated systems and ensure the ability to maintain multiple environments for development, testing, training, and production.

A pre-bid meeting is scheduled for April 16, 2026. All vendor questions must be submitted by April 30, 2026. The resulting contract term will be five years.

Source attribution

This Settle analysis is based on the issuing organization’s public RFP listing.

Similar RFPs