Government HIMS procurement checklist
A non-official HIMS RFP checklist for Nepal government hospitals
Turn a generic module list into testable requirements. Each item below should identify the responsible team, evidence, exception path, data ownership, and acceptance result.

1. Scope, governance, and responsibility
Name the facilities, departments, beds, extensions, stores, laboratories, pharmacies, outreach sites, users, patient volume, implementation phases, and contract boundaries. Define which responsibilities belong to the hospital, vendor, hosting provider, interface owner, and authority.
- Project board, clinical safety owner, finance owner, pharmacy owner, IT owner, and acceptance authority
- In-scope and future facilities, departments, modules, reports, interfaces, devices, and data
- Data ownership, confidentiality, permitted processing, subcontractors, export, retention, and exit
- Deliverables, milestones, dependency register, risk register, change control, and payment evidence
2. Patient and clinical workflows
Specify the complete patient journey and its exception paths. A requirement such as “OPD module” is not testable until the hospital defines identity, states, documents, roles, and downstream effects.
- Patient search, identity, duplicate resolution, alerts, contacts, consent, and documents
- Appointment, walk-in, arrival, queue, triage, consultation, referral, observation, and admission
- Emergency timeline, procedures, critical results, disposition, and free emergency route
- Beds, transfers, nursing, medication rounds, procedures, discharge summary, and final bill
- Dental, laboratory, radiology, theatre, blood bank, and other specialty requirements
3. Pharmacy, stores, and free care
Government facilities need a clear distinction between patient sale, HIB or programme supply, ward use, donated stock, and authorised free medicine. Each route must retain the same batch custody while posting different financial responsibility.
- Medicine master, formulary, generic and brand, units, packs, batch, expiry, FEFO, and controlled stock
- Prescription validation, substitution, counselling, partial issue, return, recall, and stock-out
- Free medicine beneficiary, programme, authority, zero charge, value, batch, dispenser, and separate register
- Store, pharmacy, ward, transfer, consumption, replenishment, count, variance, quarantine, and disposal
- Requisition, approval, purchase, receipt, supplier invoice, liability, purchase return, and payment
4. Billing, HIB, accounting, and reporting
Define each funding route and correction. Require a current interface or report contract instead of accepting “integration available.” Include errors, retries, denials, refunds, credit notes, and reconciliation.
- Patient, deposit, HIB, payer, government, donor, waiver, emergency-free, and free-care routes
- Invoice, confirmation bill, receipt, credit note, return, refund, write-off, settlement, and journal
- HIB member, referral, provider, diagnosis, evidence, outbox, idempotency, denial, resubmission, and settlement
- Sales, returns, purchase, credit note, VAT, Annex 5, archive, and other authority-defined evidence
- HMIS and management output definitions, mapping, version, aggregate logic, export, and acceptance
5. Security, infrastructure, and continuity
Specify the complete operating environment. Security and uptime depend on identity, devices, network, power, hosting, backup, patching, monitoring, staff behaviour, and incident response together.
- Tenant, facility, role, least privilege, duty separation, privileged access, and staff exit
- Clinical signature, addendum, financial approval, reversal, configuration, and audit retention
- HTTPS, certificates, credentials, firewall, endpoint security, patching, vulnerability and incident process
- Internet, LAN, Wi-Fi, power backup, local continuity, printers, labels, barcode and QR devices
- Backup schedule, encryption, off-site copy, restore test, recovery time, recovery point, and downtime procedure
6. Migration, training, UAT, and acceptance
Require at least one migration rehearsal and reconciliation before final cutover. User acceptance must cover each role, the normal path, high-risk exceptions, printing, security, downtime, and reports.
- Source inventory, mapping, cleansing, duplicate handling, rejected rows, documents, images, and archives
- Patients, balances, deposits, claims, suppliers, stock, batches, invoices, returns, and control totals
- Role-based training, attendance, competency check, super users, shift coverage, and refresher plan
- Test cases, expected results, evidence, severity, defect owner, retest, sign-off, and open-risk threshold
- Cutover, data freeze, rollback, go-live support, stabilisation, SLA, escalation, and transition to operations
7. Evidence to request from every vendor
Request evidence relevant to the proposed version and architecture. A logo list, old screenshot, or unrelated customer does not prove your requirements.
- Live end-to-end demonstration against the hospital’s scripted patient journey
- Architecture, security, backup, recovery, data model, API, and deployment documentation
- Sample migration reconciliation and report-parity evidence
- Current interface dependencies, credentials, test environment, and failure handling
- Named implementation and support team, escalation, response targets, and reference scope
- Complete data export, documentation handover, transition assistance, and exit terms
Primary and authoritative sources
Sources support the Nepal context and official direction. Product-specific statements are based on the local Xodont implementation and remain subject to deployment acceptance.
- 1. MoHP Digital Health Infrastructure
Nepal public-health infrastructure, continuity, connectivity, security, and health-facility context.
- 2. MoHP Digital Health Platform
National direction for connected public facilities, appointments, records, HMIS, EHR, and the Health Facility Registry.
- 3. Standards and Interoperability Lab Nepal
MoHP interoperability direction, including standards-based testing and secure health-data exchange.
- 4. Health Insurance Board real-time API notice
Official notice concerning real-time claims through an API for service-provider health institutions.
- 5. DDA Hospital Pharmacy Service Guideline
Official Nepal Department of Drug Administration context for hospital-pharmacy service responsibilities.
- 6. Nepal Privacy Act, 2075
Official legal context for privacy; deployment obligations still require qualified institution-specific review.
- 7. Nepal IRD electronic-billing guidance
Official IRD context for electronic billing; listing, permission, formats, and production acceptance are authority processes.