Contracting & Compliance Validation
Contracting & Compliance Validation
Category: Customer Lifecycle | Audience: undefined | Page: 27 of 33
Table of Contents
- Manage Breach Notification Timelines
- Create a Data Retention Policy
- Delete Data at End of Contract
- Request and Review Audit Reports
Contracting & Compliance Validation
Welcome to the onboarding guide for Contracting & Compliance Validation at Elixia Health. This document will help you understand the essential compliance and contractual information needed to ensure smooth operations and adherence to regulations.
Key Concepts
- Sub-processors: Third-party services used by Elixia Health to support clinical trials.
- Subcontractor Vetting: Process of assessing and approving subcontractors to ensure they meet necessary qualifications.
- Breach Notification: Automated system to manage GDPR compliance for data breaches.
- Data Retention Policy: Guidelines for how long data is retained in the system.
- Data Deletion: Process for securely deleting data at the end of a contract.
- DSARs (Data Subject Access Requests): Requests from data subjects to access or modify their personal data under GDPR.
- Customer Audits: Process for reviewing audit reports and conducting inspections to ensure compliance.
What You Can Do
- Vet and approve subcontractors
- Manage breach notification timelines
- Create and manage data retention policies
- Delete data securely at the end of contracts
- Support DSARs
- Request and review audit reports
How To
Vet Subcontractors
- Prepare and Send the Vetting Questionnaire to the subcontractor:
- The questionnaire should cover the following areas:
- Organization Information: Company name, registration details, location, years in operation
- Data Protection Compliance: GDPR, HIPAA, or other applicable regulation compliance certifications
- Security Practices: Information security policies, data encryption methods, access controls, and incident response procedures
- References and Experience: Previous clients in healthcare/clinical trial industry, case studies
- Audit and Certification Status: ISO 27001, SOC 2 Type II, or other relevant certifications
- Data Processing: How they will process, store, and protect PHI/PII
- Subcontractor Relationships: Whether they use further sub-processors and their vetting processes
- Financial Stability: Proof of financial viability and insurance coverage
- Allow 2-4 weeks for the subcontractor to complete and return the questionnaire
- Review the Questionnaire with subject matter experts:
- Assemble a review team including:
- Compliance Officer: Reviews regulatory and compliance requirements
- Security Officer: Evaluates security practices and certifications
- Operations Lead: Assesses operational capability and reliability
- Evaluate responses against your organization's vetting criteria and risk tolerance
- Identify any gaps or concerns that require clarification
- Request additional documentation (certifications, audit reports, contracts) as needed
- Rate each subcontractor based on your vetting matrix (e.g., Low/Medium/High Risk)
- Obtain Approval from the Business Owner:
- Prepare a vetting report summarizing:
- Subcontractor profile and background
- Risk assessment and compliance gaps
- Recommendations and concerns
- Approval or conditional approval recommendation
- Present the report to the appropriate business owner (Project Manager, Director, or C-level executive)
- Obtain documented approval (email or system-based approval) before engaging the subcontractor
- If conditional approval, clearly define conditions that must be met
- Document the approval and maintain records for audit purposes
- Execute Data Processing Agreement (DPA):
- Once approved, execute a Data Processing Agreement outlining:
- Scope of data processing activities
- Data protection obligations and responsibilities
- Audit and inspection rights
- Data breach notification requirements
- Data deletion or return procedures at contract termination
- Maintain all vetting and approval documentation in a centralized register
Manage Breach Notification Timelines
- Create a SharePoint Site for GDPR breach management:
- Navigate to your SharePoint tenant and create a new site titled "GDPR Breach Management"
- Select "Team Site" as the site template
- Configure permissions to restrict access to authorized personnel (see step 4)
- Add a description and governance policy for the site
- Enable versioning and auditing on all lists within the site
- Set up Lists for breach tracking and notification:
- Create the Breach Incident Register list with the following columns:
- Breach ID (unique identifier)
- Date of Breach Discovery
- Date Breach Occurred
- Description of Breach
- Category (e.g., Unauthorized Access, Data Loss, Malware)
- Number of Data Subjects Affected
- Type of Personal Data Involved
- Risk Level (Low/Medium/High)
- Internal Owner
- Status (Identified, Under Investigation, Remediated, Closed)
- Create the Timeline Tracker list with columns:
- Breach ID (linked to Incident Register)
- Event Type (Discovery, Initial Assessment, Notification Sent, Follow-up, etc.)
- Planned Date
- Actual Date
- Description
- Owner
- Notes
- Create the Notification Templates list with columns:
- Template Name
- Recipient Type (Data Subject, Supervisory Authority, Media)
- Template Content
- Language
- Last Updated
- Version Number
- Create Notification Templates with specific fields:
- Data Subject Notification Template:
- Description of the breach (without sensitive details)
- Date of breach and discovery
- Type of data affected
- Likely consequences
- Measures taken or proposed to mitigate harm
- Contact information for more information
- Data Protection Officer details
- Supervisory Authority Notification Template (for serious breaches):
- Breach description and facts
- Likely adverse effects on data subjects
- Measures taken or proposed to address and mitigate harm
- Contact information for questions
- Data Protection Officer or authorized representative details
- Media/Public Communication (if applicable):
- Formal statement about the incident
- Measures taken to protect data subjects
- Company's commitment to data protection
- Contact information for inquiries
- Restrict Site Access to authorized personnel:
- Define access levels: Viewers, Editors, Owners
- Add specific users or security groups to the site
- Owners: Compliance Officer, Data Protection Officer (full control)
- Editors: Incident Response Team, Legal Team (can create/edit items)
- Viewers: Management/Executive stakeholders (read-only access)
- Remove inherited permissions and apply site-specific permissions
- Enable multi-factor authentication (MFA) requirement for site access
- Regularly audit access logs to ensure only authorized personnel access breach information
- Configure the Breach Incident List to track critical information:
- Set up automated workflows/Power Automate flows:
- When a breach is logged, send notification to Data Protection Officer
- Automatically calculate timeline milestones (72-hour notification deadline, etc.)
- Create timeline tracker items automatically when incident status changes
- Add views for different stakeholders:
- "High Risk Breaches" view (filtered by risk level)
- "Pending Notification" view (filtered by status)
- "Timeline Overview" view (showing all timeline events)
- Enable alerts for critical updates (e.g., when status is updated to "Remediated")
- Set up monthly reports summarizing breach metrics:
- Total breaches identified
- Average time to notification
- Categories of breaches
- Data subjects affected
Create a Data Retention Policy
- Log in to MCT or MTJ.
- Navigate to the DataRetentionPolicy table.
- Click on "Create New" to create a new retention policy.
- Fill in the required fields.
- Save the new retention policy.
Delete Data at End of Contract
- Notify the customer of the data deletion process.
- Provide options for securely deleting or returning data, including backups.
- Ensure all Contracted Processors delete or return the data as applicable.
Support DSARs
- Use the GDPR Data Subject Rights Request Form (MTJ Patient) for submissions.
- Track all DSRs using the Data Subject Request (DSR) Tracking (MCT).
- Receive automated notifications for new DSRs.
- Follow the standardized workflow for handling DSRs.
- Use escalation criteria for complex requests.
- Maintain audit trails for all DSR-related actions.
Request and Review Audit Reports
- Request an audit report or related documentation through the MCT platform.
- Review the report or documentation to ensure compliance with Applicable Data Protection Laws.
- Request further assistance and documentation if needed.
- Conduct remote inspections or audits with the Service Providerβs cooperation.
Tips & Best Practices
- Keep subcontractor vetting documents organized and easily accessible.
- Regularly test your breach notification system to ensure it functions correctly.
- Communicate clearly with customers about data deletion processes.
- Train your team on handling DSARs efficiently and within deadlines.
- Schedule regular audits to maintain compliance and identify areas for improvement.
Next Steps
- Familiarize yourself with the subcontractor vetting process.
- Set up your breach notification system in SharePoint.
- Create and implement data retention policies.
- Understand the data deletion process at contract end.
- Learn how to support and manage DSARs.
- Request and review audit reports to ensure compliance.
Navigation
β Previous: Evaluation & Due Diligence
π Documentation HomeNext: Onboarding & Integration β
Generated from MCT Knowledge Base β’ v1.1.0 β’ January 2, 2026