- **Prepared for:** Oakland University, School of Education and Human Services, Department of Counseling
- **Attention:** George Haight, Buyer, Oakland University Purchasing Department
- **Prepared by:** Carepatron, [VERIFY: who is the named preparer and title on this response, Glen or Carlos?]
- **Date:** 3 November 2026

## Executive summary

Carepatron is pleased to respond to Oakland University's Request for Information for a
clinical cloud-based EHR and video recording system. We have read the RFI with the SEHS
Counseling Center's purpose in mind. It is a teaching and research facility where graduate
students apply counselling theory in practice while providing supervised, no-cost
counselling to people in need.

Carepatron is a cloud-based, all-in-one EMR and practice management platform founded in
2021, serving more than 100,000 health and wellness professionals across a range of
specialties worldwide. Scheduling, clinical documentation, telehealth, secure messaging, a
client-facing portal, reporting and AI-assisted note-taking all live in one system with one
login. We do not bundle separately licensed modules together. Capabilities that other
platforms charge for separately, including AI documentation, are included at the practice
level.

Four things are worth calling out up front for the Counseling Center's context.

**We do not record video sessions, and that is half of what you asked for.** We are leading
with this rather than burying it. Carepatron does not record or store video sessions in any
form, native or through a partner. If recording is non-negotiable and must come from one
system, we are not your vendor, and we would rather you know that on page one. If you would
accept the EHR and the recording tool as two systems, which your own question about
third-party video relationships suggests you might, then the rest of this response is worth
your time.

**Your browser access problem is the problem we solve.** You describe an on-premises dual
system where the components that are not cloud-hosted need a resource-intensive process for
secure access to campus computers and servers. Carepatron is fully cloud-based and runs in
any modern browser on any device, with no VPN, no campus machine and no local install. For
a clinic running a split in-person and telehealth model, that removes the access layer
entirely.

**Your student count costs you nothing, and your rotating cohorts are handled.** Licensing
is per staff user only, and client records are unlimited at no per-client charge. Seats
prorate automatically as people are added or removed, and removing a team member issues a
credit for the unused part of that seat against future invoices. For a clinic that turns
over a student cohort three times a year, that is the difference between paying for the year
and paying for the semester.

**AI documentation is included for every user, not priced per clinician.** The AI Scribe
sits on every paid plan with no per-seat add-on fee. Your faculty set the note template and
output format once for the department, and students work inside that standard without
configuring anything themselves. For a training clinic, standardising how 40 or more
trainees document a session is a teaching outcome as much as an administrative one.

We answer to what Carepatron does today. Where something is not supported yet, such as video
recording, live observation and supervisor approval routing, we say so plainly rather than
selling a roadmap. Where those gaps are requirements, we are glad to discuss whether we can
close them collaboratively.

## Section III, information requested

Your Section III lists what the system needs to be capable of. We have answered each line in
your order, including the lines where the answer is no.

| Your requirement | Carepatron response |
|---|---|
| Supporting 40+ practicing students, supervisors and instructors each semester | **Supported.** There is no practical platform ceiling at this scale. Growth is a pricing-tier question rather than a capacity one. Team members are invited by email and configured with their own permissions, services and availability. Per-client assignment scopes a supervisor to their own trainees' caseloads. |
| Secure storage of client data and information | **Supported.** Data is encrypted at rest with AES-256 and in transit with TLS 1.2 or higher, hosted on Amazon Web Services. Role-based permissions are configured per team member across client profiles, documentation, scheduling, invoices and workspace settings. Document storage is unlimited on the Plus and Advanced plans, with individual uploads to 100MB and up to 150 files per client record. |
| Scheduling and appointment management | **Supported.** A multi-provider calendar with role-based visibility: administrators see all clinicians, and students see their own calendar unless given wider access. Day, week and month views, grouping by team, service or location, and filtering by team member and appointment status. Multiple clinicians can be scheduled on the same appointment. |
| Direct and indirect hour tracking | **Partial, and this needs a conversation.** Calendar events cover appointments, tasks, reminders, meetings and out-of-office blocks, and you can create your own appointment statuses. Direct hours come from the appointment record, and indirect activity can be tracked as tasks and meetings. Attendance reporting pulls appointments across a date range with each status as a distinct line, and appointments export filtered by date range and team member. [VERIFY: is there any report or export that totals direct and indirect hours per individual trainee, as a practicum hour log? If not, this is a gap worth naming to the buyer, because CACREP-style hour logging is core to a training clinic.] |
| Clinical documentation: progress notes, intakes, treatment plans, discharge summaries, contact notes | **Supported.** Progress notes support SOAP, DAP and other structured formats, drawing on built-in templates plus a community library of more than 9,000 templates. Notes are created from the client record or directly from a calendar appointment, autosave as they are written, and can be locked once finalised. Every client has a single record holding demographics, documentation, relationships, files, communication history and billing. Treatment plans are built from the template library. They are template-driven documents rather than a separate care-plan module with goal tracking, and we would rather say that than imply otherwise. |
| Live observation | **Partial.** Carepatron telehealth supports group calls, so a supervisor can join a student's session as an additional participant. Hosts control the attendee list and can mute or remove a participant. A waiting room is enabled on every call and cannot be switched off. [VERIFY: can a supervisor join a telehealth session as a silent or hidden observer, invisible to the client, or do they always appear in the participant list? This decides whether we can answer "live observation" as a yes.] |
| **Video recording** | **Not currently supported.** Carepatron does not record or store video sessions. This is a design decision rather than a configuration option, so there is no setting that turns it on. The AI Scribe produces a text transcript of the conversation, not an audio or video recording. No workaround inside Carepatron produces a reviewable session video. We are flagging this honestly. It is a real gap for your use case and we would rather name it now than discover it post-contract. |
| Video retention of 120 to 180 days (Policy 481) | **Not applicable, because there is no video to retain.** For the text transcript the scribe does produce, the transcript attaches to the note and a practitioner can permanently delete it from the note settings. [VERIFY: can a retention or auto-deletion schedule be configured at workspace level, so transcripts and notes purge on a 120 to 180 day cycle without manual action?] |
| Video transcripts | **Partial, and not of video.** The AI Scribe transcribes the session as it happens and drafts a structured note into the template in use, with no manual input during the appointment. In a Carepatron telehealth call the scribe runs from an in-call sidebar, and the note is created against the client record and the appointment as soon as the call ends. The same workflow covers in-person sessions captured on our mobile app, and sessions held on a non-Carepatron video platform. So you would get a searchable text record of every session, but not a recording to play back. |
| Video timestamped | **Not applicable.** No recording exists to timestamp. Access to records is separately logged: complete, timestamped audit trails record who accessed a record, what changed and when. |
| Admin download of video | **Not applicable.** No recording exists to download. |
| Friendly end-user management for department staff and technical support | **Supported.** Team members are invited by email and configured with personal details, permissions and their own services and availability, with date-specific overrides. Removing a team member stops them being booked but leaves their notes, files and invoices intact in the workspace. Granular permissions sit on the Advanced plan. There is no resend-invite action today; the documented workaround is to remove and re-add the person, or share the manual registration link. |
| SSO/MFA integration | **Partial, with a gap on the SSO half.** Multi-factor authentication through an authenticator app is supported at no additional cost, set up per user, with an email recovery path. Clients can enable MFA on their portal account too. Sign-in today is email and password with MFA, or Google and Apple single sign-on. **Carepatron does not support SAML or OIDC enterprise single sign-on, and there is no SCIM provisioning.** Accounts are created by invitation and managed in the workspace. For a university standardised on an institutional identity provider, this is a real gap. One distinction worth drawing: Outlook calendar and email sync are supported, which is often what an institution means by Microsoft integration. SSO is the part that is not available. [VERIFY: is there an administrator setting that enforces MFA across all users in a workspace? Our documentation describes per-user setup only, and MFA applies to email and password sign-ins rather than Google or Apple sign-in.] |
| Secure web browser | **Supported.** Carepatron is fully cloud-based and works from any modern browser on any device. Telehealth runs on current Chrome, Firefox and Safari, iOS 11 or later and Android 7 or later. Native iOS and Android apps are available, along with installable desktop apps for Windows and macOS. |
| HIPAA compliant | **Supported.** Carepatron is HIPAA compliant and designed to protect ePHI in line with the HIPAA Security and Privacy Rules. A Business Associate Agreement is included on paid plans, accepted as part of the terms at account creation, with a PDF copy available. The BAA covers PHI handling across our services, including AI note generation and transcription. Our wider posture includes SOC 2 Type II, HITECH and GDPR. HIPAA compliance is shared: you remain responsible for configuring and using the platform to meet your own obligations. |
| ADA compliant | **Not currently supported as a conformance claim.** Carepatron is a modern, responsive web application, but we have not specifically implemented WCAG conformance in the product today, and we hold no VPAT or accessibility conformance report. Assistive tools can be used alongside Carepatron. We are not going to claim ADA compliance we cannot evidence. Where accessibility is central to an institution's mission, we would welcome a deeper conversation about the specific requirements for staff and for the client-facing portal. One related point: we have no built-in live captioning. The supported approach is a third-party CART service, where the stenographer joins the call as a normal participant. Carepatron charges nothing extra for this, and the CART service is a separate vendor cost. |

## Your questions for vendors

### Architecture and security

**How and where do you store client data and video?** Client data is hosted on Amazon Web
Services, with DDoS protection, data loss prevention, backups, status monitoring and
continuous monitoring in place. Our published sub-processor list names AWS (hosting, US,
Australia and Europe), Google Cloud (hosting, US and Singapore), Stripe (payments), Claim.MD
(claims clearinghouse) and Intercom (customer support). Sub-processors must encrypt data at
rest and in transit, restrict access to authorised personnel and maintain incident response
plans. Hosting regions align with applicable local requirements, but we cannot commit to a
customer-selectable data region. No video is stored, because none is recorded.

**Do you incorporate AI features? In what manner and for what purpose?** Yes, and the detail
matters for a training clinic. The AI Scribe transcribes a session as it happens and drafts
a structured note into the template in use. The clinician reviews and approves every note
before it is finalised; the AI produces a draft, never a final record. A pre-appointment
summary gives the clinician a briefing drawn from the client's previous documentation. An AI
consent template is available in our library and can be included in your standard intake
packet, so clients consent to AI-assisted documentation before their first session. On data
handling: our BAA covers PHI across our services including AI note generation and
transcription, and our enterprise agreements with cloud infrastructure providers prohibit
customer data being used for model training. If your IT review needs the specific model or
inference sub-processor named, we will route that through our formal compliance package
rather than answer it here.

**What are your backup schedules, retention periods and recovery timelines?** Backups,
status monitoring and continuous monitoring are part of our controls and are listed in our
Trust Center. [VERIFY: we do not publish backup frequency, retention, geographic redundancy,
restore testing, RTO or RPO. Glen, is there anything we can state here, or does this route
to the compliance team as a contract term? This is a scored question for a university IT
review and answering it with silence is costly.]

**What cloud providers or platforms do you use?** Amazon Web Services is our hosting
provider. Our sub-processor list also names Google Cloud. Detailed architecture
documentation is available through our Trust Center at trust.carepatron.com.

### Platform requirements and support

**Are there end-user hardware or software requirements?** Nothing beyond a current browser.
For telehealth we recommend a computer from the last three to five years with a 2.5GHz
processor and 4GB RAM, and at least 0.35 Mbps of bandwidth, with 10 Mbps or more preferred.
A clinic running several simultaneous clinician calls should have 35 Mbps or more. These are
recommendations, not licensed requirements.

**Does your solution support cross-platform, multi-device use?** Yes. Full-featured iOS and
Android apps give clinicians their schedule, notes, billing, messaging and the AI Scribe for
in-person sessions. Carepatron also installs as a desktop app on Windows and macOS, and the
web application is fully responsive. The client portal is mobile-responsive and needs no app
download. One note of precision: our App Store listing is US-only, and users outside the US
install by adding the mobile web app to the home screen.

**How many institutional administrators or account managers are included?** Administrator is
a permission level rather than a separately licensed seat, so any number of your staff users
can hold administrative rights at no extra cost. Granular role-based permissions sit on the
Advanced plan. On the relationship side, the Advanced plan includes one named account
manager for the department.

**What end-user support model is provided, and is it 24x7?** Support runs 24/7 through
in-app chat and our help centre, with a named account manager on the Advanced plan. An
in-app Help button opens Ava, our AI assistant, which answers directly and escalates to a
human support team member on request. For general questions the fastest route is the 24/7
support infrastructure rather than the account manager. We do not publish resolution-time
SLAs today, and we would rather tell you that now than point at a number we do not commit
to.

### Video and recording capabilities

This is the section where we fall short of what you asked for, so we have answered it
directly rather than reframing the questions.

**Is your video solution natively built into the EHR/EMR, or is it a third-party
relationship?** Video calling is native. HIPAA-compliant video is built into the platform
and is not a separately licensed module. Sessions launch from inside the appointment, and
clients join from a single link with no software, extension or meeting ID to manage. Group
calls support up to 250 participants, each joining from their own appointment confirmation
or reminder link, on the Plus or Advanced plan. A waiting room is enabled automatically on
every call. **Recording is neither native nor available through a third party.** We want that
read as a flat no rather than a qualified yes about video.

**Does your solution integrate with Zoom or other applications?** Zoom connects as an
integration from Connected Apps. Google Meet, Microsoft Teams and Doxy.me can be used as
virtual locations by pasting the meeting link, which is a manual link rather than a live
integration. A clinic that wants to keep its existing video platform can do so, and the AI
Scribe still works on those calls through the client record. This is the practical route if
you pair Carepatron with a separate recording tool: run the session on the platform that
records, and keep the clinical record, transcript and note in Carepatron.

**Does your solution compress video for storage or pricing purposes?** Not applicable. No
video is stored.

**Does your video solution allow pins or annotations?** Not currently supported. There is no
recording to annotate, and we have no in-call whiteboard.

**What is the expected latency under standard network conditions?** [VERIFY: we publish
bandwidth recommendations but no latency figure, and I will not invent one. Glen, is there a
measured figure we can give, or does this become a "we do not publish this" answer?]

### Clinical and supervisory workflows

**Does your solution allow routing or return for signature and approvals?** **Partial, and
this is the second real gap.** A clinician inserts a drawn signature into a note, form or
template from the note toolbar to signify approval before it is shared. A completed note can
be locked from the note menu, which restricts further editing. Notes are private by default,
visible only to the author and team members with permission, until explicitly shared.
[VERIFY: is there a formal routing workflow that sends a note to a supervisor for approval
and returns it to the student, with a co-signature? Our sources document the signature
itself but no co-signature or sign-off workflow. Glen, this is the single most important
open question in this response after recording, because supervised trainee documentation is
the buyer's core workflow.]

**Does your solution support multi-supervisor review, routing and approval for a single
student trainee?** [VERIFY: same question, extended to several supervisors over one trainee.
Role-based permissions and per-client assignment let multiple faculty see a student's
caseload, but we cannot claim a multi-approver routing chain from our sources.]

**How do faculty and supervisors review or comment on student notes?** Role-based
permissions control this. Documentation access can be set to none, assigned clients only, or
everything, for view and edit independently, and access can be scoped further by assigning
specific clients to a team member. So a supervisor sees their trainees' documentation and
nobody else's. Secure in-app messaging covers internal team members as well as clients.
[VERIFY: can a supervisor leave an inline comment or annotation on a student's note, as
distinct from editing the note or messaging the student separately?]

**Do you offer online client intake forms?** Yes. Digital intake and consent forms are built
natively and sent automatically ahead of the first appointment, or from the client record in
a few clicks. Clients complete them through a secure, mobile-friendly link with e-signature
support, and completed forms file straight to the client record. A client can complete a
form without signing in if you prefer. Any template can also be published as a public form,
shared as a direct link or embedded on your website. Note that intake links expire 30 days
after they are sent and must be reissued after that.

**What does the intake process look like for a new client?** Templates placed in a starred
Intake folder are sent automatically to every newly created client through the onboarding
workflow, and that folder holds up to nine forms or templates. Any template can also be
flagged as the intake default so it attaches whenever an appointment is booked with that
client. Workflow automations trigger on client and documentation events, scheduling events
and communication events, so the intake send is automatic rather than a task someone
remembers.

**Do you have pre-built, editable intake templates, or do we build our own forms?** Both,
and you should not have to rebuild anything. There is a community template library of more
than 9,000 templates, including standardised behavioural health instruments such as GAD-7,
PHQ-9, PCL-5, DASS-21, AUDIT, EPDS, ASRS-v1.1, the ACE questionnaire and ADHD screeners. A
scoring group field calculates results in real time as the form is completed, visible to
practitioners while hidden from clients. Forms are built in a drag-and-drop editor with
sections, reorderable questions and data chips that pre-fill from the client record.
Existing PDF forms import with labelled fields mapped automatically. Our team will rebuild
your existing forms and templates for you during onboarding. Two limits worth stating: only
single-choice fields can feed a scoring group, and there is no conditional or branching logic
in the form builder today.

**Does your solution offer client reminders?** Yes. Automated appointment reminders go out
by email and SMS, with message content and send timing set at the practice level. Reminder
templates can be translated, and a client's preferred channel, language and time zone sit on
their record. Invoice, intake and portal-invite reminders run from the same framework. Two
honest limits: only email reminders carry the appointment or video call link, and there is
no in-product delivery log confirming a reminder was sent.

### Implementation and migration

**Can you import or transfer records from a previous EHR/EMR platform?** Yes. Our customer
success team migrates client records, documentation and appointment history from your
current platform as part of onboarding. For a deployment of your size we scope this as a
dedicated migration project rather than a self-service import, so each client's history
arrives intact and care continues without interruption. We have documented import paths from
SimplePractice, TherapyNotes, Ensora (TheraNest), Office Ally, Zanda (Power Diary), Cliniko,
Session Health, TherapyAppointment, Practice Fusion, Halaxy and others, plus generic file
import accepting .zip, .csv, .xlsx and .xls. Source fields auto-match to Carepatron record
fields for review before import, and the flow includes a duplicate review step. Your current
system is an on-premises dual solution rather than one of the named platforms, so we would
scope the extraction with you at kickoff.

**What level of staff involvement is required preparing for and during launch?**
Implementation is scoped at kickoff and led by a dedicated onboarding manager, covering
workspace configuration, roles and permissions, replication of your forms and templates,
staff training and go-live support. A clinic can typically be live in two to four weeks, and
where training needs are greater, implementation support can spread over 30 to 90 days. That
two-to-four-week figure is our experience for a single-site centre of roughly 20 staff, so
treat it as indicative for your scale rather than a commitment. Training covers a 1:1
onboarding manager, live team training for clinical and administrative staff, go-live
support, a self-serve help centre and a training hub with webinars and a video library. The
1:1 onboarding manager sits on the Advanced plan. We do not quantify included training hours,
and we would rather scope that with you than publish a number.

A point specific to your clinic: your student cohort turns over three times a year, so the
recurring training burden is onboarding each new cohort, not the one-off launch. We would
build that into the implementation plan as a repeatable semester induction rather than
treating it as a single event.

## Vendor information requested

### 1. Company information

- Company name: Carepatron
- Year established: 2021
- Address: [VERIFY: registered company address to print on the response]
- Primary contact: [VERIFY: named contact, title, email and phone for this submission]
- Ownership type: [VERIFY: private, public or other, and the correct legal entity name]
- Relevant certifications: SOC 2 Type II, confirmed through independent audit that security
  controls are designed effectively and operate consistently over time. SOC 2 Type 1 is also
  listed. HIPAA compliance with a Business Associate Agreement included on paid plans.
  Reports and certifications are available through our Trust Center at trust.carepatron.com.

### 2. Experience and qualifications

Carepatron is purpose-built for outpatient counselling and wellness workflows. Intake,
scheduling, session documentation, case management, secure messaging and reporting are all
native rather than bolted on. We serve more than 100,000 health and wellness professionals
worldwide, across a range of specialties.

References from practices at a comparable scale and specialty will be made available once we
have obtained their consent, should this proposal advance. We do not name customers without
that consent.

[VERIFY: Glen, do we have a university counselling or training clinic customer who would
consent to act as a reference for Oakland? This is a scored item for a higher-education
buyer and a generic consent-first paragraph is weaker here than in a private-practice bid.]

### 3. Product and service information

Carepatron is built as a single, fully integrated workspace. Scheduling, telehealth, clinical
documentation, AI note-taking, billing, insurance claims, the client portal, secure messaging
and reporting all live in one login and one price, with minimal optional add-ons. We are not
aiming to bundle separate products together but to provide an intuitive application with
functional depth and high usability. Capabilities that other platforms charge for separately,
or require configuration at the individual-user level, are included at the practice level in
Carepatron.

The differentiators that matter for your context are the AI Scribe included for every user
rather than priced per clinician, unlimited client records at no per-client charge, native
telehealth with no separate licence, and a template library carrying the standardised
behavioural health instruments a training clinic already uses.

**Compatibility and integration with existing systems.** Named integrations today are Google
Calendar and Microsoft Outlook two-way calendar sync, Gmail and Outlook email sync, Zoom,
Stripe for payments, Claim.MD as the claims clearinghouse, DoseSpot for e-prescribing and
Google Tag Manager for booking analytics. Three limits stated plainly:

- There is no native student information system connector today, for Banner, Jenzabar,
  PeopleSoft or any other SIS.
- We have no HL7 or FHIR interfaces, ADT feeds, or lab order and result interfaces.
- A public API is live with documentation, and the current release covers client endpoints
  (get, search, create). Appointment, documentation and billing endpoints are not in the
  present scope. The endpoint set is being actively expanded, and we describe the API by what
  it does today rather than by its roadmap.

Where no native connector exists, the public API can support a scoped custom integration
built with your IT team, bounded by that client-endpoint scope. We would rather define that
scope together than imply a connector exists.

**Scalability and upgrade path.** There is no practical platform ceiling at the scale of a
20 to 100 user group, and client records are unlimited on every plan. Growth is a pricing
question rather than a capacity one. Billing is per team member per month and prorates
automatically when people are added or removed.

### 4. Implementation and support

Covered above under "Implementation and migration". In summary: a dedicated onboarding
manager, two to four weeks typical for a single-site centre of around 20 staff with support
spread over 30 to 90 days where training needs are greater, 24/7 in-app support, a named
account manager on the Advanced plan, and no published resolution-time SLAs.

### 5. Pricing and cost information

We recommend the **Advanced plan** for the Counseling Center, because role-based permissions
and white labeling sit on that plan, and permission scoping is what lets a supervisor see
their own trainees' documentation and nobody else's.

The Advanced plan includes:

- Clinical EHR and documentation
- Scheduling and the multi-provider calendar
- Integrated HIPAA-compliant telehealth, with no separate licence
- AI Scribe, with no per-seat add-on
- Client portal and secure messaging
- Billing, invoicing, payment processing and insurance claims tools
- Reporting and CSV exports
- Mobile and desktop apps
- White labeling, roles and permissions
- A dedicated account manager
- Public API access

**Illustrative pricing at list price.** Your RFI states the Counseling Center supports more
than 50 faculty and students, so we have used 55 staff users. This is an estimate for
illustration and not a quote.

| Billing | Per user per month | Monthly total | Annual total |
|---|---|---|---|
| Annual (prepaid) | $39 | $2,145 | $25,740 |
| Monthly | $49 | $2,695 | $32,340 |

Pricing shown is list pricing as at October 2026.

**Your client count adds no cost.** Licensing is per staff user only. Clients are unlimited
at no per-client charge, so the number of community members the clinic serves does not change
the price. The commercial footprint is simply your staff count.

**Factors that typically affect cost**, answering your question directly:

- Staff user count, which for a training clinic means faculty plus the student cohort. Your
  students are users, not clients, so they carry a seat each. We would rather state that
  plainly than let it surface at quote stage.
- Seat changes across the three semesters. Seats prorate automatically, and removing a team
  member issues a credit for the unused part of that seat against future invoices.
- Plan choice, where Advanced is driven by your permissions requirement.
- Billing term, where annual prepayment is lower than monthly.

**Per-use fees on top of the subscription.** These are indicative and most will not apply to
a no-cost training clinic.

| Item | Indicative cost |
|---|---|
| Card payment processing (via Stripe) | ~2.9% plus $0.60 per transaction |
| Electronic claim submission | $0.19 to $0.25 per claim, by monthly volume |
| Insurance eligibility checks | ~$0.15 per manual check |
| E-prescribing | $39 per clinician per month |
| SMS beyond plan allowance | $0.05 per message (Advanced includes 200 per user per month) |

**Enterprise structure.** We can structure an agreement as a fixed annual rate covering up to
a defined user count, with per-seat rates above that ceiling, rather than a rolling monthly
per-seat model. Growth headroom sits inside the enterprise terms rather than triggering a
renegotiation, and the agreement can include a true-up and true-down mechanism at agreed
intervals. Seat ceiling, overage rate, term length and true-up mechanics are confirmed by our
commercial team in a formal quote rather than in this response. A discounted rate beyond list
price can be discussed if the University engages in further discussions with Carepatron.

On contract length: we are open to a longer-term agreement, and multi-year terms unlock
improved rates. We would rather you confirm the product meets your requirements first.

### 6. Other information

**Potential challenges or risks to consider.** We would rather write this section about
ourselves than have you find it in a reference check.

1. **Video recording is the material risk.** If the Counseling Center cannot run a separate
   recording tool alongside the EHR, Carepatron is the wrong choice and no commercial term
   fixes that.
2. **Enterprise SSO is the second.** A university standardised on an institutional identity
   provider will find email-and-password with MFA a step backwards in account management.
3. **Accessibility documentation.** We have no VPAT, and a public institution's procurement
   process often requires one before award.
4. **Supervisory approval routing is unproven in our documentation.** See the [VERIFY] items
   above. We would rather resolve those before you score this response than answer
   optimistically now.

**Value-added services or innovations.** The AI Scribe is the clearest one, and the value for
a training clinic is pedagogical rather than purely administrative. Faculty set the
documentation standard once, and every trainee works inside it. Combined with the scoring
instruments in the template library and attendance reporting by status, the department gets
a consistent record of how its students document, not just what they document.

## Known gaps

Consistent with how we respond to every institution, here is a consolidated list of where
Carepatron does not meet every requirement you have described. We would rather put this
clearly in the response than have it surface later. It is ordered by how much it matters to
you, not by product area.

- **Video recording of sessions. Not currently supported.** Not native, and not through a
  partner. There is no workaround inside Carepatron that produces a reviewable session video.
  The only path is a separate recording platform running alongside Carepatron, with the
  clinical record, transcript and note staying in Carepatron. This is a real gap for your use
  case.
- **Video retention, transcripts of video, timestamping and admin download.** All follow from
  the line above. The AI Scribe gives you a text transcript of every session, which is a
  genuine record, but it is not a recording.
- **Live observation.** Partial. A supervisor can join a telehealth session as a participant.
  Whether they can observe without appearing to the client is unconfirmed and flagged above.
- **Supervisor approval routing and co-signature.** Unconfirmed in our documentation.
  Permissions let supervisors see trainee documentation, and notes can be locked and signed,
  but we cannot claim a formal route-and-approve workflow today.
- **Enterprise single sign-on.** Not available today. No SAML, no OIDC, no SCIM provisioning.
  Supported sign-in is email and password with MFA, plus Google and Apple SSO. Outlook
  calendar and email sync are supported, which is a different thing. If Carepatron fits
  across the rest of your requirements, we would welcome a conversation about what delivering
  institutional SSO would involve and on what timeline.
- **WCAG conformance and a VPAT.** Not implemented, and we hold no conformance report. We are
  not going to offer one we do not have.
- **Published SLAs, uptime commitments and recovery objectives.** We do not publish
  resolution-time SLAs, an uptime percentage, a service-credit mechanism, or RTO and RPO
  figures. Support is 24/7 in practice. Where your process scores an SLA, we would treat it
  as a negotiable contract term rather than answering no and moving on.
- **Student information system integration.** No native SIS connector, for any SIS. The
  public API can support a scoped custom integration, bounded by client endpoints.
- **HL7 and FHIR.** No interfaces, no ADT feeds, no lab order or result interfaces.
- **Conditional logic in intake forms.** Not available in the form builder today. Forms split
  into sections, and separate targeted forms can be sent from the client record.
- **Bulk data export is not complete.** The bulk client export covers the client record's
  Personal tab: contact details, demographics and custom fields. Notes, appointments and
  inbox messages are not in the bulk export and download per client record. A full-history
  extraction is a support-assisted exercise rather than one click. This matters for an exit
  clause, so we are naming it now.
- **Client portal branding.** Your workspace, intake forms and communications carry your
  branding. The portal itself is not white-labeled and has no custom domain.
- **Session timeout.** No automatic idle timeout or session policy is documented. Sign-out is
  manual from the profile menu.
- **Room and resource booking.** Rooms and equipment are not bookable resources with their
  own availability and conflict checking. Appointments carry a location, and multiple
  clinicians can be scheduled on one appointment.

## Schedule F, IT technical compliance

Your Schedule F asks for documentation and says that where a supplier cannot provide an item,
we should include the rationale. We have done that rather than leaving blanks.

| Item | Response |
|---|---|
| SOC 2 Type II | **Available.** SOC 2 Type II maintained and confirmed by independent audit. Reports are accessed through our Trust Center at trust.carepatron.com rather than attached to a proposal. We can walk your IT team through it under NDA. |
| HECVAT Full | [VERIFY: has Carepatron completed a HECVAT Full or Lite? If not, the rationale is that we have not yet authored one, and we should say when we could. This is a standard higher-education gate and a blank here is costly.] |
| Software Bill of Materials | [VERIFY: do we produce an SBoM? If not, state the rationale plainly.] |
| Data integration guides / architecture diagrams | [VERIFY: do we hold shareable integration architecture documentation beyond the developer console at developer.carepatron.com and the Trust Center?] |
| Email integration guides / architecture diagrams | [VERIFY: same question for Gmail and Outlook email sync.] |
| VPAT for ADA compliance | **Not available.** We have no VPAT or accessibility conformance report, because we have not implemented WCAG conformance in the product. Stated rather than deferred. |
| SSO integration / configuration | **Partial.** We can document Google and Apple SSO and authenticator-app MFA configuration. We cannot provide SAML or OIDC configuration documentation, because that capability does not exist today. |
| Implementation guides / architecture diagrams | **Partial.** Implementation is delivered as a scoped project with a dedicated onboarding manager, and we can provide the plan at kickoff. [VERIFY: do we hold a formal implementation architecture diagram suitable for a university IT review?] |
| Data retention, destruction and return processes | **Partial.** Client data exports from the client list for one or many clients. Notes export as PDF and uploaded files export as uploaded. The bulk export limit above applies. Deleting an entire workspace is permanent and does not pass through Trash, so we recommend a full export before any workspace closes. [VERIFY: is there a documented retention and destruction schedule, and a contractual data-return process on termination, that we can hand to Oakland's IT review?] |
| SLA language | **Not available as published terms.** We do not publish resolution-time SLAs, uptime percentages or service credits. We would treat SLA language as a negotiated contract term through our commercial team. |
| EULA | [VERIFY: which agreement do we provide for institutional review? Our self-serve terms are public, but an enterprise agreement is negotiated separately and self-serve refund terms should not be quoted into an institutional response.] |
| Protected data accessed | **Health Information** and **Student Information**. Credit card data would apply only if the Center later enables client payments, which your no-cost service model suggests it would not. Financial aid data: none. We are happy to confirm the final selections with your IT review before signature. |

## Recommended next steps

1. **Submit clarifying questions through MITN by 13 October, 12:00 pm EST.** Two questions
   decide whether this bid is worth completing: whether video recording may be delivered by a
   separate system alongside the EHR, and whether supervisor approval of trainee notes must
   be a formal in-system routing workflow. The addendum on 20 October would answer both,
   with two weeks still left to respond.
2. **A working session with the Department of Counseling** to walk through live observation
   and supervisory review as you actually run them, so we can answer those requirements
   against your workflow rather than against a generic description.
3. **Confirmation of your user count** across faculty, supervisors, instructors and each
   student cohort, so the illustrative pricing above becomes a real quote.
4. **A security and accessibility review with Oakland University IT**, where we would rather
   walk through the SOC 2 Type II report and name the VPAT and SSO gaps directly than have
   them surface at evaluation.

We understand this is an information-gathering exercise ahead of a possible RFP, and we are
glad to be useful at this stage whether or not we are the eventual supplier. Thanks for
considering Carepatron for the SEHS Counseling Center.

---
