Implementation

Implementation: live in 48 hours, step by step

A full Bond Health deployment with the EHR connected typically takes 48 hours, depending on the EHR, the IT review and the interface method.⁠[1] What can add time is approvals Bond does not control: the BAA, the security review, the EHR connection and, where needed, IRB review of outreach scripts. Below is what Bond does, what your team does, and what exists after each step.

Last updated Sep 24, 20269 sources

What happens in the 48 hours?

The table shows the usual order for a full deployment with the EHR connected. Steps overlap: while IT reviews security and sets up the connection, the study team works through criteria and scripts with Bond.

48 hours⁠[1]

Full deployment with the EHR connected

20 days⁠[9]

Median from site activation to first patient screened (CRIO benchmarks, 2026)

Full EHR-integrated deployment
StepBond doesSite doesOutput
1. Kickoff and BAARuns kickoff, signs the BAA, shares security documents, reviews the protocol.Names the PI, coordinator, IT and security contacts. Signs the BAA.Signed BAA, owners, dated plan
2. Security reviewAnswers the security questionnaire. Lists the data and API scopes it requests.Runs its vendor review. Picks FHIR R4, HL7 v2 or an integration partner.Security approval, chosen interface
3. EHR connectionConnects in test, then production. Checks which data and note types come through.Provisions credentials and approves scopes, following the EHR vendor's steps.Working connection
4. CriteriaTurns each criterion into checks and runs them on a sample of real records.PI or coordinator settles ambiguous criteria and adjudicates the sample.Validated, versioned criteria
5. Scripts and IRBDrafts voice and text scripts with AI disclosure and how to reach a person: a live transfer or a callback.⁠[3]Edits the scripts. Submits them to the IRB where required.Approved scripts
6. Outreach and schedulingLoads scripts, sets escalation rules, connects the calendar and CTMS or sheet, sends test calls.Supplies visit slots, escalation contacts and CTMS access. Tests as a patient.Tested outreach flow
7. TrainingTrains coordinators on the dashboard. Sets up role-based access and SSO.Decides who reviews matches and who covers escalations.Trained users
8. Go-liveTurns on screening and outreach at the agreed pace. Monitors quality.Reviews matches, takes escalations, runs screening visits.First matches and booked visits
First month after go-liveReviews accepted and rejected matches with the site.Flags wrong matches and screen failures. Approves changes.Accuracy report, funnel numbers

Typical sequence for a 48-hour deployment.⁠[1] Your dates move with the three approvals below.

What does the site need to have ready?

None of this requires patient data, and no PHI moves to Bond until the business associate agreement (BAA) is signed.

  • A PI and a lead coordinator who can settle ambiguous criteria and review the validation sample.
  • An IT contact who knows the EHR's interfaces and approves new connections.
  • A privacy or security contact to run the vendor review and route the BAA.
  • The protocol, with inclusion and exclusion criteria and the screening visit schedule.
  • The IRB of record, and whether it reviews recruitment scripts.
  • Scheduling details: the calendar for screening visits and the CTMS or sheet that tracks referrals.
  • Your EHR and its hosting, and whether IT already runs third-party FHIR apps.

Your IT team sees the data and API scopes Bond requests before approving them. Once PHI flows, it is encrypted in transit and at rest (AES-256 where applicable), with role-based access, SSO support and audit logging. Bond also runs penetration testing and keeps a Trust Center for your reviewer.⁠[1] Bond is HIPAA compliant and SOC 2 Type I compliant, and its SOC 2 Type II and ISO 27001 audits are underway.⁠[3] See security.

How does the EHR connection get approved?

Bond connects to all the major EHRs, including Epic, Oracle Health (Cerner), MEDITECH, athenahealth, eClinicalWorks, NextGen, Veradigm and OncoEMR.⁠[3] Most certified EHRs already ship a standard interface. ONC's Cures Act Final Rule required certified EHR developers to update their API technology to FHIR-based APIs under § 170.315(g)(10) and provide it to customers by December 31, 2022, and ONC reported in February 2023 that more than 95 percent of developers met that deadline.⁠[4] The criterion is built on HL7 FHIR Release 4.0.1,⁠[5] so Bond's default path is FHIR R4 and the site's work is mostly approval and provisioning. Ask your IT team whether those APIs are turned on for third-party apps.

Each EHR has its own paperwork. Per Epic's developer documentation (as of September 2026), a health system signs the open.epic API Subscription Agreement once per organization, and Epic recommends it request a licensing estimate and run a security review scoped to the app's client ID. Bulk FHIR exports also need an analytics registry built around the inclusion criteria in Epic.⁠[6] On Oracle Health Millennium, per Oracle's documentation, the customer requests a tenant ID and logs a service request to provision the app.⁠[7] Where FHIR falls short, Bond can use an HL7 v2 feed or an integration partner. See integrations, including Epic and Oracle Health.

Firms that build new integrations quote longer. Topflight Apps puts a new app's first production Epic integration at 6 to 12 months, with each added site needing, for most apps, its own approval plus roughly 2 to 4 weeks to go live.⁠[8] Bond's 48 hours cover connecting your site and setting up a study, and depend on your EHR, IT review and interface method.⁠[1]

How are criteria, scripts and consent set up?

  1. 1

    Configure and validate the criteria

    Bond reads structured fields, clinical notes, imaging data and other unstructured documents through the approved interface⁠[3] and checks them against each criterion, using a terminology graph that links codes and synonyms across SNOMED CT, RxNorm, LOINC, ICD-10-CM and other vocabularies.⁠[2] Before go-live it runs the criteria on a sample of the site's records, and the PI or coordinator adjudicates until agreement meets the study's bar. See how we validate eligibility logic and Identify.

  2. 2

    Write the scripts

    Bond drafts voice and text scripts per site and study. Each tells patients that AI assistance is used and that they can reach a person at any time: the agent transfers the call live to a coordinator or books a human callback, whichever the site prefers.⁠[1],[3] Your team owns the wording. See Engage.

  3. 3

    Clear the IRB

    Where the IRB reviews recruitment materials, the site submits the scripts with a plain description of how the agents work. The decision is the IRB's. See IRB submission language for AI outreach.

  4. 4

    Connect scheduling

    Bond connects to the site calendar and to the CTMS or a Google Sheet, so booked visits and referral status land where coordinators work. Bond is a CRIO Certified Partner; with other CTMSs it uses the vendor's API or file export where supported.

  5. 5

    Set up consent support, if used

    Consent support explains the study in plain language, answers patient questions and escalates to staff. The PI and delegated staff still obtain consent.

If a study will use ads, Bond sets up the Meta and Google ad campaigns alongside the outreach configuration.⁠[3]

What happens at go-live and in the first month?

Training happens just before go-live. Coordinators learn the dashboard: the ranked match list, the criterion-to-evidence rationale behind each match, outreach status, pre-screening answers, booked visits and escalations.

At go-live, screening turns on and outreach starts at a pace coordinators can follow up on. Patients who ask for a person go to staff. In the first month, Bond and the site review accepted and rejected matches together, and the site approves any change to criteria or scripts. After that, Bond keeps improving outreach messaging until study close-out.⁠[3] Reports cover patients matched, contacted, pre-screened, consented and randomized, time to enrollment, matching accuracy, screen-failure signals and coordinator hours saved.⁠[1]

Can a site start before the EHR is connected?

Yes. A pilot can run outreach, pre-screening and scheduling on a list the site already has before the EHR is connected.⁠[1] It fits when a study is about to activate and the site's IT approval will take longer. It still needs the BAA and your vendor review, because a candidate list is PHI. Early speed matters: CRIO's July 2026 benchmarks put the median time from site activation to first patient screened at 20 days, and 8 days for top-quartile sites.⁠[9]

  1. 1Sign the BAA and pick one study. Same agreement and security documents as a full deployment.
  2. 2Share a candidate list. The site exports patients it has already identified, for example from an EHR report, into a shared sheet.
  3. 3Approve the scripts. If the IRB must review them first, that review sets the start date.
  4. 4Start outreach. Voice and text agents contact patients, ask the pre-screening questions, book visits and escalate to coordinators.
  5. 5Add the EHR connection. When IT approves it, Bond adds EHR screening. Scripts and scheduling stay in place.

What changes for coordinators?

Recruitment tasks, manual and with Bond
TaskManual wayWith Bond
Finding candidatesRun an EHR report, then open charts one at a timeBond reads structured data and notes against each criterion and ranks candidates
Checking criteriaCoordinator reads the chart and logs a decisionEach match shows the chart evidence per criterion; the coordinator accepts or rejects
First contactCalls and voicemails during clinic hoursVoice and text agents disclose AI use and offer a live transfer to a coordinator or a human callback⁠[3]
Pre-screeningCoordinator asks the questions by phoneThe agent asks the site-approved questions and records the answers
SchedulingBack-and-forth, then manual CTMS entryVisit booked on the site calendar; status sent to the CTMS or a sheet
Record keepingSpreadsheets and call notesDashboard and audit trail

What does Bond not do?

  • It does not control your approval queues. If the security review, EHR provisioning or IRB review runs long, go-live moves.
  • It does not decide eligibility. Bond reports matching accuracy above 90 percent,⁠[1] so some matches will be wrong. Coordinators and the PI confirm each one, and the screening visit decides.
  • It does not obtain consent. The PI and delegated staff do.
  • It does not replace your CTMS or eRegulatory system. It works alongside them.
  • It does not have a public price list. Pricing is custom: a volume-based platform fee covers EHR integration, implementation and ongoing operation, with no separate integration fee, plus a success fee per randomized patient. See pricing.⁠[1]

Bring your protocol and the name of your EHR. We will lay the plan against your calendar and show which steps are yours.

Frequently asked questions

Does Bond need EHR access before the BAA is signed?
No. No PHI moves to Bond until the business associate agreement is signed.
What if our security review takes longer than the plan?
Go-live moves with it. Criteria setup and script drafting continue, but validation on real records waits. A pilot also needs the BAA and security review, so it helps only when the EHR connection is the holdup.
Does the EHR vendor charge for the connection?
That depends on your contract with the EHR vendor. Epic's developer documentation (as of September 2026) recommends that health systems request a licensing estimate early.⁠[6] Bond charges no integration fee; its integration work is covered by its volume-based platform fee.⁠[1]

Sources

  1. 1.Bond Health: platform overview, FAQ and pricing · Bond Health, 2026
  2. 2.Terminology Infrastructure and Graph-Grounded RAG for Clinical Trial Patient Matching · Bond Health (Goel R., preprint), 2026Bond Health preprint, August 2026. Describes the ClinText Graph terminology graph built from 18 biomedical vocabularies including UMLS, SNOMED CT, RxNorm, LOINC and ICD-10-CM/PCS.
  3. 3.Bond Health product information · Bond Health, 2026Capabilities, pricing and compliance status described by Bond Health, September 2026.
  4. 4.Achieving a Major Milestone: Health IT Developers Certify to Cures Update · HealthIT.gov (ASTP/ONC), 2023Blog post by Robert Anthony, February 10, 2023. Quote: "More than 95 percent of Certified Health IT developers met the compliance deadline to update and provide their customers with new technology." Also: "our requirements for standardized APIs included a provision to update certified API technology previously certified to § 170.315(g)(8) to FHIR®-based APIs in 170.315(g)(10) as well as provide that updated certified API technology to customers by December 31, 2022."
  5. 5.Certification Companion Guide: Standardized API for patient and population services · HealthIT.gov (ASTP/ONC), 2026Quote: "the standard adopted at § 170.215(a)(1) (HL7® FHIR® Release 4.0.1)"
  6. 6.Implementing Apps at Epic Customers · Epic Systems Corporation (Epic on FHIR), 2026Accessed September 2026. Quote: "Community members who wish to use FHIR APIs with a third-party application registered on the Epic on FHIR website must sign the open.epic API Subscription Agreement. This agreement applies to the organization, not to individual apps." Also: "Epic recommends that healthcare organizations proactively request a licensing estimate and complete a security review based on your client ID's scope." Also: "Using Bulk FHIR requires configuration from the health system, as they will need to create an analytics registry around specific inclusion criteria, within Epic."
  7. 7.FHIR Application Provisioning (Oracle Health Millennium Platform) · Oracle Help Center (docs.oracle.com), 2026Quote: "The customer logs an SR to Cerner Ignite APIs for Millennium for provisioning."
  8. 8.Epic EHR Integration for Health Apps: Process, Cost & Challenges · Topflight Apps, 2026Development consultancy blog by Joe Tuan, updated September 11, 2026; accessed September 2026. Quote: "Our planning range for a production integration is 6 to 12 months to the first go-live." Also: "Each additional site then needs its own setup and, for most apps, its own approval on that customer's timeline, plus roughly 2 to 4 weeks to go live" and, attributed to Scott Rossignol, who led EHR integration at Topflight: "Your implementation timeline is going to be 90% waiting for the health system to approve your integration and 10% doing, and that 10% can take two weeks to 90 days."
  9. 9.What It Takes to Start a Study: Site Start-up Benchmarks · CRIO, 2026Blog post by Raymond Nomizu, July 30, 2026: analysis of CRIO system data with the Site Accreditation and Standards Institute; sample size not stated. Quote: "The median time from activation to first patient screened is 20 days, but top-quartile performance is observed at just 8 days, or a little over a week. Bottom-quartile performance is 34 days, or just over a month."

Related pages

Ready to get started?

Enroll patients faster.

See how Bond can accelerate enrollment for your clinical trials with a personalized demo.

Book a demo

Up to 3×

faster enrollment

90%+

matching accuracy

4-6 wks

implementation