SECTION 1: ABOUT THE ORGANISATION
Society for the Promotion of Youth & Masses (SPYM) is a Delhi-based non-profit organisation managing Drug Treatment cum Rehabilitation Programmes across India. The organisation provides comprehensive rehabilitation services including de-addiction counselling, medical management, psychosocial support, and community reintegration services for individuals affected by substance use disorders.
SPYM operates drug treatment and rehabilitation services at Kotla Mubarakpur, New Delhi in collaboration with healthcare institutions and government agencies. Two separate clinical units operate independently within the same premises:
• First floor: AIIMS Community Clinic (operated in collaboration with All India Institute of Medical Sciences)
• Second floor: SPYM Drug Treatment cum Rehabilitation Centre (DTC)
The proposed software should support both units through a single integrated platform while maintaining complete segregation of patient records, dispensing data, user access, and workflows. Authorised administrators shall have oversight access across both units.
SECTION 2: PURPOSE & BACKGROUND
2.1 Current Process Overview
SPYM currently manages medicine procurement, stocking, and dispensing through a paper-based system across all its Drug Treatment cum Rehabilitation Centres. The existing process consists of four stages:
• Phase 1 — Drug Requirement & Procurement: Drug requirements are assessed by the Doctor/Nursing Staff and approved by the designated medical officer. Procurement is undertaken through a competitive quotation process (minimum 3 pharmaceutical agencies), followed by issuance of a formal Purchase Order.
• Phase 2 — Receipt of Medicines & Central Stock Management: Medicines received from suppliers at the Head Office are physically verified for quantity, batch number, and expiry date before being entered into the Central Stock Register.
• Phase 3 — Distribution to Treatment Centres & Unit-Level Stocking: Medicines issued from Central Stock to individual treatment centres are recorded in the respective Daily Stock Registers. Movement of controlled or psychoactive medicines is accompanied by mandatory Transfer Letters.
• Phase 4 — Patient Dispensing & Documentation: Medicines are dispensed strictly against a valid doctor's prescription, recorded in the Daily Dispensing Register, acknowledged by the beneficiary, countersigned by the Nurse, and verified by the Project In-charge.
At the AIIMS Centre, medicine requirements are raised by the DTC and submitted to the NDDTC AIIMS Ghaziabad store for procurement. Upon receipt, stock is verified and entered into both online and offline systems with a daily dispensing register maintained separately.
2.2 Need for Digital Transformation
The existing manual system presents the following challenges:
• Risk of data loss, transcription errors, and delayed reporting across centres
• Inability to track real-time stock levels at both Head Office and centre level
• Difficulty in generating consolidated reports for regulatory compliance and internal audits
• Duplication of effort across daily, monthly, and dispensing registers
SECTION 3: OBJECTIVE OF THE ASSIGNMENT
The objective of this assignment is to design, develop, deploy, and maintain a secure and scalable Drug Dispensing & Drug Database Management Software for:
• Centralised medicine stock management
• Prescription-based drug dispensing
• Controlled medicine accountability (NDPS compliance)
• Patient-wise dispensing history management
• Unit-wise operational segregation (AIIMS Clinic and SPYM DTC)
• Audit trail and compliance reporting
• Real-time reporting and dashboards
• Secure and role-based workflow management
The software must be scalable for future expansion to additional treatment centres and future healthcare modules.
SECTION 4: SCOPE OF WORK
At this stage, the scope is limited to digitisation and management of medicine stock and dispensing records. The system shall be designed to accommodate future expansion without architectural rework.
4.1 Drug Dispensing & Inventory Management Module
A. Central Stock Management
• Entry of medicines received from suppliers into the central stock register
• Batch-wise inventory capturing: Medicine name, Batch number, Manufacturing date, Expiry date, Quantity received, Supplier details, Invoice/reference details
• Automatic stock balance calculation with FEFO/FIFO inventory logic
• Prevention of issue of expired medicines; near-expiry alerts (configurable, default 60 days)
• Daily stock reconciliation and physical vs. digital stock variance reporting
• Buffer stock monitoring with alerts
• Drug master data including: Generic Name, Brand Names, Schedule Class, Therapeutic Category, Dosage Form, Strength, Unit of Measure, Controlled Substance Flag, Cold Chain Flag, Minimum Stock Level
B. Stock Transfer to Dispensing Units
• Transfer of medicines from central stock to dispensing units with unit-wise stock ledgers
• Transfer acknowledgement workflow and audit logs
• Minimum buffer stock monitoring (minimum 15 days)
• Batch-wise stock transfer tracking
C. Prescription-Based Dispensing
Note: Bidders must clearly specify in their proposal whether the solution covers dispensing against existing prescriptions only, or also includes doctor consultation and e-prescription generation.
• Dispensing only against active, valid doctor prescriptions with mandatory linkage to patient treatment records
• Prescription validity checks and duplicate dispensing prevention
• Dosage validation controls and daily dose tracking
• Missed dose/non-collection tracking
• Emergency dispensing workflow with approval trail and override logging
D. Digital Dispensing Register
• Patient-wise and medicine-wise dispensing records with automatic date/time stamping
• Unit-wise dispensing logs and daily dispensing summaries
• Medicine consumption analytics
E. Beneficiary Acknowledgement
• Capture of beneficiary digital signature or thumb impression as confirmation of receipt
• Timestamped acknowledgement records
• Vendor must propose a cost-effective device/method for digital signature capture; fallback: supervisor witness counter-signature if device fails
F. Verification & Approval Workflow
• Nurse/Pharmacist: daily verification and digital countersignature of dispensing records
• Project In-charge: end-of-day review and approval with pending alerts and exception reporting
• Mandatory synchronisation before end-of-day approval workflow
G. Patient Management
Bidders must include the following minimum patient master features to prevent duplicate records and ensure data integrity.
• Unique Patient ID: auto-generated with optional Aadhaar and ABHA Card linkage
• Mandatory registration fields: Name, Age, Gender, Address, Emergency Contact, Admission Date, Primary Substance of Use, Treatment Type
• Deduplication check at registration: Name + Date of Birth + Phone
• Digital consent form capture at registration
• Allergy field mandatory with red alert on dispensing conflict
• Minor patients: guardian details mandatory, separate consent
• Deceased/discharged patients: archive view only (not deleted); data retention minimum 2 years post-discharge
• Patient data export in PDF for referral to other hospitals/other doctors – Customisable Fields
• Complete patient-wise medication history with cumulative dosage records (read-only archived records)
H. Unit-wise Data Segregation
• Separate and independent management of records for AIIMS Community Clinic and SPYM DTC
• Both units operate within separate logical partitions under a common software platform
• Authorised administrators have oversight access across both units
I. Document Management
• Upload and storage of scanned prescriptions and supporting documents / OCR Technology
• Searchable digital document archive with configurable document retention policy
J. Notifications & Alerts
• Configurable alerts for: Low stock, Near-expiry medicines, pending verification/approvals, Missed dispensing, Buffer stock shortages
• Future integration capability with SMS/email notification systems / 2 factor authentication
4.2 Reports & Dashboard Module
The software shall include configurable dashboards and report generation with export options in PDF and Excel formats.
A. Drug Dispensing Reports
• Unit-wise dispensing reports and period-wise summaries
• Medicine-wise dispensing trends
B. Drug Stock Reports
• Real-time stock position and batch-wise inventory
• Expiry tracking: quantity received, quantity issued, current balance, near-expiry status, buffer stock
C. Patient-wise Dispensing Summary
• Monthly dispensing summaries and period-based patient dispensing reports
• Patient medication history reports
D. Audit Trail & Activity Log
• Comprehensive audit trail capturing: User ID, Date & timestamp, Activity performed, Before/after value tracking
E. Exception & Variance Reports
• Stock variance reports, missed dispensing reports, pending approvals, adjustment reports
4.3 Administration & User Management
Role-Based Access Control (RBAC)
Roles shall include at minimum:
• Medical Officer / Doctor
• Nurse / Pharmacist
• Project In-charge
• Medical Social Welfare Officer (MSWO)
• System Administrator
Security Features
• Secure login with minimum password policy: 8 characters, uppercase, number, special character; 90-day expiry; no reuse of last 5 passwords
• Session auto-timeout: 10 minutes inactivity
• Two-factor authentication (2FA) mandatory for Doctor and Project In-charge roles
• Account lockout after 5 failed login attempts for 30 minutes; failed login tracking and admin activity monitoring
• User activity logging and IP/session logging
• Role-based permissions with unit-based data partitioning
4.4 Technical Requirements
A. Application Architecture
• Web-based application accessible via standard browsers; mobile-responsive interface preferred
• Centralised cloud-hosted system with browser-based access and centralised database
• Modular and scalable architecture, API-enabled for future integrations
• Multi-user concurrent access support: minimum 15–20 concurrent users across both units at go-live, architecture to scale to 50+ concurrent users as additional centres are added
• Target response time: page/screen load within 3 seconds and transaction save (e.g. dispensing entry) within 2 seconds under normal load
• Multi-centre scalability: configurable for deployment at new locations
• Minimum uptime target: 99.5%
B. Offline Functionality
Offline functionality is critical for this deployment and must be fully addressed in the technical proposal.
• Local offline transaction capture with queue-based synchronisation
• Offline data encrypted using device-level AES-256
• Automatic synchronisation on internet restoration with conflict resolution (last-write-wins with conflict log for review)
• Maximum recommended offline period: 24 hours
• Core features available offline: dispensing, stock view, prescriptions
• Online-only features: reports, admin, user management
• Sync priority order: dispensing > stock > signatures > reports
• Visual sync status indicator: green = synced, amber = pending, red = failed
• Optimum internet bandwidth for sync operations: 512 kbps
• Synchronisation audit logs and data integrity validation during sync
C. Hosting & Infrastructure
• Cloud-hosted deployment preferably within India
• Daily automated backup and disaster recovery mechanism with backup restoration testing capability
• Data archival: minimum 7 years of data to be stored and available for reporting
D. Security & Compliance
• HTTPS/TLS 1.3 (minimum TLS 1.2) in transit; AES-256 encryption at rest
• Secure password hashing; OWASP Top 10 compliance
• Compliance with DPDP Act 2023, IT Act 2000, and NDPS Act 1985
• Vulnerability assessment and security audit before deployment; annual VAPT by certified agency
E. Data Ownership & Portability
• All data shall remain sole property of SPYM and NDDTC, AIIMS
• Vendor shall provide complete database export capability
• Vendor shall not retain or reuse patient data; no proprietary lock-in architecture
F. Data Migration
Bidders must clearly state in their proposal whether digitisation/migration of existing manual or paper records is: (a) included in scope, (b) partially included, or (c) out of scope with a separate cost indication.
G. Training & Change Management
• User and administrator training at Kotla Mubarakpur for staff of both units
• Training manuals, go-live support, and handholding support during implementation
SECTION 5: KEY DELIVERABLES & TIMELINES
S.No. Deliverable Timeline (from Agreement)
1 Requirement Study, Workflow Mapping & SRS 60-90 Days
2 System Architecture Document & UI/UX Wireframes / Prototype for Approval
3 Alpha Version of Application
4 Beta Version for UAT at Kotla Mubarakpur (both units)
5 UAT Feedback Incorporation & Bug Fixes
6 Production Deployment (both AIIMS Clinic and SPYM DTC)
7 User Training & Go-live Support
8 Source Code, Technical Documentation & Handover After Completion of Development of the Software
SECTION 6: MANDATORY DOCUMENTATION & TESTING DELIVERABLES
Vendor shall submit all of the following as part of the contract:
• Software Requirement Specification (SRS)
• System Architecture Document
• Database Schema Documentation
• API Documentation
• Deployment Manual
• User Manual (role-wise)
• Administrator Manual
• Backup & Recovery SOP
• Security Architecture Documentation
• Test Cases & Test Reports
• UAT Completion Report (with signoff process, acceptable defect levels, and production readiness approval criteria)
• Vulnerability Assessment Report
• Source Code Repository Access
SECTION 7: ELIGIBILITY CRITERIA
Proposals may be submitted by registered organisations as well as by individual professionals with relevant experience. Interested bidders must fulfil the minimum eligibility criteria applicable to their category, as set out below:
A. Organisations (Company / LLP / Firm / NGO-Tech wing)
• Registered Company/LLP/Firm/NGO-Tech wing under applicable Indian laws
• Minimum 3 years of experience in software/application development
• Minimum 1 completed healthcare, hospital, pharmacy, dispensing management, or NGO management software project (mandatory; to be cited with client reference)
• Experience in multi-user, multi-location enterprise applications
• Prior work with government or social sector organisations is desirable
• Positive net worth during the last two financial years
• Not blacklisted by any government or institutional agency
B. Individuals with Relevant Experience
• Individual professional / sole proprietor / freelance developer with a valid PAN and a valid government-issued photo ID and address proof
• Minimum 3 years of hands-on individual experience in software/application development, evidenced by a detailed CV
• Experience in designing or developing multi-user, multi-location applications
• Prior work with government or social sector organisations is desirable
• Income Tax Returns for the last two financial years demonstrating financial capacity to undertake the assignment (in place of the net worth requirement applicable to organisations)
• Not blacklisted by any government or institutional agency (self-declaration required)
Individual bidders shall be evaluated against the same criteria as organisations under Section 9 (Evaluation Criteria), without preference or prejudice on account of bidder category.
SECTION 8: PROPOSAL REQUIREMENTS
8.1 Technical Proposal
• Company profile (organisations) or detailed individual profile/CV (individuals), and relevant project experience
• Understanding of SPYM requirements as described in this RFP
• Proposed system architecture and technology stack
• Project implementation methodology and detailed work plan with timelines
• Portfolio of minimum 2 relevant projects
• Details of team members/sub-contractors (if any) and continuity plan (mandatory for individual bidders)
• Clarification on prescription scope: dispensing-only vs. e-prescription generation
• Clarification on data migration scope: included / partial / out of scope
• Offline functionality architecture and approach
• Data security and privacy approach
• Training and change management plan
• Support and AMC approach with proposed SLA timelines
8.2 Financial Proposal
• Item-wise costing for: requirement analysis, UI/UX design, software development, testing, deployment, cloud hosting (Year 1 & 2), training, warranty support, AMC Year 1, AMC Year 2
• Payment terms proposed by the bidder
• Total cost of ownership for Year 1 and Year 2
• Price validity period
8.3 Supporting Documents
• Certificate of incorporation/registration (organisations) or valid government photo ID and address proof (individuals)
• GST registration certificate (if applicable)
• PAN card of the entity/individual
• Audited financial statements for last 2 years (organisations) or Income Tax Returns for last 2 years (individuals)
• Client reference letters for at least 2 prior relevant projects
• Self-declaration regarding non-blacklisting
• Detailed CV highlighting relevant experience and qualifications (individuals)
SECTION 9: EVALUATION CRITERIA
Proposals shall be evaluated on Quality-cum-Cost Based Selection (QCBS):
S.No. Evaluation Parameter Weightage (%)
1 Relevant healthcare/pharmacy/NGO software experience 25%
2 Technical approach, architecture & solution design 25%
3 Security, scalability & offline capability 15%
4 Team qualifications & project management plan 10%
5 Training plan & post-deployment support 5%
6 Financial proposal (cost competitiveness) 20%
TOTAL 100%
Shortlisted bidders may be invited for a technical presentation and product demonstration.
SECTION 10: PAYMENT TERMS
Milestone Payment (%)
Requirement sign-off & SRS approval 10%
Prototype / Wireframe approval 15%
Beta / UAT deployment 30%
Final production deployment 30%
Documentation & source code handover 10%
Post go-live stabilisation support (30 days) 5%
Payments shall be released subject to milestone approval and submission of applicable invoices. SPYM typically releases payment within 30 working days of milestone approval.
SECTION 11: WARRANTY, AMC & SUPPORT
11.1 Warranty
• Minimum 12 months warranty support from date of Go-live
• Warranty shall include: unlimited bug fixing, security patches, performance optimisation, and technical support
11.2 AMC & Support
• Vendor shall provide Annual Maintenance Contract (AMC) pricing after the warranty period
• AMC proposal must define: response time SLAs, issue resolution timelines by severity classification (Critical / High / Medium / Low)
• Example SLA expectation: Critical (system down) — response within 2 hours, resolution within 8 hours; High (major feature failure) — response within 4 hours, resolution within 24 hours
SECTION 12: SUBMISSION PROCESS & TIMELINE
Step Activity Date
1 RFP Issued 29.09.2026
2 Last Date for Queries / Clarifications 01.10.2026
3 Proposal Submission Deadline 14.10.2026
Proposals submitted after the deadline will not be considered. SPYM reserves the right to modify the timeline with prior notice.
SECTION 13: GENERAL TERMS & CONDITIONS
• SPYM reserves the right to accept or reject any proposal, in whole or in part, without assigning reasons.
• Submission of a proposal does not guarantee award of contract.
• All costs incurred in preparing and submitting proposals shall be borne solely by the bidder.
• SPYM reserves the right to negotiate scope, timelines, and financial terms with the selected bidder.
• The selected vendor shall sign a Non-Disclosure Agreement (NDA) and a Data Protection & Confidentiality Agreement prior to commencement of work.
• All patient and organisational data shall remain strictly confidential.
13.1 Intellectual Property Rights
All source code, documentation, database structures, APIs, workflows, and associated intellectual property developed under this assignment shall vest with SPYM upon full payment. Vendor shall provide complete source code, database scripts, technical documentation, deployment files, and administrative credentials.
13.2 Data Protection & Confidentiality
Vendor shall maintain strict confidentiality of all patient and organisational data, not share or reuse data outside approved infrastructure, and comply with applicable data protection laws including the DPDP Act 2023 and IT Act 2000. Vendor shall remain liable for any breach arising due to negligence or non-compliance.
13.3 Indemnity
Vendor shall indemnify SPYM against data breaches, third-party claims, copyright and licensing violations, and negligence-related losses.
13.4 Termination
SPYM may terminate the contract for non-performance, breach of confidentiality, delayed delivery, or regulatory non-compliance. Upon termination, vendor shall provide transition support and complete data handover.
13.5 Force Majeure
Neither party shall be liable for delays caused by force majeure events beyond reasonable control.
13.6 Governing Law & Jurisdiction
The contract shall be governed by the laws of India. Disputes shall first be attempted to be resolved amicably. Courts at New Delhi shall have jurisdiction.
SECTION 14: CONTACT INFORMATION
Field Details
Organisation : Society for the Promotion of Youth & Masses (SPYM)
Contact Person : Aaditi Wahi, Research Assistant
Phone +91 8178693893
SECTION 15: ANNEXURES TO BE SUBMITTED WITH PROPOSAL
• Annexure A — Bidder Profile (Name, registered/residential address, year of establishment or start of professional practice, legal status — organisation or individual, key clients); individuals to attach a detailed CV
• Annexure B — Technical Proposal (as per Section 8.1)
• Annexure C — Financial Proposal (as per Section 8.2 — to be submitted in a separate sealed envelope or separate email)
• Annexure D — Portfolio of Relevant Work (minimum 2 projects with client contact details)
• Annexure E — Declaration of Non-Conflict of Interest
• Annexure F — Copies of registration/identity proof, GST (if applicable), PAN, and audited financials/Income Tax Returns