DOC-REF: FRC-2026-04-28Rev 04 / 2026

Section 8.4 - Register entry

DOC-REF: FRC-MKT-FR2528336463

DSS Health Cloud (DSSHC)

Document Storage Systems, Inc. (DSS, Inc.) lists DSS Health Cloud (DSSHC) on the FedRAMP Marketplace with the status FedRAMP Certified, at High impact, on the Agency path under the Rev5 process. Package FR2528336463, read from the marketplace feed as of September 3, 2026.

FedRAMP CertifiedRev5Agency path

Section A. Register entry

What the marketplace records

FedRAMP package ID
FR2528336463
Cloud service provider
Document Storage Systems, Inc. (DSS, Inc.)
Certification status
FedRAMP Certified
Impact level
High
Certification class
Class D (High)
Authorization path
Agency
Certification type
Rev5
Marketplace phase
Ongoing Certification
Deployment model
Government Community Cloud
Register snapshot
September 3, 2026
Service model
PaaS, SaaS
Independent assessor
Coalfire Systems, Inc.
Certification date
July 27, 2026
Status date
July 27, 2026
Annual assessment
June 9, 2011
Agency authorizations
1
Business categories
Analytics, Cybersecurity & Risk Management, Health & Wellness, Network Management, Operations Management, System Administration
SAM.gov UEI
EJL2XFJ1BZJ1
Milestones on record
2

The marketplace carries DSS Health Cloud (DSSHC) under package FR2528336463 with 19 recorded fields. Its certification date is July 27, 2026. Coalfire Systems, Inc. is named as the independent assessor, with an annual assessment date of June 9, 2011. 1 agency is listed as having authorized it, among them Department of Veterans Affairs. It is delivered as PaaS and SaaS on a government community cloud, filed under 6 business categories including Analytics, Cybersecurity & Risk Management, Health & Wellness and 3 more. Its SAM.gov unique entity identifier is EJL2XFJ1BZJ1.

Section B. Milestones

2 entries in the marketplace event log

Most recent first, as recorded by FedRAMP.

Event log
DateCategoryRecorded
July 27, 2026Status ChangeStatus changed from PMO Review to FedRAMP Certified
August 28, 2025Status ChangeStatus set to Agency Authorization In Process

Section C. Cost context

What reaching High costs

Our own published ranges for a provider going through this level. Nothing here is a figure this provider has disclosed.

Cost context

Budget for a High authorization

Initial authorization$2,500,000 to $5,000,000+
Continuous monitoring$300,000 to $600,000+ a year
Typical timeline18 to 24 months
Control baseline421+ controls
Annual assessment$180,000 to $450,000 a year

Our published planning range for a provider pursuing High. It is not a figure any listed provider has disclosed.

Read the FedRAMP High cost guide / annual assessment cost / continuous monitoring cost

Path

Agency Authorization is the route for 578 of the offerings on the marketplace. Our cost pages put it at $800,000 to $2,000,000 over 12 to 18 months for Moderate. Agency authorization cost

Assessment and monitoring

An annual assessment date of June 9, 2011 is on the record, and that assessment recurs for as long as the package stays listed. Annual assessment cost / continuous monitoring cost

Section E. Agencies on the record

1 agency listed against this package

As published on the marketplace. An agency named here has issued its own authorization to operate; FedRAMP does not issue ATOs itself.

  • Department of Veterans Affairs

Section G. Nearest entries on the register

Comparable offerings

Scored on impact level, path, status, shared business categories and how close the two entries sit in the register's own timeline.

Section H. Description

As published on the marketplace

The provider's own description of the service, reproduced from the FedRAMP feed without edits.

DSS Health Cloud is delivered as a PaaS/SaaS offering using a multitenant Government-Only Cloud computing environment. It is available to VA Hospital system(s). As a cloud-based solution hosted in AWS GovCloud, the DSS Health Cloud provides to VA Clinicians, Administrators, Managers, and Users the TeleCare Record Management Plus-Clinical Triage (TRMW), Patient Case Manager High Reliability Organization (PCM HRO/VSPM), RxTracker (RTVX), and Juno EHR (JEHR) applications for the purpose of conducting clinical and administrative activities in a reliable and high-security federal cloud environment. SaaS The following SaaS applications are provided within the DSS Health Cloud solution. TeleCare Record Manager Plus-Clinical Triage (TRMW) is a web based application that provides VHA healthcare facilities with an intuitive, user-friendly interface for telecare triage providers. TRM Plus-CT creates progress notes which are then seamlessly incorporated into the patient's existing EHR. • Centralized web-based interface which allows users to access all VistA facilities from a single interface. • Enterprise-wide ad hoc analytics that delivers reporting at the local, VISN, or enterprise level. • Seamlessly integrated with VistA Scheduling Enhancements (VSE) to allow creation, update, and cancelation of appointments. • Is VA Technical Reference Model compliant. Patient Case Manager High Reliability Organization (PCM HRO) standardizes workflows and combines data visualization tools and analytics to reduce Veteran suicide prevention care variation and impact Mental Health SAIL metrics. • Actively monitors suicide prevention processes, performance, and outcomes. • Automates data capture and reporting to prevent lapses in care. • Improves transparency in the management of high-risk patients across the enterprise • Automates identification and escalation of scenarios requiring intervention. • Automates case load reporting and changes over time. With PCM, hospitals leverage real-time data and analytics for greater oversight and more effective, standardized workflows. Providers will save time, reduce medical errors, and ensure every patient receives the care and satisfaction they deserve. • Improve Patient Safety • • Monitor Quality and Performance • • Maximize Patient Throughput with the Patient Flow Module RxTracker is a single, comprehensive ePrescribing solution that gives providers the ability to effectively perform their full clinical workflow for all care settings: inpatient, outpatient, and ambulatory. 1. Proactive and Reactive Patient Safety Alerts 2. EPCS 3. Metrics, Reporting, and Auditing Juno EHR is a cloud-based electronic health record suite of applications that automates administrative and clinical workflows within a healthcare organization. The solution provides features to manage all aspects of patient care such as scheduling, registration, clinical notes, order entry, and electronic prescription. All DSS Health Cloud Software applications, with their corresponding components, are hosted within the SaaS authorization boundary. Applications are VA VistA integrated and follow a role-based design model. Using the VA provided and managed PIV smart card, users are authenticated through the VA Identity Authentication Management System (IAM). During the login authentication process, users with active and valid credentials are logged into the application following all FedRAMP High, VA, and organization protocols. All web transactions and data transmissions between the applications and the integrated VistA database go through a VPC/Palo Alto Firewall into the VA Network. The VPC/Palo Alto firewall controls access and monitors LS 1.2 CI/CD pipelines, external services, communication with the VA Network, and with the internet. Software application input activities are recorded into audit logs, which meet the FedRAMP high-security level as well as DSS organizational auditing security standards. All audit logs are collected by the Splunk SIEM tool, which triggers near-real-time alerts and notifications to DSS Health Cloud Engineers for analysis and continuous monitoring. Logs are stored within the FedRAMP authorization boundary into S3 buckets for seven years for after-the fact investigations of security incidents and to meet regulatory and organizational information retention requirements. PaaS DSS Health Cloud offers the VA hospital Systems a robust and secure multi-tenant PaaS platform that allows flexible integration with other VA vendors' software applications.

Next step

What the same authorization would cost you

The worksheet turns an impact level, an existing security posture and an organization size into a line-by-line budget, with the 3PAO fee split out.

Provenance and independence

Source: the FedRAMP Marketplace product feed, produced by the General Services Administration. The feed's own last-change stamp is September 3, 2026; this copy was taken on September 5, 2026.

GSA's disclaimers page states that FedRAMP content about a specific commercial product or service is provided for the information and convenience of the public and “does not constitute endorsement, recommendation, or favoring by the General Services Administration”. A listing here is a record of a certification status, not a judgment about the product.

FedRAMPCost.com is an independent cost reference. We are not affiliated with FedRAMP, the GSA, any provider listed on this page, or any assessment organization, and no provider pays to appear in this register.

DOC-REF: FRC-2026-04-28 / Updated 2026-04-28