Phase 5: Booking Participant Travel
Applies to: All staff involved in booking, coordinating, or communicating participant travel for in-person engagements
Sequence note: Phases 0-4 sequential; phase 10 anytime; not all phases apply
What you'll learn
- Execute the required kickoff call and program brief steps before initiating any patient or HCP travel booking
- Apply the correct data-handling rules for travel communications, vendor data sharing, and PHI-adjacent information
- Recognize when a patient need requires a travel policy exception and follow the written-approval process before booking
Lesson
Step 1 - Contact Amy Grow's Travel Team for a Kickoff Call
Scheduling a kickoff call with Amy Grow's travel team is the required first step before any patient or HCP travel is initiated. Before the call, prepare a program brief that includes: client name, job number, event dates and location, number of travelers, and what travel needs to be booked (flights, hotel, ground transportation, number of nights). Include any known patient-specific needs in the brief - accessible rooms, companion travel, medication refrigerator, or dietary restrictions - because these may require client travel policy exceptions and should be flagged early. After the kickoff call, Amy's team builds a custom Cvent registration page and sends the registration link to travelers to collect their information securely.
Source: slide 16 - June 30, 2026 Status Meeting (Travel)
Step 2 - Obtain the Client's Travel Policy Before Any Bookings
Request the client's travel policy and guidelines before making any bookings. Every pharmaceutical company has its own travel policy and HCP/patient engagement policy; all bookings must comply with the specific client's requirements. Amy's travel team stores all client travel policies centrally and checks them before booking. Review the policy for any restrictions that may conflict with patient needs - such as companion travel limits, room type caps, or meal per diem amounts - and flag potential conflicts with Client Services before the first booking is placed.
Source: slide 16 - June 30, 2026 Status Meeting (Travel)
Step 3 - Escalate Travel Exceptions Before Booking
Patient travel frequently requires exceptions to the client's standard travel policy. Common examples include: traveling with a companion, booking an accessible room, car service requiring accessibility, and accommodations that exceed the client's standard allowance. When a patient's need conflicts with the client's travel policy, Client Services must request written exception approval from the client's compliance team before the travel is booked. Amy's team flags the exception need to Client Services when they identify it; Client Services then coordinates the approval with the client.
Source: slide 17 - June 30, 2026 Status Meeting (Travel)
HARD STOP - Do Not Book Outside Policy Without Written Approval
Do not book any travel outside the client's policy without written approval from the client's compliance team. This is not a step that can be deferred or completed retroactively. Booking before written approval is received is a protocol violation regardless of how urgent the timeline is.
Source: slide 17 - June 30, 2026 Status Meeting (Travel)
Step 4 - Encrypt All Travel Confirmation Emails to Patients
All travel confirmation emails sent to patients must be encrypted. Add the word 'Encrypt' or 'Secure' to the email subject line to trigger automatic encryption. Never put PHI, disease state, or the reason for travel in the subject line because the subject line is not encrypted even when the body is. Hotel room lists and transfer manifests shared with vendors must be sent via password-protected spreadsheets and may include only: name, stay dates, flight details, and special accommodations.
Source: slide 17 - Quick Guide - Email_Encryption_User_Guide
Step 5 - Collect Traveler Information via Cvent
The travel team sends a unique, invitation-only Cvent registration link per event. Open links are available but sending email invites to invitees only is recommended. Cvent is a GDPR-compliant event registration platform. Only designated travel administrators have access to Cvent. Collect only the data needed to coordinate travel and event logistics.
Source: slide 18 - June 30, 2026 Status Meeting (Travel)
Step 6 - Create Traveler Profiles in Perk
After collecting traveler information through Cvent, the travel team creates traveler profiles in Perk using that information. All traveler profiles are housed within the A*I company account in Perk. Phone numbers are collected from travelers with disclosure that the information will be shared with transportation vendors.
Source: slide 18 - June 30, 2026 Status Meeting (Travel)
Handle PHI-Adjacent Travel Data with Care
Travel data includes PHI-adjacent information such as allergies, dietary restrictions, and mobility needs. Dietary and allergy information must be shared with venues in aggregate only (for example: '3 vegetarian, 2 gluten-free'), so that foods can be labeled for individuals to self-select. Do not link dietary needs to individual names. If an accessible room or medication refrigerator is needed, request it by name only without disclosing the reason or disease state. Disease states are never shared with vendors or venues.
Source: slide 18 - PHI Handling and HIPAA Safeguards_Final_8-2026
Scenario
You are coordinating travel for a patient advisory board. The client's travel policy caps hotel rooms at a standard rate. One patient requires an accessible room and companion travel; both exceed the client's standard allowance. Amy's team has flagged both needs to you. The event is in four days and the project lead is pressing you to confirm all bookings today to give the hotel a firm rooming list. You also need to send the patient a confirmation email that includes the hotel name and room assignment.
The accessible room and companion travel both exceed the client's standard policy allowance, but you have not yet received written exception approval from the client's compliance team. The project lead wants bookings confirmed today. What should you do?
Incorrect. Retroactive approval does not satisfy the requirement. Written approval from the client's compliance team must be received before any out-of-policy booking is made, no matter how tight the timeline.
Incorrect. The policy requires written exception approval for any booking that exceeds the client's standard allowance, including accessible rooms. There is no carve-out for accessibility requirements in the booking-approval process.
Correct. Written exception approval from the client's compliance team must be obtained before any out-of-policy travel is booked. The deadline pressure does not override this control. Client Services must coordinate with the client to get the approval in time, or the project lead must adjust the timeline.
Incorrect. Internal authorization from a project lead does not substitute for written exception approval from the client's compliance team. The exception must be approved by the client, not internally.
You are ready to send the patient a travel confirmation email that includes the hotel name, room type, and check-in date. The patient has a documented gluten allergy. How should you handle the email?
Incorrect. The subject line is not encrypted even when the body is. Including the dietary restriction in the subject line exposes PHI-adjacent information. Never put PHI, disease state, or the reason for travel in the subject line.
Correct. Adding 'Encrypt' or 'Secure' to the subject line triggers automatic encryption of the email body. Hotel name, room type, and check-in date belong in the encrypted body. The subject line must contain only the encryption trigger word - no PHI, disease state, or reason for travel.
Incorrect. All travel confirmation emails sent to patients must be encrypted, regardless of whether the content appears to be 'only logistics.' Hotel and room details about a patient are PHI-adjacent and require encryption.
Incorrect. A password-protected attachment does not replace the subject-line encryption requirement. The full email must be encrypted by adding the approved keyword to the subject line.
Knowledge Check
Select an answer to see feedback. This is practice - it does not affect your score.
What is the required first step before any patient or HCP travel is initiated in Phase 5?
Incorrect. The Cvent link is sent after the kickoff call, once Amy's team has built the custom registration page.
Incorrect. Obtaining the client's travel policy is Step 2. The kickoff call with Amy's team comes first.
Correct. Contacting Amy Grow's travel team to schedule a kickoff call is the required first step before any patient or HCP travel is initiated.
Incorrect. Perk profiles are created using information collected via Cvent, which comes later in the process.
When must exception approval be obtained for travel that falls outside the client's policy?
Incorrect. Post-booking approval is not compliant. Written approval from the client's compliance team is required before the travel is booked.
Correct. Written exception approval from the client's compliance team must be obtained before any out-of-policy travel is booked. There is no retroactive option.
Incorrect. Approval after the booking is made violates the control. Approval must precede the booking.
Incorrect. There is no percentage threshold. Any booking outside the client's policy requires prior written approval regardless of the amount of the overage.
How must dietary and allergy information be shared with venues?
Incorrect. A password-protected spreadsheet does not satisfy the requirement when it links individual names to dietary restrictions. Dietary needs must be shared in aggregate only.
Correct. Dietary and allergy information is shared with venues in aggregate only (for example: '3 vegetarian, 2 gluten-free'). Dietary needs must not be linked to individual names.
Incorrect. Written patient consent is not listed as the control mechanism for this data. The control is aggregate-only sharing regardless of consent.
Incorrect. Linking dietary restrictions to individual names by any method - including encrypted email - violates the aggregate-only requirement.
Key Controls Recap
- [RULE] Step 2 - Obtain the Client's Travel Policy Before Any Bookings
- [RULE] Step 3 - Escalate Travel Exceptions Before Booking
- [WATCH OUT] HARD STOP - Do Not Book Outside Policy Without Written Approval
- [WATCH OUT] Step 4 - Encrypt All Travel Confirmation Emails to Patients
- [WATCH OUT] Handle PHI-Adjacent Travel Data with Care
You've completed the Phase 5 learning module.
Return to Dayforce and take the Phase 5 quiz.