Health system CIOs have long vetted technology vendors for security, reliability and compliance. Increasingly, they’re also being asked to answer for who those vendors are outside healthcare.
The question has sharpened in recent months after Portland, Maine-based MaineHealth and New York City-based NYC Health + Hospitals faced public pressure over their contracts with Palantir, the data analytics firm whose work with immigration enforcement agencies and the military drew objections from nurses, activists and city council members. NYC Health + Hospitals ultimately declined to renew its roughly $4 million agreement with the company.
For IT leaders elsewhere, the episodes are forcing them to find the line between evaluating the technology and judging the organization behind it.
Christian Lindmark, chief technology officer of Palo Alto, Calif.-based Stanford Health Care, told Becker’s his organization does weigh a vendor’s ethics and outside business practices, but treats them as part of a broader risk review rather than a separate test.
He said Stanford’s evaluation centers on security, privacy, reliability, regulatory compliance and data stewardship, along with how a vendor manages third parties and responds when concerns are raised about its products. A vendor’s activities beyond healthcare become relevant, he said, when they create a meaningful risk to patients, employees or the health system’s mission and reputation.
“For me, the line is crossed when a vendor’s practices are fundamentally inconsistent with our obligations to patients or create a level of ethical, operational or reputational risk that we cannot responsibly mitigate through contractual, technical or governance controls,” Mr. Lindmark said. “At that point, even an excellent technology product may not be the right technology for our organization.”
For strategic or highly visible vendors, he said, that assessment draws in IT, business and clinical leadership, security, legal, privacy, compliance and, where appropriate, executive leadership — a structure that mirrors how some health systems are folding AI vendor decisions into enterprisewide governance councils that review new tools before they reach patients.
Muhammad Siddiqui, CIO of Richmond, Ind.-based Reid Health, said he applies a single practical heuristic rather than a formal checklist.
“My view is pretty simple: I draw the line at relevance,” he said.
A vendor relationship, Mr. Siddiqui said, isn’t an endorsement of everything a company does or every customer it serves, and health systems shouldn’t try to police every business decision a technology vendor makes outside of healthcare. But when a company’s conduct connects to patient trust, privacy, security, data use or employee confidence, he said, it becomes part of the evaluation.
“If one of our patients, nurses, physicians, board members, or community members asked me, ‘Why are you doing business with this company?’ could I explain the decision clearly and be comfortable with the answer?” Mr. Siddiqui said. “If I can, then we probably made the decision for the right reasons. If I can’t, we need to do more homework.”
He described the standard with a phrase he said he uses often: “trust before scale.”
“Technology can be technically excellent and still not be the right fit for an organization,” he said.
Not every CIO is convinced a fully consistent standard is achievable. Curtis Cole, MD, chief global information officer of Ithaca, N.Y.-based Cornell University, said health systems often have little choice in the vendors they use because of industry consolidation, and that the same institutions applying ethical screens to vendors are themselves far from ethically pure.
“There are two main challenges with using ethical standards in contracting,” Dr. Cole said. “One is how to be consistent.”
That tension is part of why CIOs describe the decision as closer to enterprise risk management than a one-time judgment about a company’s character. For Mr. Lindmark, that framing is the point: the technology has to work, but the company behind it has to be a partner the health system can defend.
“We want technology partners whose products meet our requirements and whose business practices are consistent with our responsibilities as a healthcare institution,” he said.
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.