By Ganesh Ramamoorthy, Senior Vice President, Onix
Today’s digital healthcare professionals face unprecedented complexity. The quality and accessibility of clinical data is vital to delivering the best possible patient outcomes. Yet clinicians often struggle to quickly find and retrieve relevant information.
In fact, the sheer volume of data is staggering. A single hospital can produce 137 terabytes of data every day, or roughly 50 petabytes of data per year. This data tsunami is only getting worse, due to rapid expansion of digital health tools, electronic health records and connected devices.
As a result, healthcare administrative costs continue to skyrocket. In fact, administrative spending is estimated to be between 25-30 percent of the nearly $5 trillion spent annually for U.S. healthcare expenditures. More importantly, failure to tame the data dilemma can substantially impact both regulatory compliance as well as patient outcomes.
The healthcare industry is in dire need of transformation, but change happens slowly. How can healthcare providers navigate this massive, complex system to streamline data management in order to reduce costs, grow revenues and increase efficiencies?
Empower Intelligent Insights
To address this issue, a growing number of healthcare leaders are leveraging the latest artificial intelligence (AI) advancements to transform their legacy data systems into a modern, scalable and agile data platform. In this way, healthcare chief information officers (CIOs) are able to take full advantage of augmented intelligence to unlock predictive data analytics and clinical insights, enabling measurable improvements without adding administrative burden.
Indeed, AI-powered data modernization enables organizations to realize substantial clinical and operational benefits, while improving return on investment (ROI). With the help of enterprise-grade agentic AI and generative AI (Gen AI) technologies, healthcare organizations can achieve measurable results such as 10-25 percent reduction in the cost of care, 15-20 percent drop in hospital readmissions, and substantial reduction in mortality rates.
Collaborative Compliance
It’s no secret that administrative friction in healthcare is a significant challenge, with nearly 25 percent of every dollar spent on paperwork. A primary driver of this cost is the prior authorization (PA) process, which typically requires a significant amount of time to conduct manual reviews, send faxes and make phone calls. This burden not only increases costs, but also delays patient care through a “missing information” loop, where simple administrative omissions trigger denials and appeals.
By leveraging the latest agentic and Gen AI, healthcare professionals can transform their workflow from “Reject and Appeal” to “Detect and Clarify” to greatly improve the speed, precision and outcomes of the PA process. The system works by ingesting unstructured clinical notes and matching them against insurance policies, enabling AI agents to perform a real-time gap analysis.
When information is missing, the AI agent flags the issue and drafts a clarification for the provider in less than a minute, ensuring valid claims are approved on the first pass. This not only streamlines billing, it also allows nurses and doctors to focus on patient outcomes rather than paperwork.
Privacy Protections
Of course, when dealing with sensitive patient data, it’s paramount that hospitals and healthcare organizations have access to reliable, secure data they can trust to ensure regulatory and HIPAA compliance. This means that a key aspect of selecting the best AI solution is to ensure it is an enterprise-grade offering that prioritizes a high level of security, data governance and compliance.
In fact, advanced AI capabilities enable additional privacy innovations as well. For example, with the help of GenAI, hospitals can generate millions of records of synthetic data, allowing them to train and test new AI models without exposing sensitive protected health information (PHI). Plus, by compressing processes that otherwise take hours or weeks into minutes, AI agents return valuable time to medical practitioners.
It’s important to note, however, that healthcare CIOs need to implement robust governance policies when taking advantage of AI technology. As the number of AI agents making autonomous decisions increases throughout the healthcare industry, responsible AI practices will become a mandatory business requirement with decisions being driven by trust and transparency.
Healthcare Transformation Success
Today’s healthcare industry is poised for progress, and responsible AI deployments will be an integral part of this transformation – from building a new level of personalized patient experiences, to realizing substantial gains in productivity for improved patient outcomes.
Armed with the right tools, intelligence and insights, healthcare leaders are empowered to realize this transformation and build a brighter future for their patients. The true differentiator for successful healthcare enterprises will not be if they use AI, but rather how they responsibly manage and fully integrate AI into established processes.
In a reflection of its accelerating investment in AI, automation, data management, and company growth, AGS Health announce the expansion of its executive leadership team. These appointments underscore the company’s commitment to delivering on the promise of revenue cycle AI through practical innovation, clinical expertise, and ROI-driven solutions.
As a provider of tech-enabled revenue cycle management (RCM) solutions and a strategic growth partner to healthcare providers nationwide, AGS Health is focused on delivering measurable improvements in financial performance while enhancing the patient experience.
“Healthcare providers are navigating a highly complex and rapidly shifting industry landscape, one where reimbursement pressures, rising costs, workforce challenges, regulatory change, and the evolution of AI are converging in ways that demand more from their RCM partner than ever before. Providers don’t just need a partner that keeps pace with change. They need one that anticipates it and turns it into a strategic advantage,” said AGS Health Managing Director and CEO Patrice Wolfe. “The leaders we’re announcing today aim to bring exactly the visionary thinking, customer-first mindset, and creative problem-solving it takes to do that. Together with our broader executive team, they will help AGS Health continue innovating on behalf of our clients and try to ensure every provider we serve has the footing to not just navigate this moment, but to thrive in it.”
The appointments span four critical domains: commercial growth, AI and data, marketing, and customer success.
Cheryl Cruver was named President, US Markets & Chief Commercial Officer. Cruver, who was previously AGS Health’s Chief Revenue Officer, has unified oversight of all revenue-generating functions, including sales, marketing, customer success, and transition functions. She will also play a key role in advancing AGS Health’s AI-enabled transformation. Throughout her career, spanning more than three decades, Cruver has helped healthcare providers leverage data, technology, and innovation to strengthen financial performance, improve operational efficiency, and enhance patient outcomes.
Balaji Sundararajan was appointed to the newly created role of Chief Data and AI Officer (CDAIO), reflecting the central role of data and AI in AGS Health’s strategy. In this role, Sundararajan will accelerate the development of the company’s AI capabilities across its product portfolio and operations, oversee data governance and analytics, and promote data literacy and responsible AI use across the company. He previously served as AGS Health’s Senior Vice President and Global Head of Engineering and brings more than 30 years of technology leadership experience, including two decades driving AI and automation innovation.
Susan Worthy joins AGS Health as Chief Marketing Officer, leading the company’s global marketing strategy to drive growth and showcase innovation. Worthy brings to AGS Health a reputation for translating complex solutions into clear and compelling market narratives, aligning marketing with business priorities for health IT and tech-enabled services organizations, and building high-performing teams. Previously, she was CMO at Gainwell Technologies and has held marketing leadership roles at Amwell, Optum, and Aetna.
Joel Gleason was named Chief Customer Officer in addition to his existing role as Senior Vice President of Customer Success. He leads the company’s customer success organization, working to deepen client relationships, expand its footprint, and help customers achieve their business objectives through AI-driven technology and embedded global services. With more than 30 years of health IT and services experience, Gleason brings a strong customer-first approach to his role, along with a reputation for building scalable teams, driving repeatable processes, and delivering measurable value and outcomes.
“Cheryl, Balaji, Susan, and Joel each bring exceptional depth in their disciplines, and together they strengthen our ability to deliver the AI-driven, outcomes-focused solutions our clients need to compete in today’s healthcare environment,” said Wolfe. “I’m proud to welcome our new executive team members and am confident this team will define what’s possible for AI-driven revenue cycle management.”
To help healthcare organizations fight these headwinds, MDaudit, an award-winning continuous risk-monitoring platform, offers a suite of revenue integrity solutions grounded in its standard of Meaningful AI, in which technology is judged by its return on investment (ROI), the friction it removes, and whether a human remains firmly in control of every decision.
The newest expression of this standard is Auditor Assist, an AI-powered companion that helps auditors review more cases more quickly and with greater rigor — without surrendering the judgment auditors are trained to exercise.
Meaningful AI: A Standard, Not a Slogan
MDaudit’s Meaningful AI framework is grounded in independence and accuracy and rests on three commitments: a clear line to ROI, a focus on stripping out process friction rather than adding it, and a non-negotiable human-in-the-loop on every determination. The standard exists because the stakes keep rising. Payer audit volume and dollars at risk continue to climb across nearly every audit type, and coding accuracy remains the single largest driver of industry-wide industry wide. MDaudit’s own analysis of 2026 payer audit activity found that coding errors account for nearly seven in 10 completed denials.
“Meaningful AI means we ask one question before anything ships: does this change the outcome?” said MDaudit CEO Ritesh Ramesh. “ROI, less friction, a human who keeps the final say; that’s the test every release must pass. Auditor Assist is the latest to do so.”
It is a standard MDaudit has long applied to its suite of solutions. For example, Payer Audit Workflow uses AI to extract and organize information needed for Additional Documentation Requests (ADRs), helping customers retain more than $375 million in revenue in 2025 by responding to payer requests faster and more efficiently. AI Assist gives users at every level of an organization, including the C-suite, the ability to ask questions in plain English and get answers instantly, without relying on report writers or technical interpreters. Auditor Assist is the newest addition to that lineup.
The Latest Example: Auditor Assist
Auditor Assist leverages medical records and coded claims to assess coding integrity, and learns from every auditor decision, while keeping the experienced auditor firmly in control of the final call. Built as the auditor’s AI partner for accurate, defensible coding, it sits between provider and payer AI, serving as a defensibility layer over machine-coded claims.
Every AI output is sourced and traceable, built to hold up under payer and regulatory scrutiny, and the auditor decides what happens next — always.
“Auditor Assist is Meaningful AI in its purest form,” said Ramesh. “It does not replace the auditor’s judgment; it sharpens it. The auditor still makes the call. What changes is how much ground they can cover, and how much evidence stands behind every decision they make.”
The result is a shift in the economics of auditing. Instead of sampling a small fraction of claims reactively, audit teams can review more cases earlier and support each finding with evidence, turning auditing from a constrained, manual function into a scalable, proactive program. Even the smallest teams can work beyond their headcount and help ensure their organization is paid accurately and fully for the work it performs.
“We’ve been an AI-powered platform since before the label was trendy,” said Ramesh. “Auditor Assist doesn’t change our direction; it confirms it. Every time we expand our suite of continuous risk monitoring solutions, the strategy is the same: More ROI, less friction, a human in the loop.”
More information on Auditor Assist can be accessed here.
By Rob Ware, senior vice president and general manager of RCM Services, ModMed.
The financial health of medical practices is under strain. Historically, revenue cycle management (RCM) has been treated as a back-office administrative function, but today’s environment of rising operational costs, staffing shortages, and reimbursements that fail to keep pace with inflation demands a new approach.
Adding to the pressure, the industry remains plagued by considerable inefficiency. One study found that insurers, offering qualified health plans through HealthCare.gov, denied 19% of in-network claims and 37% of out-of-network claims. In this situation, administrators spend valuable time going back and forth with insurance companies while patients get hit with surprise bills. Financial stress goes up, institutional trust goes down, and the entire RCM process gets more complicated.
Prevention is the New Strategy
For decades, healthcare organizations have operated under a reactive RCM model. A claim is submitted, a denial occurs weeks later, and staff scramble to identify the problem, correct it, and resubmit the claim. The process has become an expensive cycle of administrative catch-up that drains resources and delays reimbursement.
But healthcare can no longer afford to manage revenue after the fact.
Predictive RCM represents a shift from revenue recovery to revenue prevention. By leveraging historical data and AI-powered insights, practices can identify potential issus before a claim is submitted.
Think of it as a navigation system for the billing workflow. Rather than notifying a user that they missed a left turn after they are already lost, predictive technology highlights potential roadblocks, such as missing authorization requirements, eligibility issues, or coding inconsistencies, while a claim is still being prepared.
The result is fewer preventable denials, faster reimbursement, and less time spent fixing avoidable mistakes.
Empowering the Back Office, Supporting the Front
One of the most important shifts occurring in healthcare today is strengthening the connection between clinical and financial workflows and teams.
Historically, those functions have operated in separate worlds. Yet many reimbursement challenges originate long before a claim reaches the billing department. Missing documentation, incomplete patient information, authorization gaps, and coding discrepancies can often be detected and addressed at the top of the patient journey.
Predictive RCM can help close this gap by identifying claims at risk of denial earlier and creating greater alignment between front-office, clinical, and billing teams. Rather than treating denials as isolated billing problems, providers can address root causes before they impact reimbursement.
This proactive approach not only aims to improve financial performance but also to reduce administrative friction across the practice.
When technology handles highly repetitive and predictable tasks—such as monitoring claim status, identifying missing information, or validating payer requirements—it allows revenue cycle professionals to focus on higher-value work, including complex appeals, payer negotiations, and strategic financial planning.
The benefits extend beyond the back office.
When front-office teams have access to accurate eligibility verification, timely coverage information, and reliable patient cost estimates, they are better equipped to have clear and compassionate financial conversations with patients. Instead of uncertainty, patients receive greater transparency and a clearer understanding of their financial responsibilities before care is delivered.
By shifting from reactive firefighting to predictive prevention, practices can potentially avoid costly denials while giving staff valuable time back.
The Human Impact
And then there’s the patient. Few experiences create more frustration for patients than receiving an unexpected bill months after an appointment.
As patients assume greater responsibility for healthcare costs, financial transparency is becoming an increasingly important part of the overall care experience. Providing accurate information upfront helps reduce anxiety, improve trust, and strengthen the provider-patient relationship.
When patients understand their coverage, expected costs, and payment options before treatment, practices are better positioned to create a more positive financial experience while reducing confusion and collections challenges later.
Ultimately, predictive RCM is about more than preventing denials. It represents a broader shift in how healthcare organizations think about financial operations.
In the years ahead, recovering revenue quickly will be only one piece of the financial success puzzle. Providers will be able to prevent revenue leakage before it occurs, align clinical and financial workflows more effectively, and create a more transparent experience for both staff and patients.
There is a version of a radiology report I have seen hundreds of times. The imaging is done well. The finding is documented. And the report ends with a sentence along the lines of: “Please correlate clinically. Further imaging may be warranted.”
That sentence sounds reasonable. It is also, in many cases, clinically useless. It does not say what should happen next. It does not indicate urgency. It does not tell the ordering provider whether this is a finding that needs action in two weeks or two years. This is called “hedging.” It’s defensive language designed to limit liability without committing to a specific recommendation. And it is one small symptom of a much larger structural problem in imaging.
Radiology-specific AI has made significant gains in detection. Algorithms are getting better at identifying lung nodules, incidental lesions, and abnormalities that might have been missed a decade ago. That progress is real, and it matters. But most of the industry conversation around imaging AI has focused on the front end of the workflow—what the model can find, what it misses, and the usefulness of AI enabled detection—while largely ignoring the back end: what happens after the finding hits the report.
That back end is where care actually breaks down.
The Downstream Problem Nobody Designed For
Every flagged finding is the beginning of a workflow. A follow-up study needs to be ordered. A patient needs to be contacted. A referral may need to be placed. A timeline needs to be tracked. When the finding is serious, those steps carry genuine clinical urgency. When they do not happen, patients get lost.
The data on this is sobering. Research published in the Journal of the American College of Radiology found that overall adherence to recommendations for additional imaging of incidental findings was just 39.1%. Other studies put the figure closer to 50 percent. However you measure it, the gap between what is found and what gets followed up on is enormous, and it widens as imaging volume grows.
And volume is growing. The Neiman Health Policy Institute projects that imaging utilization could increase by as much as 26.9% by 2055, while radiologist supply is expected to grow at a roughly comparable rate, meaning the current shortage is unlikely to improve without deliberate intervention. Radiologist attrition has accelerated since the pandemic, with departure rates up 50% from pre-COVID levels. Under that kind of pressure, report language gets less specific, recommendations get more vague and the downstream infrastructure (which was never adequate to begin with) absorbs more volume than it can handle.
This is the paradox at the center of imaging AI right now. Better detection tools surface more findings. More findings generate more downstream work. And the hard task of translating a finding into actual care relies on a workforce and systems already running at capacity.
More Dashboards Will Not Solve This
Health systems have tried to address the follow-up gap with worklists, tracking spreadsheets, and manual processes. I have watched care navigators spend hours every morning reconciling data from radiology systems against the EHR to figure out which patients still need to be contacted. In many organizations, that manual reconciliation is not a temporary workaround. It is the process. It is also the reason people fall through the cracks.
The limitation of most existing approaches is that they create visibility without creating accountability. A dashboard can tell you that a lung nodule was flagged. It cannot often tell you whether the follow-up was ordered, whether the patient was contacted, whether the appointment was scheduled, or whether the result came back. Those are different operational problems, and each one requires a different handoff.
What is needed is infrastructure that connects detection to completed care. Not just a view of what was found, but an operational layer that routes findings based on actual clinical risk, manages outreach, tracks completion, and escalates when something stalls.
What Completed Care Actually Looks Like
Radiology is often the starting point for a patient’s journey through the health system. From the moment an image is captured to the next step in care, each pathway is different. Patients have different needs, priorities, and resources. Technology workflows have different gaps that require different levels of support to close. Providers serve different populations with different barriers to care. There is no single worklist, workflow, or outreach strategy that can reliably solve every situation, every time.
In an environment defined by high variability and high stakes, high reliability becomes essential. It requires layered processes that apply the right tools to the right problem, with the goal of ensuring that no patient falls through the cracks. This means shifting our focus from task completion to patient outcome. Instead of asking, “Did the provider receive a notification?” we ask, “Did the patient receive the right next step in care?”
That distinction matters. True follow-up requires accounting for the complexity of the patient journey, including the reality that the right next step may change as new information, barriers, or circumstances emerge. High reliability is not measured by whether a task was checked off a list. It is measured by whether the system produced the intended action and result for the patient.
The Real Question for Imaging AI
The radiology AI market has spent the last several years racing to build better detection. That was the right starting point. But the industry is now at a point where the bottleneck is no longer whether a finding can be identified. The bottleneck is whether a finding, once identified, reliably reaches the right clinician, generates the right action, and results in completed care.
Health systems that invested heavily in AI detection tools are beginning to discover that the return on those investments depends almost entirely on what happens after the algorithm runs. A finding that surfaces in a report but never reaches the patient is not a detection success. It is a care failure that started with accurate imaging.
The next chapter of imaging AI needs to be about care completion: building the infrastructure between the radiology report and the EHR, between the finding and the follow-through, between what was identified and what was actually done about it. That is where patient safety lives. And right now, for too many health systems, it is also where patient safety breaks down.
AI is shaping the future of how healthcare organizations manage data, whether they’re ready or not. According to new research, 41% of healthcare organizations are already using AI for database management purposes, with a further 40% considering integrating it soon.
Many practices are already finding value in leveraging AI for their operations, with top applications including data quality assurance, automating database management, and data modeling.
While AI has the ability to generate massive upside for efficiency, it can also wreak havoc across existing data estates if they’re not properly prepared for adoption and integration. When piloting a new AI initiative, it’s imperative that there’s a solid foundation for the model to work on top of. An unstable base could topple down in an instant, unraveling years of work.
Where DBAs should look first
Database administrators (DBAs) must take stock of the key issues with their estate and address them before AI is added into the system. The keys to successful AI adoption can be easily broken down into three key categories: people, process, and data.
DBAs need to first ask if their team is ready to adopt AI. If the humans overseeing it aren’t prepared, then your initiative could fail before takeoff. When timelines are compressed to meet ROI projections set by stakeholders. That means training people with the skills to use AI and the freedom to deploy what they learn in the workflows they are familiar with. Top-down AI usage mandates are not going to help.
Next, DBAs must have a strong grasp on how value flows throughout the organization. Understanding key bottlenecks, which processes are load-bearing, and how to achieve measurable operational outcomes is essential to AI success. Without clarity, AI can be implemented in the wrong places, cascading chaos. It’s easy to point it at a problem that generates no value, or have it contribute to meaningless metrics rather than real outcomes. And fixing the current ones will not be sufficient. Once the first bottleneck is resolved, new ones will emerge that need to be addressed.
Finally, the most critical problem is the data itself. Healthcare databases can be enormous. Estates and their management processes are often passed down from managers from past years or decades. These legacy processes can lead to platforms that are a jumbled mess of software that doesn’t work together, programs that can’t communicate with each other, fragmented estates, undocumented schema changes, and split ownership. AI doesn’t magically clean up these problems, it simply acts as if there’s nothing wrong. If you don’t create a good foundation for AI to operate, then it will churn out confident answers based on broken information, providing solutions that generate no value
Building real foundations
Database governance should be the top priority for any DBA who’s looking to deploy AI. Right now, nearly 40% of all healthcare practices operate across 4 or more database platforms. The best way to address problems of database fragmentation and software sprawl is to pull everything together under a single umbrella, offering a unified view. Without full visibility, issues quickly turn into costly downtime, impacting revenue and customer satisfaction.
Addressing problems with the database’s structure is only half the battle. Once DBAs have cleaned up issues from the past, they must prepare for the future. The most crucial step is to create clear management processes so teams are aligned. Fragmentation occurs when there’s no standardized process for deploying changes or creating pathways. DBAs need to set clear guidelines for deploying updates and tracking schema developments. When engineers have no guiding principles, they create sprawl which could decimate AI processes down the line.
It might be a pain in the short term, but DBAs who dedicate the time to clean their data estate will realize exponential value down the line.
Looking forward
AI is set to revolutionize the way healthcare data is managed. It has the potential to quickly anonymize massive datasets, streamline database management, design schema, and much more.
However, most practices aren’t prepared to realize AI’s true value, and many will suffer due to poor implementation. DBAs need to be cognizant of the foundations that AI needs to thrive, audit their team’s ability to work with AI, identify the bottlenecks within their organization, recognize which internal processes are load bearing, understand how to generate measurable outcomes, and scrutinize the data itself.
AI can only thrive within clear governed processes and solid support. Don’t fall into the trap of thinking it will automatically fix everything.
By Leigh Burchell, vice chair, EHR Association Information Blocking Compliance Task Force.
The HTI-5 proposed rule, Health Data, Technology, and Interoperability: ASTP/ONC Deregulatory Actions To Unleash Prosperity, includes several significant updates to information blocking compliance provisions. The proposed changes raised red flags because they increase compliance challenges rather than providing the simplification, guidance, and education needed to cut through the complexity of current policy.
The EHR Association, which represents nearly 30 health IT developer companies whose technologies support the vast majority of hospitals and ambulatory providers across the US, has several additional overarching concerns, including ASTP/ONC’s overstated predictions about the burden-reduction outcomes of its proposed changes and its underestimation of the true economic impact of both the current and proposed information blocking policy. The reality is that the proposed changes will increase the administrative burden on software developers and other stakeholders who interact with our community as they determine the best path forward for accessing, exchanging, and using information, and the agency should have conducted and included an economic impact analysis of the implementation costs that will be borne by the industry if the proposed changes are finalized.
In the months prior to the proposed rule’s issuance, ONC leadership made it clear that information blocking enforcement was entering a new era. Dr. Thomas Keane, the National Coordinator for Health IT, has repeatedly emphasized since then that certification status and information blocking behavior are linked and that certification nonconformity will be a powerful enforcement tool.
As EHR developers, we support the intent of the information blocking prohibition: seamless information sharing and nationwide interoperability. However, ONC’s policy is not achieving that intention.
Our analysis of HTI-5’s information blocking proposals identified new ambiguities, administrative requirements, and risks for developers and providers. In addition, the HTI-5 proposed rule downplayed the operational and economic impact for covered actors.
Exacerbating the Already-Complex Infeasibility Exception
Among the proposed changes to the Infeasibility Exception are the removal of the “third party seeking modification use” condition and an increase in the number of alternative manners required before an actor can claim the Manner Exception is exhausted.
Most developers rarely use the Infeasibility Exception, yet HTI-5 explicitly implies misuse. Rather than conclude that their policy is overly complex and difficult for even sophisticated actors to understand, ONC’s language in the proposed rule was inflammatory. Real-world examples would be more helpful for the industry to understand how regulators interpret the exception and better allow stakeholders to react accurately and specifically.
The proposal also overlooks the fundamental operational reality that — as the EHR Association has noted since the infeasibility exception was initially proposed — the 10-business-day response window is simply unworkable. Understanding and scoping a connectivity request, reacting to the original manner requested, and then possibly assessing and negotiating up to three alternative manners cannot be completed within that timeframe. For many health IT developers, especially smaller vendors, the volume of requests alone makes this impossible. We have long recommended amending the regulation to require that the 10-day clock begin after negotiations conclude, not upon receipt of the request.
A Shift Toward Ambiguity in Manner Exception Exhausted
HTI-5 would replace Manner Exception Exhausted wording that actors offer the “same” access, exchange, or use with an “analogous” one. While seemingly minor, this change introduces significant ambiguity. What is “analogous” in one system architecture may not be in another. ONC’s own example implies that all write APIs or filters are inherently analogous, which notably oversimplifies the diversity of technical implementations across the industry.
This ambiguity complicates both compliance and enforcement. OIG and private litigants increasingly cite information blocking exceptions in disputes. Subjective terminology raises the stakes for everyone, particularly in private litigation, where judges frequently lack the requisite technical knowledge to assess the situation accurately. That is why we recommend retaining the current “same” standard.
Putting Innovation at Risk
HTI-5 also proposes that if any entity receives a requested manner of access, exchange, or use, the Manner Exception Exhausted cannot apply. This would discourage technical pilot projects, custom development for healthcare organizations, and early-stage innovation — precisely the activities that advance interoperability. If a single-pilot implementation sets a precedent for all future requesters, developers could be far less willing to experiment.
We strongly recommend to ONC that the Manner Exception Exhausted condition be retained and improved by both clarifying expectations for negotiation and setting more realistic timelines.
New Manner Exception Definitions, Burdens, and Conflicts
HTI-5 attempts to clarify the Manner Exception by introducing new requirements around market rate, contracts of adhesion, and general market value. Unfortunately, these changes create more confusion than clarity and risk slowing processes specific to innovation and contracting.
Fair Market Value (FMV) requirements are u Defining “market rate” as Stark Law FMV would require developers to obtain formal valuations for potentially every product, module, or custom integration. ONC did not estimate the costs of this often-lengthy process, but they would be substantial and would slow innovation, including emerging AI-driven capabilities.
Contract-of-Adhesion language conflicts with other ONC r ONC requires standardized, publicly posted API terms and pricing. Yet HTI-5 suggests that standardized terms may be considered contracts of adhesion. Developers cannot be simultaneously required to publish consistent terms and penalized for using them.
Flexibility for custom work is eliminated. Removing paragraph (a)(2) from the Manner Requested Condition and forcing all arrangements into the Fees and Licensing Exceptions would undermine the fundamental purpose of the Manner Exception. Custom integrations often require custom pricing. Restricting that flexibility would discourage innovation, limit vendors’ flexibility to meet clients’ unique requests, and reduce the availability of unique, mutually beneficial exchange arrangements.
Burden Estimates: A Missing Piece of the Regulatory Puzzle
Our assessment is that the information blocking elements of HTI-5 are, in fact, the opposite of deregulatory, given the burden they would impose. Despite introducing the possibility of new negotiation expectations, valuation requirements, and interpretive standards, ONC provided no economic impact analysis for these proposals in the HTI-5 NPRM. The absence of these estimates is especially concerning, given the disproportionate impact on small developers and the cascading compliance obligations for both providers and third-party partners.
Accurate burden estimates must include:
Expected volume of Manner Exception negotiations
Time and staffing required for multi-step negotiations
Costs of FMV valuations
Impact on innovation, especially AI and custom integrations
Without this analysis, HTI-5 proposals cannot reasonably be considered deregulatory. We suggest that the proposals specific to information blocking not be finalized without additional rulemaking proposals that include economic impact assessments, provide an opportunity for industry input, and verify the accuracy of that analysis.
The EHR Association suggests that the information blocking sections of the HTI-5 NPRM require significant rework to achieve greater clarity, practicality, and accuracy before any related concepts are finalized. We strongly support a regulatory framework that encourages, rather than constrains, innovation and interoperability, but the current proposals are not yet there.
When a hospital’s systems go dark, the danger doesn’t stay in the server room. It moves to the bedside.
That’s not a hypothetical. Recent threat intelligence found that healthcare organizations experienced a cyberattack roughly every 10 hours between January 2025 and February 2026 — the highest incident rate of any sector analyzed. Ransomware alone accounted for nearly 60% of those attacks.
HBO’s “The Pitt” dramatizes exactly what that looks like in practice. When two nearby hospitals are hit by a cyberattack, the fictional Pittsburgh Trauma Medical Center shuts down its connected systems to contain the threat. The digital patient board goes dark. Doctors revert to paper charts. Medication orders are delayed, lab results go missing, and clinicians are left making time-sensitive decisions without the patient histories they depend on. A missed life-threatening diagnosis follows.
The show is fiction. The operational risk it depicts is not.
Downtime Is a Patient Safety Problem
Healthcare has become an attractive target because disruption creates immediate pressure. Attackers understand that hospitals depend on continuous access to data, systems and connected devices. They also understand that downtime can affect patient flow, procedures, pharmacy operations, lab ordering and clinical decision-making.
The healthcare threat intelligence report describes healthcare as a sector with “life-or-death operational dependency,” high-value protected health information, chronic security underinvestment and complex legacy infrastructure. That combination makes hospitals vulnerable to attacks that affect both data security and care delivery.
When systems go down, the effects ripple across the organization. Ambulances may be diverted, procedures may be delayed or canceled, pharmacy systems may become unavailable and clinicians may lose access to electronic health records, prior diagnoses, medication histories, allergies and test results.
In a hospital, those are the foundations of safe, coordinated care. Cyber threats, therefore, carry greater risk than routine workflow interruptions.
“The Pitt” illustrates this dynamic by focusing on the mechanics of downtime. The tension comes from clinicians trying to work without the information and processes they normally rely on. Paper charts replace digital records. Verbal handoffs replace system visibility. Manual steps replace automated safeguards.
This is where healthcare leaders can focus their efforts. One takeaway from the show is not that hospitals should fear a dramatic ransomware scenario. The lesson is that downtime readiness must be treated as part of patient safety planning.
The Weak Points Are Often Familiar
Attackers don’t need sophistication, they need an opening. In healthcare, those openings are rarely exotic. The most common entry point is authentication bypass: flaws that let attackers reach privileged systems without proper credentials. In an environment where dozens of platforms, vendors, contractors and devices all need access to keep care moving, that risk compounds quickly.
The pattern that follows is predictable. A weakness in one layer – an unpatched remote access portal, an overlooked vendor credential, a known vulnerability that never got remediated – creates a failure somewhere else entirely. Lab ordering goes down. Pharmacy systems become unavailable. Imaging access disappears. What began as a security incident becomes a clinical one.
Every tracked vulnerability in our analysis appeared in the CISA Known Exploited Vulnerabilities catalog. Securin’s latest healthcare threat report makes the implication hard to ignore: the sector is overwhelmingly exposed to vulnerabilities we already know how to fix. That’s not a resource problem, it’s a prioritization one. Attackers follow the path of least resistance, and known, unpatched vulnerabilities remain valuable precisely because they persist in operational environments long after they’re publicly disclosed.
The report also found that many healthcare organizations, under pressure to restore operations quickly, continue to pay ransoms. That calculus is understandable at the moment, but it funds the next attack. Healthcare’s combination of operational urgency and chronic security underinvestment has made it the most reliably profitable sector for ransomware operators.
Cyber Resilience Has to Include Clinical Downtime
Preventing intrusions matters, but it’s not enough. The harder question for healthcare leaders is this: when critical systems become unavailable, can your hospital keep delivering care safely?
That question exposes a gap in how most organizations think about cyber risk. Security controls live in the IT department. Downtime procedures, if they exist, often live in a binder somewhere. But the consequences of a cyberattack play out in the ED, the pharmacy, the lab and the OR. Resilience planning has to reflect that.
The vulnerabilities most likely to cause hospital-wide disruption are well known: internet-facing systems, remote access tools, identity and authentication platforms, and administrative interfaces. Addressing those isn’t glamorous work, but leaving them unpatched while investing in more sophisticated defenses is like reinforcing the roof while leaving the front door open.
Operationally, the gap between security and care delivery has to close. Downtime procedures should be practiced with the people who actually deliver care – clinicians, nurses, pharmacists, lab teams – not just tested in an IT tabletop exercise. Teams need to know how to place paper orders, reconcile medications, track patients and hand off information safely when digital systems aren’t available. When systems come back online, the process of restoring and reconciling that information carries its own risks.
The Bedside Is Now Part of the Cyber Risk Model
The most frightening moments in “The Pitt” are not the attack itself. They are the human ones that follow: a missing patient history, a delayed medication order, a clinician making a life-or-death decision with incomplete information. The show resonates because it understands something that healthcare security teams have been trying to communicate for years – that in a hospital, a cyber incident is never just an IT problem.
Healthcare leaders cannot assume every attack will be prevented. The threat intelligence is too consistent, the attack surface too broad and the incentives for attackers too strong. But prevention is only half the mandate. The other half is ensuring that when systems fail -and some will – care teams can keep patients safe anyway.
That requires security fundamentals: closing the known vulnerabilities attackers are already exploiting, enforcing stronger access controls, segmenting networks so one compromised system doesn’t become a hospital-wide crisis. It also requires something harder to operationalize – a genuine integration of cyber resilience into patient safety planning, tested with the people who deliver care, not just the people who manage infrastructure.
When connected systems go dark in a hospital, the consequences move fast. A missed diagnosis. A lost order. A bad handoff. The gap between a cyber incident and a patient safety event can close in minutes.