29.1 IT Selection, Acquisition & Maintenance
Key Takeaways
- IT selection is a multi-criteria leadership decision—strategy fit, clinical workflow, interoperability, total cost of ownership, vendor viability, security, and change capacity—not a feature bake-off.
- Acquisition covers RFP/RFI discipline, contracting (data ownership, SLAs, exit, BAAs), implementation funding, and governance of scope, risk, and value realization—not only license purchase.
- Maintenance includes patching, version upgrades, conversions/migrations, interface health, user support, optimization, and planned technology lifecycle replacement.
- Technology lifecycles (introduction → growth → maturity → decline/replacement) drive capital planning; delayed upgrades create security, support, and interoperability debt.
- FACHE executives own portfolio prioritization, clinical engagement, and post-go-live accountability so systems remain safe, usable, and aligned over years—not only at go-live.
IT Selection, Acquisition & Maintenance
Quick Answer: FACHE leaders must know what drives selection of IT systems, how acquisition and contracting protect the organization, and how maintenance, upgrades, conversions, and technology lifecycles sustain value. The Board of Governors outline expects executives who resource and govern systems across their full life—not only champion a go-live date.
Healthcare Technology and Information Management items on selection and maintenance often present a rushed vendor choice, an underfunded upgrade, or a legacy system past vendor support. Strong answers treat IT as a capital and operating program with clinical, financial, and risk consequences. Weak answers treat selection as a demo contest or maintenance as an invisible IT back-office chore.
Why Selection Is an Executive Decision
IT systems shape how clinicians document, how revenue is captured, how patients access care, and how leaders see performance. Choosing poorly locks the organization into years of workarounds, interface cost, and staff frustration. Choosing well without funding optimization still fails. Selection therefore sits at the intersection of strategy, operations, finance, quality, and cybersecurity.
Typical selection triggers include:
- Strategic growth (new service lines, ambulatory network, hospital-at-home)
- Regulatory or payment program requirements (certified EHR, quality reporting, interoperability)
- End-of-life vendor support or unacceptable security risk
- Merger/affiliation requiring platform consolidation
- Chronic operational failure (throughput, denials, documentation burden)
- Clinical safety or quality gaps that technology can address when paired with process redesign
Executives should require a problem statement and success metrics before a product shortlist. “We need a new module because a competitor has one” is not a business case.
Factors That Influence Selection
Selection criteria should be explicit, weighted, and applied consistently. Common factors:
| Factor | Executive questions |
|---|---|
| Strategic alignment | Does this advance access, quality, growth, margin, or equity goals? |
| Clinical / operational workflow fit | Will it reduce friction for the people who do the work every day? |
| Interoperability | How does it connect to EHR, RCM, HIE, devices, and analytics? |
| Evidence and usability | Is there credible performance data and local evaluation design? |
| Total cost of ownership (TCO) | License, implementation, interfaces, training, support, analytics, cyber, upgrades? |
| Vendor viability and roadmap | Financial health, product direction, peer references, support model? |
| Security and privacy | Risk analysis, BAAs, audit rights, incident history, architecture? |
| Change capacity | Can the organization absorb training and workflow change now? |
| Equity and access | Language, disability, broadband, and digital literacy impacts? |
| Exit and data portability | Can we leave with our data in usable form? |
Best-of-breed vs. enterprise suite is a recurring trade-off. Suites can simplify support and integration; best-of-breed may excel in a specialty. Either path requires a funded integration and ownership plan. FACHE scenarios often punish leaders who approve a stand-alone tool without interface budget, clinical champion, or analytics definitions.
Acquisition Process and Contracting
Acquisition is more than signing a quote. Disciplined organizations use stages such as:
- Needs assessment and requirements — clinical, operational, technical, regulatory
- Market scan / RFI — understand options without premature commitment
- RFP and demos — scripted scenarios from real workflows, not vendor slide decks alone
- Reference checks and site visits — peers of similar size and complexity
- Security, legal, and privacy review — parallel to functional scoring
- Total cost and value model — multi-year TCO, benefits, risks, sensitivity analysis
- Negotiation and award — price, SLAs, remedies, data rights, exit, upgrade path
- Implementation governance — steering committee, scope control, readiness gates
Contract terms executives should insist on understanding (with counsel and CIO/CISO input):
- Scope of licenses and users — named vs. concurrent; affiliate expansion; telehealth volumes
- Service levels — uptime, response times, credits, escalation
- Implementation responsibilities — who owns data conversion, interfaces, training, testing
- Data ownership and portability — formats, timelines, fees on termination
- Security obligations and breach cooperation — notice, forensics, liability allocation
- Business associate agreement (BAA) where ePHI is involved
- Price protection and renewal caps — avoid surprise escalation after lock-in
- Audit rights and transparency — usage metrics, performance reports
- Subcontractor and cloud residency — where data lives and who touches it
Underfunding implementation and first-year optimization is a classic failure mode. Capital committees that fund software but not training, super-users, interface monitoring, or downtime procedures buy a license, not a capability.
Upgrades and Conversions
Upgrades keep a current platform current: major version releases, regulatory content updates, security patches, and module enhancements. Conversions (migrations) move from one system or major architecture to another—EHR replacement, cloud migration, archive of legacy data, or consolidation after merger.
Upgrade readiness factors:
- Vendor end-of-support dates and security bulletin criticality
- Regulatory content (coding, quality measures, e-prescribing rules)
- Interface and custom code impact—customizations often break first
- Training delta for clinicians and revenue-cycle staff
- Testing environments and regression test capacity
- Timing relative to peak census, surveys, fiscal close, or flu season
Conversion readiness factors:
- Data mapping quality (identity, allergies, meds, problems, historical results)
- Dual-system period risks (wrong chart, incomplete med lists)
- Cutover vs. phased strategies and command-center staffing
- Legal/medical-record retention and archive access for closed systems
- Revenue-cycle continuity (claims holds, coding, charge capture)
- Explicit success criteria and rollback/contingency plans
Executives should treat major upgrades and conversions as operational events, not pure IT projects. Clinical leaders, HIM, revenue cycle, and communication teams belong on the steering structure. “IT will handle it over a weekend” is a red flag for multi-hospital platforms.
Technology Lifecycles
Every system and device class moves through a lifecycle:
| Stage | Characteristics | Leadership focus |
|---|---|---|
| Introduction | Pilot, limited scale, high uncertainty | Controlled evaluation, stop rules |
| Growth | Expanding adoption, integration demands | Standardization, support model, training |
| Maturity | Core operations rely on it; optimization focus | Reliability, value realization, metric governance |
| Decline / end-of-life | Vendor sunsets support; security risk rises | Replacement planning, data exit, budget |
Lifecycle mismanagement creates technical debt: unsupported operating systems, unpatched medical devices, brittle interfaces, and skill shortages for obsolete platforms. Boards should see multi-year application portfolio roadmaps—what will be optimized, replaced, or retired—linked to capital and cyber risk, not only new shiny projects.
Hardware (workstations, scanners, servers, network gear), clinical devices with software, and cloud subscriptions all have refresh cycles. Deferred refresh can cost more than planned replacement when emergency purchases collide with ransomware exposure or downtime.
Maintenance as Ongoing Operations
Maintenance is the continuous work that keeps systems safe and useful:
- Preventive — patching, database maintenance, certificate renewal, capacity planning
- Corrective — incident response, defect fixes, interface failures
- Adaptive — configuration for new services, order sets, payer rules
- Perfective — usability improvements, report development, workflow optimization
- User support — help desk tiers, clinical informatics on-call, super-user networks
Service management practices (incident, problem, change, release) protect production environments. Change control that is too loose causes outages; change control that is too rigid blocks urgent safety fixes. Executives set the expectation that production change has owners, testing, and communication—including downtime windows coordinated with clinical operations.
Key performance indicators for maintenance maturity include critical patch latency, mean time to restore, backlog of enhancement requests by priority, user satisfaction, interface error rates, and percent of systems within supported versions.
Governance Model for Selection Through Lifecycle
A practical executive model:
- Demand management — intake and prioritization against strategy and capacity
- Architecture and security standards — preferred platforms, identity, integration patterns
- Investment committee — capital/operating decisions with TCO and risk
- Project governance — scope, risk, benefits realization, clinical readiness
- Operations governance — uptime, optimization backlog, vendor performance reviews
- Sunset discipline — funded decommission and data retention plans
Clinical informatics leaders (CMIO/CNIO where present), privacy/security, finance, and operational owners should share accountability. Vendors do not own strategy; they deliver products under contract.
Pitfalls FACHE Leaders Avoid
- Selecting on feature checklists or free dinner demos without scripted workflow scoring
- Ignoring TCO: interfaces, training, analytics, cyber, and upgrade years two through five
- Approving acquisition without BAA, exit clauses, or data portability
- Underfunding conversion quality and dual-system risk mitigation
- Skipping lifecycle replacement until a security incident or vendor shutdown forces crisis spend
- Treating maintenance as optional overhead while demanding 24/7 clinical reliability
- Customizing so heavily that upgrades become unaffordable
- Failing to engage physicians, nurses, and revenue-cycle staff until after contract signature
Executive Decision Lens
When a selection, upgrade, or conversion proposal reaches the C-suite or board, FACHE leaders ask: What operational or strategic problem does this solve, and how will we measure success? What is multi-year TCO and residual risk if we wait? How do security, interoperability, and data exit work? Who owns clinical workflow and benefits realization after go-live? What else must pause so change capacity is real? Selection chooses a partner and a path; acquisition locks commitments; maintenance and lifecycle management determine whether patients and staff actually benefit for the next decade.
A service line wants to buy a specialty system after a vendor demo. Which set of factors BEST reflects FACHE-level IT selection discipline?
Leadership is planning a major EHR version upgrade and a separate conversion of a legacy ancillary system into the enterprise platform. What is the MOST important executive distinction?
A capital committee funds software licenses but refuses training, interface monitoring, and first-year optimization resources. Which outcome is MOST likely?