When organizations evaluate healthcare technology, it’s easy to focus on what they can immediately see. 

  • Does the platform have the features we need?
  • Will it improve clinician efficiency?
  • Can it automate manual work?
  • Does it integrate with our existing systems?

These are all important questions. But after spending much of my career evaluating enterprise software – as an engineer, technology executive, Chief Technology Officer (CTO), and now Chief Information Security Officer (CISO) – I've learned that the most important questions often come much later. 

Early in my career, I assumed software evaluations were primarily about functionality. If a platform solved the business problem, fit within the budget, and users were excited about adopting it, we were well on our way to making a decision. 

evaluating-software

Over time, that changed. 

I’ve now participated in hundreds of software evaluations from both sides of the table. I’ve been the customer asking difficult security questions, and today I’m part of the organization responsible for answering them. One thing I’ve noticed is that the vendors who initially impressed us weren’t always the ones we ultimately trusted. Sometimes, the shift happened during the security review. 

The product demonstration went well. The feature set checked every box. Pricing was competitive. Business stakeholders were excited. Then, we’d start asking different questions. How do you secure administrative access? How do customers monitor activity inside your platform? How do you govern AI? How do you respond when, not if, a security incident occurs? How quickly do security improvements become product improvements? 

Those conversations often told us more about a company than the product demonstration ever could. That’s because technology decisions are ultimately trust decisions. 

Despite the many advantages of adding new tools to their tech stack, practice leaders must recognize the security threats these tools can introduce – and their consequences. You’re not simply choosing software. You’re choosing a company that will become a steward of some of your organization’s most sensitive information.  

Each vendor added increases the potential for sensitive data to be exposed – and for data breaches to erode trust and accumulate hefty fines.

software-security
Security Is More Than Compliance

Healthcare organizations often begin vendor evaluations by asking whether a company is HIPAA-compliant or maintains certifications like SOC 2. 

Those are important questions, and they should absolutely be part of the conversation. But they aren’t the entire conversation. 

Compliance demonstrates that an organization has invested in repeatable processes and independent validation. It doesn’t tell you how security decisions are made. It doesn’t tell you whether security influences product design. And it doesn’t tell you how a company will respond to the next threat that hasn’t been written into a compliance framework yet. 

Security is an operating discipline.  

The strongest organizations I’ve worked with don’t view security as something they achieve. They view it as a matter of continuous improvement.

Security Should Safely Enable Innovation

One of the biggest misconceptions I’ve encountered is that security slows innovation. In practice, strong security can do the opposite.   

The organizations that innovate with the greatest confidence are often those with the strongest security foundations. They’ve built the governance, engineering discipline, and operational processes that allow them to adopt new technologies without creating unnecessary risk. 

Healthcare is changing rapidly. AI is transforming documentation and clinical workflows. Automation is reducing administrative burden. Interoperability is allowing information to move more efficiently across systems. 

These advances all have tremendous potential to improve care. I’ve never believed security exists to say “no.” Our responsibility as security leaders isn’t to slow that progress down; rather, it’s to help organizations adopt these capabilities thoughtfully and responsibly. 

Good security asks, How can we help our customers adopt this safely?”

The Best Security Is Built In

One of my personal goals as a CISO is that customers don’t have to become security experts to use our products safely. 

The best security experiences are often the ones customers barely notice because secure defaults, thoughtful design, and continuous improvements are already built into the platform. 

As our industry evolves, customers will continue to expect stronger identity management, greater visibility into security events, more transparent AI governance, and security controls that reduce risk without increasing complexity. 

The best organizations anticipate where customer expectations are heading and continuously invest in meeting them. They don’t wait until customers have asked for these capabilities to recognize their importance.  

Security should evolve alongside the product – not behind it.

questions
Questions I’d Ask Every Technology Vendor

Whether you’re evaluating a practice management platform, an AI solution, or another healthcare technology partner, I’d encourage every organization to ask a few practical questions. 

How does security influence product decisions? 

Is security involved early in product development, or only after features have already been designed? 

How do you protect customer identities? 

Transparency builds trust. Customers should understand how their environments are being protected and how vendors help them respond to evolving threats.  

How do you approach AI? 

AI presents tremendous opportunities, but organizations should understand how customer data is handled, what governance exists, and how privacy is protected throughout the lifecycle. 

How do you improve security over time? 

The most important question is often the simplest. “How is security reflected in your product roadmap?” 

Every technology company has room to improve. What matters is whether leadership recognizes those opportunities, invests in them, and continually raises the bar for its customers.

looking-ahead
Looking Ahead

Patients trust providers with deeply personal information. Providers trust technology partners to help protect that information. Neither relationship should ever be taken for granted. Healthcare runs on trust.  

As security leaders, we must protect the data to continue earning that trust. 

That means being transparent. Continuously improving. Listening to customers. Building security into products instead of around them and remembering that every product decision is also a trust decision.

A Question Worth Asking

The next time you’re evaluating a technology partner, don’t just ask whether they are secure today.  

Ask yourself this, too: 

“Based on everything I’ve learned about this company, do I believe they’ll be more secure two years from now than they are today?” 

Because you’re not simply choosing a product.  

You’re choosing a partner whose willingness to learn, invest, and improve will matter long after the procurement process ends. 

In healthcare, that’s one of the strongest indicators of trust.

Posted in

Unlock potential for next-level care

You may also like...

Related information and stories

CentralReach Names Joseph Adu as Chief Information Security Officer

December 1, 2025

Adu’s security, technology, and business expertise strengthen the company’s commitment to data security and privacy. Fort Lauderdale, Fla., December 2, 2025 – CentralReach, a leading provider of Autism and IDD…

CentralReach Completes SOC 2 Type 2 Annual Certification for Security Operations and Data Protection Services

April 29, 2025

For the fifth consecutive year, the company receives certification for its best-in-class privacy and security practices. FORT LAUDERDALE, Fla., April 29th, 2025 CentralReach, a leading provider of Autism and IDD…

CentralReach Receives Renewed Attestation of EU-U.S., U.K. Extension, & Swiss-U.S. Data Privacy Verification Requirements

April 8, 2025

TRUSTe attested to CentralReach’s compliance with data privacy framework verification requirements, underscoring the company’s commitment to security and privacy FORT LAUDERDALE, Fla., April 8th, 2025 – CentralReach, the leading provider…