When organizations evaluate healthcare technology, it’s easy to focus on what they can immediately see. 

  • Does the platform have the features we need?
  • Will it improve clinician efficiency?
  • Can it automate manual work?
  • Does it integrate with our existing systems?

These are all important questions. But after spending much of my career evaluating enterprise software – as an engineer, technology executive, Chief Technology Officer (CTO), and now Chief Information Security Officer (CISO) – I've learned that the most important questions often come much later. 

Early in my career, I assumed software evaluations were primarily about functionality. If a platform solved the business problem, fit within the budget, and users were excited about adopting it, we were well on our way to making a decision. 

evaluating-software

Over time, that changed. 

I’ve now participated in hundreds of software evaluations from both sides of the table. I’ve been the customer asking difficult security questions, and today I’m part of the organization responsible for answering them. One thing I’ve noticed is that the vendors who initially impressed us weren’t always the ones we ultimately trusted. Sometimes, the shift happened during the security review. 

The product demonstration had gone well. The feature set checked every box. Pricing was competitive. Business constituents were excited. Then, we’d start asking different questions. How do you secure administrative access? How do customers monitor activity inside your platform? How do you govern AI? How do you respond when, not if, a security incident occurs? How quickly do security improvements become product improvements? 

Those conversations often told us more about a company than the product demonstration ever could. That’s because technology decisions are ultimately trust decisions. 

Despite the many advantages of adding new tools to their tech stack, practice leaders must recognize the security threats they present – and their consequences. You’re not simply choosing software. You’re choosing a company that will become a steward of some of your organization’s most sensitive information.  

Each vendor added increases the potential for sensitive data to be exposed – and for data breaches to erode trust and accumulate hefty fines.

software-security
Security Is More Than Compliance

Healthcare organizations often begin vendor evaluations by asking whether a company is HIPAA-compliant or maintains certifications like SOC 2. 

Those are important questions, and they should absolutely be part of the conversations. But they aren’t the entire conversation. 

Compliance demonstrates that an organization has invested in repeatable processes and independent validation. It doesn’t tell you how security decisions are made. It doesn’t tell you whether security influences product design. And it doesn’t tell you how a company will respond to the next threat that hasn’t been written into a compliance framework yet. 

Security is an operating discipline.  

The strongest organizations I’ve worked with don’t view security as something they achieve. They view it as a matter of continuous improvement.

Security Should Safely Enable Innovation

One of the biggest misconceptions I’ve encountered is that security slows innovation. In practice, strong security can do the opposite.   

The organizations that innovate with the greatest confidence are often those with the strongest security foundations. They’ve built the governance, engineering discipline, and operational processes that allow them to adopt new technologies without creating unnecessary risk. 

Healthcare is changing rapidly.AI is transforming documentation and clinical workflows. Automation is reducing administrative burden. Interoperability is allowing information to move more efficiently across systems. 

These advances all have tremendous potential to improve care. I’ve never believed security exists to say “no.” Our responsibility as security leaders isn’t to slow that progress down; rather, it’s to help organizations adopt these capabilities thoughtfully and responsibly. 

Good security asks, “how can we help our customers adopt this safely?”

The Best Security Is Built In

One of my personal goals as a CISO is that customers don’t have to become security experts to use our products safely. 

The best security experiences are often the ones customers barely notice because secure defaults, thoughtful design, and continuous improvements are already built into the platform. 

As our industry evolves, customers will continue to expect stronger identity management, greater visibility into security events, more transparent AI governance, and security controls that reduce risk without increasing complexity. 

The best organizations anticipate where customer expectations are heading and continuously invest in meeting them. They don’t wait until customers have asked for these capabilities to recognize their importance.  

Security should evolve alongside the product – not behind it.

questions
Questions I’d Ask Every Technology Vendor

Whether you’re evaluating a practice management platform, an AI solution, or another healthcare technology partner, I’d encourage every organization to ask a few practical questions. 

How does security influence product decisions? 

Is security involved early in product development, or only after features have already been designed? 

How do you protect customer identities? 

Transparency builds trust. Customers should understand how their environments are being protected and how vendors help them respond to evolving threats.  

How do you approach AI? 

AI presents tremendous opportunities, but organizations should understand how customer data is handled, what governance exists, and how privacy is protected throughout the lifecycle. 

How do you improve security over time? 

The most important question is often the simplest. “How is security reflected in your product roadmap?” 

Every technology company has room to improve. What matters is whether leadership recognizes those opportunities, invests in them, and continually raises the bar for its customers.

looking-ahead
Looking Ahead

Patients trust providers with deeply personal information. Providers trust technology partners to help protect that information. Neither relationship should ever be taken for granted. Healthcare runs on trust.  

As security leaders, we must protect the data to continue earning that trust.. 

That means being transparent. Continuously improving. Listening to customers. Building security into products instead of around them and remembering that every product decision is also a trust decision.

A Question Worth Asking

The next time you’re evaluating a technology partner, don’t just ask whether they are secure today.  

Ask yourself this, too: 

“Based on everything I’ve learned about this company, do I believe they’ll be more secure two years from now than they are today?” 

Because you’re not simply choosing a product.  

You’re choosing a partner whose willingness to learn, invest, and improve will matter long after the procurement process ends. 

In healthcare, that’s one of the strongest indicators of trust.

Introducing: The Trust Center

Healthcare organizations should have full visibility into any potential technology partner’s security practices. That information should be simply presented and easily accessible.  

At CentralReach, we created the Trust Center to provide a centralized view of the safeguards, standards, and practices that help protect our customers and their data. 

Through the Trust Center, organizations can explore information about:

  • Compliance and independent validation, including HIPAA, SOC 2 Type 2, and TRUSTe 
  • Product security, including audit logging, data security, and integrations 
  • AI security and governance, including our approach to AI monitoring and responsible AI practices 
  • Data security and privacy, including how we protect customer data and follow applicable privacy regulations 
  • Legal resources, including our Data Processing Addendum and Terms of Service 
  • Infrastructure and status monitoring 
  • Security and compliance documentation, with additional reports and materials available through a security review request

The Trust Center also gives organizations the ability to request access to sensitive security documentation and connect with our team when additional information is needed. 

Security isn’t static, and neither is our Trust Center. We’ll continue to update it as our security practices, products, and capabilities evolve, giving customers and prospective customers a clearer view into how we approach the responsibility of protecting their data. 

Visit the CentralReach Trust Center to explore our security, privacy, compliance, AI governance, and related resources.

Posted in

Unlock potential for next-level care

You may also like...

Related information and stories

CentralReach Continues to Scale as Category Leader in Autism and IDD Care Software, Names Chief Sales Officer Dan Freund

July 30, 2026

Company Continues to Grow Revenue More Than 20% and Serves Over 4,600 Customers Fort Lauderdale, Fla., July 30, 2026 - CentralReach, a leading provider of autism and IDD care software, continues to build on strong…

How Helping Hands Family Scaled Documentation Quality and Reduced Administrative Burden Across 50 Clinics

July 28, 2026

As Helping Hands Family grew to 50 clinics, maintaining consistent documentation standards became increasingly complex. Leadership needed a way to reduce the time clinicians spent on administrative tasks while ensuring documentation remained accurate, compliant, and…

5 Use Cases to Automate Clean Claims at Scale

July 23, 2026

Your manual claim processes don’t just slow cash flow. They create room for avoidable, costly errors. Manually generating claims, reviewing accuracy, making corrections, and submitting them to payors requires significant time and coordination. As a result,…