EHR and Medical Billing Vendor Due Diligence: Which Claims You Can Actually Verify Before You Sign
A practice choosing an EHR or a billing company is asked to trust an organization it knows very little about, on the strength of a demo, a reference list the vendor assembled, and a set of claims nobody independently checks.
Health IT vendors have become very good at presentation. A professional site, a few testimonials and a confident capability list can make almost anything look established. Those things are not useless. They are just weak evidence on their own.
The useful question in every one of these conversations is the same, and it is deliberately unflattering: what can I verify without asking the vendor to reassure me?
It turns out the answer splits cleanly. A few of the claims made to you have a public record behind them that anyone can pull in minutes. Most do not, and those need a completely different approach.
The Claims That Have a Public Registry
Start here, because these are free, fast and decisive.
Certification
If a vendor says its product is certified health IT, that is not a matter of opinion. ONC maintains the Certified Health IT Product List, a public database of every certified product, the specific criteria each one is certified to, the version, the certifying body and the testing results. You can look up a product yourself in about two minutes.
What that gets you is more useful than a yes or no. Certification is granular, so a product may be certified to the criteria you care about, or to a different set entirely. “We are ONC certified” and “we are certified to the criteria your program requires” are different statements, and the registry is where the difference becomes visible.
Corporate and nonprofit status
For any entity claiming nonprofit status, whether a foundation attached to a health system, a patient assistance program or a partner organization, the IRS Tax Exempt Organization Search confirms tax exempt status and, where available, filings such as Form 990 returns.
Most people will not read a tax filing line by line, nor should they have to. But confirming that an organization exists under the name it uses, holds the status it claims and has a filing history is a far stronger starting point than recognizing a logo.
Research and clinical claims
If a vendor or a partner cites a study behind a clinical feature, registered studies appear on ClinicalTrials.gov with sponsor, phase, eligibility criteria, recruiting status and locations, and it shows previous versions of a record when details change.
Not every legitimate piece of research has a trial record, and plenty of good work is years from human testing. The point is knowing what stage a claim actually describes. “Researchers are investigating” is different from “a trial is recruiting,” and “a study showed an effect in animals” is different from “patients saw an improvement.”
The general principle
The FTC’s advice on charitable giving is written for donors, and it transfers to procurement without modification: look the organization up independently rather than relying only on the message, ad or pitch that brought you there. That extra search uncovers a surprising amount, and it costs nothing.
The Claims That Have No Registry At All
This is the larger category, and it includes the two things practices care most about.
“HIPAA compliant”
There is no federal registry of HIPAA-compliant software. Nobody certifies it. The phrase on a sales page is a self-assessment, which is why it should be treated as the beginning of a conversation rather than the end of one.
What is real is the HIPAA Security Rule itself, which requires audit controls that record and examine activity in systems holding protected health information, unique user identification, and application of the minimum necessary standard so people reach what their role requires and no more. Those give you testable questions:
- Are permissions genuinely role-based, and can you see the role definitions rather than a description of them?
- Can you produce an access log for one patient’s chart over a date range, yourself, without asking the vendor?
- What happens at termination? How fast is access removed when someone leaves, and who verifies it happened?
- Is there break the glass access for emergencies, and does using it generate a reviewable record?
- Will they sign a business associate agreement without negotiation, and what does it say about breach notification timelines?
CureMD’s description of its HIPAA-compliant EHR lists role based access controls among its security features, which is the kind of specific a practice can put on a review checklist and test in a demo rather than accept as a slogan.
Patients will never use the phrase “role based access control.” Their version is simpler: who can see my chart? That is the standard the technology has to survive.
Billing performance numbers
Revenue cycle vendors quote collection rates, clean claim rates, denial rates and days in accounts receivable. None of those are audited, defined consistently, or published anywhere you can check.
Two vendors quoting a 98% clean claim rate may be measuring completely different things, because the denominator is a choice. So the questions that matter are definitional before they are numerical:
- How is each metric defined, in writing, in the contract rather than the deck?
- Measured across which book of business? A number from their best specialty tells you nothing about yours.
- What happens to a claim they cannot collect? Written off, returned to you, or worked indefinitely?
- Who owns the data if you leave, in what format, and within how many days?
- References you choose, from their client list, in your specialty, rather than the three they offer.
That last one does more work than the rest combined. A vendor comfortable letting you pick from a full client list is telling you something a reference call cannot.
The Newest Thing You Are Owed: AI Transparency
Healthcare AI can be useful without being visible. A clinician uses it to draft part of a note. Coding software suggests a billing code. A system sorts messages or flags a record. None of that is obvious from the outside.
As of ONC’s HTI-1 rule, a good deal of it is no longer optional to explain. The rule introduced a Decision Support Interventions certification criterion, the first substantial revision to certified clinical decision support requirements since 2012. It defines a Predictive DSI as technology supporting decision making based on algorithms or models that derive relationships from training data and produce a prediction, classification, recommendation, evaluation or analysis. Certified modules must let users access information about how those interventions were designed, developed, trained and evaluated, through a defined set of source attributes: thirteen for evidence based interventions and thirty one for predictive ones.
Read as a buyer rather than a regulator, that is a concrete entitlement. If a predictive feature sits inside a certified EHR, you can ask for the source attributes, including what it was trained on and whether it was evaluated. It is a documented answer you are owed, not a favor you are requesting.
An AI-enabled EHR can genuinely reduce repetitive administrative work, and the practice still has to decide where human review sits. Four questions settle it: can staff tell what was generated automatically, can they edit it, does the system retain a record of changes, and who signs off before generated content is treated as final.
The reason this matters more than it sounds is that automation makes mistakes look authoritative. A typo in a handwritten note looks like a typo. A neatly formatted generated summary can look finished even when something important is missing.
The Middle Ground: A Published Process
Between a public registry and an unverifiable claim sits a third thing, and it is worth recognizing because a lot of good organizations live there.
Some publish their own process and outcomes in a form that outlasts their marketing. A Race Against Blindness, for instance, maintains a page describing how its fundraiser winners are selected and where past announcements are archived. That is a documented process a reader can examine rather than a claim they have to accept.
It is still not independent confirmation, and the useful habit is knowing the difference. A published process is evidence of intent and a thing you can hold an organization to later. A registry entry is evidence a third party checked. Applied to vendors, the same distinction sorts a published uptime page or a security whitepaper (useful, self reported) from a certification listing or an audit report issued by someone else (stronger).
The Mirror: What Your Practice Owes Patients
Everything above is a practice applying the test to its vendors. Patients apply the same test to the practice, usually without the vocabulary.
Nobody praises a practice because they can see that a prescription request is still pending. They do notice when they cannot. Most patient frustration starts in the gaps: a test completed Tuesday with no result showing, a call that was promised, a pharmacy that says it sent a refill request, an insurance portal showing one amount and the bill showing another.
A patient portal that exposes records, results, appointments, messages and billing removes the need to phone the front desk for every update. The version that actually reduces calls is narrower than “we have a portal.” It is status visibility: not only the result when it arrives, but the fact that the order exists and is pending. An absent result and an unplaced order look identical to a patient, and only one of them warrants a phone call.
A Short Due Diligence Checklist
- Look the product up on the certified product list and confirm the specific criteria, not just that a listing exists.
- Ask for the AI source attributes for any predictive feature you will rely on.
- Get every performance metric defined in writing, with the denominator stated.
- Pick your own references from the full client list, in your specialty and size.
- Test the access log yourself during the demo rather than asking whether one exists.
- Read the exit clause first. Data ownership, export format and timeline tell you how the relationship ends before it starts.
- Look up any affiliated entity independently, using the registries above.
The Takeaway
Trust in healthcare technology is not a feeling, it is a research task, and it is a short one. The strongest vendors leave enough behind for a buyer to check what they have been told: a certification listing, a source attribute set, an access log you can run, a contract that defines its own numbers, a client list they are comfortable letting you sample.
None of that guarantees a good outcome. All of it makes blind trust unnecessary, which is the most any buyer should be asking for.
So before the next contract, pick one important claim and see whether you can verify it somewhere other than where you first read it. It takes an afternoon and it tells you a great deal about who you are dealing with.