Back to Knowledge Base

Industry GTM Playbooks

In Healthcare, the Security Review Is the Evaluation

The healthcare software sales cycle has one stage that dwarfs the rest. One CEO account puts six to eight months on the technical security assessment alone, and that stage is where the buying decision actually gets settled.

A signed pilot report on a dark desk, dwarfed by a long security questionnaire unrolling beside it.

A clinical lead finishes the pilot and says the thing every vendor wants to hear: this solves a real problem for my team. Then a spreadsheet arrives. Hundreds of rows, sent by someone whose name nobody on the deal has heard before, with no deadline and no context. That person cannot sign the deal. They can stop it, and for the next two quarters they mostly decide its pace.

That spreadsheet is what this article is about. In healthcare software sales, the security review is not a formality that follows the evaluation. It is the evaluation -- the longest stage of the sale, and the stage almost nobody in marketing owns. What follows is the case for treating it as go-to-market work, then a procedure for building the file that gets a vendor through it: what goes in, how to assemble it from your own deal history, and how to get the material out of teams that do not report to you.

I write this as a product marketing department of one, responsible for seventeen products. I used to treat that spreadsheet as admin, something to hand to whoever had capacity and answer between other work while the real go-to-market thinking happened elsewhere. The real thinking was needed in the spreadsheet.

A hospital's suspicion of a vendor is not a mood. Under the HIPAA rules, a software company that handles protected health information on behalf of a health system becomes a business associate, and from that point a defined set of the rules stops being the health system's problem alone and applies to the vendor directly. The health system must obtain written assurances first, in the form of a business associate agreement, before disclosing protected health information. HHS Office for Civil Rights The buyer carries real exposure for a decision about someone else's software, so the caution is self-interested.

That is the legal half of the suspicion. The measured half is sharper. A study in Health and Technology coded HHS breach filings and found that of 831 healthcare ransomware incidents, 33.8% involved a business associate. The author calls it a hub-and-spoke risk model: one compromised vendor propagates across many providers. Munoz Cornejo, Health and Technology, December 2025 That figure is a share of past incidents, not a forecast about any one supplier. It does not say a third of vendors cause breaches; it says that when ransomware reaches a provider, a vendor was in the path a third of the time. Seen from the reviewer's chair, that is reason enough to treat every new supplier as another door into the hospital, while the clinical benefit sits in somebody else's column.

A hospital at the centre of a wheel, with one darkened vendor spoke spreading outward.
One compromised vendor. Many exposed providers.

Six to eight months, after the product has won

The scale of the review is easy to underestimate from a marketing plan. Rock Health surveyed 85 digital health founders in 2017 and interviewed more than fifteen startup chief executives and health enterprise leaders. In one of those interviews, a CEO laid out the timeline for contracting with a health plan -- one CEO's account from 2017, and a payer rather than a hospital, so treat it as the shape of the cycle rather than a benchmark. At least 18 months in total: six months generating interest or a pilot, a couple of months finding an executive sponsor, six to eight months for a technical security assessment, then four to six months for contracting. Rock Health, August 2017

Six to eight months. On the security assessment alone. That single stage runs longer than many companies' entire enterprise sales cycle, and it begins after the product has already won on merit. Through those months, the product's only competition is the risk of doing nothing.

An 18 month timeline printed on a sheet, with the security assessment band shaded darkest.
Six to eight months of it is one stage.

The buyer's clinicians ask for assurance first

Clinicians show the same instinct, asking for assurance before capability, and on the clinical side it is measured. The American Medical Association found that 47% of physicians ranked increased oversight as the number one action needed to increase their trust in adopting AI tools. AMA, February 2025 By the AMA's 2026 survey, 81% of physicians reported using AI in practice, and 88% named safety and efficacy validation as critical. AMA, March 2026

Adoption is already high, and the ask is still assurance. A messaging strategy that leads with capability is answering a question these buyers have largely stopped asking.

Two columns on a printed sheet, assurances stacked higher than capabilities.
Adoption is high. Assurance is still the ask.

What a certificate buys, and what it does not

The buyers do not think the process works either. The Health 3rd Party Trust Initiative, whose council includes large health systems and payers, published survey findings that 60% of covered entities and 72% of their vendors believe current third-party risk management practices are not effective, and 68% and 79% respectively called the process inefficient. Health3PT, July 2023

One finding in that survey matters most for anyone planning a certification budget: 47% of vendors reported customers unwilling to accept third-party validated assessments and certifications in place of their own proprietary questionnaires. A certificate shortens some conversations and does nothing to others. Worth knowing before a year of budget goes into one on the assumption that it removes the gate.

The defence file

The reviewer is answering two questions. Does this product do what it claims with the data it claims, and could I defend having said yes if this goes wrong in eighteen months. The second question is the one nobody prepares for, and the defence file is what answers it: the full set of documents a reviewer needs, readable without a meeting and without the vendor in the room.

The audit that produces the file is a non-champion question audit, and it starts from evidence rather than from imagination.

  1. Pull the last three healthcare deals out of the CRM and the shared inbox. Three deals are enough to show repetition without turning collection into a project.
  2. Collect every question that came from someone who was not the clinical champion -- security, privacy, IT, legal, procurement -- verbatim, in one place. Verbatim matters, because paraphrase smooths away the exact wording the next reviewer will use again.
  3. Mark each question with one of three answers: a document answers this and a stranger could read it without a meeting; an answer exists but lives in somebody's head or a thread; no answer exists. The three marks route to three different kinds of work.

The second category is the file that does not exist yet, and filling it is mostly writing down what the company already knows.

The third category needs splitting, and this is where a marketing project can quietly become dishonest. Sometimes there is no answer because nobody wrote it down. Sometimes there is no answer because the control does not exist -- log retention, encryption at rest, a tested incident process, someone who actually holds the pager. The first is a documentation gap, and closing it is most of what the assembly time below buys. The second is engineering work, and no document substitutes for it. A file that papers over a missing control does not fail in the review. It fails in month six, in front of the person who signed for it, which is a worse day for everyone than a real gap declared in month one.

A shelf of labelled folders, three of them empty, on a dark desk.
Every question a non-champion asked, and whether a document answers it.

A complete file tends to hold six things. The data map: what is collected, where it travels, who can see it, how long it is kept. The executed business associate agreement, ready to send rather than ready to draft. The certification with its scope statement, saying plainly what it covers and what it does not. The last twelve months of questionnaire answers, kept as one living document instead of re-answered each time. The incident path: what happens on a breach, who is notified, and inside what timeline. And a named person who answers security questions, with a stated response time.

The named person is unglamorous and moves deals. In the same Rock Health survey, founders rated finding the right buyer the hardest stage of the sale. Rock Health, August 2017 A named responder on the vendor side removes the mirror image of that problem, which is the champion not knowing who to ask.

Written for someone who reads it alone

A defence file is read without the vendor present, by someone who did not attend the demo and has no stake in the clinical benefit. So it is written in plain claims, scoped honestly, with the limits stated by the vendor rather than discovered by the reviewer. Stating a limit feels risky, and it works the other way round. A reviewer who finds an unstated limit stops trusting the rest of the document. A reviewer who sees limits declared has something they can take to their own committee.

This is the same constraint as a message that has to survive being repeated by someone who is not you, and the same room described in the piece on buying committees, where the champion needs a document that settles an argument rather than one that flatters its reader. Healthcare adds one thing: the person reading has a professional obligation, and in some cases a legal one.

A document with its limitations written plainly in the margin in amber ink.
State the limit before the reviewer finds it.

Three weeks against eight months

Assembling the file is mostly collection -- two to three weeks of one person's time if the answers exist and only need finding, more the moment the audit turns up a missing control. Against that sits the six to eight months of security assessment in the Rock Health account. Nobody has published a real figure for how much a file like this compresses that stage, so anyone quoting a percentage is guessing. What can be counted is narrower: the review rounds that happened only because an answer was somewhere in the company and nobody could find it. Those rounds are visible in any deal history, and they are the ones the file removes.

The file also holds its value. Every deal after the first inherits it, which is the opposite of a persona deck rebuilt each quarter and opened by nobody. The honest limit: the file does not remove the review itself -- 47% of vendors report institutions insisting on their own questionnaires regardless -- it changes how long each round takes and how many rounds there are.

Twelve blocks in a row with eight shaded for security review, against a small three-week card.
The file is assembled once. The review is faced every deal.

The material belongs to people who do not report to you

Security owns the controls, legal owns the agreement, engineering owns the data map, and none of them answer to marketing. A PMM asking three functions for documentation is asking a favour in a quarter where everyone is already behind. Two things make the request land.

Arrive with the questions instead of the request. A list of verbatim questions real buyers asked, sorted by how often they came up, is a different conversation from asking security to go and write something. Most of the answers already exist somewhere; the list never has.

Hand back the reduction. Security answers the same handful of questions every quarter, in email, one deal at a time, and the file takes that work off them permanently. Say so out loud in the first conversation. For a revenue leader who wants the quarter back, the accurate framing is that this is the one piece of go-to-market work that does not decay. A campaign expires. The answer to how long audit logs are retained does not.

If healthcare is a market and not an account

If the product never touches protected health information, most of this falls away and the cycle looks like ordinary B2B. If the buyer is an individual clinician paying personally, there is no review to prepare for. If the company has one healthcare deal and no plan to pursue more, answer that one questionnaire well and move on, because a reusable file is premature. I think the structure would transfer to other regulated markets, and the specifics here are HIPAA-shaped, so I would rebuild the file rather than reuse it.

The file earns its cost when healthcare is a market, and deals are visibly stopping after the clinical yes. A team that runs this audit is not making an asset because someone asked for one. It is working the longest stage of its own sales cycle, the stage where the deal is actually decided. The review is the evaluation. Build the file that passes it.

Source ledger

References used in this article

HHS Office for Civil Rights - "Business Associates"Tier 1 - the regulator's own guidance, primary source.Munoz Cornejo, G. - "Third-party risk in U.S. health care ransomware incidents: business associate involvement and breach size"Tier 1 - peer-reviewed journal article, open access, built on regulator data.Rock Health - "Streamlining enterprise sales in digital health"Tier 2 - established sector research firm, named methodology, first-person account clearly attributed.American Medical Association - "2 in 3 physicians are using health AI - up 78% from 2023"Tier 1 - the professional body's own survey reporting.American Medical Association - "AMA: AI usage among doctors doubles as confidence in technology grows"Tier 1 - the professional body's own dated press release.Health3PT - "Health3PT Releases Blueprint for Third Party Risk Management"Tier 2 - industry initiative whose council includes large health systems and payers. The article attributes the findings to Health3PT by name rather than presenting them as neutral industry data.

Run the non-champion question audit on your last three healthcare deals, then build what it exposes.

Explore the Knowledge Base