James Lindsey is the IT Strategy and Innovation Principal at Texas Oncology.
I’ve long argued that in healthcare technology, the hard problem is trust, not capability.
Previously, I wrote about ethical AI in healthcare, and how the real question isn’t what technology can do, but rather what it should do. In another article, I argued that the return that matters in healthcare technology is often influence: whether clinicians and patients will actually use what you built.
If the environment around the technology is leaky, both points collapse. That’s why some of the least glamorous line items (identity, segmentation, logging, vendor control and data minimization) in a multi-year technology program determine how effective the rest of the spending was.
Why Independence Does Not Mean Isolation
Whether it’s community oncology, cardiology or another specialty, healthcare isn’t a closed system. Practices can operate dozens or even hundreds of sites, participate in research and run precision-medicine subsidiaries. However, they can still depend on a dense web of business partners, such as distributors, specialty pharmacies, laboratories, cloud platforms, patient engagement tools and the SaaS products those partners use to take orders and manage cases.
Patients don’t parse that web of business relationships. Instead, they experience one relationship: the practice. They focus on how they’re being treated. Data might move through a partner, but in the patient’s mind, the name attached to that data is the practice’s, not the partner’s. To the patient, it’s a matter of trust.
That’s why, when it comes to healthcare technology, leaders need an investment approach that goes beyond what’s in their control. The approach has to include the systems they don’t operate, the identities they don’t issue and so forth. For example, a physician-led practice might have its own proprietary scheduling system, but use a third-party platform for billing. That third-party billing platform isn’t in their control, but if something goes wrong with it, such as a data breach, their practice’s reputation is on the line.
What A Serious Technology Investment Actually Looks Like
So, what does a serious technology investment actually look like? In my experience, the work that matters most doesn’t trace back to a single platform. Rather, it traces back to a series of unfashionable decisions.
For one, leaders should treat identity as a clinical control, not an IT convenience. They should assume that a convincing phone call is all it takes to undo a decade of architecture, and take measures such as implementing privileged access and phishing-resistant authentication.
Leaders should also govern APIs and integrations as products with owners, rather than treating them as side doors.
Additionally, leaders should build technologies, such as ambient documentation, genomic pipelines and patient portals, on foundations that provide transparency and accountability, so that it’s easy to answer questions, including who accessed what, why they accessed it and whether a human was still in the loop.
It’s also vital for leaders to build with continuity and confidentiality in mind. A clinic that stays open while a specialty dataset leaves through a partner system has only solved half the problem.
Finally, leaders should write partner expectations into contracts before an incident arises. When an incident arises, assigning or mentioning expectations can feel like blame.
These steps are what enable practices to roll out technology, such as AI, precision workflows and EHR-agnostic tools without asking patients to underwrite the experiment.
I’ve also written that no company has all the answers on AI adoption. I still believe that’s true. What leaders can choose, however, is sequence. I recommend focusing on security and data stewardship first, then speed.
Innovation That’s Fit For Patient Care
The people who have to use the tools leaders implement need to trust those tools for adoption to hold. Clinicians won’t want to dictate into a tool they don’t trust. Patients won’t want to share their full health histories with a practice they feel is careless with their data. Boards won’t want to keep funding innovation that can’t survive ordinary operational pressure.
In healthcare, new models and new throughput matter. But the quieter obligation is to make those tools fit for patient care. That obligation doesn’t belong only to organizations with the largest balance sheets. It belongs to every practice. Patients need to believe that their data will be treated as seriously as their care.
Security isn’t the opposite of innovation. It’s the part of the investment that lets you look a patient in the eye after the innovation ships.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

