Every business eventually faces a version of the same decision: you cannot build it yourself, so you must choose a partner, and the choice will follow you for years. Nowhere is that decision currently sharper than in American healthcare, where insurers are selecting the technology vendors who process the medical data behind billions in government payments, while federal auditors check the results line by line.
The stakes there are extreme, but the selection discipline being forged is useful to any buyer of consequential technology. Watching a regulated industry learn to choose partners under audit pressure is a masterclass in questions the rest of us should have been asking all along.
The market that grew up overnight
For years, vendors in this space sold a simple promise: our software finds more revenue. Health plans are paid according to how ill their members’ records show them to be, so tools that surfaced additional diagnoses from old charts paid for themselves quickly. Selection criteria were correspondingly simple. Who finds the most? Who charges the least per chart?
Then the enforcement era arrived. Government audits published in March 2026 found that at three plans, 81 to 91 percent of sampled high-risk diagnosis codes lacked supporting records. A major insurer paid 117.7 million dollars to settle federal claims over review programmes that added codes while almost never removing wrong ones. Audit teams scaled to roughly two thousand coders working quarterly cycles, with sampled error rates extrapolated across whole contracts.
Overnight, the buying question inverted. The vendor who finds the most is now potentially the vendor who creates the most liability. Buyers started asking a different question: whose output survives inspection? Guides on how to choose a risk adjustment vendor now lead with audit-readiness, evidence trails, and accuracy validation, with cost per chart demoted to a footnote. The inversion took less than two years.
The questions that transfer
Strip away the healthcare specifics and the new selection discipline generalises into five questions worth asking any technology partner whose output you will be accountable for.
Can they show their work, per output? Aggregate accuracy claims are marketing. The healthcare buyers burned worst were the ones who accepted “95 percent accurate” without asking whether any individual result could be traced to its evidence. If your partner’s system produces a conclusion, a score, a flag, a recommendation, ask to see the trail behind one specific example, chosen by you.
Do they correct in both directions? The forensic signature of every recent healthcare enforcement action was one-directional error correction: systems that only ever found mistakes that increased the customer’s revenue. An honest system finds errors both ways. Ask your prospective partner for examples where their product told a customer something the customer did not want to hear. Silence is an answer.
What happens under adversarial review? Not “do you have compliance certifications”, though ask that too, but: walk me through the last time a customer’s regulator, auditor, or opposing counsel examined your output. Vendors seasoned by real scrutiny answer with process. Vendors who have never been tested answer with adjectives.
Who owns the evidence? When the partnership ends, or the audit arrives, can you reconstruct decisions without the vendor’s goodwill? Data portability and retained lineage sound like procurement boilerplate until the day they are the whole ballgame.
Does their incentive match yours over time? The healthcare vendors now winning were structurally paid for accuracy rather than volume. Wherever a partner’s revenue grows with the quantity of their output rather than its quality, you have bought a conflict of interest with a service-level agreement stapled to it.
The deeper shift
What makes the healthcare story more than an industry drama is the pattern it previews. Wherever technology output carries financial or legal consequence, and that is an expanding share of everything, buyers eventually stop purchasing capability and start purchasing defensibility. Finance made that turn after 2008. Data-driven industries made it after GDPR. AI-heavy sectors are making it now, with regulators worldwide demanding explainable, auditable systems.
The buyers who navigate the turn well share a habit: they evaluate partners against the worst day, not the demo day. The demo day shows the dashboard. The worst day is the subpoena, the audit letter, the front-page error. Healthcare buyers now run selection processes that simulate the worst day explicitly, mock audits of vendor output, adversarial sampling, reconstruction drills. It slows procurement by weeks and has saved individual plans from nine-figure exposure.
The takeaway
Choosing a technology partner has always been an act of trust. What the audited industries teach is that trust can be engineered: demanded in evidence trails, tested in adversarial review, and written into incentives. The vendors who resent those demands are telling you something. The vendors who welcome them, who arrive with their receipts organised because they always expected someone to ask, are telling you something better.
In a decade where every consequential industry is acquiring its own version of the auditor with a clipboard, buy from partners who were built for the clipboard. The demo will be slightly less dazzling. The worst day will be survivable. That is the whole trade, and it is a bargain.




