Executive ← Insights

Common Healthcare IT Procurement Mistakes: A Governance and Risk Guide for Executives

When a healthcare technology investment fails, the post-mortem almost never blames the software itself. It blames the process that selected it. The most damaging procurement failures in hospitals and health systems are governance failures — decisions made in the wrong order, by the wrong people, on the basis of the wrong numbers. These mistakes are predictable, and because they are predictable, they are avoidable. This article sets out the procurement pitfalls that most often turn a promising system into a budget crisis or a clinical liability, and the governance safeguards that prevent them. It is written for boards and executive teams in the United States, the European Union, and the United Kingdom, where the regulatory context differs but the underlying discipline of good procurement does not.

Mistake 1: Evaluating vendors before defining requirements

The single most common procurement error happens before anyone signs anything: the organization begins looking at vendors before it has agreed what it actually needs. Executives attend polished demonstrations, fall in love with a best-case workflow, and then work backwards to justify a system that was never measured against a defined set of requirements. The result is a decision anchored to a sales narrative rather than to operational reality.

The evidence that this matters is long-standing. In the foundational Standish Group CHAOS analysis of IT project outcomes, the three leading causes of project failure cited by IT executives were lack of user input (12.8%), incomplete requirements and specifications (12.3%), and changing requirements and specifications (11.8%) [4] — together the dominant reasons projects miss their objectives. In practice, the requirements definition and needs assessment that precede a request for proposal are not paperwork; they are the instrument by which vendors are later evaluated and held to account. Without them, an evaluation has no objective yardstick and defaults to whoever demos best.

The governance safeguard is simple to state and harder to enforce: define requirements first, in writing, ranked into "must-have" and "desirable," and only then invite vendors to respond to them. In our experience, organizations that shortlist just three to four finalists against pre-agreed weighted criteria make markedly better decisions than those that let the market shape their thinking.

Mistake 2: Letting IT drive a decision that requires clinical ownership

Healthcare technology is not a back-office purchase. A clinical system reshapes how physicians, nurses, and pharmacists work, and a decision made without their ownership will be resisted at the point of care no matter how sound the technology. Too many organizations treat system selection as an IT project with clinical "input," when it should be a clinically owned decision with IT validation.

The consequences of getting this wrong are now well documented. In its EHR Implementations 2025 analysis, KLAS Research found that just 38% of organizations reported their post-pandemic implementations "hit the mark," while 62% said their implementations either missed the mark significantly or had areas needing improvement [1]. The organizations that succeed consistently share one trait: a formal governance structure with defined decision rights, executive sponsorship, and physician and nursing leadership embedded from the start rather than consulted at the end.

The safeguard is a documented governance charter that names who owns the decision. Clinicians own requirements, demo review, and pilot design; IT validates technical feasibility and security; finance stress-tests the cost model. A named C-suite sponsor carries the project for its full duration. Where those decision rights are ambiguous, projects drift, and accountability evaporates the moment problems surface.

Mistake 3: Letting a preferred or incumbent vendor shape the evaluation criteria

A subtler governance failure is allowing a favored vendor — often the incumbent — to influence the criteria against which all vendors are judged. This can happen innocently: the incumbent knows your environment, helps you "scope" the requirement, and in doing so quietly writes the specification around their own product's strengths and competitors' weaknesses. The evaluation then looks rigorous while being rigged.

The safeguard is to insulate the criteria-setting process from any commercial party. Requirements and weighted scoring should be finalized and signed off by the internal governance committee before vendors are engaged, and material help with specification drafting should come from independent advisors, not from bidders. A transparent, auditable evaluation process is also increasingly a compliance expectation in public procurement — for example, NHS organizations in the United Kingdom are directed to buy digital products through structured framework agreements with published, standardized selection processes precisely to reduce this risk.

Mistake 4: Underestimating total cost of ownership

Underestimating total cost of ownership (TCO) is one of the most damaging and most common procurement errors. Organizations fixate on the initial license or subscription fee while underweighting the costs that actually dominate a large deployment: implementation and configuration services, interface and integration development, staff training and change management, ongoing support and maintenance, and — the line most often omitted entirely — the productivity loss during the transition period. In our experience, implementation services alone frequently run several times the annual software fee on complex projects, and the license is only a minority of the true multi-year cost.

The real-world cases are sobering and public. NYC Health + Hospitals signed its Epic EHR contract in January 2013 and reported investing $764 million over six years to implement and maintain it — a figure many multiples larger than the underlying software contract [3]. The University of Vermont Health Network said its $151.7 million Epic implementation was partially responsible for a $10 million operating loss in the first quarter of 2020, as costs exceeded expectations and physician productivity fell while clinicians adjusted to the new system [2]. Other systems have publicly attributed multimillion-dollar operating losses to EHR go-lives, including Ector County Health District (which blamed its $55 million Cerner implementation, in part, for financial losses and a Fitch bond downgrade) and Centra Health (a $65 million Cerner project) [2]. In every case, the technology was capable; the financial pain came from costs that were foreseeable but not budgeted.

The safeguard is a business case that models five-year costs, not year-one, and that treats productivity loss and internal staff time as real line items. CaboLabs advises clients to carry a contingency budget of at least fifteen to twenty percent of implementation cost for the scope changes that predictably emerge once implementation begins; this figure reflects our experience across engagements rather than a single published benchmark, but the principle — budget for the surprises you know are coming — is universal.

Mistake 5: Neglecting the contract

Many organizations invest months in selecting a system and then sign the vendor's standard agreement with minimal legal review — accepting terms drafted to favor the vendor in every dispute scenario. The contract is where leverage is either captured or surrendered, and leverage is never greater than in the moment before signing.

The clauses that most reward negotiation are consistent across jurisdictions: data ownership and export rights (you should own your data and be able to extract it in a usable format at any time); termination provisions and transition assistance; service-level definitions with meaningful remedies rather than token service credits; price-escalation caps on renewals and add-ons; and a precise definition of what constitutes the licensed product versus billable customization. Engaging experienced healthcare IT legal counsel before signing is an investment that almost always pays for itself, particularly as regulation raises the stakes: the EU's European Health Data Space will require contractual attention to interoperability, logging, data quality, and standards-update responsibilities in supplier agreements, making early legal and procurement alignment a practical necessity rather than a nicety.

Mistake 6: Ignoring implementation reality — clinicians, timelines, and data migration

Three related mistakes cluster at the point where procurement meets implementation. The first is insufficient clinician and end-user involvement in requirements gathering, which produces systems that are technically correct but clinically unusable. The second is accepting an unrealistic implementation timeline — often one driven by budget cycles or political pressure rather than operational readiness. The third is failing to plan for data migration and interoperability up front, treating the movement of legacy records and the building of interfaces as afterthoughts rather than as central, costed workstreams.

The safeguard for all three is due diligence before commitment. Reference checks and site visits with comparable organizations — matched by size, specialty, and geography — surface the implementation risks that no demo will reveal; pairing your clinicians and managers with their counterparts at a live site is one of the most valuable things a selection team can do. Data migration scope and interface requirements should be defined and priced during procurement, not discovered during go-live, and the implementation timeline should be tested against the readiness of the organization rather than the ambitions of the sponsor.

Common MistakeGovernance Safeguard
Evaluating vendors before requirements are definedWritten, ranked requirements signed off before any vendor is engaged
IT-led decision without clinical ownershipGovernance charter with clinical decision rights and a named C-suite sponsor
Preferred/incumbent vendor shapes the criteriaCriteria finalized by an internal committee; independent advice on specification
Focusing on license fee aloneFive-year TCO model including training, interfaces, support, and productivity loss
Signing the vendor's standard contractNegotiated data-export, termination, SLA, and price-escalation terms with expert counsel
Unrealistic timelines and unplanned data migrationReference-site due diligence; migration and interfaces scoped and costed up front

Interoperability and open standards as a procurement criterion — and how CaboLabs helps

One requirement deserves explicit treatment in any modern healthcare procurement: the ability to exchange and reuse data on open standards. This is no longer a technical preference; it is a business and compliance requirement, and it differs by region. In the United States, the ONC (ASTP) HTI-1 final rule advances certified health IT toward standardized, FHIR-based interoperability and algorithm transparency [5]. In the European Union, the European Health Data Space Regulation (Regulation (EU) 2025/327) establishes mandatory interoperability and logging requirements for EHR systems, with the first cross-border primary-use exchange of priority data — patient summaries, ePrescriptions and eDispensations via MyHealth@EU — becoming mandatory in all Member States from 26 March 2029 [6]. In the United Kingdom, NHS England mandates a consistent approach to interoperability through the UK Core FHIR standard, published under section 250 of the Health and Social Care Act 2012 [7].

For executives, the governance point is straightforward: procurement criteria should require that a system's data can leave it as easily as it enters, on recognized open standards such as HL7 FHIR and openEHR. This protects the organization's negotiating position, reduces future switching costs, and keeps the institution on the right side of a tightening regulatory landscape. CaboLabs advises US, EU, and UK clients on embedding these standards-based requirements into procurement — from RFP criteria through contract clauses — and builds Atomik, an openEHR-native clinical data repository, precisely so that health data remains the property and the asset of the provider rather than of any single vendor. Good procurement governance and open standards are two expressions of the same principle: keep control of your data, your costs, and your options.

References & Verifiable Sources

  1. KLAS Research: What Is Needed for a Successful EHR Implementation? (KLAS Arch Collaborative "EHR Implementations 2025" data showing just 38% of organizations said their post-pandemic implementations "hit the mark" while 62% missed the mark or needed improvement — supporting the claim that most implementations fall short and that governance and clinical ownership drive success.)
  2. Becker's Hospital Review: 6 health systems that blamed Epic, Cerner EHR installs for losing millions (Documents real cost-overrun cases including University of Vermont's $151.7M Epic implementation and associated $10M Q1 2020 operating loss and productivity drop, Ector County's $55M Cerner project and Fitch bond downgrade, and Centra Health's $65M Cerner go-live — supporting the TCO-underestimation argument with named cases.)
  3. Healthcare IT News: NYC Health + Hospitals adds $289 million revenue cycle system to Epic EHR (Reports the $764 million Epic EHR rollout as a multi-year investment, illustrating how large the true cost of a clinical system is versus its headline license — supporting the five-year TCO recommendation.)
  4. Standish Group CHAOS Report (cited in academic literature, arXiv): Project Success in Agile Development Projects (Cites the Standish CHAOS finding that the leading causes of IT project failure were lack of user input (12.8%), incomplete requirements (12.3%), and changing requirements (11.8%) — supporting the claim that requirements definition and user involvement are decisive.)
  5. ONC / ASTP (HealthIT.gov): HTI-1 Final Rule (Official US regulatory source confirming the HTI-1 rule's advancement of certified health IT interoperability, standards, and algorithm transparency — supporting the US regulatory driver for interoperability as a procurement criterion.)
  6. European Commission: European Health Data Space Regulation (EHDS) (Official EU source confirming mandatory interoperability and security requirements for EHR systems, and the March 2029 primary-use application milestone — supporting the EU regulatory driver.)
  7. NHS England Digital: DAPB4020: UK Core FHIR Release 4 Governance (Official NHS England information standard, published under section 250 of the Health and Social Care Act 2012, mandating a consistent FHIR UK Core approach to interoperability — supporting the UK regulatory driver.)

Do you have any questions?

Let us know how we can help you.

Company CaboLabs Health Informatics
Address Juan Paullier 995, Montevideo, Uruguay
Phone +598 99 043 145