The audit as a sequence of decisions
- Which department to name first. Known: IT sprawl was the loudest pain, and the person who owns IT is a principal of the group. The question was whether an "IT audit" named on day one reads as a review of a business or of a person. It reads as a person. So the cost work went into the agreement as vendor, software and subscription rationalization inside a general audit, and the IT owner gets a better vendor relationship out of it rather than an investigation. The first document the client's side read did not make an enemy.
- Whose time the audit consumes. Known: the department heads are the constraint. A handful of HR people cover every office, and the finance team is mid-rebuild. The question was how much of the audit can run without scheduled time from them. Nearly all of it. We lead the vendor calls, the contract reviews and the technical due diligence ourselves; leadership time goes to decisions, not discovery.
- The topology question, asked before anything else. Known: the owned offices run one practice-management platform. Not yet answered: whether that is one multi-clinic database or a separate on-premises instance in each office, and one early call described the offices' systems as plural, which the map has to settle. One database means a data foundation in about two weeks. Many instances means about three months and a VPN or replication project before a single row lands in a warehouse. Read from a replica, write only through the API, and verify the API exposes the writes a later build needs. Nothing downstream, the warehouse, the analytics, patient outreach, marketing attribution, is scoped until this is answered.
- Vendor governance before vendor replacement. Known: there was no register of vendors, business associate agreements, service levels or renewal dates. The question was what replacing a vendor buys if the next one arrives into the same absence of governance. Nothing durable. So the frame comes first: standardized due diligence, a BAA on file for every vendor that touches PHI, SLAs, a renewal calendar and one owner, then consolidation and renegotiation. The cloud practice-management evaluation, which would remove the per-location connector cost, waits for the topology answer and the register, so it does not become one more conversion that leaves the cost base intact.
- Patient communications: on infrastructure that signs a BAA, or not at all. Known: the original build brief assumed a general marketing-automation platform, GoHighLevel, would carry patient texting and email. It is not a HIPAA-covered platform on ordinary plans, and its transport runs through Twilio and Mailgun regardless of the plan. The question was whether the convenience of one platform survives contact with PHI. It does not. The patient-communications layer is built on parts that will each sign a BAA: Twilio under a BAA for SMS, HIPAA-capable email, a self-hosted n8n for workflow, and a language model under a BAA. A2P 10DLC carrier registration for every office's number is the go-live bottleneck for any SMS workflow, so it starts in the first cycle.
- Clinical AI: buy and integrate, not build. Known: image review, ambient documentation and charting are a mature vendor class, with a handful of specialist vendors as the names in it. The question was whether any version of building this in-house beats buying it. None does. Buy it, integrate it through the platform's API, and spend the build budget on the integration layer the group will own. Two line items came off the plan and the credibility of everything left on it went up.
- The phones. Known: an outsourced call center handles inbound and after-hours scheduling and bills per call; an AI answering pilot booked more appointments and drew some negative feedback on the interaction itself. The question was what the pilot is measured on. Booking rate and patient sentiment, side by side, office by office, before it expands and before any product decision. A cost decision became an outcome decision.
- Websites and scheduling. Known: two vendors at per-office monthly rates, each office keeping its own brand, doctor-partners resisting centralization, scheduling that depends on fragile plugins. The question was what has to stay local and what does not. The brand stays local. Performance, cost and the scheduler do not. So the call is a templated, brand-flexible framework with each office's identity intact, and a scheduler the group owns instead of a plugin. The doctor-partners can accept that consolidation because the part they care about does not move; whose incentive built the sprawl decides how it gets unwound.
- The money flows with weak controls. Known: payroll about 75 percent computed centrally and 25 percent in the offices before central processing, with reporting in Excel; doctor-partner compensation (draws, true-ups, percentages, bonuses) error-prone with spot checks as the only control; insurance reimbursement landing in 30 to 60 days, which makes accruals hard. The question was which of these can go wrong silently. All three. So the first moves are one office-by-office payroll view, a control on the compensation calculation, and an accrual policy for reimbursement timing. The payroll platform evaluation waits on those, because frustration is not a requirements document.
- Documents and HR. Known: a SharePoint migration run by an underperforming outside partner with no metadata schema, and HR running on email. The question was whether it is cheaper to define the schema now or retrofit it later. Now. The schema (date, version, keywords, owner) is defined during the migration; an HR ticketing platform goes in; two back-office automations, HR onboarding and offboarding and FP&A report assembly, are piloted to show time saved before anything wider is promised.
- Quick wins near day 25 of each cycle. Known: three categories of money nobody owns. The question was what can be fixed before each day-30 report without a decision from leadership. Consolidating duplicate tools, enabling missing security configurations, and stopping payments to vendors paid twice. The day-30 report opens with something already done.
What exists so far, and how the engagement started
The audit is under way under retainer. What exists so far is the current-state map (Attachment A), the vendor-rate register as rates (B), the revenue-cycle analytic the second cycle runs (C), the scorecard template (D), the cycle plan (E), and the tool that opened the door.
The acquisition vetting engine
A hosted scoring rubric: five weighted criteria, six intake questions per target, a composite out of 100 per practice. It runs on practice-level operational and financial inputs only: collection and denial rates, days in accounts receivable, provider tenure and patient concentration, local demographics and payer mix, deferred capital spend and lease term, and open compliance flags. No patient record is ever needed, so it never touches PHI. The weights are placeholders until the client's own buy-box criteria load. Common Ground runs the scoring and keeps running it.
The client buys practices for a living, and a buyer whose profession is judging evidence discounts a capabilities deck and weights a working instance of its own judgment. So there was no pitch. I built the engine, sourced practices that were for sale that week, and scored them.
They buy practices for a living, so I did not pitch them. I scored practices that were for sale that week and let them argue with the output.
The client argued with the output, which was the point. Scoring targets it already held a private opinion about turned a demonstration it could politely admire into a result it had to agree with, correct or dispute. Three of the five sit close enough together that their order is not decisive; the top and bottom are not in doubt. The paper ran on its own clock in parallel: the retainer went through outside counsel before signing.
Keep, replace, integrate, add: the calls and who put each system in
What was faulty in the original logic was not any one choice. It was that every choice was made for one office at a time by the person closest to it, and nobody was ever asked to own the whole. Why it has to change now: the sponsor's exit clock, the compliance exposure that vendor sprawl carries in a HIPAA environment, and two new leaders, a CFO and a CMO, who can carry the changes through their departments.
The three rules the audit runs on
Read from a replica, write only through the platform's API. No protected health information in anything Common Ground hosts. Audit, analysis and recommendation only; any build is its own statement of work, scoped after its gate is answered.
| Function | System | Who put it in, and why | The call |
|---|---|---|---|
| Practice management | One platform across the owned offices | Each acquired office, then a group-wide conversion | Keep. Settle the topology. Switch on the verification module it already ships. |
| Data pipeline and BI | A practice-data connector into BigQuery, then Power BI by hand-written SQL | Analysts, office by office, without a designed backend | Keep the tools. Document the backend. Decide on the connector after the topology. |
| Practice analytics | A per-office reporting subscription | Offices individually | Replace with the intended reseller alternative once the warehouse carries the reports. |
| Finance | Sage, a close automation, an Excel plug-in, Ramp for AP and cards | Previous finance leadership; Ramp under the new CFO, three to four months in | Keep and integrate. Finish Ramp. Write the accrual policy. |
| Payroll | A payroll platform, reporting in Excel | Central finance, a quarter of the calculation left in the offices | Controls first. Evaluate replacement after. |
| HR | A central team, email, no system of record | Grew with the office count; nobody chose email | Add a ticketing queue. HRIS after the queue shows the volume. |
| Documents | SharePoint, mid-migration | An outside partner without a schema | Keep. Define the schema during migration. Bring configuration in-house. |
| Phones | A call center billed per call; an AI answering pilot | Predates the group's scale; the pilot is a vendor trial | Measure booking rate and sentiment before expanding the pilot. |
| Websites and scheduling | WordPress via one vendor, a second agency, plugin scheduling | Each office's original vendor, kept at acquisition | One brand-flexible framework. A scheduler the group owns. |
| Patient communications | Minimal, opt-in by practice | Nobody, yet | A BAA-native stack. Never PHI through a marketing platform. |
| Clinical AI | The vendor class exists; none installed by us | Not yet a group decision | Buy and integrate, not build. |
| IT and network | Per-location connectors and VPN, a long tail of vendors | The IT owner, vendor by vendor, as offices arrived | Govern first, then consolidate. Evaluate a cloud platform after the topology answer. |
| Marketing | A small internal team managing outside vendors | Vendor by vendor; a fractional CMO now owns it | Fit the website framework and scheduler to the CMO's plan. Measure vendors before adding any. |
What it costs to hold the line, and what I watch
The line costs real things. The demonstration was unpaid engineering and analysis with no guarantee of a close; billing for it would have reintroduced the generic-proof problem the approach was built to avoid. Showing a sophisticated buyer a working scoring method hands it something it could approximate; what stays ours is the bench that built it in days rather than weeks, and the running of it. Holding scope to audit-only means saying no, in writing, to mid-cycle build requests; they become statements of work and wait for their gate. Keeping the IT work framed as vendor rationalization rather than an audit of a department costs some directness on day one and buys the department head's cooperation for ninety days.
What I watch. The topology answer, because if the platform turns out to be many instances the roadmap's data timeline moves by months and the cloud-platform evaluation moves up. The doctor-partners' response to the website consolidation, because centralization without proof is how a group like this loses its doctors. The AI answering pilot's sentiment number, not just its booking number. Whether redeploy-not-cut survives the sponsor's clock once the cost-out figures are real. And whether the client's own buy-box criteria load into the engine, because until they do, the five scores are a demonstration of a method, not a recommendation to buy anything.
What it produced
Under retainer; the 90-day audit is under way. The introduction became a signable audit contract in 18 days, after the client argued with a live scoring engine rather than a pitch. The current-state map, the vendor-rate register, the revenue-cycle analytic, the vetting scorecard and the cycle plan are the audit's first attachments. What happens next turns on one open question: whether the practice-management platform is one database or many, which moves the data timeline by months either way.
A slice of the project list
A few related projects.
- Sublime Medical: fractional COO, a cosmetic medical group billing and coding fix (2015)
- A property management launch: advisor seat, Phoenix (2023 to present)
- Modular housing fabrication center: operating model, Arizona (2026)
- Village San Juan: property operations for a homeowners association (2015 to 2022)