đź‘‹ Hi, I'm Markus, your AI assistant that can help explore PrepMD solutions. Dismiss
Skip to main content

The Clinic You Own but Don’t Control

Why the cardiac device clinic violates nearly every assumption health IT is built on. Part 1 of 2.

By Jack Collier, CTO, PrepMD

As a CIO, you are accountable for patient data that lives in systems you did not build, cannot consolidate, and only partly govern. Every instinct in health IT works to keep that from happening. One program in your hospital has been running this way for years, and it carries your name on every bit of the risk: the cardiac device clinic.

It sits inside your walls, runs on your network, and carries your name on its liability. And it quietly violates nearly every assumption on that list. Most leaders never learn how different it is until something forces the question: a security review, a billing audit, a malpractice claim, a vendor outage. This is the version you would rather read first.

What you assume about your systems What the device clinic actually does
One or two platforms, one login Four separate vendor ecosystems, no shared interface
Your PHI sits where you can point to it Some data lives overseas, reached by offshore staff, with little visibility into either
An unread result is a backlog to clear An unreviewed transmission may put patient care at risk and create medicolegal exposure
Every result follows an order and a charge Data arrives unsolicited, with no order, on its own schedule
No data is a neutral, safe state A silent patient looks monitored while being invisible

Four ecosystems, no shared login

Every other part of your hospital pushes toward consolidation. The device clinic cannot follow. The four major manufacturers each run their own remote-monitoring platform (Medtronic on CareLink, Abbott on Merlin.net, Boston Scientific on LATITUDE, Biotronik on Home Monitoring), and none of them interoperate. A single clinic logs into all four every day, each with its own hardware, portal, and data format. Each manufacturer has developed its own remote monitoring ecosystem, optimized for its devices. As a result, these platforms do not natively interoperate, and absent a deliberate effort to consolidate information, your clinic staff must work across all four.

And the leverage you’re used to is different. When a SaaS vendor wants your business, they complete your security questionnaire, sign your BAA, and answer to your third-party risk process. Cardiac device manufacturers operate differently. These are FDA-regulated global medical device companies with established platforms and governance models. The result is that health systems often find themselves responsible for multiple parallel ecosystems they did not design, cannot consolidate on their own, and only partially govern through traditional vendor management processes.

Your patients’ data may not live where you think

Most CIOs assume PHI sits in infrastructure they can locate. For device data, that assumption often breaks. There is no federal data-residency requirement for PHI in the United States, and HIPAA permits storage and access abroad as long as a business associate agreement is in place. Many major manufacturers host their remote-monitoring data on servers outside the U.S., and offshore staff may be the ones reaching it. Where the data sits and who can access it are two different questions, and for device data you may have real visibility into neither. The risk, though, does not travel with the data. If something goes wrong, the covered entity, meaning you, still owns it.

The unread inbox is a liability, not a backlog

A single clinic can receive thousands of remote transmissions in a month, and most are noise. In one large real-world analysis, roughly three quarters of device alerts proved non-actionable, and only about 7 percent led to a follow-up visit. But a handful signal a patient in a dangerous rhythm right now, and staff have to separate that signal from the noise every single day while the volume only climbs.

Here is the part that should get a risk officer’s attention: an unreviewed transmission that later proves clinically significant is a documented medicolegal exposure. The data is already in your systems, timestamped. If an alert goes unactioned and the patient has an event, the unread inbox is discoverable. The clock starts the moment the data arrives, whether or not anyone has looked.

It breaks the order-to-result model your EHR is built on

Your integration layer assumes a tidy sequence: appointment, then order, then result, then charge, with each result tied to something a clinician requested. Device data honors none of it. Transmissions arrive unscheduled and unsolicited, at all hours, with no order behind them. Billing follows device type and calendar rules rather than a one-to-one match with each result. Forcing this into a standard EHR workflow is like running a river through a turnstile.

The most dangerous patient is the one you hear nothing from

Alert triage is about handling the data that arrives. The harder problem is the data that does not. A meaningful share of enrolled patients quietly stop transmitting, whether from a dead transmitter, a move, or a changed router, and still appear “monitored” in the system. Across most of your hospital, no data is a neutral state. Here, silence looks identical to a healthy patient, right up until it is not. You have to actively chase the absence of data, which is at once a safety gap and a billing gap.

Iceberg diagram contrasting what leadership sees about the cardiac device clinic — a once-a-year in-person visit and one clean line in the EHR, above the waterline — with what actually runs it below the surface: data accessed offshore, unreviewed transmissions, patients who stop transmitting, and no clear owner or budget.

So what?

These are real problems, and they need real management, not reassurance. The same clinic that generates this risk is also, run well, one of the highest-value service lines in the hospital. You cannot manage what you have never been shown, and most of these realities stay invisible until they force their way into view. What does it take to turn the list around — to get ahead of the risk these differences create and transform that same clinic into one of your health system’s strongest performers? That’s the question every health system should be asking.

Coming next: Taking Control of the Clinic You Own