Understand it, align it, act on it, keep it aligned.

Whichever audit you start with, the engagement behind it is laddered. Each stage is fixed-scope and stands on its own. Each one qualifies you for the next, and none of them commits you to the one after it.

The four engagements Understand, align, act, sustain

Four engagements, laddered.

Each engagement is fixed-scope and stands on its own. Each one qualifies you for the next, and none of them commits you to the one after it. Understand the operation first. Then align it. Then act. Then keep it aligned as it changes. What "understand the operation" actually means is set out under each audit above.

ENGAGEMENT 01 · UNDERSTAND

Operational Reality Mapping

We document how your data, reports, workflows, teams, and processes actually connect, working with individual contributors and frontline clinical staff, not only the process owners. End-to-end process with handoffs, owners, dependencies, and decision points. Data element inventory with source, lineage, and manual adjustment points. Report inventory with frequency, audience, purpose, and the duplicates nobody retired. Interface and code-set inventory: HL7 v2 ADT, ORM, ORU and SIU feeds; FHIR R4 endpoints; C-CDA exchange; ICD-10-CM/PCS, CPT/HCPCS, SNOMED CT, LOINC, RxNorm alignment.

What you keep: a documented model of how your organization actually operates, in language your clinical, revenue cycle, IT, and vendor teams can all use.

Deliverable: operational model & current-state findings
ENGAGEMENT 02 · ALIGN

Translation & Vendor Facilitation

We translate operational reality into vendor-facing requirements and sit in the discovery, design, workflow validation, and specification sessions as a translation layer. We help your team ask the right questions, resolve where you and the vendor use different words for the same function, and surface where proposed build does not meet an operational requirement. Where a one-to-one replacement does not exist, we facilitate the alternatives and document what each one costs you downstream, in denial exposure, in clinician minutes, in reporting fidelity.

What you keep: documented requirements, specification requests, named gaps, agreed alternatives, and a decision record with an owner attached to every entry.

Deliverable: operational requirements & decision record
ENGAGEMENT 03 · ACT

Implementation, Adoption & Validation

We stay through implementation to protect operational continuity and confirm the result works. Tracking whether documented requirements are actually being built. Interim workflows and safeguards so clinical operations, charge capture, reporting, and decision-making keep running through cutover. Rebuilding workflows in the new environment with roles and handoffs intact. Validating reports and migrated data field-by-field against the agreed specification. Then testing whether the new process is genuinely being used at the bedside and the desk, investigating why where it is not, and closing the gap.

What you keep: validated workflows and reports, documented decisions and exceptions, adoption findings with corrective actions, and a closeout record of remaining risk.

Deliverable: validated implementation & adoption closeout
ENGAGEMENT 04 · SUSTAIN

Continuity Partnership

An operating model that isn't maintained becomes a document. We stay on as your operational partner, revalidating the model against how the organization is actually running now, pressure-testing proposed changes against it before they're made, and keeping the lateral view current as service lines are acquired, payers change behavior, regulation moves, and the vendor ships new functionality. When something drifts, you find out from the model rather than from the denial report.

What you keep: a living operational model, change-impact reviews on demand, and a standing read on where alignment is starting to slip.

Three audits, two checkpoints, one year. System, security and people, run at month six and month twelve, scoped and priced with the engagement rather than sold afterward. See what each lens tests →

Deliverable: maintained model, six scheduled audit reads & ongoing change assurance
When to start

The mapping engagement is best completed four to six months before a vendor transition process begins, while there is still time to consolidate reports, retire duplicates, remediate the master patient index, and fix inefficiencies rather than carrying them into a new system at full cost. Most organizations start there, because that is where the expensive surprises hide, and decide on the later engagements with the facts in hand rather than at the vendor's table. If you are not facing a transition at all, Engagement 01 still stands alone: the model is worth having whether or not anything is being replaced.

What we measure The continuity scorecard, six domains

The continuity scorecard.

Shared understanding is only real if it is measurable. We baseline these at the start of an engagement and re-read them at close, using your systems and your definitions, not industry averages. Which of them matter is set by your operation, not by us.

Domain 01

Patient Identity & Data Integrity

  • Duplicate record error rateConfirmed duplicates ÷ total MPI records
  • Duplicate creation rateNew duplicates ÷ registration events, by access point
  • Overlay and overlap volumeComingled and cross-facility identity defects
  • Demographic completenessPopulated rate on the fields the matching algorithm actually weights
  • Merge queue ageDays from detection to resolution
Domain 02

Revenue Cycle Continuity

  • Initial and final denial rateSplit clinical vs. technical vs. RFI
  • Denial overturn rateAnd cost per appeal worked
  • DNFB and DNSP daysDischarged not final billed / not submitted
  • Clean claim rateFirst-pass acceptance without manual touch
  • CDM integrityCharge codes without an owner, a mapping, or recent activity
Domain 03

Clinical Workflow Burden

  • Chart closure intervalEncounter close to note signed
  • Time in system per scheduled hourAnd after-hours "pajama time"
  • In-basket volume and turnaroundBy message class and pool
  • Order set utilizationVersus free-text and workaround ordering
  • Workaround incidenceDocumented deviations from designed workflow
Domain 04

Data & Reporting Layer

  • Report inventory and duplicationActive reports, overlapping definitions, orphaned owners
  • Metric definition varianceNumber of live definitions per named KPI
  • Discrete capture rateStructured data vs. scanned documents and free text
  • Extract-to-decision latencyClarity / Caboodle / HealtheIntent refresh to leadership use
  • Report validation coverageShare of load-bearing reports with a tested specification
Domain 05

Interoperability & Interfaces

  • Interface error queue depthBy feed: ADT, ORM, ORU, SIU, DFT
  • Message rejection and retry rateHL7 v2 and FHIR R4 endpoints
  • C-CDA reconciliation rateInbound documents actually reconciled into the chart
  • USCDI element coverageAgainst the version your certification requires
  • External exchange participationTEFCA / QHIN, HIE, payer and registry feeds
Domain 06

Organizational Alignment

  • Decision traceabilityShare of design decisions with a named owner and rationale
  • Change-impact coverageChanges assessed laterally before implementation
  • Requirement realizationDocumented requirements actually built and validated
  • Adoption conformanceDesigned workflow vs. observed workflow, post go-live
  • Downtime readinessTested procedures per department, with last-exercise date

A note on benchmarks. We do not open an engagement by telling you what the industry average is. Industry averages describe organizations that do not operate the way yours does. We baseline your numbers, show you which ones are moving each other, and hold the improvement to targets your leadership sets. The published figures elsewhere on this page are context for why the work matters, not the standard we hold your operation to.

Three audits. Two checkpoints. One year. Then we tell you whether it worked.

Most consulting ends at the deliverable, which leaves the client to decide on its own whether the thing it paid for changed anything. We schedule the audits into the engagement before the work starts and price them with it, rather than selling them afterward. Three lenses, because an implementation can pass one and fail the other two while everybody involved is telling the truth.

Month 0
Engagement close. Targets, definitions, owners and thresholds written down and signed.
Month 6
Checkpoint 01. All three lenses. Was it built, is it safe, are people doing it.
Month 12
Checkpoint 02. All three again. Did it hold, did it drift, did it work.
AUDIT 01

System Audit

"Documented is not the same as built."

Tests whether the configuration actually does what the model says it does, end to end, in evidence rather than in assertion.

  • Sample walkthroughs. Encounters traced across all nine stages, from charge master entry to remit and to the accumulator decision, confirming every system agrees on the same item.
  • The mapping table. Current and reconciled across EHR, OPAIS, accumulator and claim, with a review date and a name on it.
  • Requirement realization. Documented requirements actually built, versus the ones quietly dropped into the build backlog.
  • Reports and interfaces. Load-bearing reports validated against specification. Interface error queues, rejections and retries by feed.
  • Exception queue health. Late charges, unit outliers, drug file mismatches: open volume, age, and whether anyone is working them.
AUDIT 02

Security Audit

"Every operational change is a security change. Nobody treats it that way."

Tests whether the data and the access behind the operating model can be defended. Run against the same map, by the same team, so a security finding can be ranked against an operational one.

  • Risk analysis, refreshed against change. The HIPAA Security Rule risk analysis re-read against what the last six months actually changed, rather than reissued unchanged.
  • Access, identity and provisioning. Who has access to what in the EHR and the reporting layer, how it is granted and removed at hire, transfer and exit, break-glass use, and service accounts nobody owns.
  • PHI egress and data flow. Where protected data physically moves: interfaces, scheduled extracts, vendor feeds, and the spreadsheets people built because the report did not exist.
  • Third-party exposure. Bolt-ons, clearinghouses, registries, split-billing and analytics vendors, checked against actual BAA coverage and against what each one can genuinely see.
  • Downtime and recovery. Procedures tested per department with a last-exercise date, because continuity is a security control before it is an operations one.
AUDIT 03

People Audit

"Most implementations pass the system audit and fail this one."

Tests whether the humans in the eleven roles are actually doing the work the model describes, and whether the organization could survive losing any one of them.

  • Observation at the point of work. What people actually do, watched where they do it, not what a survey says they do.
  • Handoff conformance. Every pass on the map has a named owner, that owner knows they own it, and the pass is being executed as documented.
  • Workaround inventory. The shortcuts people have already invented, which are the fastest and most honest signal that a design does not fit the work.
  • Knowledge concentration. Which steps depend on one person's undocumented memory, and what happens to the chain the week that person leaves.
  • Training reach. Whether instruction reached the people who actually perform the step, and whether it survived the last round of turnover.
Why the security lens is the differentiator

Every operational change is a security change. The two are never assessed by the same people.

Operational consultants do not do security work. Security firms do not do operational work. So the two assessments arrive months apart, written for different readers, and nobody in the building can rank a finding in one against a finding in the other. A charge trigger change and an access provisioning gap land on different desks, in different formats, on different clocks.

We run both against the same map, with the same owners, on one list. A finding gets ranked by what it would actually cost this operation, not by which consultant found it.

Why it is also the way in

The security risk analysis is already required and already budgeted. It is the cheapest door into the whole model.

The work a security audit demands is the work the operating model demands: a data lineage map, an access and identity map, an inventory of every third party touching your data, and a real account of where information moves. Most organizations pay for that discovery twice, in two engagements, a year apart. One engagement produces both.

Where our boundary is. We are not a certifying body. We do not issue HITRUST or SOC 2 attestations and we do not sign them. We do the operational work that makes those reviews survivable, and we say plainly and early when what you need is a certified assessor.

System
Security
People
Month 6Was it built?

Sample walkthroughs, mapping table reconciliation, requirement realization, report and interface validation, exception queue health.

Risk analysis re-read against the six months of change, access and provisioning review, PHI egress map, third-party and BAA coverage, downtime test evidence.

Observation at the point of work, handoff owners confirmed, workaround inventory, knowledge concentration, training reach.

Month 12Did it hold, and did it work?

Recurrence: is the same defect back. Denial rate by cause, DNFB and DNSP days, late charge rate by department, accumulator variance, report count and definition variance.

Did the exposure close or reopen. Access drift since the last review, new extracts and vendors added without review, whether the risk analysis is still current against today's estate.

Did the behavior retain through turnover, a reorg or an acquisition. Adoption conformance against the designed workflow, and which single points of failure remain.

We write the targets down before the work starts, so neither of us can move them afterward. If the numbers did not move, that finding is the deliverable. An audit that can only return good news is not an audit, it is a renewal pitch.

How it is scoped. These are audit reads, not staff augmentation: we are not in your queues day to day, and the cadence between the two checkpoints is yours to set, monthly, quarterly or twice a year depending on volume and risk. All three lenses are scoped, dated and priced with the engagement, and they run whether or not you retain us for anything beyond them. Findings are written to your compliance and internal audit standard so they can be used as evidence rather than filed as opinion, each with a severity, a named owner and a due date. Anything unresolved at month six carries into month twelve with its age attached, so nothing quietly ages out. If a finding says the work did not achieve what we said it would, you get that in writing, with our reasoning, and you are free to do whatever you want with it.

The bill for a missing operating model arrives in the metrics.

None of these numbers are software failures. Every one of them is what happens when decisions get made inside a domain without visibility into what they move everywhere else.

$48.4B1

Net revenue leakage across 2,300+ hospitals in 2025, revenue that was earned and not collected. Up roughly 25% year over year, driven by clinical denials tied to medical necessity and prior authorization.

Kodiak Solutions, 2025 full-year benchmark
22%2

Share of organizations achieving AHIMA's 1% duplicate medical record error rate. A further 29% could not state their duplicate rate at all, the identity layer every downstream system inherits.

AHIMA Patient Identification Survey
$17.4M3

Annual cost of patient misidentification to the average facility in denied claims and lost revenue. Registration behavior, priced at the back end of the revenue cycle.

ECRI Institute, cited by AHIMA
20.3 hrs4

Physician hours per week on indirect care and administration, order entry, documentation, results review, referrals, prior auth, out of a 57.8-hour week. The workflow tax of an operating model nobody designed.

AMA, 2024 physician practice data

And the transitions that are supposed to fix all of this keep getting larger. The VA's Oracle Health modernization now carries a lifecycle estimate near $37 billion, against an original $16 billion contract. Northwell is $1.2B into consolidating more than 30 legacy EHRs across 28 hospitals onto one Epic instance; Trinity Health, $800M across 92 hospitals; UAB, $380M.5 These are not software purchases. They are attempts to buy an operating model, and an EHR cannot sell you one. It can only encode the one you already have, including the parts that don't work.

1 Kodiak Solutions 2025 revenue cycle benchmark (2,300+ hospitals, 350,000+ physicians), reported by Fierce Healthcare, April 2026. Median final denial rate rose 2.5% → 2.7%; average clinical initial denial rate 2.4% → 2.6%; overturn success fell 42.7% → 42.1%.
2 3 AHIMA, A Realistic Approach to Achieving a 1% Duplicate Record Error Rate, citing its 2020 Patient Identification Survey and ECRI Institute patient-identification research.
4 American Medical Association, 2024 physician practice data: 57.8-hour average week: 27.2 hrs direct patient care, 13.0 hrs indirect patient care, 7.3 hrs administrative.
5 Becker's Hospital Review, Most expensive EHR projects underway in 2026, June 2026.

Compliance discipline. This work follows the same HIPAA-aware, BAA-ready discipline as the rest of the NoBullStrategy practice, with PHI handled on a minimum-necessary basis and de-identified or synthetic data used wherever the work allows. A Business Associate Agreement is executed before any protected health information is accessed. NoBullStrategy does not practice medicine and does not provide legal advice; compliance, coding, and legal determinations are confirmed with your counsel and your compliance officer.

Start a Conversation

Every organization is different. That's the whole reason to talk first.

One direct conversation. We'll tell you honestly which engagement fits where you are, what the work looks like, and whether the sequencing makes sense given what you're facing. No deck, no retainer pitch, no software to sell you.