VENDOR EVALUATION / RESEARCH NOTE

What should our team request from a healthcare AI vendor?

Request evidence for the workflow and release your team plans to use: who may request an action, which record confirms the promised milestone, who owns unfinished work, and how staff review uncertain outcomes. Ask for the artifact, its scope and version, and a person who can explain it. Record vendor claims separately from supplied evidence and your own review. Use those records to prepare a purchasing discussion; this guide does not score or independently verify a vendor.

INTENDED READER

Procurement with security and operations

AUTHOR

Access Red Team

UPDATED

12 September 2026

EVIDENCE

Proposed review question

THE BUYING QUESTION

Ask what the evidence covers and who can explain it.

Define the purchase decision.

Write down the workflow, site, connector and release the evidence is supposed to cover. Clarify whether your team is evaluating a product, accepting a pilot, or expanding a configured service. Evidence from another setting may be useful background; record the differences your implementation owners still need to resolve.

Identify the people who can answer the question and the people who must accept the result. A procurement owner can collect artifacts, while security, integration and patient-access owners interpret the parts they are responsible for. The six acceptance questions provide a shared starting point.

Map questions to artifacts.

These are Access Red Team's proposed review questions. Adapt the requested artifact to your workflow and approved evidence-handling process.

Questions, evidence to request and suggested reviewers
QuestionArtifact to requestSuggested reviewer
Which workflow and release does the evidence cover?Scope statement, configuration version and exclusions. Acceptance planning.Release owner
Who may request the action?Applicable permission rule and evidence that it is applied to the intended requester and action. Authority guide.Security and access-policy owner
What confirms the promised milestone?Mapping between the reported milestone and the authoritative record. Outcome guide.Integration
Who accepts unfinished work?Receiving-team acceptance, due window and closure process. Ownership guide.Patient access
Who can review an uncertain outcome?Review and escalation process, including the evidence the reviewer can access. Oversight guide.Operations

An example evidence request.

Fictional purchasing example: a team is considering a callback workflow for one clinic. A demonstration shows the assistant promising a callback. The buyer needs to understand how staff receive and close that work.

For the callback configuration proposed for our pilot, please identify the record that shows the request was received, which team accepted it, the agreed due window and the closure reason. State which release the example covers and which steps remain outside the evidence supplied.

This is a suggested request, not evidence about a real vendor. The fictional callback story illustrates the distinction between a promise and accepted ownership.

Read the worksheet accurately.

Keep claims, supplied artifacts and your own review distinct. A blank cell means “Not recorded”; it does not establish a failed control. A recorded review means someone on your team entered that status. The website has not checked the document or validated the vendor.

Keep confidential documents in your approved systems. The worksheet stores names, statuses and notes in page memory; export before reloading. Access Red Team's own supplier facts are a separate purchasing reference.

Prepare the next conversation.

Use the questionnaire to collect questions and name the people who should discuss the answers. If a decision still depends on evidence your team cannot establish, describe that gap when considering a scoped assessment. The public worksheet does not certify a supplier or approve a purchase.

Updated 12 September 2026: added an example evidence request, artifact links and guidance for reading user-recorded statuses.

NEXT DECISION

Build the vendor questions with your team.