Beyond Compliance: Why Trust is Health Tech's Most Critical Asset

September 23, 2025

We are in the golden age of health innovation. From AI-driven diagnostics to personalized wellness platforms, our work is fundamentally reshaping the future of care. This progress is fueled by an unprecedented flow of data. Yet, a critical vulnerability exists at the core of our industry: the growing deficit between our technological capabilities and the trust of the patients we serve.


The prevailing model of opaque data collection and secondary monetization is not just a reputational risk; it is an unsustainable business strategy. The next generation of market leaders will not be defined by the cleverness of their algorithms alone, but by the robustness of their trust architecture.


The HIPAA Paradox and the Coming Regulatory Storm: As an industry, we navigate our data strategies around HIPAA (in the US, GDPR and others around the world). We treat it as the definitive rulebook for patient privacy. But this perspective is dangerously narrow. HIPAA is a floor, not a ceiling, and it was built for a world that no longer exists. It governs covered entities, leaving a vast, unregulated ecosystem of wellness apps, wearables, and direct-to-consumer platforms in a compliance gray area. This regulatory gap is well-documented by the Department of Health and Human Services, which clarifies that data shared with many third-party apps falls outside HIPAA's protections.


This regulatory gap is closing. With state-level privacy laws like the California Consumer Privacy Act (CCPA) setting new precedents and the FTC signaling more aggressive enforcement via its Health Breach Notification Rule, the era of regulatory ambiguity is ending. Relying on a minimalist, check-the-box approach to compliance is a strategy with a rapidly expiring shelf life. The question is no longer if a stricter regulatory framework will arrive, but when. The smart play is not to wait for it, but to build for it proactively.


Deconstructing the Flawed Value Exchange: The current unspoken contract with the user is often a lopsided one. We offer a service, and in exchange, we capture data whose downstream value far exceeds the immediate benefit provided to the user. This data flows into a complex secondary market of data brokers and aggregators, a market projected to be worth hundreds of billions of dollars, fueling everything from pharmaceutical research to targeted advertising.


While the process of "de-identification" provides a layer of legal and ethical cover, we know its limitations. The increasing sophistication of analytical techniques means that re-identifying individuals from de-identified data is often possible by cross-referencing datasets. More importantly, this model creates a fundamental misalignment. When users discover how their data is being leveraged, trust is broken, often irreparably. This leads to increased churn, negative brand perception, and a user base that is increasingly unwilling to share the very data our innovations depend on. It is a house of cards.


Trust as a Competitive Moat - An Architectural Blueprint: In a crowded market, the most defensible competitive advantage is not a feature or a price point; it is trust. Companies that treat trust as a core business metric rather than a legal hurdle will attract more engaged users, command greater pricing power, and build more resilient brands. Research consistently shows that a lack of trust is a significant barrier to the adoption of digital health technologies. (Hey, my book talks all about this!) Here is a blueprint for moving beyond compliance to build a foundation of trust:


  1. Frame Transparency as a Brand Pillar. Your data policy should not be a document crafted by lawyers to minimize liability. It should be a manifesto, written in plain language, that your marketing team can proudly feature. Use your onboarding, UI, and communications to be radically transparent about what you collect, why you collect it, and the value it creates.

  2. Engineer an Equitable Value Exchange. For every data point requested, you must clearly articulate the direct, tangible benefit the user receives. Move away from implicit collection and toward explicit, granular consent. If the value exchange is strong enough, users will willingly opt in. If it is not, the problem is with your value proposition, not the user's reluctance. This is why we allllllll share our data with Google maps for example. We get immense value from up to date directions, and precise placement of where all the construction delays are. Take my data!

  3. Build for User-Centric Governance. Empowering the user means more than a settings page. It means building intuitive privacy dashboards, enabling effortless data portability, and providing a simple, verifiable process for data deletion. The future is user-owned health records, and the platforms that embrace this will render closed-silo competitors obsolete.

  4. Champion Data Stewardship. The ultimate evolution is to shift the corporate mindset from being a data processor to a data steward. This means accepting a 'fiduciary-like' responsibility to act in the best interest of your users and their data. This is not altruism; it is a long-term strategy for building enterprise value.


A Strategic Call to Action: The conversation about data needs to move from the legal department to the C-suite and the product roadmap. It is a fundamental strategic issue that will define the winners and losers of the next decade in health tech.


This week, ask these questions within your organization:


  • How clearly do we articulate our data value exchange in the first 60 seconds of a new user's experience?


  • Could a non-technical user read our privacy policy and feel empowered rather than confused? (cough cough, the answer today is probably no!)


  • How would our business model be impacted if our users could instantly port their data to a competitor?


The future of healthcare innovation depends on a foundation of trust. It is our collective responsibility to build it.....and it's good business for the future.


#StayCrispy


-Dr. Matt

Beyond Compliance: Why Trust is Health Tech's Most Critical Asset
By Sarah Matt February 16, 2026
The Moral Injury of Being a Liability Sponge Let me be direct with you. Healthcare AI has had its honeymoon phase. The conference keynotes. The breathless press releases. The "transformative potential" slide decks. We all sat through them. Some of us gave them. That era is over. 2026 is the year where every AI tool, every vendor, and every health system strategy gets measured against a single question: Does this actually work at scale, and can we prove it? If the answer is no, the budget is gone. The pilot is dead. The vendor is off the approved list. Welcome to the proving ground. But as we enter this phase of accountability, we’ve stumbled into a dangerous trap. We keep talking about the "Human in the Loop" (HITL) as a design gold standard. In reality, HITL has become a legal strategy used to offload 100% of the malpractice risk onto the provider, while the system captures 100% of the efficiency gains. I’m all for AI, heck I've built a career on it! But the current implementation doesn't feel right. The providers are exhausted, and we aren't the ones getting the benefit. 1. The Liability Sponge: All the Risk, None of the Shield In the current legal landscape, the clinician is in a double-bind. If you follow the AI’s suggestion and it leads to a "hallucination" or error, you are liable for failing to exercise independent clinical judgment. If you override the AI and your intuition is wrong, you are liable for ignoring a "validated" clinical decision support tool. We are being used as a "Liability Sponge." Vendors often use "click-wrap" agreements to disclaim responsibility, leaving the person with the MD or RN after their name to hold the bag. According to Bell Law Firm’s 2026 analysis , technology is no longer a neutral tool; it is a causal chain of injury, and yet the "Human in the Loop" is the only one who answers for it in court. To derisk this, we must advocate for Statutory Safe Harbors . If a provider uses a certified, validated tool as intended, they should not face higher standards than the machine itself. We need shared liability, where vendors put their balance sheets behind their 99% accuracy claims. 2. The Productivity Trap: The "15-Minute" Repossession Ambient listening (AI scribing) was the great hope for 2026. It was supposed to let us look patients in the eye again. And it does save time, roughly 30 to 45 minutes of documentation a day . But here’s the catch: In many health systems, that "gift of time" is immediately repossessed by administration to increase RVU targets. We’ve automated the clerical task of writing a note, only to replace it with 2–3 more high-stakes human interactions. We are trading clerical fatigue for emotional exhaustion. The "Human in the Loop" isn't just a safety net; they’ve become an accelerator for the system’s bottom line. We aren't getting a break; we're just being asked to run a faster race. 3. The Vendor’s Dilemma: Finding the Middle Ground I’ve been on the vendor side. I know the fear. If a tech company takes on unlimited clinical liability, they effectively become an insurance company. Most wouldn't survive their first major malpractice suit. So, how do we break the standoff? Clinical Accuracy Warranties: Forward-thinking vendors are beginning to offer performance guarantees. They aren't promising perfection, but they are guaranteeing their model stays within a specific "standard of care" band. The Registry Solution: We need a National AI Incident Reporting System, like the FAA’s "black box" for aviation. If a model fails in a specific clinical scenario, that data should be shared immediately so every other "Human in the Loop" knows to watch for it. Check the Epstein Becker Green Checklist for the five critical points your 2026 vendor agreement must cover to ensure you aren't the only one at risk. Get the "Clinical Reality Check" Before Everyone Else. I send these briefings to my private list 24 hours before they hit social media. Join other healthcare leaders who get the raw, uncensored analysis first. [Join the Clinical Realist List] The Bottom Line In 2026, the "cool factor" is dead. We are entering the era of Clinical Pragmatism . I want AI to win. I want it to help us. But a system where the provider is the "Liability Sponge" and the vendor is a "Ghost" is unsustainable. We don't need faster AI; we need a fairer contract. If the system wants us to be the final authority, it needs to give us the authority to slow down. Stay Real, -Dr. Matt
By Sarah Matt February 9, 2026
On February 5, the White House launched TrumpRx.gov , a direct-to-consumer platform connecting Americans to discounted prices on 43 brand-name prescription drugs. The site runs on GoodRx-style coupon technology and allows cash-paying patients to access manufacturer discount programs through most favored nation pricing agreements with 13 pharmaceutical companies, including Eli Lilly, Novo Nordisk, Pfizer, and Amgen. The next day, Mark Cuban sat on stage at the Silicon Slopes Summit with U.S. Medicare Director Chris Klomp and said the quiet part out loud: "Of the drugs we both carry, we are cheaper on 90%." Two platforms. Two approaches. Same promise: lower drug prices for Americans. But which patients actually benefit? And which ones are, once again, invisible? I wrote The Borderless Healthcare Revolution to make a simple argument: access is not a widget. It is a system. And any system that ignores the infrastructure underneath it will fail. This week, I want to apply that framework to both platforms and expose what the headlines are missing. TrumpRx: The Headlines vs. The Reality The headline numbers are real. Eli Lilly's Zepbound starts at $299 per month (down from roughly $1,060). Novo Nordisk's Wegovy pill drops to $149 per month. AstraZeneca's Bevespi inhaler falls to $51. For uninsured patients paying cash for GLP-1 medications or fertility drugs, these discounts are meaningful. But headlines do not treat patients. Systems do. So let me run TrumpRx through the Five-Pillar Access Audit from my book and see where the roof caves in. Pillar 1: Physical Access TrumpRx is a website. It requires an internet connection, a device, and the ability to navigate a government platform. According to the FCC, roughly 24 million Americans lack broadband access. Many are rural patients who also happen to live in communities where independent pharmacies are closing at record rates . Some of the listed drugs ship direct-to-consumer from manufacturer fulfillment centers. That assumes the patient has a reliable mailing address and someone available to receive temperature-sensitive medications like injectable GLP-1 drugs. For the tech executive in Manhattan, this is seamless. For the patient in rural Kentucky whose nearest pharmacy just closed and whose mail comes to a PO box, this is a wall. Pillar 2: Financial Access This is where it gets uncomfortable. TrumpRx.gov is designed strictly for cash-paying patients—a group that includes roughly 27 million uninsured Americans . However, for the 85% of Americans with health insurance, the math rarely works. Most insured patients will likely find that their existing pharmacy benefit offers a lower price than the "discounted" rates on the government portal. The "Cash Only" Barrier for Medicare & Medicaid A major point of confusion surrounds Medicare and Medicaid patients . While they are not technically "banned," they can only use the platform if they bypass their government benefits entirely and pay 100% out-of-pocket. See the Cultural Pillar below. The HHS Office of Inspector General (OIG) recently issued a Special Advisory Bulletin attempting to create a "low-risk" roadmap for manufacturers to sell directly to these patients. This guidance is a workaround for the federal Anti-Kickback Statute , which criminalizes offering incentives for items reimbursable by federal programs. For now, this pathway remains narrow and untested; many manufacturers may still avoid it to mitigate legal risk. The Deductible "Invisible Man" There is a hidden cost to using this portal: TrumpRx payments do not count toward your insurance deductible. . If an insured patient uses the platform for even one medication, every dollar they spend remains invisible to their insurance plan . For those with high-deductible plans, this means they aren't making any progress toward their annual out-of-pocket maximum. The Generic Problem Finally, there is the issue of brand-name bias . TrumpRx lists the brand-name drug Protonix for approximately $200 . Meanwhile, the generic version, pantoprazole , is widely available for as little as $6 through services like GoodRx or Mark Cuban’s Cost Plus Drugs . Analysis shows that about half of the drugs currently on TrumpRx have significantly cheaper generics available elsewhere. Without a pharmacist to guide them, a patient could easily pay six times more for a brand-name "deal" on the government site than they would for the generic at their local pharmacy. Pillar 3: Cultural Access The TrumpRx website launched in English. For the roughly 25 million Americans with limited English proficiency, this is not a minor inconvenience. It is a barrier. The coupon redemption process requires a level of pharmacy literacy that many patients do not have. The "Shadow Exclusion" of Federal Beneficiaries Perhaps the most confusing cultural signal comes from the HHS Office of Inspector General’s (OIG) January 27, 2026, Special Advisory Bulletin . In a move designed to "clear the path" for the platform's launch, the OIG provided a low-risk roadmap for manufacturers to sell directly to Medicare and Medicaid patients who choose to pay cash. However, a cultural disconnect remains at the point of entry: the TrumpRx.gov attestation form . To access these "deals," users must still check a box confirming they are not enrolled in any government-funded program. This creates a "shadow exclusion"; where the legal theory says yes, but the government’s own digital interface says no. For a clinician, this is the ultimate red flag: we are asking the most vulnerable, high-utilization patients to either misrepresent their status or forfeit their hard-earned federal benefits just to participate in a "revolution" that wasn't actually built for them.The attestation form asks users to confirm they are not enrolled in government health coverage. For immigrant patients, entering personal information on a .gov website carries real fear, real risk, and real consequences that the platform designers clearly did not consider. Pillar 4: Digital Access This pillar is where TrumpRx collapses most visibly. The platform creates what pharmacists call a "dangerous information vacuum." A patient buying blood pressure medication through TrumpRx, a cholesterol medication at a retail pharmacy, and a diabetes medication through a different direct-to-consumer program has effectively fragmented their own medication record. No single pharmacist sees the full picture. The risk of drug interactions, duplicate therapies, and dosing errors multiplies. There is no integration with electronic health records. No pharmacy claims data flows back to the care team. We spent two decades and billions of dollars building EHR infrastructure specifically so clinicians could see the whole patient. TrumpRx routes around that infrastructure entirely. Get the "Clinical Reality Check" Before Everyone Else. I send these briefings to my private list 24 hours before they hit social media. Join other healthcare leaders who get the raw, uncensored analysis first. [Join the Clinical Realist List] Pillar 5: Trust and Knowledge Trust is the currency of healthcare. TrumpRx has a trust problem on multiple fronts. First, sustainability. What happens to these prices when the current administration ends? Patients who restructure their medication access around TrumpRx have no guarantee these deals survive a change in government. Starting a patient on a medication they can afford today but not tomorrow is not access. It is a setup for medication abandonment . Second, data. When patients bypass their insurance plan to buy through TrumpRx, the plan loses utilization and adherence data. This sounds bureaucratic until you realize that data drives formulary decisions, drug coverage, and cost forecasting. We are trading short-term savings for long-term blindness. Third, the pharmacist relationship. If direct-to-consumer platforms pull even modest volume away from pharmacies, we lose the most accessible healthcare professional most Americans have. The pharmacist is often the last line of defense against a prescribing error. Removing them from the equation to save a few dollars is a clinical risk disguised as a consumer benefit. Now Enter Mark Cuban Cuban's Cost Plus Drug Company launched in 2022 with a radically different model: sell generic medications at acquisition cost plus a flat 15% markup and a $5 pharmacist fee. No coupons. No middlemen. No opaque pricing. Just transparent math. The contrast with TrumpRx is stark. Drug selection: TrumpRx offers 43 brand-name drugs. Cost Plus Drugs offers over 6,000 medications, overwhelmingly generics. Cuban pointed out that TrumpRx added many brands that have generic equivalents , and Cost Plus beats them on price "usually by a lot." Pricing model: TrumpRx uses manufacturer coupons and discount cards, meaning the underlying list price stays high and the "discount" is a marketing decision. Cost Plus Drugs publishes the actual cost of the drug and adds a transparent markup. One model obscures the economics. The other exposes them. Insurance compatibility: Cost Plus Drugs accepts coverage from more than two dozen insurance providers. TrumpRx is cash-only and explicitly excludes government insurance. The partnership twist: Cuban confirmed that Cost Plus Drugs is sharing its API with TrumpRx so the government platform can pull pricing data. Cuban's bet is that displaying Cost Plus prices alongside brand-name TrumpRx prices will drive patients toward the cheaper generic option. It is a shrewd move: use the government's marketing budget to grow your own customer base. The Medicare and Medicaid Problem Nobody Wants to Talk About Here is the uncomfortable reality that both platforms share: neither one adequately serves the patients who need the most help. TrumpRx explicitly excludes Medicare and Medicaid patients from using its coupons. That is over 150 million Americans on government-funded health coverage. The anti-kickback statute creates a legal wall that TrumpRx has not figured out how to climb, despite HHS guidance attempting to create a narrow pathway. Cost Plus Drugs does not accept Medicare. Its transparent cost-plus model does not fit cleanly into the Medicare Part D rebate structure. Research from the Journal of Urology estimated Medicare could save $1.29 billion annually if generic drug prices matched Cost Plus levels. A separate PharmacoEconomics study put potential Part D savings at $8.6 billion. The savings are there. The regulatory framework to capture them is not. The government is making moves on the margins. Medicare recently negotiated lower prices on key GLP-1 medications : $245 per month for Ozempic, Wegovy, Mounjaro, and Zepbound, with a $50 monthly copay for beneficiaries. State Medicaid programs can access the same rates. For the first time, Medicare will cover Wegovy and Zepbound for patients with obesity. (This starts in 2027) But these are individual drug deals, not systemic reform. They do not address the structural problem: the pharmacy benefit manager (PBM) layer that sits between manufacturers and patients, extracting value at every turn. Cuban said it clearly at the Silicon Slopes Summit: "Those big insurance companies are too big to care." His prescription? Break them up. The Five-Pillar Scorecard If I run both platforms through my Five-Pillar Access Audit, neither one passes: Physical: Both are online-only platforms. Neither solves the broadband gap or pharmacy desert problem. TrumpRx adds a direct-to-consumer shipping layer that assumes stable housing. Cost Plus ships to homes but also partners with a mail-order pharmacy. Neither has a walk-in option for patients without internet. Financial: TrumpRx helps a narrow slice of uninsured, cash-paying patients and excludes government insurance. Cost Plus Drugs is cheaper on most overlapping medications and accepts some insurance, but does not accept Medicare. Both leave the 150+ million Americans on government coverage largely untouched. Cultural: TrumpRx launched English-only with an attestation form that deters immigrant populations. Cost Plus Drugs has a cleaner interface but still assumes English literacy and digital fluency. Neither platform has invested meaningfully in multilingual access or community health worker integration. Digital: TrumpRx creates a fragmented medication record with no EHR integration. Cost Plus Drugs shares prescription data with its partner pharmacy (Truepill/pharmacy network), but does not integrate with a patient's primary care EHR either. Neither platform solves the information vacuum problem. Trust: TrumpRx's sustainability depends on who occupies the White House. Cost Plus Drugs is a private company with a transparent model, which is more durable but still subject to market forces. Neither platform has built the community-level trust infrastructure (local champions, clinic partnerships, navigator programs) that my book identifies as the foundation of lasting access. The Bottom Line TrumpRx is not a bad idea. Neither is Cost Plus Drugs. Lowering drug prices for Americans is a legitimate goal, and both platforms deliver real savings for specific populations. But both are 'Castle' solutions. They were designed for people with broadband, health literacy, and English fluency. TrumpRx does not account for the grandmother in Appalachia without broadband. Cost Plus Drugs does not account for the Medicare patient in a food desert who cannot afford the bus fare to a pharmacy, let alone a monthly subscription. Neither accounts for the immigrant mother who is afraid to enter her name on any website, government or otherwise. If you are a health system leader reading this, run your own Five-Pillar Audit before recommending either platform to patients. Ask: which of my patients does this actually reach? And which does it leave behind? The answer will tell you everything about where the real work still needs to be done. What to Do Next Audit Your Medicine Cabinet: Before your next refill, cross-check your brand-name prescriptions against TrumpRx.gov and Mark Cuban’s Cost Plus Drugs . If you find a massive price gap that doesn't make sense, let’s talk about it. Subscribe to The Clinical Realist: If you want more "no-filter" breakdowns of how policy actually hits the pavement in your clinic or boardroom, join the community on Buzzsprout so you never miss an episode. Drop Me a Note: I want to hear from the front lines. Are your patients actually asking about TrumpRx, or is this just more "health tech theater"? Reply to this email or DM me, I read every single message.  -Dr. Matt
By Sarah Matt February 1, 2026
In 2022, I was part of the team at Oracle, helping lead the post-close diligence and integration of the Cerner acquisition. I worked alongside brilliant clinical and technical minds dedicated to a singular mission: proving that a cloud giant could fix the fragmented heart of healthcare. But in 2026, the "hospital of the future" is facing a $156 billion competitor: The GPU. This week, the industry was rocked by reports from TD Cowen stating that Oracle is evaluating a sale of Cerner and potentially cutting 30,000 jobs. The reason? A staggering financial pivot to fund its $300 billion OpenAI infrastructure deal. As a surgeon who has lived in the EHR and a strategist who saw the integration roadmap from the inside, I see this not as a failure of the team, but as a "Regulatory Darwinism" event. Oracle isn’t just selling a business unit; they are paying an "AI Tax" to stay in the hyperscale race. The $156 Billion Gravity Well Oracle is currently building the "Stargate" of AI infrastructure. To meet its commitments to Sam Altman and OpenAI, the company needs to deploy roughly 3 million high-end GPUs . The math is brutal: Oracle’s capital expenditure for 2026 has jumped to $50 billion. Total debt has climbed past $100 billion, and to keep the lights on, Oracle is reportedly requiring some customers to pay 40% deposits upfront. In a world where a giant has to choose between a service-heavy EHR and a high-margin GPU cluster, the clinical record becomes "Slow Money." And in 2026, the market only wants "Fast Money." The New Map: Winners & Losers of the Great Divestiture If these reports lead to a sale or spin-off, the healthcare landscape doesn't just shift—it shatters. Here is how the pieces land: The Big Winner: Epic Systems Epic is the last titan standing. With over 42% of the U.S. acute-care market, they are now the default "safe" choice. While Oracle fought integration friction, Epic focused on embedding ambient AI natively. Their win is a victory for stability, but it’s a warning for competition. We are entering a "Monopoly Era" for the clinical record. The Ultimate Loser: Healthcare Providers & Innovation This is where the real damage happens. When Oracle (the only credible threat to Epic’s dominance) retreats, providers lose their only "Plan B." The Leverage Crisis: Without a viable alternative, health systems have zero leverage during contract renewals. We’ve already seen lawsuits, like the Texas AG’s case against Epic, alleging that this market power is already raising costs and stifling competition. The Innovation Winter: Monopolies don't have to innovate; they only have to maintain. If the "EHR War" is over, the pressure to improve clinician UI or lower implementation costs evaporates. The "Service-Heavy" Trap: If Cerner is sold to a private equity firm (a common fate for "legacy" assets), the focus will shift to cost-cutting, not clinical excellence. The doctors at the bedside will be the ones who pay that price in the form of stagnant software and reduced support. Get the "Clinical Reality Check" Before Everyone Else. I send these briefings to my private list 24 hours before they hit social media. Join other healthcare leaders who get the raw, uncensored analysis first. [Join the Clinical Realist List] The Global Implications: A "Single Point of Failure" This isn't just a U.S. problem. Globally, the EHR market is becoming a massive cybersecurity "tail risk." Cybersecurity Concentration: As noted in recent clinical research, having 90% of U.S. patient records in the hands of essentially two vendors creates a catastrophic single point of failure. One breach could paralyze the global healthcare infrastructure. The Sovereign Data Conflict: Many nations (especially in the Middle East and UK) were betting on Oracle’s sovereign cloud to host national health records. If Oracle sells the "clinical" layer, those national security agreements could be thrown into legal chaos. The Clinical Realist Take I loved my time at Oracle because the vision was grand. But a vision without a sustainable financial tether is just a dream. We are seeing the decoupling of the Clinical Application from the Data Infrastructure . Oracle might sell the "tank" (the software), but they will fight to keep the "fuel" (the data) on their cloud. As leaders, we have to stop asking which EHR is better and start asking: Who actually owns the ground your data sits on? Call to Action Audit your "Distraction Risk." If your primary vendor is under $100B+ in debt and pivoting to AI infrastructure, your implementation roadmap is at risk. Demand Data Portability. Ensure your clinical data isn't trapped in a "legacy silo" that could be sold to the highest bidder. Bet on the "Middle Layer." Stop waiting for the EHR monolith to innovate. Look for agile startups that can sit on top of any EHR, ensuring you aren't held hostage by a monopoly. Are you doubling down on a monolith, or are you preparing for the deconstructed future? Send me a note! I’d love to hear how your system is protecting its leverage.