Key takeaways

  • A clinical conversion usually finishes after go-live, and most practices keep read-only access to their old system for 90 to 120 days while billing winds down. Your data is at its freshest during this window.
  • The risk with AI in healthcare is what the tool can reach: old documentation that has been sitting in your environment for years and still contains protected health information (PHI).
  • Before you turn AI on, the work is getting your data tagged and your controls in place so an agent only sees what it should.
  • Any AI vendor you consider for patient data should be able to sign a business associate agreement (BAA).
  • Readiness is really an IT, security, and data problem at the same time, which is why it holds together best with one partner who owns all three rather than three vendors passing it between them.

By the time you go live on a new EHR, it feels like the hard part is behind you. The demos, the contract, the training, the go-live date you circled months ago: done. But the days right after go-live are when something quietly important is true about your practice, and most people never stop to notice it.

Your data has just been touched, moved, and reorganized more than it will be for years. That makes this the natural moment to get it ready for what comes next, instead of treating that as a separate project you get to later.

If AI is anywhere on your radar, this is where readiness starts. Not with the tool you pick, but with the data it would be reading. The rest of this walks through what that means and why the timing works in your favor right now.

What just happened to your data

A conversion doesn’t move everything at once, and it doesn’t move everything at all. Clinical data usually converts after go-live, because you’re on your legacy system right up until the day you switch. Your old charts get signed off and closed out, then extracted, and the clinical conversion runs on the back end. That typically takes about six to eight weeks from the time your new team receives the records.

Financial data is a different story. It’s industry-wide that your financial information doesn’t move from one system to the next, so you run a billing wind-down, usually 90 to 120 days after go-live, working your old claims down in your old system while new billing starts in the new one. That’s why practices are told to keep read-only access to the legacy system for that same 90 to 120 days, so a historical chart note is always one tab away.

None of that is a flaw in the process. It’s just what a real conversion looks like, and it means that for a few months after go-live your data is unusually exposed and unusually fresh at the same time.

The check-in most practices skip

managed it service provider asking questions to clinic personnel

Once the clinical conversion is nearly done and things have settled, a good conversion partner circles back. The honest version of that conversation is simple: we just handled all of your data, so do you have anyone helping with the security and IT underneath it? Most practices don’t, and most have never been asked.

That gap is the one Focus is built to close. As a Unified Partner across Managed IT, Managed Security, and Managed Data, we’re often the ones asking that question, because we’re the team that handled the conversion and knows what the data looks like underneath.

That question used to be about firewalls and backups. Now there’s a newer reason it matters, and it’s the AI-readiness question you came here for.

Why old data becomes a new risk the moment AI shows up

Bringing AI into a practice sounds like a tooling decision. In healthcare, it’s really a data decision, and the trouble starts with data you forgot you had. If you point an agent at your environment, it can start crawling documentation that has been floating around for years and surface protected health information you didn’t know was still there.

The reason makes sense once you hear it. Not everyone had the security controls in place to protect their data five or six years ago. If those controls weren’t there then, an agent turned loose today can reach a whole lot of things you never intended it to see. You hear the same story across the industry: PHI exposed unintentionally, not through an attack, but because a tool was given more reach than the data was ever governed for.

Getting your ducks in a row before you turn the lights on

The advice from our security team is blunt, and it’s worth repeating in healthcare: get your ducks in a row on security and data tagging before you turn the lights on with AI. The order matters. Readiness comes first, then the tool.

This is the same order we work in at Focus, on every engagement: fix what’s exposed, stabilize the foundation, then enable AI to run on top of it. In practice, that readiness work looks like a few specific things:

  • A readiness assessment goes in first. It maps how ready the practice really is and finds PHI floating around in places it shouldn’t, like old shared drives, email, chat channels, and documents left over from before your current controls existed.
  • Access controls and a security wrapper are in place before any agent is pointed at your environment, keeping business data and PHI separated so a tool can’t cross the line.
  • Your content gets tagged by who it’s really for. Every email, calendar invite, chat channel, and document carries a simple answer to who the audience is and who should have access, and AI tools then respect those tags in what they read.

Done in that order, an AI tool sees what it’s supposed to see and nothing else. Skip it, and you’re relying on the tool to be careful with data you never made safe in the first place.

The vendor question worth asking early

gavel on top of contract

There’s one more question that decides whether an AI tool belongs anywhere near patient data. A business associate agreement, or BAA, is a legally binding contract that says a vendor is handling patient data appropriately and putting the right controls around how it’s accessed and used. Those agreements are only available with certain AI vendors, some more readily than others, and with some you have to pay to get one.

So the right AI tool for your practice isn’t the one with the best demo. It’s the one that will sign a BAA and stand behind how it treats your patients’ data. That’s a short conversation to have before adoption, and an expensive one to have after. Vetting that, and bringing the right tools in on top of a foundation that’s already ready, is part of what we do rather than something we leave you to sort out alone.

What an AI-ready foundation looks like after go-live

If you’ve just gone live, here’s the short version of what to have in place before you bring in any AI tool:

  • Old data reviewed for PHI sitting in places it shouldn’t be, and cleaned up before anything crawls it.
  • Content tagged by audience so access boundaries are clear and machine-readable.
  • Access controls and a security wrapper in place, keeping business data and PHI separated.
  • Any AI vendor confirmed to sign a BAA before it touches patient data.

Questions we get about this

Can’t we deal with this later, once we’re ready to use AI?

You can, but the cleanup gets harder the longer you wait, and the risk sits there in the meantime. The reason to do it now is timing: right after a conversion, your data has already been touched and organized, so the readiness work rides along with the work you’ve already done instead of becoming its own project a year from now.

We just switched systems. Why would old data still be a risk?

Because a conversion moves your records into the new system, but it doesn’t erase everything that accumulated around the old one. Documentation, exports, and files from years back can still be sitting in your environment, and if the controls weren’t there when they were created, an AI agent can reach them now.

How do we know if an AI tool is safe to use with patient data?

Start with one question: will the vendor sign a BAA? If the answer is no, or if it’s buried behind a paywall, that tells you how the vendor thinks about patient data. From there it’s about matching the tool to an environment you’ve already made ready.

Where this leaves you

The window right after go-live is short, and it closes quietly. Your data is as organized as it’s going to be, your team is already in transition mode, and the risk of doing nothing doesn’t show up until an AI tool goes looking. If you’ve just gone live and nobody has looked at what your data looks like underneath, that’s a conversation we have often.

This is where one partner across IT, security, and data changes the math. AI projects stall in healthcare because those functions usually sit with different vendors, and the gaps between them are exactly where protected data leaks or a tool reaches something it shouldn’t. When one team owns the environment underneath, readiness stops being its own scramble and becomes part of the work you just did.

That’s the role Focus plays. We’re healthcare-exclusive, with 20+ years of experience, 2,000+ EHR conversions across 1,500+ organizations, working as a Unified Partner across Managed IT, Managed Security, and Managed Data. The same logic runs through all of it: fix what’s exposed, stabilize the foundation, and only then enable AI to do real work, so you end up with a strategy instead of another firefly. You just moved everything. This is the moment to make sure it’s ready for what you bring in next.

Start the conversation