Buyer Intelligence

Who Approves Clinical AI in a Hospital

A clinical AI purchase at a health system clears four or five separate reviews before anyone signs. Here is the whole chain, who sits in each seat, and what each one is actually looking for.

The short answer

No single person approves clinical AI at a hospital. A purchase typically clears a clinical sponsor, an informatics review, an information security and privacy review, a finance review, and increasingly a dedicated AI governance review, and only then reaches whoever holds signature authority for that dollar amount. The person who researches the product and the person who can approve it are almost never the same person, and they are not looking for the same things.

Explained at three levels

1 Plain English

A hospital does not buy software the way a business buys software. Several different groups each have to say yes, and any one of them can say no. A doctor who loves your product cannot buy it. A technology officer who approves the integration cannot fund it. The finance office that funds it will not evaluate whether it works clinically. Everyone is checking a different thing, and they check in roughly this order: is this clinically worth doing, can we actually run it, is it safe with our data, can we afford it, and who is accountable when it misbehaves.

2 Informed buyer

The chain is mostly sequential but the reviews overlap, and the sequencing matters more than the count. Security review and integration assessment can run in parallel with clinical evaluation, but neither can start until there is a named internal requester and a defined use case. Finance cannot price the request until integration scope is known. Governance cannot assess the monitoring plan until the clinical claim is specified. A vendor who supplies everything at once compresses a cycle that otherwise runs serially, each handoff costing a committee meeting.

3 Technical and professional detail

Signature authority is a matrix, not a person: it is set by dollar amount, by funding type (capital versus operating), and frequently by whether the purchase is inside an existing master agreement. In a multi-site system, a hospital-level approval may have no force at the amount involved. Ask early and directly which entity signs, at what threshold, and whether this specific category has already been delegated. The answer determines whether your champion can actually win.

The five reviews

Different organizations name these differently, and smaller hospitals collapse several into one committee. The functions are consistent even when the titles are not.

1. The clinical sponsor

Someone inside the organization has to want it. This is the clinical champion: a physician, nurse leader, pharmacist, or informaticist who experiences the problem personally and is willing to spend internal credibility getting it solved.

What they need is not a demonstration. It is ammunition. The champion writes or drives the internal submission, answers questions in rooms the vendor is not in, and absorbs the cost if the purchase disappoints. The quality of the material you give them to work with is the one thing at this stage a vendor still fully controls.

A committee that senses a purchase rests on exactly one enthusiastic person will ask what happens when that person leaves. It is a fair question and it kills proposals.

2. Clinical informatics

The CMIO, and for anything touching bedside workflow the CNIO, assess whether the thing can actually be run here. This is the one review that can credibly evaluate both the clinical claim and the integration story, which is why it is usually the most substantive technical conversation a vendor has.

Informatics is asking: does this fit the workflow people actually have, what does it add to or remove from the record, who supports it after go-live, and what does our analyst team have to staff. A product that works beautifully in a demonstration and requires three clicks nobody will make fails here, correctly.

3. Information security and privacy

The third-party risk assessment runs independently and can block a purchase that has cleared everything else. It covers security attestations, data flow, subcontractors, breach notification, business continuity, and what happens to the data at termination.

This is the review most often missing from vendor timelines. A queue of several weeks at a large health system is normal and is not a signal about how the deal is going. The way to shorten it is to arrive with the packet assembled: current SOC 2 Type II, architecture and data flow documentation, subcontractor list, and a signable Business Associate Agreement.

4. Finance

Finance is evaluating total cost of ownership, not your quote. Interface build and maintenance, internal analyst time, training against real workforce turnover, the parallel process during rollout, and for AI specifically the ongoing monitoring and revalidation effort.

Whether the money is capital or operating determines both the calendar and who can approve it. That is a bigger lever on timeline than almost anything else and it is frequently decided by accident.

5. AI governance

This is the newest seat and the one changing fastest. Where a formal AI governance body exists, it is asking a different question than the other four: not whether the tool works, but whether the organization can demonstrate that it knows the tool is still working.

In practice that means an entry in the AI model inventory, a named accountable owner, a stated validation population, a post-deployment monitoring plan with thresholds and a withdrawal procedure, and a process for being told when the vendor updates the model.

The absence of a monitoring plan is one of the more common reasons a proposal gets sent back rather than rejected. It is fixable, and fixing it before submission saves a full committee cycle.

Where the research actually happens

All five of these reviews are preceded by something less visible: someone searching for an answer before any of it starts.

That is worth sitting with, because it inverts the usual assumption about who to write for. The queries that show institutional intent are rarely product names. They are procedural: what documentation does a board need, how do health systems evaluate this category, where does procurement-ready documentation come from, what do informatics teams say about vendor support after deployment.

Those are the questions of people building a case, not people choosing a product. They come earlier, they are more specific, and almost nobody is answering them.

What this means if you are selling

Three things follow, and none of them is about the demonstration.

First, write for the reviewer, not only for the enthusiast. The champion is your entry point, not your audience. Four other people read what the champion assembles.

Second, arrive with the packet. Every one of the five reviews has a predictable document request. Supplying them unprompted is unusual enough that it is remembered, and it removes serial delays that no amount of relationship can compress.

Third, find out who signs. Early, explicitly, and without treating it as a rude question. Most stalled healthcare deals are not lost, they are sitting in a queue nobody named at the beginning.

Where this goes next

More in Buyer Intelligence