A quiet gap, honestly arrived at
Most executive directors we work with can name their IT provider in one breath. Fewer can say what their board approved, when, or on what basis.
That is not a criticism of anyone. It reflects how these relationships usually begin. A trusted person recommends someone. That someone turns out to be competent and responsive. Invoices arrive, systems work, and the arrangement settles into the background where useful things go. Nobody decided to route a governance question through an operational channel. It simply happened, the way most sensible arrangements do.
What has changed is not the relationship. It is what the standards say about who is answerable for it.
The standard already exists
Accreditation standards in force today place approval of major contracts and arrangements affecting care with the governing body — not with administration, and not with the vendor. That includes arrangements for external services, and it includes activities or services delegated to another entity.
Read that second phrase slowly, because it is doing more work than it appears to. Services delegated to another entity. An electronic health record is a service delegated to another entity. So is a managed IT provider. So is an imaging archive, a remote reading physician, a scheduling platform, and any documentation tool with artificial intelligence built into it.
The governing body is also responsible, directly or by appropriate professional delegation, for the operation and performance of the organization, and for defining the scope of services the organization provides.
None of this is new. None of it is proposed. It is the expectation in force now.
What this does not mean
It does not mean your board should be reviewing firewall configurations. Boards are not equipped for that, and a standard that required it would be unworkable in an organization with fourteen employees and a part-time IT contractor.
It means something narrower and more achievable. The board should be able to say which technology arrangements exist, that it approved them, and how it knows they are still appropriate. That is a governance record, not a technical one.
Four questions, one board meeting
This is the practical version. None of it requires a technical background, and all of it is answerable in a single sitting.
What arrangements do we have?
A list. The vendor, what they do for you, what patient or client information they can reach, and whether a business associate agreement applies. Most organizations are surprised by the length of the list once they write it down, because tools accumulate quietly and nobody has ever had a reason to count them.
Who approved each one, and when?
If the answer is that nobody formally did, that is the finding — and it is a common one. It is also correctable in an afternoon. A board can ratify existing arrangements at its next meeting and start the record from there. What cannot be recovered later is a year of decisions nobody wrote down.
What would we do if one failed?
Not a disaster plan. A named person, a phone number, and a written sense of what happens to patient care while a system is unavailable. The organizations that handle an outage well are rarely the ones with the best technology. They are the ones where somebody had thought about it in advance, on paper, when nothing was on fire.
How do we know this is still current?
A review cadence. Annually is defensible. Never is not. This is the question that turns a one-time cleanup into oversight, and it is the one most often skipped.
Why this matters now
Organizations are increasingly asked to demonstrate rather than assert. A policy stating that vendors are reviewed is not the same as minutes showing that a board reviewed one. Surveyors evaluate through documentation, interview, and observation — three methods, and only the first is satisfied by a binder.
That is an observation about the environment, not a warning about your organization. The environment has been moving in this direction for some time, and the direction is reasonable: it asks organizations to be able to show the governance they already practice.
The organizations that will find this straightforward are the ones that start keeping the record now, while it is a short list and a quiet conversation, rather than assembling it later against a deadline.