The Short Answer
A health system can own the platform its clinical AI runs on. On ibl.ai you own all the code and the data, so protected health information is processed inside the clinical network rather than a vendor's cloud β no business associate for the platform, no subprocessor chain. It is model-agnostic with no per-seat pricing, so you can deploy anywhere, including fully air-gapped.
Scheduling, triage, ambient documentation, coding, billing, prior authorization. Each arrived as a separate product, with its own contract, its own EHR integration, and its own model.
McKinsey's assessment is that this arrangement is ending: AI solutions are proliferating faster than most organizations can absorb them, and leaders are moving toward a modular, connected architecture that brings point solutions, data infrastructure, and intelligent agents into one whole.
That is a consolidation story, and consolidation changes what a purchasing mistake costs.
Why does consolidation raise the stakes on a single decision?
Because the blast radius changes.
When clinical AI was five unrelated tools, choosing badly cost you one contract and one integration. You swapped the vendor and the rest of the estate carried on.
When AI becomes the layer that scheduling, documentation, coding, and triage all plug into, that same choice determines where a health system's clinical data flows, what its audit trail looks like, and how hard it is to change direction in three years.
McKinsey's framing puts data governance at the core of this transition, and that is the right emphasis. A platform decision is a data-path decision wearing different clothes.
What does a BAA actually settle, and what does it leave open?
A business associate agreement obliges the vendor to safeguard protected health information, restrict its use, and report breaches. It is a real control and the standard way healthcare technology is bought.
What it does not do is stop PHI from leaving the network. It governs the disclosure rather than preventing it, which is a distinction most procurement processes flatten and most risk committees eventually reopen.
There is also a scope trap. BAAs attach to named products and tiers, so an organization that treats one agreement as covering every adjacent feature is usually wrong about that β and the mismatch surfaces during an audit rather than during the sale.
Self-hosting removes the question instead of answering it: if inference runs inside the clinical network, there is no disclosure to a business associate, because there is no business associate.
We set the two approaches side by side in HIPAA BAA vs Self-Hosted AI and covered the practical architecture in HIPAA-Compliant AI: Keeping PHI on Your Own Infrastructure.
Which layer should a health system actually own?
Not every application. The one everything else depends on.
Ambient documentation from a specialist vendor is a reasonable purchase. So is a scheduling optimizer. What should not be rented is the layer underneath them β the retrieval over clinical content, the permissions model, the agent orchestration, and the audit trail.
That layer is where three things live that are painful to relocate later: the data path, the governance model, and the integration surface with Epic, Oracle Health, or athenahealth.
Owning it means a specialist tool becomes replaceable, because the platform beneath it did not come from the same vendor.
McKinsey's clinical-data foundry idea points the same direction. Converting patient records into a durable enabler only pays off if the resulting asset belongs to the health system rather than accumulating inside a supplier's product.
This is not a theoretical arrangement. More than 1.6M users across 400+ organizations already run the ibl.ai platform this way, on their own infrastructure with the source code in their possession.
They include NVIDIA, MIT, and Syracuse University, which reported roughly 85% lower cost than the per-seat alternatives it evaluated.
What does per-seat pricing do at health-system scale?
It prices the deployment nobody wants and penalises the one everybody does.
Per-seat licensing runs roughly $30 per user per month for Microsoft Copilot and about $60 for ChatGPT Enterprise.
Applied across clinicians, nurses, schedulers, coders, and administrative staff, extending AI to everyone who touches a patient encounter is the most expensive configuration available.
Vertical healthcare AI is often priced per agent or per encounter instead, which is fairer but still unbounded β the bill grows with exactly the adoption the programme is trying to achieve.
A flat, self-hosted licence bounds cost at the compute. That is the difference between a pilot in one department and a platform the whole system uses, which we work through in AI Cost Math for Hospitals and in the Hippocratic AI comparison.
How should a health system sequence this?
Decide the platform layer before buying the next point solution.
That inverts the usual order, in which a documentation tool is bought, then a scheduling tool, then a triage tool, and eighteen months later someone asks why four vendors each hold a copy of the same clinical data under four different agreements.
Three questions, in order: where does PHI go while a model reasons over it, who can produce the complete audit trail for one patient encounter, and can we change the underlying model without rebuilding the integrations.
A health system that can answer those three has an operating system. One that cannot has five point solutions and a diagram that claims otherwise. The broader infrastructure argument is in Healthcare AI Infrastructure and HIPAA.
