The CRM stops where the chart starts.
Provider organisations and health tech run two systems that were never meant to meet. The EHR holds the record of care. The CRM holds referral partners, payers and the long sale into a health system. We draw the line between them, write down what crosses it, and build the operation on the CRM side.
Referrals arrive by fax and die in an inbox.
Intake takes the call, the coordinator keeps a spreadsheet, eligibility gets checked in a payer portal, and the EHR only learns about the patient once care starts. Nobody can say which referring office sent the most admissions last quarter, or how many inquiries were lost waiting on authorisation.
The BAA decides what crosses.
Health care — boundaryThe operation that sits beside the chart.
Referral attribution
Referring practices, physician groups and health systems held as companies with the individual referrer attached, so every admission attributes back and a source going quiet shows up in reporting.
Access and authorisation
One pipeline from inquiry through insurance verification, benefit check, prior authorisation and first scheduled appointment, with the reason recorded every time a patient falls out of it.
The PHI boundary
A written rule for what crosses from the EHR into the CRM. Identifiers and status flags cross. Diagnoses, notes and clinical detail stay in the system of record.
BAA and tracking scope
The signed BAA mapped to the tools it actually covers, then forms, cookies, chat and analytics configured so no protected data reaches a vendor outside that scope.
Payer and contracting cycles
Credentialing, contract renewal and rate negotiation tracked as dated records with owners, so nothing renews silently and nothing lapses mid-quarter.
Health system sales
Long enterprise deals modelled as they actually run: clinical champion, IT and security review, privacy review, value analysis committee, pilot site, then rollout across the system.
The boundary first, the build second.
Diagnose
Time with intake, billing and the clinical leads, following one referral end to end, listing every system, portal and spreadsheet it touches on the way.
Design
The referral and access process modelled in BPMN, technology-agnostic, with the compliance boundary and the data allowed to cross it agreed in writing first.
Build
Objects, pipelines, authorisation stages, integrations and reporting built to that model, inside the tools the BAA covers and nowhere else.
Hand over
Intake coordinators trained on the pipeline they will actually work, documentation for the privacy officer, and a period running it alongside your team.
Marketing gets switched off by legal.
Nobody budgets for the moment privacy review reads the tracking script. Pixels on a patient portal, a form that collects a condition, a chat transcript sitting with a vendor outside the BAA — each one ends with a campaign paused rather than fixed. We build the marketing surface for that review up front, so it is a checklist rather than a shutdown.