Platform and RIS

Radiology Information System Vendors: How to Choose the Right One

Feature lists rarely separate the finalists. What separates them is whether the system removes re-keying rather than relocating it, whether the integrations are specific, who was in the room for the demo, and what the vendor commits to after go-live.

The short answer

Radiology information system vendors are best separated on four questions. Does the system remove re-keying rather than relocate it? Are its integrations specific and supported rather than merely claimed? Were the people who use it daily part of the evaluation? And what does the vendor commit to after go-live? Feature lists rarely separate the finalists. These four questions do.

Two healthcare executives in discussion across a table during a vendor evaluation
Key takeaways
  • Demo with your schedulers and front desk present. They are the heaviest users and they find the friction a scripted demo hides.

  • "Integrates with your PACS and EHR" is marketing, not a specification. Ask which interfaces, in which direction, maintained by whom.

  • Open source is a support and staffing decision, not a licensing saving.

  • The implementation, not the software, is what usually goes wrong.

Does the system remove re-keying, or just move it?

Most radiology information system demos look alike, because most vendors demonstrate the same screens. The difference shows up in the seams between them.

A single outpatient exam touches registration, scheduling, insurance verification, the modality worklist, the report and the claim. Each step is a chance to re-key a name, a date of birth, an accession number or an order code. A system that removes two of those steps and adds one elsewhere has relocated the work rather than removed it.

What should you count during the demo?

Ask each vendor to run your scenario rather than theirs, and count these as they happen.

  • How many times a demographic field is typed after the order arrives.

  • Where the accession number is created, and which system owns it.

  • Whether the modality receives the scheduled procedure electronically.

  • Which fields the billing claim pulls automatically, and which a coder retypes.

Which standards should you make radiology information system vendors name?

"Integrates with your PACS and EHR" is a marketing sentence. The specification underneath it names a standard, a direction, and a party who maintains the interface. Ask for all three in writing, for every endpoint.

What does each standard actually do?

  • HL7 v2 carries registration, orders and results between systems. HL7 International lists among its benefits that it "provides a framework for negotiations of what is not in the standard". Two conformant systems still have to build and agree an interface.

  • FHIR is HL7's newer specification, built on reusable Resources, commonly exchanged over a RESTful API. HL7 notes you do not have to use REST to use Resources, so "supports FHIR" is not a specification either.

  • DICOM Modality Worklist lets the scanner query scheduled procedure information instead of the technologist typing it at the console. It removes the most re-keying at the scanner.

  • DICOM Modality Performed Procedure Step, shortened to MPPS, sends state back. The modality reports whether a step is in progress, completed or discontinued, so the information system can reschedule or cancel it.

  • IHE XDS-I.b governs image sharing between affiliated organizations. The source publishes a DICOM manifest to a repository, while the images stay at the source.

For every named interface, ask which direction it runs, whether it is live or batched, and who builds it. Then ask who maintains it after go-live, and for a reference customer running that exact interface.

Should you consider open source?

Open source is a real option, and it is a staffing decision rather than a licensing saving. Compare the two on total obligation rather than on the license line.

Open source vs proprietary RIS
Comparison
Open sourceProprietary
License costNonePer seat or per study
Real costIn-house engineering and ongoing maintenanceLicense plus implementation
CustomizationUnlimited, if you have the peopleBounded by the roadmap
SupportCommunity, or a contractor you retainContracted, with an SLA
Compliance workYours to evidenceUsually vendor-evidenced
SuitsOrganizations with in-house developmentEveryone else

The honest summary: open source moves cost from a license line to a staffing line. For most imaging centers, which do not employ developers, that is a worse trade rather than a cheaper one.

What does the total cost actually include?

The license or subscription is the number that gets quoted first and matters least. Ask every finalist to price the whole program in one document, including the lines that are hard to estimate, and to price interfaces per endpoint rather than as a bundle.

Where the money actually goes
Comparison
LineUsually quotedUsually underestimated
License or subscriptionYesNo
Implementation and configurationYesSometimes
Interface build, per endpointPartlyOften
Data migrationRarely in fullAlmost always
Training and change managementRarelyAlmost always
Temporary productivity dip at go-liveNeverAlways
Ongoing support and upgradesYesNo

The two lines that are hardest to quote, migration and training, are the two that decide whether the project lands. A single quoted figure for "integration" also hides how many separate interfaces you are actually buying, which is why the count of endpoints belongs in the quote.

How to run the evaluation

  1. 1

    Write down what is actually broken.

    Not "we need a new RIS" but "scheduling takes three calls" or "claims reject on missing demographics." That list is your scorecard.

  2. 2

    Score against your list, not the feature matrix.

    Every vendor will tick every box. Ask each to demonstrate your three worst problems, live.

  3. 3

    Interrogate the integrations.

    Which standard, which direction, who maintains it, what is the support path when it breaks, and can you speak to a customer running that exact interface.

  4. 4

    Include the daily users.

    Schedulers and front desk staff, in the room, clicking.

  5. 5

    Get the after-sale in writing.

    Implementation scope, training, data migration responsibility, support hours, and what happens if go-live slips.

What should you demand of any vendor on HIPAA?

Three HIPAA obligations bear directly on which vendor you pick, rather than on how you operate once the system is in. Each one is answerable in writing before you sign, and a vendor who will not answer them in writing has told you something.

HIPAA bears on vendor selection through three specific obligations rather than a general commitment to privacy. All three belong in an RFP.

Will the vendor sign a business associate agreement?

A covered entity may let a vendor create, receive, maintain or transmit protected health information only if it obtains satisfactory assurances that the vendor will safeguard it, documented in a written contract. That is 45 CFR 164.502(e). HHS names IT vendors and cloud providers holding electronic PHI as business associates, so a RIS vendor and its host are both in scope.

45 CFR 164.504(e)(2) sets out the required contents. Among other things, the agreement must require the vendor to:

  • report breaches of unsecured PHI to you;

  • bind its own subcontractors to the same terms;

  • return or destroy the PHI it still holds at termination, keeping no copies, where feasible.

That last clause is your exit clause. Read it before you sign rather than when you leave.

What should you ask about the vendor's risk analysis?

The Security Rule makes risk analysis a required implementation specification, not an optional one. It calls for an accurate and thorough assessment of risks to the confidentiality, integrity and availability of electronic PHI, at 45 CFR 164.308(a)(1)(ii)(A). Business associates carry that obligation themselves. Ask when the vendor last completed one, what it covered, and who performed it.

Your own analysis has to cover the new system too. HHS guidance puts all electronic PHI an organization creates, receives, maintains or transmits in scope, so a hosted RIS joins your analysis the day it goes live.

What does the vendor commit to when the system is down?

The contingency plan standard at 45 CFR 164.308(a)(7) requires a data backup plan, a disaster recovery plan and an emergency mode operation plan. Ask for recovery point and recovery time objectives as contract terms, ask when the plan was last tested, and ask what your staff does during an outage.

How does your data get in, and how would it get out?

Migration is the schedule risk on most RIS projects, for a structural reason. Radiology has a shared information model for images and none for the rest of the record.

A study of a simultaneous RIS and PACS replacement, published in the Journal of Digital Imaging in 2000, found that DICOM-organized image archives transferred with full fidelity. The RIS replacement did not. It took extensive labor to translate data between dissimilar information models, and some data were inevitably lost.

What should you settle before you sign?

  • Which records migrate, which are archived read-only, and which are abandoned.

  • Who performs the migration, who validates it, and against which sample of real records.

  • The export format you can demand at any time, and whether it covers report text and scanned documents rather than demographics alone.

  • Whether the vendor is an actor under the information blocking regulations at 45 CFR Part 171, which reach developers of certified health IT and health information networks.

  • The fee for a full data extract, stated as a number in the contract.

Answers

Frequently asked questions

What should you ask a RIS vendor?

Which interfaces they support and in which direction, who maintains them, what implementation includes, what training is provided, and for a reference customer running your exact modality mix and integrations.

Is open source RIS a good idea?

Only if you employ developers. The license saving is real; the maintenance, compliance evidencing and support burden transfers to you.

How long does RIS selection take?

Plan for months rather than weeks, because the useful part is testing your own workflows rather than watching demos.

What is the most common mistake?

Choosing on feature count, then discovering the integration that mattered is a nightly export rather than live.

Do you need a business associate agreement with a RIS vendor?

Yes, if the vendor creates, receives, maintains or transmits protected health information on your behalf. HIPAA requires satisfactory assurances documented in a written contract at 45 CFR 164.502(e). HHS lists IT vendors and cloud service providers among business associates.

Which integration standards should a RIS support?

Ask by name for HL7 v2 for registration, orders and results, and FHIR where a modern API is needed. Ask for DICOM Modality Worklist to send scheduled procedures to the scanner, MPPS to send status back, and IHE XDS-I.b if you share images with other organizations.

Why does RIS data migration cost more than expected?

Because there is no shared information model for RIS data the way DICOM provides one for images. Records have to be translated between different structures, and some content does not survive.

What should the contract say about leaving?

It should name the export format, the fee and the timeline. It should also state what the vendor returns or destroys at termination, which a business associate agreement must already address under 45 CFR 164.504(e)(2)(ii)(J).

Sources

See it on your own worklists.

Bring your own numbers and we will walk through them with you.