Heads are rolling. In the past two weeks, two dominant systems of record in healthcare voluntarily went under the knife as Cognizant TriZetto and PointClickCare both made sweeping changes to how third parties access their platforms.
Salesforce’s proactive example of a system of record beheading itself was just a harbinger of these moves (and more to come). When the dominant system of record in CRM voluntarily exposed every capability as an API, MCP tool, or CLI command, it wasn't altruism and it wasn't openness. It was an obvious pricing strategy: convert invisible browser clicks into metered, billable agent calls.
So now healthcare’s systems of record are arriving at the same conclusion, albeit from different directions. Some decapitations are planned, though, while others seem like more desperate triage.
Cognizant Trizetto
We don’t talk about payer systems of record all that much, but Core Administrative Processing Systems are the Bizarro Jerry version of EHRs. As There Will Be Bundling detailed, Cognizant's TriZetto suite (Facets, QNXT, QicLink) processes over 50% of all insured lives in America. It is, by any measure, the Epic of claims administration. And like Epic, it has spent years accumulating workflow gravity, data gravity, and the litigation that tends to follow both.
Cognizant’s Unify is stitched from the same cloth as Salesforce’s Headless 360.
"This is the first move in opening our healthcare platforms to a new kind of consumer," said Prasad Sankaran, President, Cognizant AI Products and Platforms. "AI agents are increasingly joining human users in enterprise workflows, and for regulated industries like healthcare, that requires a platform that is policy-governed, auditable and built on industry-standard healthcare interoperability protocols. Every future solution built on the TriZetto Unify platform strategy will treat agents as first-tier consumers from the start."
It’s quite limited and opaque, but we should expect it to expand rapidly. Indeed, all systems of record will follow a similar pattern. All of a sudden, AI agents will hammer user interfaces, so a logical response is to build sanctioned interfaces to funnel that demand lest you be smothered and suffocated by the horde of bots. APIs are being rapidly developed and deployed to meet demand. Is this the market working?!
Hard to say. There’s a paucity of real information available here about the limited APIs and MCP they mention in the press release. Developer documentation and pricing are nowhere to be found. So my main critique is that if you are claiming the headless moniker, you simply must go further!
The Salesforce example is instructive precisely because it went all the way:
Real, publicly accessible developer documentation
API specs
CLI references
MCP tooling
That’s what “open for agentic business” actually looks like. Without a doubt, that business certainly comes with tolls and fees, but the tools at least exist and the price of admission is knowable before you build.
True headlessness is not “Da Vinci prior authorization APIs only, plus a handwavy MCP server”. So while applaudable, it’s hard not to see this as just convenient, as CRD, DTR, and PAS are not acts of generosity. They are what CMS-0057 requires by this January. Without further transparency, the headless framing is just a smoke screen to make a regulatory mandate look like a strategic vision.
Full headlessness (in healthcare and elsewhere) actually looks quite different. As mentioned in “Super Integration Fighter III”, there are really only three ways to integrate with software (and perhaps a nascent fourth category for agentic interfaces from “Why Don’t EHRs Allow Write Access?”):
APIs for structured standards-based exchange
RPA for the workflow integration or data exchange that APIs haven’t caught up to
Database access for bulk use cases like analytics and AI training that neither of the first two serve.
TriZetto has only touched a tiny corner of the first tier. They’ll continue to find their systems assaulted by the horde so long as they remain selectively headless.
PointClickCare
So systems of record need to go further. But how far should they go? And do they know where to stop?
Healthcare has unique pressures beyond traditional SaaS, though. AI agents are adding demand, for sure, but information blocking regulations change the equilibrium in ways that have no analog elsewhere. So it’s seemed obvious we’d see not just large investments into APIs, but also metering and gating of Robotic Processing Automation (RPA), as well as other innovative programs and methods to convert gray market extraction into structured, governed, billable demand. From “The Iceberg Fallacy”:
Monetized RPA and agentic access are thus inevitable and will become a prevalent form of exchange. If you cannot build out the API surface fast enough to satisfy the regulatory obligation, and you cannot afford the maintenance tail of the API surface you do build, the path of least resistance is to let a third party do it for you, riding on top of the UI you already maintain for clinical users.
The bots are already in the building. With the ONC now promoting agentic access, the only question has been whether to evict them and incur regulatory risk or charge rent to the squatters and see who leaves.
And kudos (I suppose) to PointClickCare for answering that call.
Authorized Screen Scraping: Reinforcing our longstanding commitment to data sharing, and in response to demand for this new mode of access, PCC has established a new authorized screen scraping program. Screen-scraping workflows will be formally reviewed, approved, and operated within PCC’s governance framework, including implementation of appropriate technical and organizational controls, to help ensure they are safe, secure, and scalable.
This is really cool! It’s the first time we’re seeing sanctioned RPA, as far as I know. It’s seemingly an honest acknowledgment that API surfaces will never fully cover the workflow. Yes, “in response to demand for this new mode of access” is a funny way of referencing the RTMS case, but that’s okay! Progress is progress and the right answer forced at gunpoint is still the right answer, especially when you’re ahead of everyone else. Formalizing RPA access (reviewing it, governing it, making it auditable) is a much more mature position than pretending the bots aren't there like every other EHR still seems to be doing.
But it’s not all roses for point solutions. As PCC is opening this door formally, it’s closing others:
All data extraction facilitated through PCC must occur only via authorized pathways that meet PCC’s applicable security, operational, technical, and compliance requirements. Unauthorized data access methods are not permitted, including unsanctioned screen scraping, bots, browser extensions, credential sharing, or other attempts to bypass or weaken security controls. Custom Extracts and Data Relay are not approved for third-party vendor access, and PCC is no longer accepting new Letters of Authorization (LOAs) for Data Relay. PointClickCare will continue to support existing LOAs until further notice.
Data Relay is (was?) PCC's legacy bulk data access mechanism - automated EHR extracts delivered to whatever analytics or reporting tool a customer pointed at it, authorized via a customer-signed Letter of Authorization naming the third-party vendor.
Data Relay existed in parallel to PCC's API program but, according to industry observers, the API didn't provide sufficiently broad access for analytics use cases. An entire LTPAC analytics ecosystem (Megadata, PrimeView, SNF Metrics, BluePurpose, AR Proactive) grew up pulling PCC data. How many of them depend on Data Relay specifically is unclear. But the blast radius here feels substantial.
Sanctioned RPA is where things are headed, but it's worth being clear about what it is and isn't. Screen scraping sees what a user sees and clicks what a user clicks. That is tremendously useful for transactional workflows that APIs haven’t caught up to. It is a brutally inefficient substitute for bulk data access. Population level replication is separate and distinct from user interface integration or filling the API gap. For Data Relay use cases like census trends, PDPM modeling, or quality benchmarking across facilities, I imagine this swap is going to be reviled. Multiply out the clicks needed to access each data point, by each patient, by the frequency required and most economics fall apart fast.
The part that’s a bit confounding to me - why not just monetize Data Relay too? Sure, a database credential is harder to meter than a scraping session, but not impossible. It’s exactly what Epic is doing with Kit. So it’s a conscious product decision to not pursue that approach. My take is that supporting and appropriately monetizing the surface area of three distinct integration paradigms (API as much as possible, bulk data for population level egress, and RPA or some wonky new agentic framework for anything else) may be necessary in this coming era (especially for developers of certified health IT), so I’m surprised by that choice.
Do third party applications have room to push back? IANAL, but at a minimum, it seems it will be a harder fight than RTMS was. The Manner Exception largely allows actors to negotiate an alternative pathway as long as it's an equivalent substitute. Sanctioned scraping plus expanded Marketplace APIs is the alternative PCC seems to be offering. Is that information blocking or is that just a deal apps don’t like? Are there similarly situated Time (and hopefully not another regulator, judge or jury) will tell.
Month in Review
Here is the monthly review. As a reminder, this is a regular round-up of the month’s posts and other content to surface things you may have missed across regulation, litigation, interoperability, and beyond.
Articles Published:
None this month
Video Content:
The Information Exchange: Lumon on Steroids (May 18): The full four-deep crew reunited to cover the nature of Epic, systems of record, antitrust, information blocking, and competition writ large — including a dig into why a company that spent 40 years letting the work speak for itself is now doing Freakonomics and Katie Couric after Acquired and Forbes the year prior.
The Information Exchange: The TEFCA Report Card (May 26): A Memorial Day primer and rundown on the successes and failures of America’s only statutorily blessed nationwide health data exchange two years in — what’s actually working, what isn’t, and what the rails really do at this point. Debuted the new “Pryce Transparency” segment and Brad as a Trusted Exchange Guinea Pig.
Regulatory:
None the WISeR (May 15): GAO published B-337994 in response to a request from Senators Wyden, Murray, Blumenthal, and Gillibrand, finding that CMS skipped a step when launching the Wasteful and Inappropriate Service Reduction (WISeR) Model. CMS had argued the notice was a guidance document, that guidance documents aren’t rules, and that voluntary models don’t alter rights — GAO walked through each element of the APA’s definition of “rule” and found WISeR satisfied all of them, rejecting the same “informal notification” approach HHS had tried in 2012 and 2019.
The Invisible Agenda (May 27): The Unified Agenda (the semiannual publication mandated by Executive Order 12866 and the Regulatory Flexibility Act that catalogs every planned rulemaking action) has gone from “reliably late” to “functionally optional” in roughly sixteen months under the current administration. The closest thing the federal government has to a public roadmap of its regulatory intentions has effectively disappeared, with downstream implications for anyone trying to plan around health tech policy.
Court cases:
Veeva v. Epic: Dismissed With Prejudice (May 1): Judge Conway dismissed Veeva’s declaratory judgment challenge to Epic’s non-competes with prejudice, ruling that no Wisconsin court has recognized standing for a potential employer to challenge restrictive covenants between a potential employee and that person’s existing or former employer. A bigger swing than I expected (I had bet on path two — dismiss with leave to amend) and a meaningful win for Epic, though appellate courts tend to frown on killing cases over procedural questions.
Epic v. Health Gorilla: Civil War (May 4): The mass-tort class action ecosystem spawned from Epic’s lawsuit has ballooned, with twelve class actions across five federal districts already consolidating in pieces and an MDL looking inevitable. The real fight today isn’t plaintiff vs. defendant — it’s a plaintiff civil war as firms poach plaintiffs from rivals, dismiss and refile to broaden defendant lineups, and jockey for lead-counsel posts in the consolidations forming across the country.
Particle v. Epic: The Grandaddy Lawsuit Returns (May 8): As Phase I discovery winds down, both sides filed dueling letters on what comes next — Epic pushing for early summary judgment on market definition, Particle pushing for full discovery and accusing Epic of dodging the Court’s three Phase I questions. A flurry of activity (privilege rulings, dueling letters, Buchwald giving Epic a one-day window to respond) made clear the case had gotten spicy again.
Right to Read, but Wrong to Write (May 12): The biggest information blocking court development since RTMS v. PCC — Judge Maddox signaled a split preliminary injunction in Vyne v. Henry Schein. HSOne got its CFAA win on the write-back behavior (always Vyne’s weakest ground given the decrypted config files, super credentials, API key generation, and shifting CTO explanations), but Vyne’s printer driver method for reading data is protected, stopping HSOne from cutting off customer access to provider-selected EHI.
The DOJ’s No Good, Very Bad Day (May 14): A Rhode Island judge eviscerated DOJ for forum-shopping to Fort Worth in his order granting emergency motions to quash a HIPAA fraud-backed subpoena seeking every minor patient’s gender-affirming care records at Rhode Island Hospital going back five years — the eighth federal court to reject these subpoenas. Outside my lane, but eight losses on the direct path is the context for understanding at least one unique angle of the health technology litigation we’ve been tracking.
AADJ v. Epic: The Motion to Dismiss (May 20): Epic finally filed its MTD in American Association for Disability Justice v. Epic and the plaintiffs are in trouble. Cravath brought the heat count-by-count, methodically dismantling with a mix of narrative inversion, black-letter antitrust doctrine, and Fifth Circuit case law. Epic opened by establishing that 2.7 million records were sent to SSA in 2025 — the opposite of the bottleneck the complaint alleged.
The Take-Home Exam (May 28): Eight months, two fights, and one Solomon-lite ruling after Judge Buchwald’s unusual Phase I experiment, the parties brought their answers to the three threshold questions back for teacher review. Spoiler: not great. Both sides mostly reheated motion-to-dismiss arguments instead of answering the questions, and Buchwald’s exasperation is palpable. Rather than take either party’s preferred path, she’s making them try again.
Epic Litigative Universe: Blockbuster Season (May 29): May is blockbuster season in Hollywood and the Epic Litigative Universe followed suit with a string of quick hits beyond the Particle take-home exam — including movement in Fischman v. Epic (where the pro se plaintiff’s “assisted with AI” banner on her brief has Epic arguing that confidential discovery materials should be off-limits for AI tools, citing a recent Colorado case) and a host of other procedural developments.
EHRs:
Aura Farming (May 13): Epic added Labcorp — the nation’s second-largest lab — to its Aura platform, expanding the existing Invitae entry into full menu integration. While Epic Payer Platform has been the focus of analyst (and antitrust) attention, Aura is sneakily becoming Epic’s golden goose, with 18 labs now on the platform (Fulgent, BillionToOne, GRAIL, and others). The march toward dominance continues unabated despite the slings and arrows.
Industry Analysis
Vision, Not Voice (May 6): Vision, not voice, is the modality most likely to define the next phase of AI in clinical care. Active voice (Oracle’s direction) faces repetition, privacy, and latency barriers; passive vision (cameras in exam rooms) has higher capital costs with limited upside. The real unlock isn’t a new input modality but a new output surface — AR glasses that surface clinical information in the clinician’s actual field of view. Voice freed the clinician’s hands; vision can free their eyes.
The Iceberg Fallacy (May 11): We talk about a common cognitive trap inverted from the sunk cost fallacy: underweighting future maintenance obligation rather than overweighting past investment. athenahealth’s API change log illustrates the cost: a steady drumbeat of corrections, deprecations, field additions, version bumps. Under EBITDA and growth pressure, every dollar paying down yesterday’s API tail is a dollar not spent on next quarter’s headline feature. Information blocking has reoriented this equation by expanding legally required surface area faster than any CFO will fund.
Doximity Unbound (May 19): Four meaty strategic maneuvers in roughly ten days — the DoxGPT-to-Ask rebrand, a Surescripts end-around partnership, dropping their tools into one of the country’s largest VBC networks, and amended counterclaims in the OpenEvidence lawsuit. Taken together, the moves tell a single story about the weaknesses of PLG: the BAA ceiling, the midmarket distribution gap, and the ways companies flee to escape the AI labs they rely on.
Build and Compete (May 22): Information blocking regulation has had a generally positive (if unpredictable) net effect on the industry. The yardstick of investigations and enforcement actions misses how policing actually works — the threat of being caught reshapes behavior at the margin. RTMS v. PCC crystallized hypothetical liability into real risk, and EHR general counsels are updating risk models accordingly. Epic’s relaunch of Open@Epic, expansion of self-service proprietary APIs, and rewrite of the Vendor Services agreement are the visible product of that shifted incentive structure.
Why Headway Wants Your Face (May 31): Headway’s move to require digital identity proofing for patients and providers triggered the familiar “why do I have to hand over my face to get my medication?” backlash. The privacy concern is fair, but the why-now is easy to trace: psychiatric medication management routinely involves controlled substances (stimulants, benzodiazepines, sleep agents), and prescribing abusable drugs is exactly the kind of high-trust action that historically required physical presence. Identity is the unsexy infrastructure that makes the rest of digital health convenience defensible.
Cross-industry Comparisons:
The Interoperability Doctrine (May 2): Concurrences’ special bulletin on interop topics surfaced an emerging EU “interoperability doctrine” — thematically similar to but practically distinct from the Digital Markets Act provisions. The European Court of Justice’s 2025 Android Auto ruling moved the standard for compelled interoperability from “indispensability” (the third-party app literally cannot survive without platform access) to “attractiveness to consumers” (platform integration makes the app more appealing to end users). A meaningful lowering of the threshold for when a dominant platform can be compelled to open up.
The Wall and the Toll (May 9): SAP published a policy document warning customers against using external AI agents — Salesforce, ServiceNow, OpenClaw — to access data they store in SAP apps without official endorsement, with non-compliance risking “throttling, suspension, or termination.” The earnings call drew the thin line: customer data is customer data, but the semantic model, ontology, process graphs, and accumulated workflow knowledge baked into SAP over decades? That’s the platform’s IP. Business logic remains the last battleground — the yin to last month’s Salesforce toll-the-bots yang.
Other News:
The Broken Gauge (May 5): Good work comes from constraints. Pre-kids and pre-LLM, I was bounded by time and effort and had built an internal gauge for when good was good enough. Phase II of generative AI has broken that gauge — software development, data analysis, industry research, legal learning all feel achievable prompt by prompt. False fluency rises as the cost of exploration drops, and no single step costs enough to trigger the instinct to stop. The superpower in this era is no longer all that we can learn or do, but knowing when we’ve done enough.
External Media:
AH108 - Fixing Healthcare Interoperability and Modernizing Digital Workflows (May 29): Justin Venneri hosted me on Judi Health’s Astonishing Healthcare podcast for a 22-minute conversation on the current state of interoperability, the impact of CMS rulemaking on prior authorizations, the true cost of switching systems of record, and why empathy matters in solving healthcare’s most stubborn problems.
Posts I Liked:
Epic and Apple are both platforms. Neither is your friend. One still leaves builders better off. by Adam Carewe MD: Adam reframes the Epic-vs-vendor framing into the more useful Epic-vs-Apple comparison. I don’t totally agree with the conclusions (Apple is bluntly extractive - they’ve literally lost antitrust cases for those behaviors) but it’s thought provoking.
Information Blocking Enforcement and Market Behavior by xCures: A nice riff on “Build and Compete”. The post extends the deterrence argument by tying it to the operator’s lived reality of chasing records across fragmented systems, framing the better question as whether patient data is becoming easier to access and use in real workflows, not whether the enforcement headlines are loud enough.
Three Months on LinkedIn by Peter Oppermann: Peter shared a thoughtful field report after three months of actively using LinkedIn including the AI slop problem, the value buried in comment threads, and generous shout-outs. He also surfaced a handful of voices worth following I second (John Lee, Taryn Shipley, Jackie Gerhart, Rachel Neill)




























The headless move may be less about opening healthcare data than about preserving bad workflows in a more scalable form.
A painful interface for humans creates a certain kind of evidence. Clinicians complain, workarounds appear, delays accumulate, and eventually the system has to admit that the workflow itself is part of the problem. But once an agent can operate the same interface, and once that access becomes sanctioned, governed, and metered, the pain no longer needs to be solved. It can simply be endured by software.
That is where the organizational consequence sits. RPA is not only a bridge until APIs catch up. It can also become a way to leave the underlying work untransformed while making extraction governable and billable. The clinician’s friction was a signal. The bot converts it into throughput.
So the question may not be only API versus RPA versus bulk access. It is which forms of failure will be fixed, and which will be productized once no human has to suffer them visibly.
Headless healthcare could free people from bad interfaces. It could also make bad interfaces economically immortal.
This is the agentic-healthcare layer I keep coming back to: the interface is no longer only for human usability, it is what work can be represented, audited, metered, and reversed. For OR-adjacent workflows, I would want to know whether agent access exposes enough state to close a readiness or handoff loop without turning screen-scraping into a shadow clinical process.