CG Common Ground | A PE-backed medical group: operating audit (2026)
What we did and what it producedActive

The work, decision by decision

The audit as a sequence of decisions

  1. Which department to name first. Known: IT sprawl was the loudest pain, and the person who owns IT is a principal of the group. The question was whether an "IT audit" named on day one reads as a review of a business or of a person. It reads as a person. So the cost work went into the agreement as vendor, software and subscription rationalization inside a general audit, and the IT owner gets a better vendor relationship out of it rather than an investigation. The first document the client's side read did not make an enemy.
  2. Whose time the audit consumes. Known: the department heads are the constraint. A handful of HR people cover every office, and the finance team is mid-rebuild. The question was how much of the audit can run without scheduled time from them. Nearly all of it. We lead the vendor calls, the contract reviews and the technical due diligence ourselves; leadership time goes to decisions, not discovery.
  3. The topology question, asked before anything else. Known: the owned offices run one practice-management platform. Not yet answered: whether that is one multi-clinic database or a separate on-premises instance in each office, and one early call described the offices' systems as plural, which the map has to settle. One database means a data foundation in about two weeks. Many instances means about three months and a VPN or replication project before a single row lands in a warehouse. Read from a replica, write only through the API, and verify the API exposes the writes a later build needs. Nothing downstream, the warehouse, the analytics, patient outreach, marketing attribution, is scoped until this is answered.
  4. Vendor governance before vendor replacement. Known: there was no register of vendors, business associate agreements, service levels or renewal dates. The question was what replacing a vendor buys if the next one arrives into the same absence of governance. Nothing durable. So the frame comes first: standardized due diligence, a BAA on file for every vendor that touches PHI, SLAs, a renewal calendar and one owner, then consolidation and renegotiation. The cloud practice-management evaluation, which would remove the per-location connector cost, waits for the topology answer and the register, so it does not become one more conversion that leaves the cost base intact.
  5. Patient communications: on infrastructure that signs a BAA, or not at all. Known: the original build brief assumed a general marketing-automation platform, GoHighLevel, would carry patient texting and email. It is not a HIPAA-covered platform on ordinary plans, and its transport runs through Twilio and Mailgun regardless of the plan. The question was whether the convenience of one platform survives contact with PHI. It does not. The patient-communications layer is built on parts that will each sign a BAA: Twilio under a BAA for SMS, HIPAA-capable email, a self-hosted n8n for workflow, and a language model under a BAA. A2P 10DLC carrier registration for every office's number is the go-live bottleneck for any SMS workflow, so it starts in the first cycle.
  6. Clinical AI: buy and integrate, not build. Known: image review, ambient documentation and charting are a mature vendor class, with a handful of specialist vendors as the names in it. The question was whether any version of building this in-house beats buying it. None does. Buy it, integrate it through the platform's API, and spend the build budget on the integration layer the group will own. Two line items came off the plan and the credibility of everything left on it went up.
  7. The phones. Known: an outsourced call center handles inbound and after-hours scheduling and bills per call; an AI answering pilot booked more appointments and drew some negative feedback on the interaction itself. The question was what the pilot is measured on. Booking rate and patient sentiment, side by side, office by office, before it expands and before any product decision. A cost decision became an outcome decision.
  8. Websites and scheduling. Known: two vendors at per-office monthly rates, each office keeping its own brand, doctor-partners resisting centralization, scheduling that depends on fragile plugins. The question was what has to stay local and what does not. The brand stays local. Performance, cost and the scheduler do not. So the call is a templated, brand-flexible framework with each office's identity intact, and a scheduler the group owns instead of a plugin. The doctor-partners can accept that consolidation because the part they care about does not move; whose incentive built the sprawl decides how it gets unwound.
  9. The money flows with weak controls. Known: payroll about 75 percent computed centrally and 25 percent in the offices before central processing, with reporting in Excel; doctor-partner compensation (draws, true-ups, percentages, bonuses) error-prone with spot checks as the only control; insurance reimbursement landing in 30 to 60 days, which makes accruals hard. The question was which of these can go wrong silently. All three. So the first moves are one office-by-office payroll view, a control on the compensation calculation, and an accrual policy for reimbursement timing. The payroll platform evaluation waits on those, because frustration is not a requirements document.
  10. Documents and HR. Known: a SharePoint migration run by an underperforming outside partner with no metadata schema, and HR running on email. The question was whether it is cheaper to define the schema now or retrofit it later. Now. The schema (date, version, keywords, owner) is defined during the migration; an HR ticketing platform goes in; two back-office automations, HR onboarding and offboarding and FP&A report assembly, are piloted to show time saved before anything wider is promised.
  11. Quick wins near day 25 of each cycle. Known: three categories of money nobody owns. The question was what can be fixed before each day-30 report without a decision from leadership. Consolidating duplicate tools, enabling missing security configurations, and stopping payments to vendors paid twice. The day-30 report opens with something already done.

What exists so far, and how the engagement started

The audit is under way under retainer. What exists so far is the current-state map (Attachment A), the vendor-rate register as rates (B), the revenue-cycle analytic the second cycle runs (C), the scorecard template (D), the cycle plan (E), and the tool that opened the door.

The acquisition vetting engine

A hosted scoring rubric: five weighted criteria, six intake questions per target, a composite out of 100 per practice. It runs on practice-level operational and financial inputs only: collection and denial rates, days in accounts receivable, provider tenure and patient concentration, local demographics and payer mix, deferred capital spend and lease term, and open compliance flags. No patient record is ever needed, so it never touches PHI. The weights are placeholders until the client's own buy-box criteria load. Common Ground runs the scoring and keeps running it.

The client buys practices for a living, and a buyer whose profession is judging evidence discounts a capabilities deck and weights a working instance of its own judgment. So there was no pitch. I built the engine, sourced practices that were for sale that week, and scored them.

They buy practices for a living, so I did not pitch them. I scored practices that were for sale that week and let them argue with the output.

The client argued with the output, which was the point. Scoring targets it already held a private opinion about turned a demonstration it could politely admire into a result it had to agree with, correct or dispute. Three of the five sit close enough together that their order is not decisive; the top and bottom are not in doubt. The paper ran on its own clock in parallel: the retainer went through outside counsel before signing.

Keep, replace, integrate, add: the calls and who put each system in

What was faulty in the original logic was not any one choice. It was that every choice was made for one office at a time by the person closest to it, and nobody was ever asked to own the whole. Why it has to change now: the sponsor's exit clock, the compliance exposure that vendor sprawl carries in a HIPAA environment, and two new leaders, a CFO and a CMO, who can carry the changes through their departments.

The three rules the audit runs on

Read from a replica, write only through the platform's API. No protected health information in anything Common Ground hosts. Audit, analysis and recommendation only; any build is its own statement of work, scoped after its gate is answered.

FunctionSystemWho put it in, and whyThe call
Practice managementOne platform across the owned officesEach acquired office, then a group-wide conversionKeep. Settle the topology. Switch on the verification module it already ships.
Data pipeline and BIA practice-data connector into BigQuery, then Power BI by hand-written SQLAnalysts, office by office, without a designed backendKeep the tools. Document the backend. Decide on the connector after the topology.
Practice analyticsA per-office reporting subscriptionOffices individuallyReplace with the intended reseller alternative once the warehouse carries the reports.
FinanceSage, a close automation, an Excel plug-in, Ramp for AP and cardsPrevious finance leadership; Ramp under the new CFO, three to four months inKeep and integrate. Finish Ramp. Write the accrual policy.
PayrollA payroll platform, reporting in ExcelCentral finance, a quarter of the calculation left in the officesControls first. Evaluate replacement after.
HRA central team, email, no system of recordGrew with the office count; nobody chose emailAdd a ticketing queue. HRIS after the queue shows the volume.
DocumentsSharePoint, mid-migrationAn outside partner without a schemaKeep. Define the schema during migration. Bring configuration in-house.
PhonesA call center billed per call; an AI answering pilotPredates the group's scale; the pilot is a vendor trialMeasure booking rate and sentiment before expanding the pilot.
Websites and schedulingWordPress via one vendor, a second agency, plugin schedulingEach office's original vendor, kept at acquisitionOne brand-flexible framework. A scheduler the group owns.
Patient communicationsMinimal, opt-in by practiceNobody, yetA BAA-native stack. Never PHI through a marketing platform.
Clinical AIThe vendor class exists; none installed by usNot yet a group decisionBuy and integrate, not build.
IT and networkPer-location connectors and VPN, a long tail of vendorsThe IT owner, vendor by vendor, as offices arrivedGovern first, then consolidate. Evaluate a cloud platform after the topology answer.
MarketingA small internal team managing outside vendorsVendor by vendor; a fractional CMO now owns itFit the website framework and scheduler to the CMO's plan. Measure vendors before adding any.

What it costs to hold the line, and what I watch

The line costs real things. The demonstration was unpaid engineering and analysis with no guarantee of a close; billing for it would have reintroduced the generic-proof problem the approach was built to avoid. Showing a sophisticated buyer a working scoring method hands it something it could approximate; what stays ours is the bench that built it in days rather than weeks, and the running of it. Holding scope to audit-only means saying no, in writing, to mid-cycle build requests; they become statements of work and wait for their gate. Keeping the IT work framed as vendor rationalization rather than an audit of a department costs some directness on day one and buys the department head's cooperation for ninety days.

What I watch. The topology answer, because if the platform turns out to be many instances the roadmap's data timeline moves by months and the cloud-platform evaluation moves up. The doctor-partners' response to the website consolidation, because centralization without proof is how a group like this loses its doctors. The AI answering pilot's sentiment number, not just its booking number. Whether redeploy-not-cut survives the sponsor's clock once the cost-out figures are real. And whether the client's own buy-box criteria load into the engine, because until they do, the five scores are a demonstration of a method, not a recommendation to buy anything.

What it produced

Under retainer; the 90-day audit is under way. The introduction became a signable audit contract in 18 days, after the client argued with a live scoring engine rather than a pitch. The current-state map, the vendor-rate register, the revenue-cycle analytic, the vetting scorecard and the cycle plan are the audit's first attachments. What happens next turns on one open question: whether the practice-management platform is one database or many, which moves the data timeline by months either way.

A slice of the project list

A few related projects.