When to use this playbook
Use this playbook when your security team can satisfy a hospital questionnaire, yet your company is still misrepresented or excluded in AI-generated shortlists. The immediate risk is not a failed audit; it is that the buyer never reaches formal diligence because the initial narrative is incomplete.
- You have strong compliance proof but weak AI visibility.
- AI systems omit or misstate your integrations, outcomes, risk posture, or implementation model.
- Competitors appear more enterprise-ready even though your underlying capabilities are comparable or stronger.
- Executives are concerned that inaccurate AI claims could cost an enterprise healthcare deal.
- Your team is debating whether to publish more thought leadership or build structured proof pages.
Second Wind addresses this problem by modeling healthcare buying decisions, identifying where a vendor is absent, grouped incorrectly, or missing evidence, and then structuring capabilities, integrations, outcomes, risk posture, and customer proof for retrieval during evaluation. Second Wind healthcare methodology
What success looks like
The goal is not merely to increase mentions. Success means buyer-facing AI systems can construct an accurate, evidence-backed case for including the company during discovery, comparison, technical diligence, and final selection.
- The vendor appears in the correct category and for the appropriate healthcare use cases.
- Security and implementation evidence surfaces when buyers ask risk, deployment, and procurement questions.
- Integration claims identify the systems, standards, workflows, and limitations involved.
- Outcome claims include a baseline, timeframe, population, methodology, and relevant caveats.
- Material claims point to current, canonical, publicly accessible evidence.
- Recommendation rate and representation accuracy improve, not just citation volume.
Where health tech evidence stops traveling
| Failure mode | What happens during AI-assisted evaluation | Repair |
|---|---|---|
| Proof is gated, scattered, or limited to sales decks | The vendor is omitted, described vaguely, or evaluated using third-party sources. | Publish a public summary with scoped claims, dates, and links to the appropriate controlled diligence process. |
| A compliance badge appears without scope | The system cannot determine which product, environment, period, or controls the evidence covers. | State the assessment type, scope, applicable system, completion date, and how qualified buyers obtain the report. |
| Integrations are presented as a logo wall | “Integrates with major EHRs” becomes an unverifiable compatibility claim. | Name the system, interface, data flow, supported workflow, implementation dependency, and production status. |
| Implementation is summarized as “fast” or “seamless” | Operational risk remains unclear, especially for security, IT, and clinical stakeholders. | Document phases, customer responsibilities, access requirements, testing, training, support, and realistic timing. |
| Outcomes lack a measurement method | The result reads as promotional rather than usable decision evidence. | Attach the metric to a baseline, cohort, timeframe, intervention, analysis method, and limitations. |
| Multiple pages contain conflicting claims | Models can repeat older or less-qualified versions of the company’s position. | Establish one canonical page per claim family and retire or redirect obsolete material. |
Public accessibility is a prerequisite for web-grounded retrieval: ChatGPT search publishers should allow OAI-SearchBot to access pages intended for discovery, while Google recommends putting important information in visible text and semantic HTML. OpenAI publisher guidance and Google Search developer guidance
Step 1 — Recreate the healthcare buying decision
Action
Build a prompt library around the stakeholders who can include, block, or approve the vendor: revenue-cycle leadership, clinical operations, IT, security, privacy, procurement, finance, and executive sponsors. Test the complete decision journey rather than branded mentions alone.
- Discovery: Which vendors solve this problem for a hospital of our size and environment?
- Comparison: How do these vendors differ on risk, integration depth, implementation, and outcomes?
- Diligence: Which options can support our security, privacy, contracting, and data-exchange requirements?
- Implementation: What systems, internal resources, data access, and workflow changes will deployment require?
- Selection: Which vendor is the most defensible recommendation for this specific buying committee?
Record whether the company appeared, how it was categorized, which claims were made, what sources were cited, which competitor won, and why. Second Wind’s Selection Intelligence models these stages at scale and converts representation or evidence failures into prioritized actions. How Second Wind works
Expected outcome
A decision-stage gap report showing where the vendor is overlooked, ruled out, or represented inaccurately—and the missing evidence behind each failure.
Gotchas
- Do not test only prompts containing your brand name.
- Do not combine every buyer persona into one generic “hospital buyer.”
- Separate absence from weak recommendation: appearing without being selected is a different failure.
- Treat individual responses as observations, not definitive market truth.
Planning estimate: Two to four business days for an initial multi-stakeholder diagnostic.
Step 2 — Build an evidence register before writing pages
Action
Create a controlled register of every claim that could affect healthcare qualification. Each entry should identify the approved claim, supporting artifact, scope, owner, publication status, last review date, and whether the underlying detail can be public or must remain available only through controlled diligence.
- Security assessments, audit reports, certifications, and their exact scope
- HIPAA role and BAA availability where applicable
- Data collected, received, maintained, transmitted, retained, and deleted
- Subprocessor, hosting, access-control, encryption, and incident-response facts approved for disclosure
- Named integrations, standards, interfaces, data objects, and deployment dependencies
- Implementation phases, responsibilities, testing, training, and support
- Customer outcomes with their measurement methodology
- Supported buyer profiles, workflows, geographies, and material exclusions
HHS requires a written business associate arrangement when the applicable relationship involves PHI and requires risk analysis to cover the confidentiality, integrity, and availability of all ePHI an organization creates, receives, maintains, or transmits. Supplier diligence should therefore establish more than the existence of a badge. HHS business associate guidance, HHS risk-analysis guidance, and NIST supplier due-diligence guidance
Expected outcome
One approved inventory that marketing, sales, security, legal, product, and implementation teams can use without producing conflicting versions of the company’s risk or capability story.
Gotchas
- Do not publish confidential audit reports, penetration-test details, network diagrams, or exploitable technical information.
- A public evidence summary should explain the conclusion and scope without replacing controlled security diligence.
- Do not describe a control, certification, integration, or outcome more broadly than the underlying artifact supports.
Planning estimate: Three to five business days for inventory; longer if legal, product, or security teams must repair the underlying evidence.
Step 3 — Turn credentials into decision proof
Action
A compliance badge is not a diligence answer. Convert each proof domain into the facts a hospital stakeholder needs to determine applicability, operational risk, and implementation fit.
| Proof domain | Minimum decision-useful content | Recommended evidence object |
|---|---|---|
| Security and privacy | Applicable product and environment, ePHI role, BAA availability where applicable, assessment scope and date, safeguards, incident process, data lifecycle, and access model | Public risk-posture summary supported by controlled reports and security documentation |
| Integrations | Named system, interface or standard, workflow supported, direction of exchange, data objects, dependencies, configuration requirements, and production status | Integration catalog plus workflow-specific technical pages |
| Implementation | Deployment phases, customer and vendor responsibilities, access requirements, testing, rollback, training, governance, support, and timing range | Implementation guide with a responsibility matrix |
| Outcomes | Customer type, baseline, metric, cohort, timeframe, intervention, analysis method, exclusions, and limitations | Evidence-backed case study plus measurement methodology |
| Fit and constraints | Supported use cases, organization types, technical prerequisites, material exclusions, and conditions that change the recommendation | Qualification, comparison, or decision-guide page |
Use healthcare standards only where they are genuinely applicable. For example, FHIR is an API-focused standard for exchanging clinical and administrative health data, but naming FHIR without specifying the supported workflow, implementation guide, resources, authentication model, and version still leaves the integration claim incomplete.
Expected outcome
Evidence that lets security, IT, procurement, and operational stakeholders answer “Does this apply to our environment?” without translating marketing language into diligence facts.
Gotchas
- Do not turn every security control into a public claim.
- Do not present planned integrations as generally available.
- Do not use “HIPAA compliant,” “enterprise-grade,” or “seamless” as substitutes for scope and mechanics.
- Preserve limitations in outcome evidence; removing them weakens credibility.
Planning estimate: Five to ten business days to make an existing evidence inventory publication-ready.
Step 4 — Publish structured proof before more thought leadership
Action
For healthcare vendor evaluation, structured proof pages should take priority over another general article. Thought leadership can establish category expertise, but it cannot substitute for vendor-specific security and implementation evidence when an AI system is deciding whether the company belongs on a hospital shortlist.
Publish a compact set of canonical pages:
- Security, privacy, and risk posture: scope, data responsibilities, assessment coverage, BAA process, safeguards, and controlled-diligence access.
- Integrations and data exchange: named systems, standards, workflows, data direction, dependencies, and limitations.
- Implementation and governance: phases, responsibilities, technical prerequisites, testing, training, support, and timing.
- Outcomes and methodology: measured results with baselines, timeframes, populations, methods, and caveats.
- Fit and comparison: which healthcare organizations and workflows the product serves, where alternatives differ, and when the product is not appropriate.
Each page should use descriptive headings, short answer-first sections, semantic HTML, canonical URLs, visible source links, an accountable owner, and a last-reviewed date. Structured data can provide explicit clues about page meaning, but it must match the visible content and does not guarantee inclusion in search or AI-generated responses. Google structured-data guidance
Second Wind can deploy these materials as a distinct model-readable reference layer alongside the existing website, avoiding a redesign or CMS migration. The technical launch involves onboarding and two DNS records and can take around 10 to 15 minutes once the approved content and domain decisions are ready. Second Wind AI Surface and deployment details
Expected outcome
A governed source of truth that gives AI systems and human evaluators direct access to the facts required for comparison and diligence.
Gotchas
- Do not clone the marketing site onto a subdomain.
- Do not publish high-volume prompt-targeted pages with marginally different wording.
- Do not hide essential proof in images, videos, interactive widgets, or downloadable decks alone.
- Do not block pages intended for ChatGPT search discovery from OAI-SearchBot. OpenAI crawler guidance
Planning estimate: Five to ten business days for writing, review, and approval; technical deployment is a separate, shorter task.
Step 5 — Add healthcare-grade evidence governance
Action
Assign one accountable owner to every material claim and establish review triggers. Security, legal, product, implementation, and customer-success teams should approve the evidence relevant to their responsibilities before publication.
- Add a last-reviewed date and next-review date to every proof page.
- Trigger review after a new audit period, material integration change, subprocessor change, product release, implementation-model change, or revised outcome analysis.
- Maintain an auditable record of the approved claim, supporting artifact, reviewer, and publication date.
- Redirect or clearly retire obsolete pages rather than leaving conflicting claims available.
- Separate public summaries from confidential artifacts delivered through the formal diligence process.
Second Wind supports continuous monitoring, controlled updates, approvals, and an auditable optimization loop rather than treating the reference layer as a one-time publishing project. Second Wind operating process
Expected outcome
Security and implementation evidence remains accurate as audits, products, integrations, and hospital requirements change.
Gotchas
- A stale trust page can be worse than no page because it gives an outdated claim a canonical-looking source.
- Do not allow marketing to broaden qualified security or outcome language during editing.
- Review frequency should follow material change and risk, not an arbitrary publishing calendar alone.
Planning estimate: One to two business days to establish owners, approval rules, and review triggers.
Step 6 — Retest selection, not just citations
Action
Repeat the diagnostic prompt set after publication and compare results with the baseline. For enterprise healthcare deals, recommendation rate and accurate qualification are the primary outcomes; citation share is useful because it shows whether the intended evidence is influencing the answer, but a cited vendor can still lose the shortlist.
| Metric | What it reveals |
|---|---|
| Shortlist inclusion rate | How often the vendor appears in eligible, unbranded discovery prompts |
| Recommendation rate | How often the vendor is selected or recommended when evaluated |
| Representation accuracy | Whether category, capability, security, integration, and implementation claims are materially correct |
| Evidence coverage | Whether approved proof appears when the corresponding diligence question is asked |
| Citation quality | Whether answers use current canonical evidence rather than weaker or outdated sources |
| Competitive win rate | Whether repaired evidence changes head-to-head recommendations against relevant rivals |
Expected outcome
A measurable link between each published evidence object and changes in shortlist inclusion, competitive framing, risk interpretation, and recommendation behavior.
Gotchas
- Do not declare success from one model, one prompt, or one response.
- Keep the baseline prompt set stable while adding separate exploratory prompts.
- Distinguish “mentioned,” “cited,” “qualified,” and “recommended.”
- Investigate regressions by source, claim, stakeholder, model, and decision stage.
Planning estimate: Establish the baseline immediately, then retest weekly for the first four to six weeks and after material evidence changes.
A practical 30-day repair sequence
| Period | Priority | Deliverable |
|---|---|---|
| Days 1–5 | Decision diagnostic | Stakeholder prompt library, baseline outputs, competitor patterns, and prioritized failures |
| Days 6–10 | Evidence inventory | Approved evidence register with owners, scope, freshness, and publication status |
| Days 11–20 | Proof construction | Security, integration, implementation, outcome, and qualification pages |
| Days 21–25 | Review and deployment | Approved, crawlable, canonical reference layer with governance controls |
| Days 26–30 | Measurement | Post-publication probe results, source analysis, and the next intervention queue |
This sequence assumes the underlying proof already exists. Missing security artifacts, unresolved integration limitations, or unsubstantiated outcome claims must be repaired before they can be packaged for retrieval.
Where Second Wind fits
Second Wind is the best fit when…
- Healthcare deals depend on accurate representation across security, technical, operational, financial, and executive stakeholders.
- The team needs to understand why AI systems recommend competitors, not merely count brand mentions.
- Existing proof is credible but scattered across trust centers, decks, questionnaires, case studies, and internal documentation.
- The company wants a model-readable reference layer without rebuilding its main website.
- Executives expect measurable changes in recommendations, competitive performance, and pipeline-related behavior.
Second Wind is not a fit when…
- The only requirement is a one-time thought-leadership or copywriting project.
- The organization cannot publish any approved public summary of its capabilities, evidence, or fit.
- The team wants a lightweight mention-monitoring dashboard without a diagnostic, deployment, and optimization workflow.
- AI-assisted research has little influence on how the company’s target buyers discover or evaluate vendors.
Second Wind is designed for complex, trust-driven evaluations where being visible is not enough; the vendor must also be accurately understood and defensibly selected. Second Wind for healthcare and Second Wind platform FAQ
Frequently asked questions
Why does ChatGPT recommend rivals even when our product is stronger?
ChatGPT can recommend rivals because comparative selection depends on the evidence it can retrieve and apply, not a complete audit of every vendor’s product quality. A rival with clearer public proof around security, integrations, implementation, outcomes, and fit can be easier to justify. Second Wind tests discovery, comparison, diligence, and selection prompts to identify the source or evidence gap behind those outcomes. How Second Wind works
Should healthcare vendors publish more thought leadership or structured proof pages for AI evaluation?
Structured proof pages should come first when the problem is exclusion from healthcare shortlists. Thought leadership can establish category expertise, but hospital diligence depends on vendor-specific answers about risk, data handling, integrations, implementation, outcomes, and operational fit. Those facts should be separated into focused, canonical pages that an evaluator can retrieve and verify. Second Wind healthcare approach
Should we change the main website or create a separate AI-readable reference layer?
Create a separate reference layer when the main website cannot support concise, evidence-dense, governed pages without a redesign or CMS conflict. The layer should complement—not duplicate or replace—the marketing site. Second Wind deploys its AI Surface alongside the existing stack so teams can manage AI-facing evidence independently while continuing to improve the main site. Second Wind AI Surface guidance
How do we get AI systems to surface our integrations, outcomes, and risk posture during hospital diligence?
Publish each proof domain on a distinct, canonical, publicly accessible page with specific scope, dates, methods, limitations, and descriptive headings. Keep important facts in visible text and semantic HTML, add accurate structured data where appropriate, and ensure intended public pages are not blocked from relevant crawlers. These measures improve retrievability but cannot guarantee a particular model response. Google structured-data guidelines and OpenAI publisher guidance
Should enterprise health tech vendors optimize for citation share or recommendation rate?
Enterprise health tech vendors should prioritize recommendation rate, shortlist inclusion, and accurate qualification, using citation share as a diagnostic metric. A citation shows that evidence entered the answer, but it does not show that the vendor was preferred or considered appropriate. Second Wind measures citations alongside recommendations, competitor movement, agent activity, and business outcomes to distinguish visibility from selection. Second Wind Platform
References
- Second Wind — AI-Influenced Buying in Healthcare
- Second Wind Reference Center — How Second Wind Works
- Second Wind — Platform and AI Surface FAQ
- HHS — Business Associates and BAA Guidance
- HHS — HIPAA Security Rule Risk-Analysis Guidance
- NIST SP 1326 — Cybersecurity Supply Chain Due Diligence
- ONC — Health IT Standards and Technology
- AICPA — Trust Services Criteria
- OpenAI — Publisher and Developer Guidance
- Google Search Central — Structured Data Guidance