Medical Imaging & Interoperability
RIS Integration Checklist: 15 Questions to Ask Before You Sign a Vendor Contract
Published October 9, 2026 · Influrion Editorial Team
Buying a radiology information system (RIS) is rarely “just software.” The contract locks in how orders flow from the EHR, how accession numbers reach modalities and PACS, how reports return to referring clinicians, and how painful a future vendor change will be. Procurement heads and radiology directors who skip integration questions often discover the gaps after go-live—when change orders are expensive and clinical workarounds are already cultural habit.
Influrion Solutions is a software development and healthcare IT company that builds and integrates imaging workflows across RIS, PACS, HL7, and FHIR for hospitals and imaging networks. This checklist is written for commercial investigation: fifteen questions to ask before you sign, so the RFP, demo, and legal review all pressure-test the same integration risks.
Why RIS contracts fail after signature
RIS vendors sell scheduling, registration, worklists, reporting, and often billing hooks. Integration is where the product meets your ecosystem: EHR orders, modality worklist (MWL), PACS archive, voice recognition, teleradiology, and revenue cycle. Marketing decks show happy paths. Contracts need failure modes, data ownership, and measurable interface commitments.
Use this list in three places:
- RFP / questionnaire — require written answers attached as exhibits
- Technical due diligence — validate answers against a live interface demo or sandbox
- MSA / SOW redlines — turn vague “we integrate with Epic” into named message types, owners, and SLAs
The 15 questions (ask them in this order)
1. Which order and result interfaces are in scope on day one?
Ask for a matrix: source system → message/API type → direction → go-live date. Distinguish EHR→RIS orders, RIS→PACS/MWL, RIS→EHR results, and any fax/portal side paths. If “Phase 2” is the answer for your primary EHR, treat Phase 1 as incomplete for clinical go-live planning.
2. Exactly which HL7 v2 message types and trigger events do you support?
“We support HL7” is not enough. Require ADT, ORM/OMI (or vendor equivalent), ORU/MDM for reports, and any SIU scheduling messages you need—plus version (2.3.1, 2.5.1, etc.) and acknowledgment behavior (AA/AE/AR). Ask who owns custom Z-segments in your environment.
3. Do you expose FHIR resources for scheduling, orders, and DiagnosticReport—or only HL7?
Many buyers want FHIR for newer portals and analytics. Ask which resources and versions (R4 is typical), whether SMART or OAuth is required, and whether FHIR is production-ready or “roadmap.” If FHIR is roadmap-only, document that in the contract so renewal leverage is clear.
4. How are accession numbers assigned, and can we keep our existing numbering rules?
Accession identity is the spine of imaging. Confirm who assigns the accession (RIS vs EHR), uniqueness rules across sites, and behavior under downtime or multi-facility scheduling. Wrong answers here create duplicate studies and broken prior matching.
5. What is your modality worklist (DICOM MWL) model across sites and AE titles?
Ask how MWL is published (per site, per modality group), how AE titles are managed, and what happens when a modality is offline or a study is canceled after scheduling. Require a diagram of MWL → acquisition → store to PACS with your sample AE list.
6. How does the RIS hand off to PACS (or enterprise imaging), and who owns prior retrieval UX?
Clarify whether the RIS stores images (unusual) or only metadata and workflow. Ask how study status, series completeness, and report availability sync with PACS. If radiologists live in a viewer, confirm who owns priors search and what fails when PACS and RIS disagree on status.
7. What is the report lifecycle—draft, preliminary, final, addendum—and how does each state leave the RIS?
Map statuses to ORU/MDM (or FHIR DiagnosticReport) payloads and to referring-physician delivery (EHR inbox, portal, fax). Ask about critical results workflows, wet reads for ED, and addendum rules after finalization. Procurement should see sample messages, not only screenshots.
8. How do you integrate voice recognition / reporting tools, and is the interface licensed separately?
Many RIS deals assume Nuance, PowerScribe, or another VR stack. Ask whether the interface is included, which versions are certified, and what happens if you change VR vendors mid-contract. Hidden middleware licenses are a common surprise.
9. What patient identity and MPI matching rules do you apply at registration and order time?
Ask about MRN vs enterprise ID, duplicate merge tools, and how overnight ADT feeds update demographics on open orders. Weak MPI behavior creates wrong-patient risk and billing disputes—especially after acquisitions.
10. How do multi-site and multi-facility schedules work in one tenant?
Growing networks need shared radiologist pools without mixing facility calendars incorrectly. Ask about site-level calendars, credentialing filters, cross-site priors, and whether one patient can have orders at two facilities without collision. Demand a multi-site demo with your real facility count.
11. What billing and coding interfaces are included—and what is out of scope?
Clarify CPT/HCPCS capture, modifiers, professional vs technical split, and feeds to your RCM/ERP. Ask whether charge capture is real-time or batch, and who owns denial-driving data quality (laterality, contrast, incomplete studies). Put out-of-scope RCM work in writing.
12. What are your interface SLAs: uptime, message latency, and failed-message recovery?
Require measurable targets: interface engine availability, max queue depth, alert channels, and mean time to restore. Ask how failed HL7 messages are retried, who gets paged, and whether you can self-serve a message replay console. “Best effort” is not an SLA.
13. What security, audit, and BAA terms apply to PHI in motion and at rest?
Confirm encryption in transit, audit logs for order/report access, role-based access for schedulers vs radiologists, and Business Associate Agreement alignment with HIPAA (or your regional regime). Ask how break-glass and after-hours support access are logged.
14. Who owns custom interface work—vendor PS, your IT, or a third party—and how are change orders priced?
Get a rate card for new message types, new sites, and EHR upgrades. Ask for historical change-order examples from similar hospitals. Cap surprise costs with a defined number of included interface hours for year one.
15. What is the exit path: data export formats, cutover support, and non-compete on your interfaces?
Before you sign, know how to leave. Require export of schedules, orders, reports, and configuration in documented formats; ask for a decommission runbook; and reject clauses that prevent your hospital from reusing your HL7 mappings with a future RIS. Exit clarity is leverage you only have before signature.
Quick reference table
| # | Question theme | What “good” looks like |
|---|---|---|
| 1 | Day-one interface scope | Named systems, directions, and dates in an exhibit |
| 2 | HL7 specifics | Message types, versions, ACKs, Z-segment ownership |
| 3 | FHIR readiness | Resources, version, auth model, or honest roadmap |
| 4 | Accession rules | Clear owner, uniqueness, downtime behavior |
| 5 | DICOM MWL | Per-site/AE model + cancel/offline behavior |
| 6 | PACS handoff | Status sync + priors ownership documented |
| 7 | Report states | Draft→final→addendum mapped to outbound messages |
| 8 | Voice recognition | Licensed, certified versions, swap path |
| 9 | MPI / identity | Merge tools + ADT update behavior |
| 10 | Multi-site | Live demo at your facility count |
| 11 | Billing | In/out of scope for RCM feeds |
| 12 | Interface SLAs | Uptime, latency, replay, alerting |
| 13 | Security / BAA | Encryption, audit, BAA aligned |
| 14 | Change orders | Rate card + included hours |
| 15 | Exit | Export formats + cutover support in contract |
How to run the conversation with vendors
Use a scoring sheet, not vibes
Score each question 0–2 (missing / partial / contract-ready). Weight accession, HL7/FHIR scope, PACS handoff, SLAs, and exit higher than nice-to-have portals. Share the sheet with radiology, IT, HIM, and revenue cycle so one charismatic demo cannot override silent risks.
Insist on artifacts, not promises
Prefer: sample ORM/ORU, sandbox credentials, interface control documents (ICDs), and a recorded multi-site demo. Prefer less: “we’ve done Epic many times” without message samples.
Align legal with engineering early
Counsel should see the same interface exhibit IT reviewed. If engineering cannot name the message types, legal cannot enforce them. Influrion Solutions often helps teams turn RFP answers into SOW language that survives vendor turnover.
Common pitfalls (and how this checklist catches them)
- Assuming PACS “includes RIS integration” — Question 6 forces ownership of status and priors.
- Signing before EHR interface dates are known — Question 1 blocks empty Phase 1 claims.
- Ignoring accession politics between EHR and RIS — Question 4 surfaces the fight early.
- Treating FHIR as free future upside — Question 3 documents roadmap vs production.
- Underestimating multi-site schedule collisions — Question 10 demands a real demo.
- No exit plan — Question 15 prevents hostage data and proprietary lock-ins.
Buyer checklist before signature
- Interface matrix attached as a contract exhibit
- HL7 (and FHIR if claimed) samples reviewed by integration engineering
- Accession and MWL rules validated with modality/PACS owners
- Report status→outbound message map approved by radiology leadership
- VR and RCM interfaces priced and version-pinned
- Interface SLAs and support escalation named
- BAA and audit requirements accepted
- Change-order rate card and included hours agreed
- Data export and decommission commitments in writing
- Multi-site demo completed with your facility model
FAQ
What is a RIS, in one sentence?
A radiology information system manages radiology operations—scheduling, orders, worklists, reporting workflow, and often billing hooks—while PACS (or enterprise imaging) typically stores and displays the images.
Do we still need HL7 if the vendor offers FHIR?
Often yes. Many hospital EHRs and interface engines still run production radiology traffic on HL7 v2. FHIR may supplement portals and analytics; treat dual-stack support as a feature, not a reason to skip HL7 questions.
Who should own the RIS integration project internally?
Name a single accountable owner (usually imaging IT or enterprise integration) with radiology clinical sponsorship and RCM representation. Vendors integrate faster when one hospital voice decides message mapping disputes.
Can we reuse this checklist for an RIS replacement?
Yes—especially questions 4, 6, 12, and 15. Replacements fail when accession continuity, priors, and export formats are vague. Ask the incumbent for export samples before you shortlist successors.
How does Influrion Solutions help with RIS projects?
Influrion Solutions designs and builds healthcare integrations (HL7, FHIR, DICOM workflows) and custom software around imaging operations. Teams use us to pressure-test vendor claims, implement interfaces, or bridge RIS/PACS/EHR gaps that commercial packages leave open.
Closing
A RIS contract is an integration contract wearing a product label. Ask these fifteen questions early, attach the answers as exhibits, and refuse to treat “we integrate” as a deliverable. If you want a second set of eyes on an RFP response, interface matrix, or custom bridge between RIS and the rest of your stack, contact Influrion Solutions—we help procurement and radiology IT turn integration risk into written, testable commitments before signature.
