← Back to blog

Health System Partnership Deal Structuring: A Founder Playbook

August 19, 2026
Health System Partnership Deal Structuring: A Founder Playbook

The winning structure looks like this: a Master Agreement paired with a Statement of Work or Order Form for services, a Business Associate Agreement (BAA) or Data Use Agreement (DUA) for anything touching patient data, and a Sponsored Research Agreement (SRA) when the engagement really is a research collaboration. That framework, plus an explicit carve-out letting the startup retain de-identified derivative datasets, is what separates founders who convert a pilot into recurring revenue from those who get stuck negotiating the same terms twice. Before you sign anything, put five things on paper: pilot success criteria, who pays for what, an IP ownership carve-out, post-termination data handling, and an ongoing performance-monitoring clause. Health system counsel will respect a startup that walks in with this structure already drafted, and The StartupMD builds this exact framework with founders before they ever sit down with a health system's legal team.

  • Pilot success criteria defined in numbers, not adjectives
  • Cost allocation spelled out before kickoff, not after the invoice
  • IP ownership carve-out for anything the startup's model touches
  • Post-termination data handling, including deletion and certification
  • A performance-monitoring clause that survives past go-live

Key Takeaways

Structuring a health system partnership means pairing a Master Agreement with the right data document, BAA, DUA, or SRA, and negotiating an explicit derivative-data carve-out before you sign anything.

PointDetails
Match contract to stageUse a lightweight clinical evaluation agreement for pilots and reserve the full Master Agreement for commercialization.
Separate data documents by purposeA BAA covers service delivery, a DUA covers limited data sets, an SRA covers defined research outcomes.
Negotiate derivative data earlyRetain de-identified derivative datasets for model improvement while licensing the clinical use back to the health system.
Tie payment to KPIsLink pricing milestones to measurable thresholds, not calendar dates, to protect runway and reduce disputes.
Get expert help before signingThe StartupMD advises founders on contract structure, data carve-outs, and investor-ready commercial models before deals close.

Table of Contents

How Does Health System Partnership Deal Structuring Work by Stage?

Every durable health system deal moves through four stages, and the contract you use should match the stage you're actually in, not the one you hope to reach next quarter.

  1. Pilot (crawl): A single site or department, 60 to 90 days, governed by a limited clinical evaluation agreement or a narrow SOW under a placeholder Master Agreement. Objective: prove clinical or operational signal.
  2. Expanded pilot (walk): Multiple departments or a second site, 3 to 6 months, still contract-light but now requiring a full BAA and often a DUA if you're pulling structured datasets for analysis.
  3. Partial roll-out (run): System-wide deployment in select service lines, 6 to 12 months, operating under the full Master Agreement with commercial pricing exhibits attached.
  4. Full commercialization: Enterprise-wide license or subscription, typically multi-year, with renewal and expansion terms baked into the original exhibits.

Stage-gate triggers matter more than calendar dates. Before advancing, confirm:

  • Pre-agreed KPIs were hit, not just discussed
  • Data pipelines and EHR integration are stable in production
  • Compliance and IT security sign-offs are documented, not verbal
  • Budget owner has confirmed funding for the next phase

Which Contracts Handle Which Risk?

Founders often default to one generic "partnership agreement," and that's the fastest way to end up renegotiating everything six months later. Spread the risk across purpose-built documents instead.

The Master Agreement sets the durable terms, liability caps, confidentiality, insurance, governing law, and it stays largely untouched as the relationship grows. Tempus Labs structures its master agreement with strategic collaboration services defined in separate exhibits and order forms rather than folded into the base contract, which is exactly the pattern to copy: it lets you add a new hospital department or use case with a two-page addendum instead of a full renegotiation.

Layer in the right data document based on what the health system actually shares. A BAA covers any arrangement where your platform touches protected health information (PHI) as part of service delivery. A DUA is required specifically when you're receiving a limited data set for analysis, and Stanford's privacy office treats it as distinct from a BAA, not a substitute for one. An SRA applies when the relationship is really a defined research collaboration with a specific hypothesis and endpoint, and it typically carries publication rights and IRB oversight that a standard commercial contract doesn't.

Clause headings worth standardizing across every document: performance SLAs, IP ownership and licensing, data use and derivative rights, audit and security obligations, and termination with exit data handling.

Pro Tip: Draft your derivative-data clause once, as a standalone exhibit, and attach the same language to every BAA, DUA, or SRA you sign. Health system legal teams move faster when they see consistent, familiar language instead of a bespoke clause in every deal.

Who Owns the Data and the Model You Build From It?

This is where most founders lose value they didn't need to give up. PHI, limited data sets, de-identified data, and derivative model assets are four different things, and each carries different retention and use rights. PHI stays tightly restricted under HIPAA. A limited data set strips direct identifiers but still requires a DUA. Fully de-identified data, once it meets the Safe Harbor or expert determination standard, generally falls outside HIPAA's use restrictions. Derivative assets, meaning the model weights, embeddings, or algorithm improvements your platform generates from that data, are a separate category entirely, and most health system contracts don't address them unless you write the language yourself.

Stanford's own guidance on research collaborations recommends structuring these deals around a BAA or SRA depending on whether the work is service delivery or defined research, while explicitly negotiating the right to retain de-identified derivative datasets for algorithm refinement. That's the tactic to use.

  • Offer the health system a perpetual, royalty-free clinical use license for the product itself
  • Retain de-identified derivative datasets for your own model improvement or resale
  • If the health system pushes back, offer a single-digit revenue share tied specifically to products trained on their data
  • Put audit rights and deletion obligations at termination into the same exhibit, not a separate document

Place this language as an exhibit to the Master Agreement or inside the SRA itself, never buried in a generic data-sharing clause.

What Pricing Model Should You Propose?

Health systems have seen every pricing structure a startup can invent, so the question isn't which one is "best." It's which one matches your runway and your evidence base at this stage of the relationship.

A no-cost pilot in exchange for data access gets you in the door fastest but leaves you with no revenue signal for investors. A paid pilot with credits toward a future subscription protects your unit economics story while still lowering the health system's initial commitment. Fixed-fee sponsored research works well when the engagement is genuinely a research question, and the Vector Labs framework treats this as one of three fair structures, alongside the royalty-free license and single-digit revenue share models described above. Equity-for-data arrangements exist but are rare outside academic medical center innovation units, and they complicate your cap table for value that's hard to price.

  • Integration and API work: usually the startup's cost, unless the health system requires custom build
  • Clinical staff training: often shared, split by hours committed
  • Data extraction and prep: negotiate this explicitly, it's the most commonly forgotten line item
  • Cloud and hosting costs: startup's responsibility unless the deployment is on-premise

Tie every payment milestone to a KPI, not a calendar date.

What Governance Structure Convinces Both Sides to Scale?

Hands configuring digital meeting device

Health systems don't expand pilots because the technology works. They expand because a credible governance structure told them it was safe to.

Build a roster with a named clinical champion, an operational lead who owns day-to-day logistics, an information governance or privacy officer, a CISO or IT security representative, procurement, and your own vendor project manager. Each needs defined decision rights, not just a seat at quarterly meetings.

  • Clinical outcomes tied to the pilot's original hypothesis
  • Utilization metrics showing real adoption, not just logins
  • Turnaround time and cost-per-case where relevant to the workflow
  • Time-to-value and basic unit economics investors will ask about later

Rock Health's analysis of more than 2,000 digital health partnerships formed since 2020 found that success depends on operationalizing six domains: vision, governance, financials, measurement, data and IP, and ways of working. Set a reporting cadence, usually monthly during the pilot and quarterly after commercialization, and define escalation paths before a dispute forces you to improvise one.

Some contract terms aren't worth negotiating around, they're worth walking away from.

HIPAA compliance starts with the BAA, but a DUA governs the specific controls around any limited data set, and research collaborations may also require IRB approval before data changes hands. Federal fraud and abuse law adds a second layer: JAMA Health Forum's analysis of academic medical center innovation centers flags Anti-Kickback Statute and Stark Law exposure whenever commercial discounts, equity stakes, or free services are tied to referral relationships. Structure pricing so it can't be read as an inducement.

  • Unlimited liability with no cap tied to fees paid
  • Breach notification windows shorter than your incident response plan can realistically meet
  • Audit rights broad enough to demand access to your entire codebase, not just the deployed instance
  • Change-of-control clauses that let the health system terminate on your next funding round or acquisition

Pro Tip: Have your own counsel redline the indemnity and liability cap sections before the health system's legal team sends their first draft. It's far easier to negotiate down from your language than up from theirs.

How Do You Design a Pilot That Actually Converts?

A pilot designed only to "prove it works" produces a case study. A pilot designed to convert produces a signed commercial contract, and the difference is in the planning.

  1. Define scope tightly: eligible patient cohort, specific data schema, exact integration points with the EHR
  2. Build a training plan for clinical staff before go-live, not during week two
  3. Set monitoring and drift-detection checkpoints from day one, this is where most AI deployments quietly fail after the pilot ends
  4. Write measurable success criteria with numeric thresholds, not vague adjectives like "improved"
  5. Map the handoff: what contract amendments trigger automatically when thresholds are hit

AI Health Pulse's procurement analysis points to lifecycle monitoring gaps as a leading cause of AI deployment failure after a pilot succeeds. Founders who build monitoring into the pilot contract from the start avoid the renewal cliff that catches everyone else.

  • Success criteria should include a measurable threshold and a deadline, e.g. "reduce turnaround time by 20% within 60 days"
  • Build the procurement story around unit economics, not just clinical enthusiasm
  • Pre-negotiate what contract amendment triggers the transition to commercial pricing

What Should You Ask for in the First Negotiation Meeting?

Sequence your asks. Get clinical buy-in first, then bring in legal and information governance to harden the language, because leading with contract terms before anyone clinical has bought in kills more pilots than any redline ever will.

  • Confirm scope and cohort size before discussing data rights
  • Raise the BAA/DUA requirement early, it signals you understand HIPAA obligations
  • Ask directly about pilot KPIs and who signs off on go/no-go
  • Clarify termination and data-return terms before you're mid-pilot and it's too late to negotiate calmly

Three clause snippets worth having ready:

Derivative data license: "Startup retains all right, title, and interest in de-identified derivative datasets and model improvements generated from Health System data, subject to Health System's perpetual, royalty-free license to use the resulting Product for clinical purposes."

Post-termination deletion: "Upon termination, Startup shall delete or return all PHI and limited data sets within thirty (30) days and provide written certification of destruction, excluding de-identified derivative datasets retained under Section [X]."

Conversion mechanic: "Upon achievement of the KPIs set forth in Exhibit A, the parties shall execute a commercial Order Form under this Master Agreement within sixty (60) days, at the pricing terms set forth in Exhibit B."

What Founders Consistently Get Wrong in These Negotiations

The clause that swings more deals than any other isn't pricing, it's the derivative data carve-out, and most founders don't raise it until the health system's lawyers have already drafted a data clause that gives the institution everything. By the time you're redlining someone else's first draft, you've already lost the framing.

The other pattern I'd flag: founders treat clinical, legal, and procurement as sequential gates instead of parallel stakeholders who need to hear the same pitch at roughly the same time. A clinical champion who loves your platform can't override a procurement officer who was never briefed on the commercial model, and by the time IG discovers the data terms in month four, the clinical relationship you spent months building starts to erode. Align all three early, even informally, and the contract negotiation moves faster because nobody is discovering the deal structure for the first time in a legal review.

Paul Bergeron, MD, MBA, founded The StartupMD after more than 25 years across medicine and healthcare business leadership, and now advises healthcare SaaS founders directly on exactly these negotiations.

How The StartupMD Helps You Structure the Next Deal

Most founders negotiating a health system contract for the first time are doing it without anyone in the room who has sat on the health system's side of the table. The StartupMD closes that gap. Paul Bergeron, MD, MBA brings both clinical and business leadership experience to the specific mechanics covered here: stage-gating your pilot, drafting the data and IP carve-outs, and building the commercial model your investors will actually underwrite.

The StartupMD

Engagements come in two forms: a project-based advisory sprint focused on a specific deal or contract review, or an ongoing fractional Chief Medical Officer retainer for startups negotiating multiple health system relationships at once. Founders who want a framework tailored to their specific commercial model can start with The StartupMD's revenue model evaluation guide, built specifically for investor-facing conversations about pricing and unit economics. If you're heading into a negotiation in the next few weeks, request a short intro call through The StartupMD to talk through your specific contract before you send the next redline.

Frequently Asked Questions

What is the fastest way to start structuring a health system partnership deal? Start with a narrow pilot agreement or SOW under a placeholder Master Agreement, and attach the BAA or DUA immediately if any patient data changes hands. Full commercial terms come later.

Do I need a Sponsored Research Agreement instead of a standard contract? Only if the engagement is a defined research collaboration with a specific hypothesis, IRB oversight, and publication expectations. Standard service delivery belongs under a BAA, not an SRA.

How do I keep ownership of the AI model I build from health system data? Negotiate a royalty-free perpetual clinical use license for the health system while retaining de-identified derivative datasets for your own model improvement, and put that language in a standalone exhibit you reuse across deals.

What's the biggest compliance risk in health system partnership deal structuring? Anti-Kickback Statute and Stark Law exposure when pricing discounts or free services are tied, even loosely, to referral relationships. Structure commercial terms so they can't be read as an inducement.

Frequently Asked Questions — overview diagram

How long does a typical pilot-to-commercial transition take? Expect 60 to 90 days for an initial pilot, 3 to 6 months for an expanded pilot, and 6 to 12 months before full commercialization, though timelines shift with health system procurement cycles.

Sources