S1E2 Health IT Infrastructure as a Commodity (ft. Zafar Chaudry, Seattle Childrens)
Healthy Uptime Podcast Dr. Zafar Chaudry _ Jordan Cooper-20260820_123610-Meeting Recording
August 20, 2026, 4:36PM
21m 22s
Jordan Cooper started transcription
Jordan Cooper 0:03
with Zafar Chowdhury, the former CDAIO of Seattle Children's and a healthcare industry expert for 40 years and a former or a licensed internist. So Zafar, thank you so much for joining us today.
Zafar Chaudry, MD 0:20
Thank you for having me, Jordan.
Jordan Cooper 0:21
So today we're going to be discussing trends in health IT, especially we want to focus on specializing health IT versus commodity health IT. So if you could, could we just start off by defining what those two concepts are and why would anybody be interested in moving towards commoditizing health IT?
Zafar Chaudry, MD 0:41
Yeah, so if you look at the services that health systems actually deliver to their clinicians and users, you can divide those. So they're the specialty services running unique applications like the electronic medical record, like ERP systems,
other clinical systems. Those are specialized services in my definition. Whereas you have commodity services, which you can buy or supply from anywhere, and that includes data centers, infrastructure, desktop services, service desk,
analytics, those type of services are services that you can actually buy from anyone. Traditionally, health systems have had a singular service where they do everything, infrastructure, networking, service desk, clinical applications, business applications.
They do everything for the health system. But as we start moving towards a time and a climate in healthcare where new federal bills will put the squeeze on hospital systems and hospital systems will lose revenue or have to be smarter,
Jordan Cooper 1:43
Mhm.
Zafar Chaudry, MD 2:01
with the money that they earn, then health IT groups in health systems need to start thinking about what are they really good at providing their customers and what are the things they could buy on scale from someone else to help provide the service they need
at the service level that they need it at, around the clock, at a price point that makes more sense. Because to give you an example, if you run a data center in downtown Seattle, you hire people to run that data center. You're paying top dollar rates from a labor perspective as well as a real estate perspective.
And clinical space is more valuable than data center space, because you can generate revenue. Now, if you don't do that in downtown Seattle, and you do that in rural Texas, as an example, the costs are lower for labor, for real estate, per square foot.
So you can actually reduce your costs that way. So I think people need to think about, well, what services are the frontline services they need to keep employees trained up on? So yeah, things like EMR, clinical workflows, you need those people to help the clinicians.
day in, day out. But look, turning on a server, adding storage, configuring a network switch, making sure your Wi-Fi works, making sure that a doctor has a working laptop or a working desktop, or even a printer, yes, God forbid, we still use printers, then those need to be thought of in a different way.
Jordan Cooper 3:43
So it sounds like there are a lot of value adds and opportunities for cost reductions by outsourcing this commoditized IT services. And I hear you distinguishing between the specialty services that need to be providing support to revenue generating activities on site versus those commodity services that can be outsourced.
I suppose, I know that when you were CDAIO of Seattle Children's, you made a decision to outsource not only Epic hosting, but also hosting of third party applications. And part of that process entailed rebadging some of your employees. I think a lot of leadership that may be considering
commodity buying their IT services from elsewhere may be concerned about the welfare of their employees. And again, you did mention how labor costs in addition to real estate costs might be less in Seattle. So suppose you have a whole cadre of employees who have been loyal to you. You want to take care of them. They're generating whatever income they're generating and you're looking to generate savings from that income.
by potentially moving them, as you say, to Texas or outsourcing them globally. How would you speak to that executive leader, maybe the CIO, who's thinking about doing this and how he could handle the opportunity to take care of his people while also reducing his or her costs?
Zafar Chaudry, MD 5:06
Yeah, so I think you don't start this journey just focusing on cost. I think if you've had loyal employees, you have to think about them. You have to think about their future, you have to think about their growth, and you have to think about their training. All the things we don't do well in healthcare. So if you look at any health
system IT budget, they spend minimal amounts on staff training every year. So employees don't get the best training, the best certifications, the best educational programs. It's just not enough money to go around. So yes, you have to absolutely think about the people. This type of work, buying services from someone else,
It's 100% a change management program. So you have to have good communication, good reasons as to why you do it. And look, I did not do it predominantly for saving money.
Jordan Cooper 5:52
Mm-hmm.
Mhm.
Zafar Chaudry, MD 6:02
Many of the problems we had was how do we give the best service delivery around the clock? And with the best teams in the world on the ground, none of your teams can work 24 hours a day. They just can't. Just as much it's very difficult for health systems to provide the best SLAs.
Uptime. You know, I defined a service as part of this where I wanted an uptime of five nines on every system. That's very hard to achieve internally without buying more hardware and accumulating more technical debt. The other thing we were trying to solve for was technical debt.
because in the traditional model of buying infrastructure, networking equipment.
You go out, you buy all this equipment, you use your capital money, comes with a warranty, and then you deprecate that equipment over a five to seven-year life cycle. Once you hit seven years, the equipment's outdated. You then need a couple 100 million to refresh that equipment in a climate where there isn't a couple of 100 million sitting around in a health system.
With A consumption-based service with a third party, they will keep your equipment running to a standard that you have requested in a contract, and you won't have to worry about those $100 million hits every seven years of buying new equipment because it's baked into the contract. If you rebadge teams,
Yes, it's difficult. It's a change management program. But when you look at the teams, the teams will get access to a technology vendor that you, whoever you choose to partner with, that technology vendor will give them the training that they were lacking.
Jordan Cooper 7:46
Mhm.
Zafar Chaudry, MD 7:47
give them access to improve themselves and even grow within that company. Because if you look at a small pediatric health system with a small footprint, how far can you really go? How far can you really progress as an employee before you have to leave and find another job?
If you look at a big technology company that's global, they have numerous ways to move, grow, expand, serve more clients in that exact same company because they're global, right?
Jordan Cooper 8:24
So I'd like to turn back to your goal. I heard you mention that the goal wasn't necessarily to save money or provide more training or certification opportunities for your employees, but essentially your goal was to fulfill your mission, which was support the organization in order to provide the best service delivery around the clock. Now, you dialed in and said, in order to do that, I want...
certain service level agreements, I want 5 nines of uptime, and I want to be able to kind of amortize my capital costs in a predictive way over time. So many.
Zafar Chaudry, MD 8:56
Yeah, we also, just to add, we also wanted to make sure that the employees also had gainful employment.
Because they will still be supporting our mission, just wearing a different t-shirt.
Jordan Cooper 9:10
Correct. So many CIOs listening to this episode right now says, all right, I kind of buy into that. That's also my goal. It's also my concern. Maybe we're going to choose Epic hosted by Epic. Maybe we're looking to host Epic and GCP or Azure or AWS. And I think they might want to hear your opinion about why
hosting in a private cloud versus what they should consider if they're considering hyperscale public cloud or perpetuating on-prem.
Zafar Chaudry, MD 9:40
So there's nothing wrong with public cloud. The challenge with public cloud becomes twofold. So one is, I have not come across in my work in this, I've not come across a public cloud service that will guarantee 5 nines uptime on anything. The standard public clouds are only 3 nines.
Jordan Cooper 9:57
Mm.
Zafar Chaudry, MD 10:01
Their SLAs are not typically backed by financial penalties, more so by service credits. And to run a stack in public cloud, you would still need a team of people to do that. And the public cloud companies don't rebadge your teams, nor do they provide
a managed service in the public cloud, they'll recommend a partner for you to do that. So now you've got a hosting company, which is the public cloud to manage, and then a third party who may rebadge your teams to manage that public cloud instance. So now you're dealing with two vendors, two contracts,
two times the complexity. When you look at a private cloud, or I like to call a clinically first cloud, when you look at that model, you as a CIO shouldn't care what hardware it sits on where it sits. What you should care about is, can you get the service levels? Can you get
the vendor, whoever vendor you choose, can you get the vendor to run it, support it, feed it, grow it?
And also, can you get the vendor to control your consumption costs for a duration of the contract? So in public cloud, it's very rare that any public cloud company is going to sign up to, this is the maximum amount you will pay every year because it's consumption based. And if you grow, they don't typically build growth into it.
But in a private cloud type of model, you can define what your consumption is, what your max consumption may be, what your growth factor would be, and then you end up getting a fixed price engagement for the duration of your negotiation. So whether that's a three-year
five year, seven-year, 10 year. It's all up to you what you want to do for your health system. But if you can then do that, you are now assured A trajectory for your organization that is palatable year on year. And that helps CFOs to future planning.
Right?
Jordan Cooper 12:06
So, Zafir, as you mentioned, consumption-based pricing and controlling costs over time. I think many of our listeners may be thinking about the elephant in the room, which these days is AI and token usage, which sometimes I've heard of some health systems using their entire annual contract worth of tokens in the first quarter of the year.
So do you have any thoughts about how, within the context of private versus hyperscaler, when we're building out AI infrastructure and we want to ensure that we can control the pricing and the costs associated
With AI, what sort of questions do we need to be asking?
Zafar Chaudry, MD 12:51
Well, that's the biggest, biggest problem that systems are going to face, right? The explosive growth of utilization of AI and then the consumption of tokens. So yes, if you get into a contract with a hyperscaler in a public cloud scenario,
you will consume tokens and you may have a cap on tokens. Problem with that would be you run out of them in two weeks of the first month, right? And then you have to pay more and more. And there's numerous news reports of health of systems running out of tokens or
Jordan Cooper 13:28
Mm.
Zafar Chaudry, MD 13:30
not predicting their future costs. I truly believe that as a CIO, you need to think about who can you partner with, which vendor can you partner with to potentially build an instance of AI dedicated to your health system. So you can actually build AI and you can even use open source AI, but you can
that in a private cloud setting where the vendor will absolutely give you a fixed monthly cost to have unlimited consumption of that dedicated infrastructure. So now you can control and manage your costs.
Because one thing I noticed when I deployed AI was as people get familiar with it as end users and customers in a health system, they absolutely go gangbusters in utilization on it. There's just no way of controlling it. But if you can work with someone
have a strategic partner where you get a private cloud that runs the models of AI that you want, whatever those are, and some want to use open source type models, it doesn't matter really. Whatever models you build in a encapsulated private cloud AI infrastructure, those models will allow you to have controlled costs,
per month, and then it will also allow your customers to use that infrastructure as much as they want for the duration of that month. That's where I think people need to think about how are they going to get a handle on this. If you keep putting stuff in public cloud, it's super great if you're a public cloud provider because
more tokens, more money, more revenue. But from a health system perspective, when you do your planning for your fiscal year, you get a finite amount of money to run that service from your CFO.
There's no increase in consumption. There's none of that that is allowed for in a health system. You can't go back to your CFO and say, well, I'm half a million or 5 million overspent on infrastructure and I need more money. Because that doesn't happen mid-cycle.
Jordan Cooper 15:44
So, Zaphyr, as we approach the end of this podcast episode, there's another significant topic that is all over everybody's minds. We already covered AI, we covered public-private cloud, but one thing I'd like to address is cybersecurity. Now, everyone may recall the change healthcare attack from early 2025 that completely disrupted a lot of health systems revenue cycle.
from any patients who came with a united coverage. And there have been many instances of ransomware and other cyber attacks hitting IDNs across the nation and other specialty healthcare delivery systems. I'd like to kind of give you an opportunity to speak to perhaps the differences between public and private cloud when it comes to cyber security and what sort of
things CIOs should be keeping in mind as they try to protect their organization in this day and age with AI-generated cybersecurity threats.
Zafar Chaudry, MD 16:38
Yeah, so that's a very, very good question in a climate where cyber is always keeping CIOs up at night. If you run your own data center and your own infrastructure, you need to provide a layer of security on top of that infrastructure, and you need to provide that around the clock. That's really hard, expensive to do.
And hiring or retaining the best cybersecurity professionals in your team is cost prohibitive for most. Now, if you think about public cloud, now public cloud is better because they have teams of security professionals that are actually keeping an eye on the prize.
around the clock. So that's really important. But the challenge is they give you standardized security that they apply to a whole series of customers. So you as a customer have less say in what you would need in terms of cyber protection.
They do a very good job, though, in the public cloud. Now, in private cloud, you as a CIO or your CISO can define in a contract what that service provider will provide in terms of cyber protection, what audits will happen, what levels of compliance will happen. It's more bespoke.
So you can define what you think your health system needs, or in this case, what your CISO recommends that you need to protect your organization.
And it'll be slightly different because some health systems are just hospitals and clinics. Some health systems are hospitals, clinics, and research institutes, because they have a whole bunch of researchers. And that security posture will be slightly different. So I think the agility you have in a private cloud partnership setting is the infrastructure is built.
To your specification, it is on an SLA that you have agreed to, backed by financial penalties, with a high uptime, a high RTO, and a high RPO, and then at the same time, the security that wraps around it, which is provided by a well-qualified team from that.
strategic partner is to the specification that your CISO wants for your organization and how to protect your organization. That's very hard to achieve in a public cloud model.
Jordan Cooper 18:51
Yeah.
So last question, we're wrapping up this episode now. Any words of advice to yourself a few years ago as you began your journey down towards a commoditized health IT infrastructure process?
Zafar Chaudry, MD 19:17
Yeah, so my advice to anyone is don't start the journey with a predefined exit, right? Start the journey with what problem am I trying to solve and look at multiple ways of trying to solve it. So it's not that I did not with my team look at
public cloud, private cloud, in-house services before we made the decision. You have to do the exercise. You also have to do the change management, how much that's going to cost. Look at your technical debt, but also build a model and a business case that makes financial sense.
for your organization. So the answer isn't finite here, right? The answer is very much, look at all the options. And don't forget the in-house option. You should always look at the do-nothing in-house option. So we always look at, I've always looked at three different ways of skinning the cat, as they say. So when you're starting this journey,
Build a model for each one of the possibilities that you may have. Define a business case, define, speak to the stakeholders. You do need good governance. So get governance involved, stakeholder engagement. What do researchers want? What do hospitalists want? What do nurses want? What do allied health professionals want?
And I'll leave you with this. If you go and walk through a health system and you ask any clinician, you know, how much downtime can you take on any system, the answer will always be 0. It's not for IT professionals to tell clinicians what they can get.
Jordan Cooper 20:49
Mhm.
Zafar Chaudry, MD 20:55
It's for IT professionals to listen to the customers that they serve and then try to provide services to serve those needs, not the needs that you come up with.
Jordan Cooper 21:06
Well, Zafar, I'd like to thank you for joining us today. And for our listeners, this has been Zafar Chowdhury, the former CDAIO of Seattle Children's. Wonderful conversation. Thank you.
Zafar Chaudry, MD 21:19
Thank you, Jordan.
Jordan Cooper stopped transcription