Build or Buy a Health AI Feature? Use a Risk-and-Economics Ledger
A product team can make either option look cheap by moving risk outside the spreadsheet. “Buy” hides integration, consent, and exit work; “build” hides ongoing operations and assurance. The useful unit is not monthly software spend. It is cost per safely completed user job, with unresolved risks recorded beside the number.
The current trigger is OpenAI’s July 23, 2026 announcement of Health in ChatGPT. According to OpenAI’s primary post, rollout is to eligible US logged-in users age 18+ on web and iOS; supported connections include medical records and Apple Health; and the dashboard can cover labs, medications, activity, sleep, and other health information. OpenAI states connected data and relevant conversations are not used to train foundation models or target ads. Treat these as attributed vendor statements, not proof that the product meets another team’s requirements.
Gate first, calculate second
Before scoring build, buy, or “do nothing,” apply non-negotiable gates:
| Gate | Required evidence | Failure action |
|---|---|---|
| User purpose | one bounded job and excluded uses | narrow scope |
| Consent lifecycle | grant, inspect, revoke, reconnect flows | stop pilot |
| Clinical boundary | interface says support, not diagnosis/treatment | redesign |
| Data exit | export/deletion obligations and owner | reject option |
| Incident ownership | named responder and kill switch | reject option |
A failed gate cannot be offset by a low price or an attractive demo. “Do nothing” should remain a real option when the team cannot staff these obligations.
The decision ledger
Use one row per assumption rather than one score per vendor:
| Variable | Build | Buy | Evidence grade | Owner | Expires |
|---|---|---|---|---|---|
| setup engineering hours | 420 | 120 | estimate | Eng lead | Aug 15 |
| monthly operations hours | 80 | 24 | estimate | Ops lead | Aug 15 |
| monthly fixed spend | $6,000 | $14,000 | quote needed | Finance | Aug 15 |
| accepted jobs/month | 8,000 | 8,000 | pilot needed | PM | Aug 15 |
| exit implementation hours | 160 | 200 | unknown | Architect | Aug 15 |
| unresolved high risks | 3 | 2 | review | Risk owner | weekly |
All numbers are fictional worked inputs, not market prices, forecasts, or OpenAI metrics. Replace them before using the ledger.
Define monthly equivalent cost:
M = fixed_spend + operations_hours * loaded_hourly_rate + setup_hours * loaded_hourly_rate / amortization_months + expected_incident_cost
cost_per_accepted_job = M / accepted_jobs
If the loaded rate is $100 and setup is amortized over 12 months, the example build subtotal before incidents is $6,000 + 80×$100 + 420×$100/12 = $17,500. The buy subtotal is $14,000 + 24×$100 + 120×$100/12 = $17,400. That near tie is the point: small changes in accepted volume, exit effort, or unresolved risk can reverse the choice.
Do not monetize severe unknowns merely to make the formula finish. Keep them as hard gates. For sensitivity, recalculate at 25%, 50%, and 100% of expected accepted jobs, and with operations hours doubled.
Define an “accepted job” before the pilot-for example, an appointment-preparation packet the user reviews and chooses to keep-not a click or generated response.
Pilot and stop rule
Run a time-boxed, reversible pilot only after gates pass. Assign each ledger row an evidence grade: source statement, contract, design review, observed pilot result, or unknown. At expiry, renew with new evidence or discard it. Stop when a high-risk item has no owner, revocation cannot be demonstrated end to end, the clinical boundary is repeatedly misunderstood, or cost per accepted job exceeds the predeclared ceiling.
OpenAI says this experience supports rather than replaces medical care and is not for diagnosis or treatment. That positioning does not automatically supply another product’s boundaries.
This ledger does not evaluate ChatGPT, establish compliance, estimate clinical benefit, or prove vendor security. It is a conversation tool, not objective truth, and procurement still requires legal, privacy, security, accessibility, and domain review.
The deciding question is not “which option has more features?” It is which variable, failed gate, or evidence expiry would make the team stop.
AI assistance disclosure: This article was drafted with AI assistance and reviewed against the cited primary source.
Comments
No comments yet. Start the discussion.