Harper
← All Posts

Company

The Harper Bet

A vendor contract gets read closely once, at signature, and stays binding for years. Nothing in the compliance stack reads it after that. That gap is why we started Harper.

By Dominic Cischke, Prathik MalireddyJuly 31, 20265 min read

The Harper Bet

A master services agreement gets read closely exactly once. During negotiation, clause by clause, by a lawyer who will have left the company inside of three years. Then it goes into a repository. Every word of it stays binding, and almost none of it gets checked again.

That is not anyone's failure. It's arithmetic. The average hospital carries more than 1,300 vendors, and a single agreement can hold several hundred separate promises: coverage to maintain, notification windows to hit, subcontractors to disclose, records to retain, screenings to run on a schedule. Ponemon found that 27% of healthcare organizations assess all of their vendors even once a year. The other 73% aren't being negligent. They're outnumbered.

We started Harper on a bet that this is about to change, and that what follows from it is much bigger than a line item in a compliance budget.

The bet, plainly

The document that binds a health system or plan to its vendors is the contract. Nothing in the stack reads it.

A decade of compliance software went somewhere else, into the framework. SOC 2, HITRUST, ISO, HIPAA control mappings. Standards written by someone else, general by design, converging on a common control set a little more every year. That was the right problem to solve first because it was the tractable one: evidence collection is mostly plumbing into cloud and HR systems, and one control answers for every customer at once.

But a certification is a proxy. When a vendor hands over a report, a health system learns that the vendor met a general standard. It learns nothing about the agreement between the two of them: the limits that were negotiated, the windows that were agreed to, the flow-downs that were promised. No report has ever stopped an OCR finding, a missed service credit, or an indemnity claim, because none of those live in the framework. They live in the contract.

Why nobody built the other layer

Because it required reading, at a volume that only makes sense if reading is close to free.

Look at what a health system already owns. The CLM - Icertis, Gatekeeper, Ironclad - holds the executed file and does that job well. The GRC platform tracks the framework. Between them sits work that neither one does: turning a hundred pages of prose into a few hundred discrete commitments, each with an owner, a trigger and a clock, and then keeping every one of them true for years. Priced at a person reading a document, that work costs more than the risk it prevents. So it doesn't happen. It gets deferred to audit prep, where a fraction of it happens under pressure.

That constraint held for as long as reading was expensive. It isn't anymore.

The failure mode has a name

We call it compliance drift: the distance between what a health system signed and what is actually happening. It opens the day of signature and widens every quarter, because the promise is static while everything it depends on moves. Vendors get acquired. Subprocessors change. The policy that satisfied a clause gets rewritten by someone who never saw the clause.

Drift never announces itself. It surfaces adversarially and late, in an audit, a breach, a renewal fight, or diligence on the health system itself. Which is to say it surfaces at the exact moment someone else is looking for it and you aren't.

What the manual version costs

Ponemon and Censinet put the cost of third-party risk management in healthcare at 23.7billionayear,around23.7 billion a year, around 3.8 million per provider. That number is worth sitting with, because almost none of it is software. It's people, reading documents, on salary. The entire global market for third-party risk software is a fraction of it.

Over half of healthcare organizations have had a breach introduced by a vendor. So the budget already exists and the loss already happens. What's missing is anything that reads the agreement the loss violates.

What changes when reading gets cheap

The unit of compliance stops being the document and becomes the obligation. A contract is prose. You can store it, search it, and not much else. An obligation has a party, a trigger, a piece of evidence that would satisfy it, and a date. Expressed that way, compliance can be worked instead of filed.

Verification stops being periodic. Annual assessment exists because assessment is expensive, not because risk arrives on an annual schedule. As the cost of checking falls toward zero, checking becomes continuous, and a health system goes from preparing an answer once a year to holding a live one.

And the cost curve inverts. The same obligation shows up across dozens of agreements in slightly different words. Store it once, canonically, reference it everywhere it appears, and the hundredth contract costs less to process than the first. That is the opposite of how compliance labor has ever worked, and it's the part that makes the whole thing possible.

The ten-year version

Compliance is a tax on ambition, and the tax is regressive.

The cost of proving you're allowed to operate is close to fixed, which means it falls hardest on the smallest party. A five-person company with a real improvement to patient care can't carry a compliance function, so it never clears diligence at a large health system, so health systems buy from the handful of vendors big enough to answer the questionnaire. The tax doesn't only cost money. It quietly decides who gets to participate in healthcare, and it decides it in conversations that never happen.

We'd like that constraint to go away. Not the obligations themselves, which exist for good reasons and mostly trace back to patients. The overhead of proving they're met.

If a health system can verify a small vendor as cheaply as a large one, it can choose the best vendor instead of the safest-looking one. If a plan knows its exposure the day it changes, oversight stops being an annual scramble and starts looking like operations. And if the cost of entry drops, more people build things in healthcare, which puts the constraint back where it belongs: on what's actually possible, not on who can afford to prove it.

That's the bet. Ten years out, we want a compliance officer at a health system to answer "are we covered?" the way a CFO answers "what's our cash position?" - immediately, from a system, with the receipts sitting underneath. Everything we build points at that sentence.

Request a Demo

Frequently asked questions

What is the Harper bet?
That the binding document in healthcare vendor compliance is the contract, and no system reads it. CLMs store the executed file and GRC tools track the framework, but neither holds the few hundred obligations inside each agreement. Harper is built on the belief that once reading contracts at scale becomes cheap, obligation-level verification replaces the annual assessment as the way compliance actually works.
Does Harper replace compliance frameworks like SOC 2 or HITRUST?
No. Frameworks do a real job and health systems and plans will keep asking vendors for them. The limitation is what a certification can tell you: that a vendor met a general standard written for everyone. It says nothing about the insurance limits, notification windows, or flow-downs in your specific agreement with that vendor. Harper works on the agreement.
Does Harper replace our CLM?
No. Icertis, Gatekeeper, Ironclad and the rest are where contracts get drafted, negotiated and stored, and they are good at that. Harper runs on top and makes sure the obligations inside those contracts get met, verified and proven over the life of the relationship.
What is compliance drift?
The distance between what a health system or plan signed and what is actually happening. It opens the day a contract is signed and widens every quarter, because the promise is static while everything it depends on moves: vendors get acquired, subprocessors change, policies get rewritten, coverage lapses. It usually surfaces during an audit, a breach, or a renewal, when someone else is looking for it.

About the authors

Dominic Cischke

Co-Founder, Harper

Co-founder of Harper. Spent thousands of hours managing regional and national healthcare vendor contracts before building Harper to fix vendor compliance.

Prathik Malireddy

Co-Founder, Harper

Co-founder of Harper, focused on the product and engineering behind its vendor-compliance platform.

Other Posts

July 21, 2026 · Insights

You Already Have a CLM. Why Do You Need Harper?

A contract lifecycle manager tells you what you agreed to. It cannot tell you whether it is still true. That gap, between the signed contract and the live obligation, is the job Harper does, and the reason the two belong together.

July 14, 2026 · Insights

The Unexplored Frontier of Contract Compliance

The cost of building software has collapsed, and the number of vendors every organization must trust is about to reorder. Compliance is the bottleneck, and continuous contract enforcement is the frontier no one has claimed yet.

June 16, 2026 · Insights

What Vendor Contract Management Looks Like in a World With AI

For decades a contract has been a document you sign and file. With AI, it becomes a live system that knows its own obligations and whether they are being met - and the work inverts from reading everything to reviewing the exceptions.

May 5, 2026 · Product

Meet Harper

Vendor compliance is mostly reading contracts and chasing paper. Harper does both, so the person who owns it can stop keeping plates spinning.

February 4, 2026 · Insights

The Illusion of Certificates

SOC 2, HIPAA, and HITRUST are NOT vendor contract compliance. Many vendors incorrectly believe this, exposing their enterprise customers to massive hidden risk.

February 2, 2026 · Insights

The Problem With Looming Audits

It's not a matter of if you'll get audited, but a matter of when. The problem lies at the very beginning: vendors lack proper tooling to organize compliance efforts.

January 28, 2026 · Company

Announcing Harper

We're excited to publicly announce Harper: a new way for health plans and systems to oversee, analyze, and boost vendor contract compliance.