What Panacea MU Stage-2 taught me about delivery

Delivery lessons from Panacea EHR at 100% MU Stage-2, and $450K+ in penalties avoided. No checklist theatre.

Panacea was an electronic health record programme. My delivery outcome on it was specific: 100 percent Meaningful Use Stage-2, and more than $450,000 in penalties avoided. This note is about what that outcome taught me about running regulated product work. It is not a Meaningful Use implementation guide. I am not going to invent measure lists, interface specifications, or a sequence of compliance steps. If you need those, they live in the regulation and in the clinical operation, not in a portfolio essay.

I was working as a project manager, QA manager, and business analyst in that part of my career, before the TEO / StableLogic years and before my current role at Systems Ltd. Healthcare is one of the industries in a 25-year span that also includes telecom, retail, analytics, and construction. The Panacea result is the healthcare mark I still use when I judge whether a compliance claim is real.

Compliance was the release, not a packet at the end

The mistake I had already seen, and refused to repeat, was treating attestation as paperwork that starts when engineering says they are done. On a Meaningful Use programme the behaviours that get attested are behaviours the practice has to perform in the software, in time for the reporting window. If those behaviours are not in the release scope early, no document set will create them in the last month.

So the delivery question was not "do we have a compliance section in the plan?" The question was "which release makes the Stage-2 outcome possible, and what are we willing to drop so that release stays intact?" One hundred percent was the bar we were aiming at. A partial story would not have been the result I now cite, and it would not have been the result that protected the penalty exposure. The $450,000-plus figure is the business reason the scope fight was worth having. Penalties avoided is a delivery outcome. It is not a slogan beside the outcome.

What I will not pretend to teach

I will not walk through Meaningful Use measures, HL7 message designs, or a security-rule procedure. I have shipped in that world. Publishing a reconstructed checklist from memory would be worse than publishing nothing, because someone might use it. The honest version is the management lesson, and the boundary around it.

What I do say, when students or early-career business analysts ask, is this. Read the actual requirement with the people who carry the operational risk. Turn it into testable behaviour. Put that behaviour in a release you can rehearse. Do not let a vendor's full catalogue define the scope if the catalogue is larger than the outcome. And do not call a programme compliant because a module was switched on.

Dental EHR is the later, smaller expression of that last point. A dental practice needed Meaningful Use–aware EHR capability without the cost and weight of a full enterprise vendor stack. I was product owner and builder. The work was compliance-aware scope, GenAI-assisted research and development, and QA. QA effort came down by 35 percent. That 35 percent is a delivery-efficiency result on the dental build. It is not a second claim about Panacea, and it is not evidence that an assistant "did compliance". The compliance judgment stayed human. The assistant helped us move inside a scope we had already narrowed.

I keep those two programmes distinct on purpose. Panacea is the Stage-2 attainment and the penalty figure. Dental EHR is a later product shape: MU-aware, lighter than an enterprise vendor stack, with a measured drop in QA effort. Mixing them into one story would inflate both.

Adjacent is not the same

Medical Claims is a healthcare-adjacent product I built, and it is not an EHR. Families needed one place to log medical expenses and export a monthly claim PDF instead of living in spreadsheets. It is a PWA. Records are private per account. I built it with Google AI Studio. It is free, at medical.samikhanapps.com.

I mention it here only to draw the line. Years around EHR work made me careful about language. A family expense log that exports a claim is useful. It is not Meaningful Use, it is not Panacea, and it is not the dental practice system. When I mentor, I ask people to keep those categories apart. Recruiters should keep them apart too. The portfolio does.

Delivery lessons I still use

These are the lessons I carried into later programmes. They are not steps in a compliance method.

Name the external consequence in the plan. On Panacea the consequence was penalties, quantified at more than $450,000, and the counter-result was 100 percent Stage-2. On CSCS, years later at TEO / StableLogic, the consequences people felt were performance, support load, and money delivered on time: 35 percent faster performance, 25 percent fewer support queries, and more than £1.5 million on time. Different domain, same habit. If you cannot point at the consequence, you will prioritise whatever is loudest in the steering meeting. The enterprise delivery page holds the CSCS, Veroxos, and Firstcom outcomes together. Panacea sits earlier. The through-line is that I attach delivery to an outcome a sponsor can audit.

Cut scope to what the operator can sustain. A practice cannot attest to behaviour the software makes heroic. An enterprise stack the practice cannot afford is not a safer stack. Dental EHR was scoped against that fact. I would rather ship the capability the attestation and the working day both require than start a platform programme that finishes late and half-used.

Put QA on the critical path early. The dental result — QA effort down 35 percent — came from GenAI-assisted R&D and tighter scope, not from skipping tests. On Panacea, QA management was part of the role because defects in the attested workflows were programme risk, not a quality-team metric. I still do not accept "we will test at the end" on anything with a regulatory or financial consequence.

Separate the claim from the atmosphere. I do not say Panacea "transformed care". I say 100 percent MU Stage-2 and $450,000-plus in penalties avoided. Specific claims age better, and they are the only ones I want attributed to me.

Where this sits now

I am not running a Meaningful Use programme at the moment. Since January 2026 I have been leading technical delivery at Systems Ltd for a major telecom client, and embedding GenAI into that delivery workflow. The healthcare lesson still changes how I behave there: regulated or not, the release is the outcome you promised, scope is what you refused, and a tool — including a GenAI tool — does not own the promise.

If you are on a similar programme and want to compare delivery scars rather than swap checklists, the longer record is at samikhanapps.com, and I am on LinkedIn. I am glad to talk about what worked. I will not invent the steps that were never mine to publish.

More

Keep reading

All notes are on the blog index, and the shipped work is on the projects overview.