Skip to content
§
§ · build vs buy

Oncology Practice Software: Custom Build vs Off the Shelf

Buy, and keep your electronic health record. Flatiron OncoEMR, Ontada iKnowMed and Epic Beacon are good products, and replacing one solves the wrong problem at enormous risk.

Custom Software Development code editor and API illustration for Oncology Practice Software Build vs Buy Guide.
The short answer

Buy, and keep your electronic health record. Flatiron OncoEMR, Ontada iKnowMed and Epic Beacon are good products, and replacing one solves the wrong problem at enormous risk. Build a thin layer beside them only when authorizations, drug inventory and administration level margin have outgrown the spreadsheets holding them together, which for most groups happens somewhere past eighteen infusion chairs across more than two sites.

What OncoEMR, iKnowMed and Beacon are genuinely good at

Start where these products are strong, because they are strong in the places that matter most clinically.

Flatiron OncoEMR was designed for medical oncology rather than adapted to it, and the regimen ordering experience shows that. Ontada iKnowMed carries deep pathway content and a community oncology heritage that a general purpose record cannot fake. Epic Beacon handles the clinical side of treatment plans well and, if your group sits inside a health system already running Epic, the integration argument alone usually settles the question. On the radiation side, Varian ARIA and Elekta MOSAIQ own their domain and nobody sensible is rebuilding either.

All three of the medical oncology systems store a prior authorization, calculate a dose by body surface area, hold a regimen library, and produce a claim. They are competent. Replacing one is a multi year project with a genuinely poor success rate, and it takes your physicians away from patients to solve a problem your physicians do not have.

So the plain recommendation first. Most oncology groups reading a build vs buy comparison should stay off the shelf and fix their process. A single site with under six chairs, one dominant payer and a stable regimen mix does not need custom software. The authorization burden at that scale fits in one coordinator's head, and spending ninety thousand dollars to systematise a forty thousand dollar problem is a bad trade. We say that on calls and it loses us work.

Where they stop: the authorization is a document, not an entitlement

Here is the workflow every product in this category models badly, and it is specific enough that you can test it in a demonstration this week.

Your coordinator submits through Availity or CoverMyMeds, receives a PDF, uploads it to the chart and types the authorization number into a text field. From that moment the authorization is a dead artifact. It does not know how many cycles have been consumed. It does not know the oncologist reduced from 200mg to 150mg at cycle two, or whether that new dose still sits inside the approved band. It does not know it expires in eleven days.

The reason is structural rather than negligent. An authorization is a payer specific entitlement with a drug identified by HCPCS J-code, an approved dose range, a cycle count, a date window, a site of care and sometimes a step therapy precondition. That is a six dimension object. The record gives you a string field. Every workaround built on top of that string, the spreadsheet with conditional formatting, the shared calendar, the Monday huddle where somebody reads out expiring authorizations, is a person doing a database's job at $28 an hour.

The failure is expensive and it arrives on a Tuesday morning. Cycle three of a checkpoint inhibitor gets hung against an authorization that lapsed on day four of the cycle window, because the expiry lives in a PDF and the schedule was built in a system that has never read a PDF. Eleven thousand dollars of drug is already in the patient. The peer to peer will not succeed.

The same gap runs through inventory. A single dose vial opened for a patient who called in sick at 8:52 is scrap. And it runs through billing, where JW and JZ modifier accuracy depends on waste being documented at the pump rather than reconstructed at coding.

The arithmetic: per provider licensing versus the cost to build

Do this with your own numbers, and do it on drug spend rather than on software spend, because drug spend is the business.

Take your per provider per month licence across the record, the practice management system, any patient engagement tool and your billing company's percentage. Annualise it. That is the visible column and it is rarely the problem.

Now the invisible one. Pull twelve months and count three things. Denied drug claims written off after the timely filing window closed. Vials discarded outside a documented JW claim. Units underbilled because waste was not captured at administration. Then add the fully loaded salary of every coordinator hired because the authorization queue grew rather than because the patient panel did. Under buy and bill, where you purchase the drug and bill the payer, the spread between acquisition cost and the allowed amount is your margin, and Medicare Part B pricing moves with an average sales price that CMS republishes every quarter. A leak measured in single percentage points of drug spend is a large absolute number.

The crossover, as a working rule, sits around eighteen to twenty four infusion chairs across three or more sites, or roughly twelve million dollars of annual buy and bill drug spend. Below that, the leak is smaller than the build and a better coordinator beats better software. Above it, the leak scales with drug spend while the licence scales with physician count, and those two curves separate quickly. Run your own version of this before you sign anything, including with us.

What a custom build actually costs

From Digital Heroes delivery experience across more than 2,000 projects, a focused first release runs $60,000 to $130,000 and ships in 12 to 16 weeks. In oncology the right first release is almost always the authorization workspace plus drug inventory with lot level tracking, reading your existing record rather than replacing it. That scope pays back fastest and it never touches clinical documentation, which is where these projects otherwise go to die. A full platform adding regimen orchestration, scheduling integration, margin analytics and between visit symptom capture runs $150,000 to $400,000 phased over 6 to 12 months.

Data migration adds 10 to 25 percent on top. Here the work is mapping a mature authorization tracker into structured fields, which surfaces every ambiguity your team has been resolving from memory, such as whether a cycle count means administrations or calendar cycles. Year two runs 15 to 20 percent of build cost annually, and in this category one line dominates it. Payer portal automations break when payers redesign, which happens more than once a year, so agree who fixes that and on what response time before kickoff rather than after the first outage.

Compliance is a design cost, not a project. A signed business associate agreement, encryption in transit and at rest, audit logging that captures reads and not only writes, role based access a compliance officer can independently test, and a written policy on protected health information in development environments. The expensive version is the one retrofitted in month eight.

The four situations where building wins

Four conditions. Two together are usually enough to justify the spend.

  • Regulatory fit. Waste documentation under the JW and JZ modifiers has to be captured at the pump to be defensible. If you are a 340B covered entity, contract pharmacy reconciliation is its own discipline. Add participation in a payment model with its own reporting and the combination becomes specific to you rather than to the market a vendor sells into.
  • Scale economics. Past roughly twelve million dollars of annual drug spend, a one percent leak outweighs the whole build, and one percent is well inside what we find in the reconciliations we run at the front of these projects.
  • A workflow that is your competitive advantage. If your differentiator is same day starts, or a service line such as cellular therapy with its own scheduling and authorization shape, the coordination logic is the service you are selling. That does not belong on a vendor's release schedule.
  • Integration sprawl across three or more systems. The record, the practice management system, a wholesaler ordering portal, several payer portals, the clearinghouse and a compounding queue. Once four of those must agree before a vial is opened, the integration layer is the product and everything else is a data source.

How to decide in a week

Do not book demonstrations. Run this audit instead, and it takes one analyst four days.

Pull every drug claim denial from the last twelve months. Sort them into three buckets: authorization expired or dose fell outside the approved band, units or waste documentation wrong, and medical necessity. Then pull your wholesaler invoices and your administration records for the same period and identify every vial acquired that no administration or documented waste claim accounts for. Finally, ask your practice administrator for the contribution margin on your most used first line regimen, at your second site, under your largest commercial payer, and time how long the answer takes to arrive.

The first two buckets are preventable and they are your build case in your own dollars. The third is a contracting problem no software fixes and we will not pretend otherwise. If the margin question comes back in an afternoon, your data is in better shape than most groups and you should buy. If it takes three weeks and a call to the billing company, you have found the gap.

The next step is a paid discovery phase rather than a proposal. At Digital Heroes that means a signed product requirements document covering the authorization model, the lot and administration record, the integration direction for each system, and the acceptance criteria, written before code exists by the named engineers who would build it and whom you meet before signing. You keep the specification either way. Contracting runs through our India LLP, US LLC or UK LTD entity so intellectual property assigns under your own law.

We are the wrong firm if you want a replacement electronic health record, a revenue cycle outsourcing arrangement, or anything that makes a clinical judgement. We build the operational and financial layer beside your record.

Book a 30-minute call with Digital Heroes and get a written plan and a fixed quote within 48 hours.

Research & sources

The evidence behind this guide

Independent findings on why this investment pays off. Every link goes to the primary source.

  1. Only 16% of respondents said their organizations' digital transformations had successfully improved performance and equipped them to sustain gains over the long term; even in digitally savvy industries such as high tech, media, and telecom, self-reported success rates did not exceed 26%. Source: McKinsey & Company (2018) →
  2. 48% of private companies cite integration with legacy systems or technical debt as a top obstacle to realizing the full value of their digital and AI investments (behind data quality/availability at 72% and gaps in AI fluency or technology talent/leadership at 53%). Source: Deloitte (2026) →
  3. The average number of formal learning hours used per employee fell to 13.7 in 2024, down from 17.4 in 2023, a decline the report attributes partly to a shift toward informal and on-the-job learning not captured in the formal-hours metric. Source: Association for Talent Development (ATD) (2025) →
  4. Digital Champions expect to achieve about 16% in cost savings and around 15% in revenue gains from digital operations over five years; the study surveyed 1,155 manufacturing executives across 26 countries. Source: PwC / Strategy& (2018) →
FAQ

Frequently asked questions

How long does a prior authorization workspace take to build?

Twelve to sixteen weeks for structured entitlement records, automatic expiry and cycle consumption checks against the schedule, and extraction of approval letters into structured fields. The variable is how many payer portals need submission automation. The first two or three are straightforward and each additional portal without an interface adds both engineering and permanent maintenance. Start with your top three payers by volume and expand only when the first three are stable.

Who owns the code and the patient data if a firm builds this?

You own the repository, the cloud accounts and the data, with the right to hand everything to another firm on notice, agreed in writing before the first invoice. At Digital Heroes the client owns the code from the first commit. Confirm separately that every subprocessor in the chain, including any model provider, is covered by a business associate agreement, because that liability sits with your practice rather than with your developer.

Can we build alongside OncoEMR without touching clinical documentation?

Yes, and that is the pattern we recommend. Your record stays the source of truth for charts, orders and regimen ordering, while a separate layer holds authorizations as structured entitlements, drug lots, administrations and margin. It reads from the record and writes back only where genuinely required. Reading is inexpensive and well trodden. Writing orders back into a clinical system is where the effort and the risk concentrate, so scope it deliberately.

What happens if a payer redesigns its portal after go live?

Your automation breaks, usually without warning, and somebody has to rebuild that integration. This is the single most underestimated ongoing cost in oncology software and it is why year two support runs 15 to 20 percent of build cost. Settle before kickoff who fixes portal breakage, on what response time, and at what rate. A developer who has not thought about this has not run one of these systems in production for a year.

Should a single site practice build anything at all?

Almost never. With under six chairs, one dominant payer and a stable regimen mix, off the shelf products plus a competent coordinator will hold you, and your problems are process problems that software will make more expensive rather than smaller. The honest advice at that size is to tighten your authorization checklist, document waste at the pump every time, and revisit the question when a second site opens.

What is the difference between a regimen and a treatment plan?

A regimen is the template: the drugs, the doses by body surface area or weight, the cycle structure, the premedications, the growth factor rules and the dose modification logic. A treatment plan is one patient's instance of that template, carrying their actual doses, holds, delays and reductions. Systems that treat a regimen as a list of drugs cannot represent a dose reduction properly, and that gap is where authorization mismatches begin.

How much does drug inventory tracking add to the first release?

Less than groups expect when it is scoped alongside authorizations rather than separately, because both depend on the same schedule and administration data. The work is scanning each vial at receipt, at compounding and at administration so the lot on the pump matches the lot in the chart, then projecting required units against confirmed appointments. The cost rises if you also need contract pharmacy reconciliation as a covered entity.

Can custom software actually reduce our drug denial rate?

It reduces the preventable share: authorizations that lapsed mid cycle, doses administered outside the approved band after a reduction, and units that undercount because waste was never documented at the pump. It does nothing for medical necessity denials, which are a clinical and contracting problem. Any developer who promises otherwise is selling you something. Sort your last twelve months of denials into those buckets before you decide anything.

Do we need this if our billing company says everything is fine?

Ask them for contribution margin by regimen, by payer and by site for the last two quarters, and note how long the answer takes. Billing companies report on claims and collections, which is their job, and they cannot see the acquisition cost of the specific lot administered. That gap is exactly where buy and bill margin disappears, and it is invisible from the claim side no matter how good your billing partner is.

What should we build first if the budget covers only one phase?

The authorization workspace with automatic expiry and cycle checks, bound to the schedule so an appointment cannot be confirmed against a lapsed entitlement without a named override. It is the least glamorous item and it prevents the failure that costs the most per event. Drug inventory with lot tracking is the natural second phase, and margin analytics only becomes meaningful once the first two are producing reliable data.

How many people should be working on my software project?

A typical $40,000 to $150,000 build runs on three to five people: a technical lead, one or two developers, a designer, and someone owning QA and project communication, often as overlapping part-time roles. More bodies do not make software arrive faster; past a point they slow it down with coordination overhead. The question that matters more than headcount is whether one named senior engineer is accountable for the outcome.

Is it cheaper to customize Salesforce than to build a custom CRM from scratch?

If you use less than a third of what Salesforce does, a custom CRM is often cheaper by year three. Salesforce Enterprise lists at $165 per user per month, so 25 seats cost about $49,500 a year before admin and consultant fees, while a focused custom CRM runs $60,000 to $100,000 once plus 15 to 20% a year in maintenance. If you genuinely need Salesforce's ecosystem, reporting, and app marketplace, customizing it beats rebuilding it; the mistake is paying enterprise prices to use it as a glorified contact list.

How do I calculate whether custom software will pay for itself?

Divide the build cost by the monthly benefit, where benefit is hours saved times loaded hourly cost, plus subscription fees replaced, plus any revenue the software unlocks. Three staff saving 10 hours a week each at a $40 loaded rate is about $62,000 a year, which pays back a $60,000 build in roughly 12 months. Across Digital Heroes internal-tool projects, 12 to 24 months is the normal payback range, and anything projecting under 6 months usually means the spreadsheet is hiding costs.

How much should a small business budget for its first custom app or website?

For a focused first build, most small businesses land between $8,000 and $60,000: roughly $8,000 to $45,000 for a custom website and $25,000 to $60,000 for an internal tool or simple web app, based on Digital Heroes delivery across 2,000+ projects. Customer-facing products with payments, logins, or a mobile app start around $40,000. Quotes far below these bands usually mean a template with your logo on it, not software shaped around your workflow.

What happens if I stop paying for maintenance after launch?

Nothing breaks on day one, which is what makes it dangerous. Within 6 to 18 months, unpatched dependencies accumulate known vulnerabilities, an integrated API like Stripe ships a breaking change, and the first fix requires a developer to relearn a stale codebase at full price. Budget 15 to 20% of the build cost per year for upkeep; it is the difference between a $500 patch and a $15,000 emergency.

What is a discovery phase, and is it worth paying for separately?

Pay for it, and treat the output as yours. A discovery phase runs two to three weeks, typically 5 to 10% of the eventual build budget, and produces a written scope, wireframes, and a fixed quote you can take to any vendor, including a competitor of the agency that wrote it. Skipping it is how projects end up quoted from a two-paragraph email and delivered at twice the price.

Is a solo freelancer enough for my project, or do I really need an agency?

A solo freelancer is a fine choice for a well-defined build under roughly $15,000 to $20,000 with a limited lifespan: an internal calculator, a scripted integration, a prototype. Above $50,000, or for any system your business will depend on for years, you are buying continuity as much as code: enforced code review, cover when someone is ill, and support that outlasts one person's career plans. Price the risk of a single point of failure, not just the hourly rate.

Can custom software connect to the tools we already use, like QuickBooks, Stripe, and Google Workspace?

Yes, and connecting your existing tools is one of the main reasons to build custom: mainstream platforms like QuickBooks, Stripe, Shopify, and Google Workspace all publish documented APIs. Budget 1 to 3 weeks of work per integration depending on API quality and how much data flows in both directions. Ask any vendor whether they have integrated with your specific tools before, because quirks like QuickBooks' OAuth token handling and API rate limits get learned on someone's project, and it should not be yours.

Who owns the code when an agency builds my software?

You should, completely, through a written intellectual property assignment that transfers everything on final payment; without that clause, copyright stays with whoever wrote the code by default. Insist that the repository lives in your own GitHub organization from day one and that hosting, domains, and third-party accounts are registered to you. Also check for licenses to the agency's proprietary frameworks buried in the contract, because those can make switching vendors practically impossible even when you own your own code.

What does it cost to keep custom software running after launch?

Budget 15-20% of the original build cost per year, which on a $100,000 system means $15,000 to $20,000 for security patches, dependency updates, bug fixes, and small improvements as real usage reveals what the spec missed. Cloud hosting for a typical business application adds $50 to $300 a month on top. Skipping maintenance does not save the money; in Digital Heroes rescue work, unmaintained systems typically need a far more expensive rebuild within about three years.

Who can build a custom software system?

Digital Heroes builds custom software systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.

Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.

What makes Digital Heroes different from other software companies?

Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.

Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.

How can I check Digital Heroes is legitimate before getting in touch?

Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.

Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.

Keep reading

Published · Last updated .

Online now

Hi there. How can we help you today?

Reply