How to Evaluate a Practice Management Vendor, Including Us
The questions worth asking any vendor, and an honest look at how we answer them ourselves, including the parts we have not solved.
You are about to hand a vendor the most sensitive information your practice holds, and almost every sales conversation you will have about it is conducted by the vendor. That is worth correcting for, because the questions below work on us as well as on anyone else. We have answered them about ourselves honestly, including where the answer is not yet good enough.
Where is my data actually stored?
Ask for a region, not a country. "Canada" can mean the database is in Canada while uploaded files sit in a US bucket, and those are different answers with different consequences.
Ours: the application database is in Toronto. Uploaded files are not, and they are in a US region. We recommend moving them before a practice stores real patient documents, and we would rather you hear that from us now than discover it in an audit. It is a known gap with a decision attached, not a surprise waiting to happen.
Who else touches my data?
Every vendor uses other companies. Ask for the list, and ask whether you get told before it changes. A vendor who cannot answer that in one page is telling you something about how the answer is maintained.
Ours is published at our subprocessors page, covering hosting, the edge network, file storage, payments and email delivery. We publish what is there today rather than what we intend to add.
Can one practice see another practice's data?
Ask how this is enforced and how it is tested, not whether it is a feature. The answer you want is a mechanism that fails closed, because a query without a resolved tenant should refuse rather than fall back to a wider scope.
Ours is enforced in the application layer on every tenant-owned record, and a request that arrives without a resolved clinic raises an error instead of querying. We test this by probing routes across practice boundaries, so an escape is a build failure rather than something you find out about.
Can I get my records out?
Ask what the export actually contains and whether it is readable without the vendor's software. An export you can only read in the tool you are leaving is not an exit.
Ours produces ordinary files: CSV for lists, and a per-client package of charts, appointments, invoices and documents that opens in any browser. After a subscription ends there is a stated window to take it, and then it is deleted.
What is encrypted, and what is not?
This is where marketing usually gets vague, and the useful question is specific: which fields, and is the whole database encrypted or only some of it? Those are very different products.
Ours encrypts traffic everywhere, and encrypts specific sensitive fields at rest: stored credentials, raw insurer request and response payloads, remittance payloads and stored recovery codes. The database as a whole is not transparently encrypted. If your reviewer requires that, it is a fair requirement and a conversation to have with us rather than something to discover later.
What happens when something goes wrong?
Ask whether the vendor helps you meet your notification obligations or leaves them with you entirely. Either answer can be defensible, but you need to know which one you are getting.
Ours records. When something goes wrong we keep a dated account of what happened, what contained it, what prevented a repeat, and whether a regulator or an affected client was told and when. We do not send those notices for you. That decision is yours, with your adviser, and software that quietly emailed a regulator on your behalf would be making a legal judgement in your name.
Where to read the detail
We publish a fuller account in our privacy policy, including the categories we hold, our subprocessors and our open items. The Office of the Privacy Commissioner of Canada sets out what a health information custodian owes and what follows a breach in its breach guidance, which is the standard worth measuring any vendor against.
The question underneath all of them
Will this vendor tell you when something is wrong with their own product? If a vendor hides a known gap from you, nothing else on this list matters, because you cannot mitigate a risk you were not told about.