Choosing practice management software: the security questions that matter
The platform that will hold every client record deserves more scrutiny than the sales demo gave it. Here are the questions to ask before you sign.
· Jake Schaaf, Founder of Atticus Rowan
The demo ran an hour. It covered intake workflows, billing, the client portal and the reporting dashboard. Security got 1 slide, the one with the padlock icon and the word “bank-grade” on it. Then the firm signed a 3 year agreement and migrated every client record into the platform.
That sequence plays out constantly in legal, accounting and consulting practices, and it deserves more friction than it gets. A practice management platform is not another app. It holds the entire client roster, engagement histories, billing records and often the documents themselves. If it fails, leaks or locks you in, the damage lands on the practice, not the vendor. The time to ask hard questions is before signature, when you still have leverage. At renewal you have almost none, because moving platforms is a 60 to 90 day project no managing partner wants to authorize twice.
Here is what to ask any vendor that will hold client records, in the order that separates serious platforms from padlock-icon platforms.
Identity: MFA and SSO
- Does the platform support MFA, and can the firm enforce it for every user rather than leave it as a personal choice?
- Does it support single sign-on with Microsoft 365 or Google, so accounts die when the employee’s main account dies?
- Is SSO included, or priced into a top tier?
Optional MFA is barely better than none, because the person who skips enrollment is the person an attacker finds. And watch for the SSO surcharge. Some vendors put SSO behind their most expensive plan, which quietly prices basic security out of small-firm reach. Treat that as a signal about the vendor’s priorities.
Your data: export and portability
- Can the firm export everything, not just contacts? Documents, notes, time entries, billing history.
- In what format, at what cost and how fast?
- Can you run an export yourself today, or does it require a support ticket?
Run a test export during the trial. A platform you cannot leave is a platform you cannot negotiate with, and export rights are the difference between a renewal conversation and a hostage negotiation. This is the same discipline we describe in our post on vendor risk for small businesses, applied to the vendor that matters most.
Breach notification, in the contract
- If the vendor has an incident affecting your data, how many days until they must tell you?
- Is that number written in the agreement, or does the contract say “commercially reasonable efforts”?
Professional practices carry their own notification duties to clients and regulators, and the clock on those duties starts whether or not the vendor was prompt. A vendor unwilling to commit to a defined notification window in writing is asking the firm to absorb that risk silently.
Retention after you cancel
- How long does client data persist after the subscription ends?
- Will the vendor certify deletion?
- What happens to data in backups?
The wrong answer is a shrug. Client records sitting in a former vendor’s systems for years are a liability with no offsetting benefit, and they complicate the retention schedule the firm is supposed to be enforcing internally.
Visibility: audit logs
- Does the platform log who viewed, edited, downloaded and shared each record?
- How long are logs kept and can the firm export them?
When something looks wrong, a mailbox rule, a disgruntled departure, an odd client complaint, the audit log is the difference between answering the question in an afternoon and never answering it at all.
Where the data lives and who touches it
- Which country hosts the data, and does that match any commitments the firm has made to clients?
- Does the vendor list its subprocessors, the other companies that touch your data?
You do not need a 40 page security questionnaire for this. You need the vendor’s SOC 2 report or equivalent third-party attestation, read with attention to scope, and a subprocessor list that does not surprise you.
Test it during the trial
Vendors answer questionnaires optimistically. Trials answer honestly. Before anyone signs, spend 1 hour of the trial on security behavior rather than features:
- Enroll a test user, then try to log in without MFA. If the platform lets you, enforcement is theater.
- Run the full export yourself and open what comes out. Count what is missing.
- Share a document externally and check what a recipient can see, forward and download.
- Deactivate the test user and confirm their sessions actually die rather than persisting until the next login.
- Ask support 1 security question and note how far they get before escalating. Support quality during the sale is the ceiling, not the floor.
An hour of this tells you more than the vendor’s entire trust page.
The red flags that end the conversation
- No MFA support in 2026
- No self-service export, or export priced as a professional-services engagement
- Breach notification defined only as “reasonable efforts”
- Security documentation that is a marketing page instead of an attestation
- A sales team that answers security questions with “nobody has ever asked that”
Any 1 of these is worth pausing over. 2 or more and the platform is telling you who it is.
Ask before you sign
Every question above costs nothing to ask during procurement and a great deal to fix afterward. The firms that get burned are rarely the ones that chose a flawed platform knowingly. They are the ones that never asked, signed for 3 years and discovered the answers during an incident. This is also the moment to inventory what the practice already uses, because the platform decision usually surfaces a tail of overlapping tools, a problem we cover in our post on shadow IT and the SaaS inventory. And once the new platform is live, make it the anchor of your standardized client file exchange rather than one more place documents scatter.
Atticus Rowan reviews practice management contracts and vendor security postures for professional practices before they sign, and builds the surrounding configuration, identity enforcement and offboarding process once they do. If your firm is evaluating platforms this quarter, bring us the shortlist and we will pressure-test it with you.
Related insights
More on Operations & OT →September 9, 2026
Stop emailing client files: secure exchange for professional practices
Tax documents and case files still travel as email attachments. Here is how a 5 to 50 person practice standardizes one secure channel without losing clients along the way.
September 4, 2026
The Windows 7 box running your CNC: legacy systems on the plant floor
When the controller PC cannot be upgraded and cannot be replaced, you still have 4 real options. Here is how to rank them honestly.
August 31, 2026
IT for construction firms chasing enterprise project work
GC prequalification packets now include cybersecurity sections. What a 15-50 person contractor needs to pass upstream security review and win bigger work.