Can we export every patient record?
Ask for the actual export format, not merely a promise that an export exists. Confirm whether patients, consultations, prescriptions, attachments, invoices, payments, audit records and configuration are included.
Can another system read the export?
An export is useful only when it is documented and portable. Ask whether common formats such as CSV, JSON and original uploaded files are supplied, and whether the data relationships are explained.
What happens to our data when we leave?
Get the exit process in writing: notice period, export timing, cost, read-only access, deletion schedule, backups and confirmation of deletion.
Where is the primary database hosted?
Understand the country, cloud or physical location, whether your clinic shares infrastructure, and which party controls the hosting account and encryption keys.
How is our clinic separated from other clinics?
Ask whether separation is enforced only by application rules or also through separate databases, accounts, networks or machines. The vendor should be able to explain the boundary plainly.
Who at the vendor can access records?
Ask about support access, approval, time limits, audit logs and emergency procedures. ‘Our staff normally do not look’ is not an access-control policy.
Who controls backups?
Confirm backup frequency, retention, encryption, restore testing, storage location and how your clinic receives a recoverable copy.
What data is sent to AI providers?
Request a feature-by-feature data-flow explanation. Text assistance, document processing and live voice features may have different paths and should not be grouped under one vague AI statement.
Does the vendor use records for advertising, analytics or model training?
The contract and privacy policy should state whether patient records, metadata or derived information are sold, shared, mined or used to train models.
Can the clinic keep operating during an outage?
Ask what happens during an internet, vendor or payment outage. Clarify whether the clinic retains read access, local operation, exports or a documented continuity process.
What will this promise look like in the contract?
Website promises are useful, but ownership, access, portability, deletion, support and breach responsibilities should also appear in the agreement you sign.
Can the vendor demonstrate the exit process?
The strongest evidence is a real sample export and restore demonstration. Ask to see one before purchasing, with synthetic data rather than real patient information.
How CliniKite answers
How CliniKite answers these questions
CliniKite is designed around data portability, documented exports, clear deployment choices and a revenue model based on software—not selling or mining patient records. Our security page explains the current architecture and its limits.
This checklist is general software-procurement guidance, not legal or medical advice. Clinics should obtain professional advice for their contractual and regulatory obligations.