Vendor security reviews · Clinical care providers
Vendor Security Review & Questionnaire Support for Mental Health & Counselling Practices
This service vets the platforms and vendors a counselling practice is considering, before a client's information reaches them, not after. Because payment here is mostly out-of-pocket or through an EAP rather than a provincial billing switch, the real leak vector is the vendor stack: the practice-management platform, the video tool, the AI note-taker, and the marketing tools running the website and newsletter. Practices call before switching platforms, before trialing an AI scribe, or after reading about the BetterHelp case and wondering what their own marketing tools actually do.
Reviewed by the Privacy Horizon team · Last reviewed
What you're protecting
The vendor decisions that carry a client's disclosures with them
Every tool a practice adopts is a decision about who else gets to see or hold a client's therapy record, so review depth follows sensitivity.
The practice-management platform
Owl Practice, Jane or a similar system holds the entire clinical, appointment and financial record, making it the single highest-stakes vendor decision a practice makes.
Video and telepractice tools
The platform delivering virtual sessions needs review for encryption, data residency and whether it retains any recording or transcript by default.
AI note-taking and scribe tools
A vendor listening to live sessions to generate notes needs the deepest scrutiny of any tool in the stack, since it is capturing the raw conversation, not just a summary.
Booking, directory and marketing vendors
Online booking widgets, Psychology Today-style directory listings, and email newsletter tools all handle prospect and client contact information, and are exactly where the BetterHelp pattern repeats if left unchecked.
Regulatory map
Why the diligence obligation is the practice's, not the vendor's
A vendor's own marketing claims about compliance do not satisfy the custodian's obligation to verify them, which is what a review documents.
Accountability that follows the record
Under PHIPA, the custodian remains accountable for personal health information even once it sits with a vendor, so a platform's breach becomes the practice's notification obligation.
CRPO's expectation of secure technology
Standard 3.4 requires the technology used for electronic practice to be secure, which the College expects the clinician to have actually assessed rather than assumed.
PIPEDA's accountability principle
Personal information handled by a processor stays subject to PIPEDA's requirements, meaning a marketing vendor's use of client contact data is the practice's responsibility to control.
The vendor claims worth verifying, not assuming
Owl Practice markets itself as built for Canadian privacy laws and Jane holds SOC 2 Type 2 and PCI DSS attestations; a review reads what those claims actually cover rather than taking the homepage at its word.
What goes wrong
What an unvetted vendor exposes in this niche
The incidents that hit this niche hardest start with a vendor decision no one looked at closely enough.
A marketing stack repeating the BetterHelp pattern
The FTC's US$7.8 million settlement with BetterHelp barred the platform from monetizing health information through advertising, after intake answers and contact identifiers were routed to Facebook, Snapchat and Pinterest for ad targeting; a Canadian practice running a pixel-tagged site or an unreviewed newsletter tool can build the identical exposure without a US regulator ever watching.
An AI scribe vendor with unclear retention
Adopting a note-taker without asking where transcripts are stored, for how long, and who at the vendor can access them means a third party may hold a raw session transcript indefinitely.
A platform without genuine Canadian hosting
A vendor's claim to serve Canadian clinicians does not always mean data is hosted or processed in Canada, a distinction that matters for both PHIPA expectations and client-facing disclosure.
A US email tool handling client newsletters
A common convenience tool for client communication may retain contact data, run analytics or share information in ways never reviewed against PIPEDA before adoption.
Our vendor security reviews for mental health & counselling practices
What the vendor review covers before you sign
The output is a decision record: which vendors are approved, which need conditions, and which should be avoided, with the reasoning attached.

Practice-management platform assessment
Review of hosting location, encryption, access controls, audit-log capability and the attestations a vendor actually holds, tested against what the vendor's marketing claims.
AI scribe and note-taker vetting
A structured set of questions on transcript storage, retention period, human review access, training use, and deletion, before any session is ever recorded.
Video and telepractice vendor review
Assessment of encryption, default recording behaviour, and whether the platform's terms are compatible with CRPO's electronic-practice expectations.
Marketing and booking vendor review
Evaluation of website tracking, directory listings and email tools for what data they collect and where it goes, closing the gap the BetterHelp case exposed.
A vendor decision file
A documented record of each assessed vendor's status, approve, approve with conditions, or reject, that the practice can point to if ever asked how a tool was chosen.
How the engagement runs
How a vendor review runs for a counselling practice
Step 1
List and tier the vendors
We inventory every tool touching client data or contact information, from the EHR to the newsletter platform, and rank them by sensitivity.
Step 2
Assess the priority tier
The platforms holding clinical records and any AI scribe under consideration get the deepest review, with follow-up questions sent where vendor documentation is thin.
Step 3
Report findings as decisions
Each vendor comes back with a clear recommendation and the specific conditions attached, ready for the practice owner to act on.
Step 4
Set a routine for new tools
A lightweight process for reviewing the next vendor before it is adopted, so diligence becomes routine rather than a one-time exercise.
What it costs
What determines vendor review pricing for a practice
The main drivers are how many vendors are in scope, how many of them touch clinical data directly versus marketing data, and whether an AI scribe evaluation is part of the engagement. A solo practitioner comparing two practice-management platforms is a compact review; a group practice auditing its entire vendor list, including video, booking and marketing tools, is a larger one.
Ongoing vendor review, evaluating each new tool as it comes up rather than once a year, is one of the standing functions built into the Virtual Privacy Officer retainer. Send us your current vendor list and we will scope the review.
Mental Health & Counselling Practices: Vendor security reviews questions, answered
Both vendors publish security information worth reading directly rather than assuming: Jane states it holds SOC 2 Type 2 and PCI DSS attestations, and Owl Practice markets itself as built specifically for Canadian privacy laws. A review confirms what those claims cover in practice, hosting location, data residency, and whether the attestation scope actually includes the modules your practice uses, rather than relying on the marketing summary.
Ask where the transcript and any recording are stored, how long they are retained, whether the vendor's staff can access session content, whether the data is used to train models, and how deletion is handled if a client withdraws consent. Also confirm whether the tool operates in Canada or routes audio through US infrastructure, since that changes the cross-border picture. A vendor that cannot answer these plainly is not ready for a therapy session.
Look past the compliance claims on each vendor's homepage to specifics: where data is hosted, how audit trails work, what the backup and recovery process looks like, and what happens to your data if you switch platforms later. A structured comparison against CRPO's Standard 5.6 gives the practice a defensible basis for the choice, not just a preference.
Both, and the directory listing is easy to overlook. A Psychology Today-style listing collects prospective client information before they ever become a client, often through forms with their own data-sharing terms, which deserves the same review attention as any vendor that will hold information about people who trust the practice with something sensitive.
More for mental health & counselling practices
Other services for this niche
About this service
Answers & guides
- How do you assess the privacy and security risk of an AI vendor?
- Can you use AI scribes in healthcare while protecting PHI?
- How do you prepare for a hospital or healthcare vendor security and privacy review?
- An AI Vendor Privacy & Security Checklist for Procurement Teams
- Building a Third-Party Vendor Risk Assessment Program That Scales
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.