Where is your clients' data? Seven questions worth asking any practice system
Medical data security has been in the news lately. It is a good moment to ask yourself a calm question: where exactly is your clients' data, and what happens to it? This is not about scaring anyone or pointing fingers. It is about you, as a therapist, knowing what to ask. Client records are among the most sensitive data there is, and the responsibility for them rests with you. Here are seven questions worth asking any system, ours included.
1. Where does the data physically sit, and is it encrypted?
Your notes, contact details and appointment histories have to be saved somewhere. It is worth knowing where. In which country? Inside the European Union? It matters for GDPR. And whether the data is encrypted "at rest", that is on the disk, not only while it travels. Encrypting medical data is a standard today, not a luxury. The question is whether the provider can confirm it plainly.
In MentAI the practice's data is encrypted and kept on infrastructure in the European Union. That is not a marketing line. It is how the system is set up.
2. Who besides you has access to it?
In a system used by many practices, one thing is key: whether one practice's data is sealed off from another's. It should be technically impossible for anyone, another practice or a random error, to look into records that do not belong to them. This is called isolation, and it does not happen by itself; it has to be built deliberately and checked.
In MentAI the isolation between practices is built into the way the database itself is structured, and clinical records are an additional, optional module with encrypted storage and an access log: you can see who looked into a record and when.
3. What happens if someone learns your password?
A password, even a strong one, is a single lock. If it leaks, through phishing or because you use the same one on another site, someone walks into your account. That is why it is worth asking about two-factor authentication (2FA): a second login step, a one-time code from an app on your phone. Then the password alone is no longer enough.
In MentAI two-factor authentication is available for every account, and when the client records module is switched on it is required. The more sensitive the data, the stronger the lock should be.
4. Is there a backup, and has anyone ever restored it?
A failure, a mistake, an accidentally deleted entry: it happens to everyone. Here the question is not "is there a backup", because everyone will say there is. The question is: has anyone checked that data can really be recovered from that copy? A backup nobody has tested is a backup that may not exist.
In MentAI backups run continuously, and restoring data from a backup is rehearsed, not assumed in theory.
5. Will the provider notice when something worrying is happening?
Good security is not only a wall but also an alarm. Will the system detect unusual behaviour, an attempt to download data in bulk, a login from the other side of the world? Silence after an incident is the worst outcome, because it means nobody was watching. It is worth knowing whether anyone is watching at all.
In MentAI automatic threat detection flags unusual activity on an account, so that action can be taken early rather than finding out at the end.
6. Is your data yours, or are you its hostage?
Security also means freedom. Can you export your data and leave at any moment? Client records belong to you and to them, not to the software provider. A system that makes leaving hard keeps you in place through fear, not quality.
In MentAI your data, contacts, appointments and billing, can be exported at any time. You stay because you want to, not because there is no way out.
7. When did you last rehearse a restore after a failure, and how long did it take? updated 8 Sep 2026
We are adding this question a month later, because question four turned out to be too gentle. "Has anyone restored the backup" can be confirmed with a nod. It is much harder to dodge three specifics: when the last test was, how long it took from the decision to a working system, and what the practice would have to do in the meantime. Good practice in the industry is a test every quarter; a backup without a restore test is an assumption, not a safeguard.
It is also worth knowing what to ask next: do they restore a single table or the whole system; does a failure mean setting a new password afterwards (in most systems yes, and that is fine as long as someone warns you); and does the provider give the time as a target or as a commitment with exclusions.
Our answer, with a date: on 8 September 2026 we rebuilt a copy of the whole of MentAI from scratch, from backups, in 8 minutes. We declare a target of 4 working hours and a commitment of up to 24 hours, excluding an outage of an entire cloud region and force majeure. Checking the public pages of other practice tools (as of 8 September 2026), we found no provider that publishes the date and duration of its own test; that does not mean they do not run one, it means it is worth asking.
What is all this for?
We do not know a perfect system and we do not claim to be one. But we take these questions seriously, which is why we can answer them with specifics rather than slogans: data encrypted and in the European Union, tight isolation between practices, two-factor authentication, tested backups, threat detection and full data portability.
Ask these questions of anyone you entrust your clients' data to. You have the right to.
And your clients have the right to expect you to ask them, of us too.
Your practice. Your data. Your decision.
Frequently asked questions
Where is client data stored in a practice-management system?
Ask directly: in which country or region does the data sit, and is it encrypted at rest, not only in transit. For medical data and GDPR it matters whether processing takes place in the European Union. In MentAI the practice's data is encrypted and stored on infrastructure in the European Union.
Can another practice see my data in the same system?
In a well-built system, no. Each practice's data should be technically isolated, so that no other practice and no mistake can open records that are not theirs. In MentAI the isolation between practices is built into the way the database itself is structured.
What happens if someone learns my password to the system?
A password alone is one factor. Ask about two-factor authentication (2FA): a second login step, a code from an app on your phone, so that the password alone is not enough. In MentAI two-factor authentication is available, and required when the client records module is switched on.
How do I know the system's backup really works?
The question is not "is there a backup", because every provider will say there is. The question is whether anyone has checked that data can really be recovered from that copy. In MentAI backups run continuously, and restoring data from a backup is rehearsed, not assumed in theory.
How long does it take to restore a practice system after a failure?
Ask the provider for the date of their last test and how long it took. MentAI: test on 8 September 2026, the whole system rebuilt from backups in 8 minutes; declared target 4 working hours, commitment of up to 24 hours, excluding an outage of an entire cloud region and force majeure.
Will the system detect someone trying to steal client data?
Ask whether the system will recognise unusual behaviour, such as an attempt to download data in bulk or a login from an unusual place, and react. In MentAI automatic threat detection flags unusual activity on an account, so that action can be taken early.
Can I export my data from a practice-management system?
Yes, and it is an important criterion when choosing. Records belong to the practice and its clients, not to the software provider. In MentAI data (contacts, appointments, billing) can be exported at any time, and the system does not make leaving difficult.
See MentAI in practice: a demo with no account needed
The product interface is in Polish. Prefer to start for real? Sign-up is open: 30 days of the full version, no card, at mentai.pl.
Related posts: AI-assisted session notes, professional confidentiality and GDPR · An AI assistant for therapists: what AI should not do · Choosing practice-management software: a comparison.
New posts every week. Follow MentAI on Facebook or Instagram (in Polish): one thing a week that takes paperwork off the practice's desk.
MentAI