AI for Mental & Behavioral Health Clinicians
Strategic · M20 · lesson 20 of 23 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
The 12-Question Behavioral Health AI Vendor RFI
📖
now learning

The 12-Question Behavioral Health AI Vendor RFI

15 min

Jordan's EHR vendor said yes. The clinical director asked whether the platform could do AI-assisted scoring for the measurement-based care rollout, and the sales engineer said yes, beamed, and moved to the pricing slide. What he did not say, and what Jordan did not know to ask, is that the vendor's subprocessor list includes a model provider that does not sign a BAA at the tier Jordan is paying for. Twenty-five clinicians, three counties, and PHI flowing to a company with no legal obligation to Jordan's clients at all. That gap, between the demo and the diligence, is what this lesson closes. By the end you will run a structured, written Request for Information across twelve areas (BAA, zero-data-retention, 42 CFR Part 2 handling, EHR integration, security certifications, de-identification, model provider transparency, training-data opt-out, breach history, support model, contract terms, indemnification) and leave with the complete 12-Question Behavioral Health AI Vendor RFI, ready to send before the first contract call.

Why the Demo Is Not Diligence: The Intake Analogy

You would never diagnose a client from their brochure. If a new client handed you a glossy one-pager that said "doing great, highly motivated, no risk factors," you would take the paper and do the intake anyway: structured questions, history, screening instruments, your own observation. The brochure is marketing; the intake is assessment. Every clinician knows the difference in the clinical room and forgets it in the vendor conference room, where a sales demo (a brochure with animations) substitutes for assessment, and where the fake "anxiety client" never mentions suicidal ideation, abuse, or substance use, because demos are built to avoid exactly the cases your practice actually sees.

Hold that analogy for the whole lesson: the RFI is your intake assessment for the vendor. A Request for Information is a set of questions the vendor must answer in writing, before contracting, with the answers attached to the eventual agreement. The written part matters more than clinicians expect. A verbal "yes, we're HIPAA compliant" evaporates when something goes wrong. A written response saying "we maintain zero-data-retention agreements with all model providers" is a representation you can hold the vendor to, escalate to your attorney with, and, if false, build a breach-of-contract claim on. In AI vendor due diligence for a therapy practice, the document is the diligence.

The RFI also sorts vendors before you spend pilot time on them. A vendor that answers all twelve areas promptly, specifically, and in writing is showing you its compliance maturity. A vendor that stalls, answers in marketing language ("we take security very seriously"), or routes question seven to "that's proprietary" is also telling you something; believe it. Most clinical directors get evaluation wrong on the first vendor because they let the demo set the agenda; the RFI takes it back. The twelve areas that follow are the behavioral health vendor RFI in full, walked through in four clusters, because each question exists to catch a failure that has already happened to a practice somewhere.

Question one: the Business Associate Agreement. Will you sign a BAA, at the tier we are purchasing, covering every service component that touches PHI? Every word is load-bearing. Plenty of vendors "offer a BAA" only on the enterprise tier while the demo, and the price the owner remembers, was the starter tier. Ask for the actual BAA document with the response, not a statement that one exists. And note "every component": some platforms BAA the core product but exclude the analytics module, the support-ticket system, or the mobile app. A BAA that covers part of the data path is a seatbelt bolted to half the chassis.

Question two: zero-data-retention. Does the vendor maintain zero-data-retention (ZDR) agreements with its model providers, meaning the underlying model provider does not store our PHI after processing or retain it for any secondary purpose? This is distinct from the BAA question, and most diligence collapses the two. A vendor can sign you a beautiful BAA and still send transcripts to a model provider under default API terms that retain data for days or weeks. The RFI forces the vendor to state, in writing, what retention applies at each hop. If the answer is vague ("data is processed securely"), treat it as a no and ask again: which providers, what retention period, under what written agreement.

Question three: 42 CFR Part 2 handling. If our practice holds records subject to 42 CFR Part 2 (substance use disorder records from a Part 2 program), how does your product segment, mark, and restrict those records, and how does it handle the redisclosure prohibition? Part 2 is stricter than HIPAA, the 2024 final rule did not erase that strictness, and a scribe that mingles SUD content into a general progress-note pipeline can manufacture a redisclosure violation at machine speed. A vendor that has never heard of Part 2 has answered a question you did not have to ask: behavioral health is not its real market. The intake analogy holds: this is where you learn whether the client has actually been in treatment before, or is just saying the words.

Cluster Two: The Technical Chassis (EHR Integration, Security Certs, De-Identification)

Question four: EHR integration. How does your product move a finished note into our EHR (true API integration, browser extension, copy-paste), and what does the integration pull out of the EHR to do it? Both halves matter. Copy-paste means every note transits a clipboard, a workflow tax your clinicians pay eight times a day and a security surface of its own. An integration that reads from the EHR is a second PHI flow that must appear in the BAA and the data map; vendors love to describe what they write into your chart and go quiet about what they read out of it.

Question five: security certifications. Provide your current HITRUST certification or SOC 2 Type II report, with the report period. The "Type II" matters: Type I says the controls existed on the day the auditor visited; Type II says they operated over a sustained window, typically six to twelve months. A vendor offering a Type I, a "SOC 2 in progress," or a self-assessment is offering a treatment plan it never followed. HITRUST is the heavier healthcare credential; either is acceptable, but the evidence must be the report itself (under NDA if needed), not a website badge. Read the exceptions section, where auditors note the controls that failed; that is where the truth lives.

Question six: de-identification. When you say our data is "de-identified" for analytics or product improvement, which standard do you use (HIPAA Safe Harbor's removal of the eighteen identifiers, or Expert Determination), who performs it, and can we see the methodology? In behavioral health this question has teeth it lacks elsewhere, because a therapy transcript is narrative. Stripping the name and birth date from a transcript that says "client described the affair with her pastor at the Fresno congregation where she directs the choir" de-identifies nothing. A vendor that hand-waves "we remove identifiers" without addressing narrative re-identification risk has not thought about your data type; "Expert Determination, annually, by an independent statistician, methodology under NDA" is what a real answer looks like.

The demo is the brochure; the RFI is your intake. A vendor that will not answer twelve written questions before the contract will not answer one hard question after the breach.

Cluster Three: The Model Layer (Provider Transparency, Training Opt-Out)

Question seven: model provider transparency. Which model providers and cloud infrastructure providers process our PHI (for example OpenAI, Anthropic, AWS, Azure, GCP), at what service tier, and under what agreements? This is the question that would have saved Jordan, and the one most diligence misses, which is why a later lesson in this chapter is devoted to it. You need the list, in writing: every third party in the data path, named, with the tier. "We use industry-leading AI" is not an answer. "Anthropic via AWS Bedrock under a BAA with zero-data-retention, plus AWS storage under our AWS BAA" is an answer. The follow-up that separates real answers from recitations: does each named provider sign a BAA at the tier the vendor actually purchases? Jordan's vendor could answer the first half truthfully and still conceal the fatal fact in the second.

Question eight: training-data opt-out. Is our practice's data used to train or fine-tune any model, by you or any subprocessor, and is the opt-out the default or something we must configure? The honest landscape is messier than vendors present: some platforms train on customer data unless you opt out, some opt you out by default, some never train on customer content, and some "do not train" themselves but pass data to a provider whose terms at the purchased tier permit it. Ask for the answer at every layer and for the contractual language, not the settings screenshot. "We do not currently train on your data" versus "we are contractually prohibited" is the distinction between a habit and an obligation, and only the obligation survives the next funding round, acquisition, or pivot.

Why does this cluster carry extra weight in a behavioral health RFI? Because the content is psychotherapy. A retail chatbot transcript leaking into a training corpus is embarrassing; a therapy transcript describing suicidal ideation, trauma history, or substance use leaking into one is a clinical betrayal with board-complaint gravity. Your clinicians' licenses sit on top of these data flows, and the consent addendum your clients signed described a tool, not a training pipeline. The RFI makes the pipeline visible before the consent language must defend it.

Cluster Four: The Relationship (Breach History, Support, Contract, Indemnification)

Question nine: breach history. Has the vendor experienced any security incident, breach, or OCR complaint in the last five years, and how was it handled and disclosed? Vendors do not volunteer this, and a clean five-year history at a young company is less reassuring than an older company's well-handled incident, the way a client who reports zero conflict ever is reporting a screening failure, not a marriage. Assess the handling: did it notify affected covered entities within the BAA's window, remediate, publish anything. A vendor that answers "no incidents" in writing has made a representation; a vendor that refuses the question has answered it.

Question ten: support model. What is the support structure (named account manager or ticket queue), what are the response-time commitments, and is there a clinical escalation path when the product produces a dangerous output, such as a note that misstates risk content? That last clause is the behavioral health twist. Every SaaS company can recite its ticket SLA; few have thought about what happens when a clinician reports that the scribe inserted "client denied suicidal ideation" into a session where the client did not. You want, in writing, who picks that up, how fast, and whether such reports feed a documented correction loop.

Question eleven: contract terms. What is the term length, the auto-renewal mechanics, the price-escalation cap, and, above all, the data return and deletion provision at termination: in what format do we get our data back, how fast, at what cost, and what is destroyed when? Offboarding is the part nobody negotiates while in love, and a vendor holding two years of your session-derived notes with no export obligation has leverage you handed it for free. Question twelve: indemnification. If the vendor's failure (its breach, its subprocessor's breach, its misrepresentation about retention or training) causes your practice regulatory penalties, breach-notification costs, or claims, does the vendor indemnify you, with what cap, and does it carry cyber-liability insurance at what limits? Most vendor paper, read closely, indemnifies the vendor against you. The RFI asks early enough that the answer shapes the negotiation instead of surprising your attorney during it.

Scoring the Responses: From Answers to a Decision

An RFI you cannot score is a questionnaire, not an instrument, so build the scoring rule before the responses arrive, exactly as you would lock an outcome measure before treatment starts. Three grades per question area: Pass (specific, written, documentary evidence attached), Conditional (responsive but with a gap that has a named fix, such as "BAA only at the next tier up," which becomes a negotiation item), and Fail (refused, vague, or marketing language where a fact was requested). Then designate non-negotiables in advance. Four areas are pass/fail gates with no conditional grade: the BAA at your tier (one), zero-data-retention or explicitly disclosed retention you have affirmatively accepted (two), model provider transparency with the BAA-at-tier follow-up (seven), and training-data opt-out as a contractual term (eight). A vendor can be conditionally acceptable on support response times; it cannot be conditionally acceptable on whether a non-BAA model provider holds your clients' trauma narratives.

Two mechanics make the instrument work. Send the RFI to at least two vendors at once: the first time you see a real ZDR answer next to an evasive one, you will never mistake the evasion again. And put a deadline (ten business days is fair) and a format requirement (answers in your document, not a link to a trust portal) in the cover note. The trust portal is the brochure again; you are running an intake, and the client answers your questions in your format.

One senior-supervisor caution: do not let the RFI become a fig leaf. The most common failure mode is the clinical director who runs it, gets a Fail on question seven, and signs anyway because the demo was lovely and the clinicians are drowning. If you already know you will sign regardless, the RFI is theater, and theater is worse than nothing because it creates a paper trail showing you knew. Run the instrument only if a Fail on a gate actually kills the deal. That discipline is the whole difference between diligence and decoration.

Reading Between the Answers: What Evasion Patterns Mean

Clinicians are trained to hear what is not being said, and that skill transfers directly to RFI review. Pattern one: the tier dodge, answers true of the enterprise tier presented as if they describe the tier you asked about. Jordan's situation is the canonical case: the model provider in the subprocessor list does sign BAAs, just not at the tier Jordan's vendor purchases, so every marketing sentence was true and the data path was still uncovered. Counter it by appending "at the tier we are purchasing" to questions one, two, seven, and eight, and by making the vendor name the plan its answers describe.

Pattern two: the future tense. "We are pursuing HITRUST," "SOC 2 Type II is on our roadmap," "Part 2 controls are planned for Q3." Roadmaps are not controls; grade the present, and if the promise matters, write it into the contract with a date and a remedy. Pattern three: the responsibility shuffle, where the vendor answers a question about its own obligations by citing its cloud provider's credentials ("we are hosted on AWS, which is HIPAA compliant"). AWS's posture does not transfer to an application built on it any more than a hospital's accreditation transfers to every clinician renting an office inside it. Pattern four: the proprietary shield on question seven. Subprocessor identity is not a trade secret; serious vendors publish subprocessor lists because their other healthcare customers demanded them. A vendor claiming confidentiality over the names of the companies holding your PHI is asserting that you may not know who has your clients' data, which is disqualifying.

Treat the evasion patterns as data about the relationship you are entering. The RFI period is the honeymoon: the vendor's responsiveness is at its lifetime peak, and every friction now will be worse after signature. A vendor that is slippery during the sale will be slippery during the breach, and the breach is when your practice needs the truth in hours, not quarters.

The Applied Problem: Build the Complete 12-Question Behavioral Health AI Vendor RFI

Your artifact is the 12-Question Behavioral Health AI Vendor RFI: a send-ready document with cover note, twelve numbered question areas, evidence requests, and a scoring sheet. Four steps.

Step one, the cover note: your practice, the product and specific pricing tier under evaluation, the ten-business-day deadline, the requirement that answers be written into the document itself, and the sentence that gives the instrument teeth: "Responses to this RFI will be attached as representations to any resulting agreement." Step two, the twelve question areas as numbered sections: 1 BAA (at our tier, all components, document attached), 2 zero-data-retention (per model provider, retention period, written agreement), 3 42 CFR Part 2 handling (segmentation, marking, redisclosure prohibition), 4 EHR integration (mechanism, and what it reads from the chart), 5 security certifications (HITRUST or SOC 2 Type II, report and period attached), 6 de-identification (standard, who performs it, narrative re-identification risk), 7 model provider transparency (every provider, named, with tier, and whether each signs a BAA at that tier), 8 training-data opt-out (every layer, contractual not configurational), 9 breach history (five years, incidents and handling), 10 support model (SLA plus the clinical escalation path), 11 contract terms (term, renewal, escalation cap, data return and deletion at termination), 12 indemnification (scope, cap, cyber-liability limits). Under each, an "Evidence requested" line naming the document you expect: the BAA itself, the SOC 2 Type II report, the subprocessor list, the insurance certificate.

Step three, the scoring sheet: a twelve-row table with columns for Grade (Pass / Conditional / Fail), Evidence Received, and Notes, with the four gate questions (1, 2, 7, 8) pre-declared, where any grade below Pass ends the evaluation. Write the gate rule as a sentence above the table so a future you under deadline pressure cannot pretend it was not the rule. Step four, the verification pass: read the finished RFI as the vendor's lawyer would, hunting for any question loose enough to answer with marketing ("Do you take security seriously?" fails; "Attach your current SOC 2 Type II report and identify the period" passes), and confirm every tier-dimension question says "at the tier we are purchasing." Done looks like a document you could email to Mentalyc, Upheal, Eleos Health, or your EHR vendor's AI team this afternoon: every answer gradeable, every gate pre-named, and a response that would have caught Jordan's missing BAA before a single transcript moved.

Key Takeaways

  • The demo is the brochure and the RFI is your intake assessment: a written instrument across twelve question areas, answered before contracting, with responses attached as representations to the agreement. In AI vendor due diligence for a therapy practice, the document is the diligence.
  • The legal spine is three distinct questions: a BAA at your purchased tier covering every component that touches PHI, zero-data-retention agreements with the model providers (a BAA does not imply ZDR), and 42 CFR Part 2 segmentation and redisclosure handling for SUD records.
  • Security evidence means the document, not the badge: a current HITRUST certification or SOC 2 Type II report with its period and exceptions section. Type II proves controls operated over time; Type I and self-assessments do not. De-identification claims must address narrative re-identification risk, because stripping eighteen identifiers from a therapy transcript can still leave the client recognizable.
  • Question seven, model provider transparency, is the one most diligence misses: every third party in the data path (OpenAI, Anthropic, AWS, Azure, GCP), named in writing with the tier, plus the follow-up nobody asked at Jordan's practice: does each provider sign a BAA at the tier the vendor actually purchases.
  • Training-data opt-out must be contractual at every layer: "we do not currently train on your data" is a habit, "we are contractually prohibited" is an obligation, and only the obligation survives an acquisition or pivot. The relationship questions (breach history, clinical escalation path, data return at termination, indemnification with cyber-liability insurance) decide what the partnership feels like after signature.
  • Score with Pass, Conditional, and Fail, and pre-declare four gates (BAA, ZDR, model provider transparency, training opt-out) where anything below Pass ends the evaluation. An RFI you would override for a lovely demo is theater, and theater creates a paper trail proving you knew.
  • Read evasion patterns as data: the tier dodge, the future tense, the responsibility shuffle ("we are hosted on AWS"), and the proprietary shield over subprocessor names are each disqualifying, because the RFI period is the vendor's lifetime peak of responsiveness.