When a small behavioral-health practice begins evaluating an AI tool, the vendor’s website almost always contains reassuring language about data protection. Phrases such as “enterprise-grade security,” “HIPAA-ready,” and “we take privacy seriously” appear frequently. None of those phrases answers the operational question a practice actually needs answered: how long will identifiable or de-identified data remain on the vendor’s systems, and under what conditions can the practice force its deletion?
This article offers a practical set of questions and follow-up tactics designed for practices that lack dedicated procurement or legal staff. The goal is not to become a security auditor. The goal is to replace marketing language with specific, written commitments that can be stored alongside the practice’s own decision record.
Why Retention Questions Matter More Than Feature Lists
Retention is the quiet risk that outlives the pilot. A tool that processes data for thirty days and then permanently deletes it creates a different exposure profile than a tool that retains logs, training samples, or cached outputs for years. Small practices rarely have the capacity to monitor vendor systems over long periods. Clear retention terms therefore function as a form of future workload reduction.
Marketing pages rarely disclose retention periods with precision. They prefer flexible language that preserves the vendor’s options. A practice that accepts that language at face value may later discover that patient-related data remains recoverable long after the clinical relationship has ended. Asking precise questions early forces the conversation into the realm of operational fact.

Core Questions That Cut Through Marketing Language
We use a short list of questions that leave little room for general reassurance. Each question is designed to produce a concrete answer that can be copied into the practice’s decision record.
What is the maximum retention period for any data submitted through this tool, including logs, temporary files, and model-training samples if applicable?
Does the retention period begin at the moment of submission or at the end of the customer relationship?
Can the practice request deletion of specific records or of all data associated with the account, and what is the documented turnaround time for that request?
Are any data elements retained after a deletion request for legal, security, or model-improvement purposes? If so, which elements and for how long?
Where are the data stored geographically, and do any subprocessors retain copies under different schedules?
These questions are intentionally narrow. Broad questions such as “Is the tool HIPAA compliant?” invite broad answers. Specific questions about retention invite specific answers or the admission that no written policy exists.
Follow-Up Tactics When Answers Are Vague
Vendors sometimes respond with links to general privacy policies or with statements that retention “depends on the use case.” In those moments we reply with a single clarifying request: “Please provide the specific retention schedule that would apply to the three structured administrative fields we plan to submit, in writing, with the name and title of the person providing the answer.”
If the vendor cannot or will not supply that schedule, the absence itself becomes useful information. It tells the practice that the operational details are either undefined or not intended for customer scrutiny. Either condition is a legitimate reason to pause or to choose a different tool.

Documenting the Answers Inside the Practice
Any written answer from the vendor is stored with the one-page decision record for that workflow. The file name includes the date and the vendor name so that future staff can locate the commitment without relying on memory or email search. If the vendor later changes its retention policy, the original commitment remains visible as a baseline for renegotiation or exit.
We also note the date of the answer and the name of the person who provided it. Vendor personnel change. A commitment that cannot be attributed becomes difficult to enforce. Attribution turns a marketing conversation into a recorded business representation.
Limits of the Questioning Process
Asking precise retention questions does not replace a Business Associate Agreement or a formal security review. It does not guarantee that the vendor will honor the stated schedule under every circumstance. What it does is convert vague reassurance into a specific claim that the practice can later cite. In a five-to-fifteen-person clinic that is often the highest level of control available.
The process also reveals the practice’s own readiness. If the team cannot clearly describe the data it plans to submit, the retention questions cannot be asked with precision. That discovery is useful. It returns the conversation to the mapping work that should precede any vendor discussion.
That’s a judgment call, not a tool question. Marketing language is designed to close a sale. Retention questions are designed to keep the practice’s future options open. Taking the time to ask them, document the answers, and treat non-answers as information has consistently improved the quality of our vendor decisions.
Slow is not the same as behind. A few focused questions about data retention often prevent months of later uncertainty when a pilot ends or a staff member leaves.