Short answer: The requirements that matter divide into three tiers. Non-negotiable: a signed BAA, audit logging, role-based access, and a full change history on amended notes. Size-dependent: supervision configuration, permissions granularity, payroll reporting, and group billing, all of which start mattering somewhere around five clinicians. Nice to have: everything a demo spends its time on.
Most requirements checklists are feature lists. This one is organised by what actually breaks, because Oasys sits at the infrastructure layer of working practices and from our ongoing conversations with therapists and group practice owners, the same four things fail in the same order as a practice grows.
Tier 1: non-negotiable, whatever your size
A signed BAA that covers subprocessors. Not just the EHR. If the platform uses a third-party AI service, a transcription vendor, or an analytics provider that touches PHI, ask whether the BAA extends to them. A BAA covering the EHR does not automatically cover a subprocessor.
Audit logging you can actually retrieve. Not "we log everything." Ask to see an export. During an investigation you need to answer who viewed a record and when, in a format you can hand over.
A full change history on amended notes. If a signed note is later unlocked and edited, the record should show who unlocked it, the stated reason, the content before and after, and when it was re-signed. Practices tell us some platforms do not produce this, and it is a genuine exposure during a payer audit. Oasys keeps all four. Other platforms vary, so ask directly and ask to see it demonstrated.
Role-based access. Your biller should not see clinical notes they have no reason to read. Once you have any non-clinical staff, all-or-nothing admin access stops being defensible.
Data export on your terms. Ask how you would get everything out in three years, and what "everything" includes. The answer tells you how the vendor thinks about lock-in.
Tier 2: the requirements that appear as you grow
These are the ones buyers under-specify, because at the point of purchase they are not yet painful.
Around five clinicians: permissions
The moment you employ an office manager, a biller, and clinicians who should not see each other's caseloads, coarse permissions start creating either risk or friction. This is also where couples and family work begins producing duplicate records if the platform cannot link them. One practice described a client completing intake individually, then needing a couples appointment: "we couldn't link them. And so they had to redo all the paperwork."
Demand: distinct roles with scoped access, and linked records for couples and family work.
Around fifteen clinicians: supervision and payroll
Supervision. Ask how supervision requirements are set. Many platforms require supervisor sign-off on every supervisee identically, including provisionally licensed clinicians who are independently credentialed with payers and do not legally require a co-signature. At three supervisees that is a nuisance. At fifteen it consumes a supervisor's week. Oasys configures supervision per role and per supervisor-supervisee relationship, so clinicians who do not need a co-signature can be exempted without switching supervision off across the practice. Other platforms handle this differently.
Payroll. This is the requirement almost nobody writes down and everybody eventually needs. One practice with a couple of dozen clinicians told us about twenty hours a week of a billing manager's time going into converting EHR data into a payroll ledger, because the software had no way to express how the practice pays people. That is half a full-time role, permanently, and it appears on no invoice.
Demand: a payroll ledger as an output, not a report you rebuild. Ask specifically whether revenue splits can vary per clinician, and whether payout can be gated on the underlying notes being signed and approved.
Around thirty clinicians: economics and observability
Per-user pricing with no volume consideration becomes the dominant line item. One practice put it plainly: "there's a point where it's going to get too expensive, because it's a cost per user." Per-transaction fees on claims, ERAs and text reminders compound exactly as you succeed.
Demand: predictable pricing you can model at double your current headcount, and practice-level reporting on revenue, retention, and utilisation without buying a second tool. One practice pays $300 to $400 a month for external analytics because their EHR does not provide them.
Group billing: the requirement with a five-minute test
If you run groups, this deserves its own line. CPT 90853 is billed per participant, so one group of eight is eight claims, each under that person's own name, insurance and authorisation.
The test: ask the vendor, live in the demo, to create one group session with eight attendees and produce eight correct claims. Count the actions. Then give two attendees different payers and a third an expired authorisation and watch what happens.
Platforms built around one clinician and one client can record a group but have no concept of fanning one clinical event into eight billable ones, so a human does it eight times.
Tier 3: what demos spend their time on
Mobile app polish, template libraries, client portal design, telehealth backgrounds. All genuinely nice. None of them is why practices leave. Weight them accordingly.
The requirements checklist
Take this into a demo and make them show you, not tell you:
- BAA covering subprocessors, in writing
- An audit log export, on screen
- An amended signed note with its full change history
- Two roles configured with genuinely different access
- A couples record linked across two clients
- Supervision configured so one clinician requires co-sign and another does not
- Eight claims produced from one group session
- A payroll ledger generated from real session data
- Practice-level reporting on revenue and retention
- A written answer on how you export everything in three years
Any vendor can pass a feature checklist. Fewer can pass this one in front of you.
A requirement most checklists miss
How you get in matters as much as what happens once you are there. Group practices in this category typically carry eight to eleven years of records, and failed migrations are common enough that the fear is rational. Practices tell us the same sentence in different words: we cannot do it twice.
Ask any vendor: will you build a migration path for my system, or hand me an importer? Does it carry completed assessments and intake forms, not just notes and demographics? What happens to appointments already on the calendar? Can I see the migrated data before I sign? Who does the work, your team or mine?
Those five questions separate vendors faster than any feature comparison.
Frequently asked questions
- What should I look for in a mental health EHR?
Start with the non-negotiables: a BAA covering subprocessors, retrievable audit logs, a full change history on amended notes, role-based access, and a clear data export path. Then add the size-dependent requirements: supervision configuration, permissions, payroll reporting and group billing.
- What are the HIPAA requirements for an EHR?
At minimum a signed Business Associate Agreement, access controls, audit controls, integrity controls, and transmission security. Ask specifically whether the BAA extends to any subprocessors handling PHI, including AI and transcription vendors.
- Does a mental health EHR need to be ONC certified?
Not for most outpatient therapy practices. It matters if you participate in programmes requiring certified technology, or if certification is a condition of a payer or health system relationship. Confirm against your own contracts rather than assuming.
- What EHR features do group practices need that solo practices do not?
Configurable supervision, role-based permissions, linked couples and family records, payroll reporting, and group billing that produces one claim per participant from a single session.
- How do I evaluate an EHR demo?
Make the vendor perform tasks rather than describe features. The ten-item checklist above is designed for exactly that, and the group-session and payroll tests are the two that most reliably separate platforms.
- What questions should I ask about data migration?
Whether they build a path for your specific system, what record types come across (assessments and intake forms are the usual casualties), what happens to future appointments, whether you can inspect the migrated data before committing, and who does the work.
Hashem Abdou··


