You're reading the online guide — prefer a copy to keep?Download as PDF →
Why this guide exists
You're an expert at almost everything — except this.
You've spent years becoming an authority in your corner of healthcare — building a career, maybe running a practice, a clinic, or a business of your own. You've made hard calls before and hired plenty of people. But building custom software is new terrain, and suddenly you're in a room where everyone speaks a language you don't. That's an uncomfortable place to make a decision that's expensive to get wrong.
Here's the good news: you don't need to learn to code to choose well. You just need to know which questions separate a team that will look after you from one that will leave you stranded — and what a good answer actually sounds like versus a polished non-answer.
The goal isn't to make you technical. It's to put you back in the chair you're used to sitting in: the one where you're in control of the decision.
How to use this scorecard
Take it into every agency conversation — or read it now, before you start, so you know exactly what's coming.
Listen for the green answers and watch for the red flags beside each one.
Score each agency 1–5 per question. Be honest; a confident pitch isn't a passing answer.
Two questions are non-negotiable. If a team fails on support or HIPAA, walk away regardless of the total.
Eight things that decide whether your build goes well, in the order they tend to come up as you talk to a team. The first — whether they truly try to understand you — tells you the most. And don’t stop before the last two: how honest their quote is, and what happens after launch, are where the costliest surprises hide.
1
Discovery & mindset
Are they trying to understand your project — or just to land the work?
Watch how they engage
Don’t ask — observe. A partner digs into your goals, your users, and how things work today before talking solutions. A vendor mostly wants to start writing code.
A good answer sounds like
They ask more than they pitch — probing your goals, your users, and how things work today.
They want to understand the whole problem before proposing a solution.
They play back what they heard, to check they’ve truly understood you.
They care about your success — your users, your business model, how the app will make money — not just shipping code.
Walk-away signals
They’re keen to start writing code before they understand the problem.
They talk mostly about themselves and their tech, not your goals.
Lots of eagerness to “get started”, little curiosity about what you actually need.
You sense they want the contract more than they want to understand you.
Why it mattersHow a team behaves in the first conversations tells you which one you’re dealing with. One who invests time to understand you before proposing anything is showing you they’ll be a partner. One in a hurry to start building is showing you they’re just a vendor.
Score this agency
12345
1 = just a vendor · 5 = a true partner
2
How they run projects
Do they actually have a system — or will this be made up as they go?
Ask them
"Walk me through exactly how you run a project from day one to launch — your process, your systems, and who does what."
A good answer sounds like
A clear, repeatable process they describe end to end without hesitating.
Defined stages — requirements, design, build, testing, launch, support — and what you get at each.
Named roles: someone manages, someone builds, someone tests. Not one person doing all three.
They show you the tools they track the work in, so nothing quietly slips.
Walk-away signals
Vague, improvised answers — "we'll figure it out as we go."
No real process; it all lives in one person's head.
They can't tell you who is responsible for what.
Testing is an afterthought — whoever builds it also checks it, at the very end.
Why it mattersA team that can walk you through its own operating system in the first meeting is a team that has one. If they can't explain how the work actually happens before you've paid anything, picture how it feels once the project is live and under pressure.
Score this agency
12345
1 = improvised · 5 = systematic
3
Proof of work
How do I judge the work when I can't read the code?
Ask them
"Can you show me a working demo of something you've built for a client like me — and put me in touch with that client?"
A good answer sounds like
A working demo — a staging build with dummy data — so you can try the real features, not just see screenshots.
Named references they'll happily connect you with.
Case studies with specifics and outcomes, not adjectives.
They mention testing and code review as part of how they work.
Walk-away signals
Only mockups and designs — nothing shipped and running.
"We can't share client names" for everything.
They offer to show a live product with real patient data — a compliance red flag, not a selling point.
No mention of how quality is actually checked.
Why it mattersAnyone can show a pretty design. A working demo on dummy data, plus a client who'll vouch for them, is proof that's hard to fake. In healthcare, watch the reverse too: a team that casually shows you real patient data is telling you how it will treat yours. And if you plan to sell this software to other businesses like yours, check they’ve built SaaS (multi-tenant) products before — not just one-off internal tools.
Score this agency
12345
1 = vague · 5 = proven
4
Communication
Will I be left in the dark while they build?
Ask them
"Who exactly will I talk to, how often, and will any of it happen in my working hours?"
A good answer sounds like
A named project coordinator who is your single point of contact.
Committed overlap hours with your timezone for live calls.
A regular rhythm — weekly check-ins, working software shown often.
You see progress every couple of weeks, not only at the end.
Walk-away signals
"Just email us anytime" — with no named owner.
No scheduled calls; everything async with long delays.
You won't see the product until it's "done."
Replies that routinely arrive a full day later.
Why it mattersA distance or timezone gap is fine — silence is not. The fix is a named person and a predictable rhythm, so you're never wondering what's happening with your money.
Score this agency
12345
1 = silent · 5 = in sync
5
Tech & ownership
Could I get trapped with this team — with no one else able to take over?
Ask them
"Why this technology for my project, who else could maintain it if you vanished — and when do I actually own the code?"
A good answer sounds like
Plain-language reasons tied to your needs, not buzzwords.
Mainstream, widely-used technology any team could pick up.
Honesty about trade-offs — and a couple of options, not one.
You own all the source code and IP — handed over as it’s built, not withheld until the final payment.
Walk-away signals
Jargon with no translation when you ask "why?"
Obscure tools only they know how to maintain.
One take-it-or-leave-it answer with no reasoning.
They keep the code until everything’s paid — or won’t hand over the IP at all.
Why it mattersThe test of "the right stack" isn't whether it's fashionable — it's whether anyone other than this team could maintain it later. Mainstream and explainable beats clever and locked-in every time.
Score this agency
12345
1 = locked-in · 5 = open & owned
6
HIPAA & patient data
Will this be HIPAA-compliant — or is a breach waiting to happen?
Ask them
"Will you sign a BAA, and is HIPAA compliance built in from day one — or bolted on at the end?"
A good answer sounds like
Yes, they'll sign a Business Associate Agreement (BAA).
Compliance designed in from the start, not patched on later.
"The developer will handle it" — with no specifics.
Won't sign a BAA, or doesn't know what one is.
Compliance treated as a final-step checkbox.
No prior work with protected health information.
Why it mattersIn healthcare, a compliance mistake isn't a bug — it's a breach, with fines and headlines attached. This is the one area where "we'll figure it out later" should end the conversation.
Score this agency
12345
non-negotiable
7
The quote
Whose quote is honest — and whose is a lowball that will grow?
Ask them
"What exactly is included in this price — and what would count as 'out of scope' and cost me extra later?"
A good answer sounds like
An itemised quote tied to the scope from discovery — you can see what you're paying for.
Clear assumptions, and a plain list of what is not included.
A defined way changes are priced, so new requests aren't sprung on you.
They can explain why the number is what it is — not just hand you a total.
Walk-away signals
A single round number with no breakdown behind it.
Clearly the cheapest, with the least detail — the classic lowball.
No mention of assumptions, exclusions, or how changes are handled.
The scope is loose, so almost anything can later be called "extra."
Why it mattersThe lowest quote is often the one that understood your project least — and what looks like a bargain becomes a stream of "out of scope" change orders once you're committed. A complete quote comes from a complete discovery. Compare what's included, not just the number at the bottom.
Score this agency
12345
1 = vague lowball · 5 = complete & itemised
8
After-launch support
What happens the day after launch, when something breaks?
Ask them
"After you hand it over, who fixes the problems that appear — and what does that cost me?"
A good answer sounds like
A written support period included after launch, in the contract.
Clear response times for when something goes wrong.
They monitor and patch, and explain ongoing costs upfront.
You receive all source code and account access — you own it.
Walk-away signals
Support is "extra" and never quite defined.
No plan for the bugs that always surface after launch.
No response-time commitment of any kind.
They hold your code or accounts — you can't leave.
Why it mattersLaunch is the midpoint, not the finish line. The first month always surfaces issues; the question is whether someone is contractually on the hook to fix them — and whether you could walk away with your software if you ever wanted to.
Score this agency
12345
1 = you're alone · 5 = covered
Reading your scorecard
How to act on the numbers
32+
32–40: a strong partner. They answered specifically, showed proof, and didn't hide behind jargon. Shortlist them.
23+
23–31: ask again. Some good signs, some vague answers. Go back to the weak questions and press for specifics before deciding.
!
Any low score on Question 6 or 8 — stop. Weak support or weak HIPAA answers are deal-breakers on their own, no matter how high the total. These are the two that cost you most if they're wrong.
Included free
Two tools to take with you
Score every agency the same way — and keep the questions in your pocket for the meeting itself.
Track it in the scorecard spreadsheet
A ready-made workbook to score and compare every agency side by side. Totals and a verdict calculate themselves, Support and HIPAA are flagged as non-negotiables, and a second tab reminds you what a good answer to each question sounds like.
All eight questions on a single screen, with what a good and a bad answer sounds like. Save it to your phone and pull it up while you’re across the table from a vendor.
We wrote this guide to help you choose well — even if that's not us. A team confident in its work has nothing to fear from a checklist. So take these eight questions into every conversation you have, ours included, and hold us to the same standard.
For the record, the green answers above are how we already work: it starts with a detailed discovery before we ever put a number on the table, then live products and real client references, a named coordinator who keeps you in the loop, three months of support included after every launch, code and IP that are yours from day one, and a dedicated HIPAA-compliant practice with healthcare builds behind it.
Want a second opinion on your specific idea?
Book a free build-readiness call. We'll give you our honest read on scope, the right approach for your project, a realistic cost and timeline, and the traps to avoid — whether or not you end up working with us.