Buying Smart

Reading a SaaS Service Level Agreement for Clinic Software

Most cloud software for clinics ships with a service level agreement. Most buyers never read it, and vendors know that. The SLA is where the marketing promise of "99.9% uptime" turns into a precise set of definitions, exclusions, and remedies that determine what you get when the system goes down during a fully booked Monday. Reading it before you sign takes an hour. Discovering its limits after an outage takes much longer.

What an SLA is and is not

An SLA is a contractual commitment about service performance, usually covering availability, support responsiveness, and sometimes performance metrics such as page load or report generation times. It is not a guarantee that outages will not happen; it is a description of how the vendor measures them and what you receive when the commitment is missed. The remedy is almost always a service credit against future fees, not a refund and not compensation for lost revenue.

The SLA also sits inside a larger set of documents: the master subscription agreement, the acceptable use policy, the privacy or data processing terms, and, for healthcare, the business associate agreement. The SLA rarely overrides those. If the master agreement disclaims consequential damages, the SLA credit is your only remedy for downtime, no matter what it costs the practice.

Uptime math

Availability percentages sound similar and mean very different things. The table below translates common commitments into allowed downtime per month, which is how most SLAs measure.

CommitmentAllowed downtime per monthPer year
99%About 7 hours 18 minutesAbout 3.65 days
99.5%About 3 hours 39 minutesAbout 1.83 days
99.9%About 43 minutesAbout 8.8 hours
99.95%About 22 minutesAbout 4.4 hours
99.99%About 4 minutesAbout 53 minutes

Three questions determine whether the headline number means anything. First, what is the measurement window? Monthly is standard; a quarterly or annual window lets a vendor absorb a long outage into a large denominator. Second, how is "unavailable" defined? Some SLAs count only a total outage confirmed by the vendor's monitoring, so a system that is technically up but unusably slow is "available." Third, does the clock start when the problem begins or when you open a ticket? A definition that starts at ticket creation shifts the burden of detection onto you.

The exclusions that matter

Every SLA excludes some downtime from the calculation. Common exclusions are reasonable in principle but vary enormously in scope:

  • Scheduled maintenance. Look for a cap on hours per month, a required notice period, and a commitment to off-hours windows in your time zone. "Maintenance as needed with reasonable notice" is not a commitment.
  • Emergency maintenance. Often unlimited and uncapped. Ask how often it was invoked in the past year.
  • Third-party services. If the vendor runs on a public cloud provider and excludes that provider's outages, the SLA covers only the vendor's own code. Ask whether their cloud provider's outages are included.
  • Customer-caused issues and internet connectivity. Fair, but the definition should not sweep in problems with the vendor's own integrations or APIs.
  • Force majeure. Standard, but check whether cyberattacks are classified as force majeure. If a ransomware event at the vendor is excluded, the SLA does not cover the scenario most likely to take you down for days.

Ask for the history. A vendor confident in its uptime will share a status page or twelve months of availability data. Compare the reported figure with the SLA definition; if they report 99.98% but define unavailability narrowly, the real experience may be worse.

Support response and resolution

Support SLAs usually define severity levels with a response time for each. Read the definitions closely. "Response" typically means a human acknowledges the ticket, not that work has begun. "Resolution" targets are rarer and usually framed as goals rather than commitments. For a clinic, the relevant questions are practical: what severity does a complete outage receive, is phone support available during your clinic hours (including early morning and Saturday if you see patients then), and is after-hours support included or an add-on?

Also check what the SLA says about support for integrations. If the interface between your practice management system and the vendor stops working, each side may classify it as the other's problem. A support commitment that covers "the service" but not "integrations with third-party systems" leaves the most common failure point uncovered.

Credits and remedies

Service credits are the standard remedy, and their structure tells you how seriously the vendor takes the commitment. A typical schedule offers 5 to 10 percent of the monthly fee for a miss and scales to 25 or 50 percent for severe misses. Details to check:

  1. Do you have to claim the credit? Most SLAs require a written request within a short window, often 15 or 30 days. Missed deadline, forfeited credit.
  2. Is there a cap? A cap at 100 percent of one month's fee is common; a cap at 10 percent makes the credit symbolic.
  3. Is the credit the exclusive remedy? Almost always yes. That means chronic underperformance produces small credits but no exit.
  4. Is there a termination right? The most valuable term to negotiate: the right to terminate without penalty if the vendor misses the SLA in, say, three months out of any six. Without it, you are locked into a failing service for the length of the contract.

Security and data terms

Some vendors fold security commitments into the SLA; others place them elsewhere. Wherever they live, a clinic should find written commitments on encryption in transit and at rest, backup frequency and retention, recovery time and recovery point objectives, breach notification timelines that satisfy the business associate agreement, and data return or deletion at termination. A recovery time objective in the SLA is particularly useful because it converts a vague "we have backups" into a measurable promise about how long a restore will take.

A buyer's checklist

  • Uptime commitment, measurement window, and the precise definition of unavailable.
  • Scheduled maintenance cap, notice period, and time-zone window.
  • Whether cloud provider outages and cyberattacks count against the commitment.
  • Support hours, severity definitions, and phone availability during your clinic hours.
  • Credit schedule, claim process, cap, and whether credits are the exclusive remedy.
  • A termination right for chronic misses.
  • Recovery time and recovery point objectives, backup retention, and data return at exit.

An SLA will never make a system reliable. It does tell you, in advance, how the vendor thinks about reliability and what your position will be on the day it fails. That is worth an hour before signing.

Common questions

What does 99.9% uptime mean in practice?

Roughly 43 minutes of allowed downtime per month, or just under nine hours per year, before the vendor is in breach of the commitment. Whether a given outage counts depends on how the SLA defines unavailability and what it excludes, so the percentage alone is not enough.

Can a clinic recover lost revenue from a vendor after an outage?

Rarely. Most subscription agreements disclaim consequential damages and make the SLA service credit the exclusive remedy. If downtime costs are a real concern, negotiate a stronger credit schedule and a termination right for repeated misses rather than expecting to recover losses.

Are scheduled maintenance windows counted as downtime?

Usually not, which is why the maintenance terms matter. Look for a monthly cap on maintenance hours, advance notice, and windows outside your clinic hours. Unlimited or loosely defined maintenance can hide a significant amount of unavailability.

Is an SLA the same as a business associate agreement?

No. The business associate agreement covers HIPAA obligations for protected health information, including breach notification and safeguards. The SLA covers service performance such as uptime and support response. A clinic needs both, and the terms should not contradict each other.