Every portal on the market calls itself secure, so the word carries no information at the point of purchase. What does carry information is a small number of ordinary controls that you can check yourself in a trial account in half an hour. Secure client portals are the ones where those controls exist, are usable by whoever runs your practice, and are actually turned on. The certifications a vendor holds matter for their own operations. These four things determine whether your clients' documents are safe in your hands.
Individual accounts, and removing them
Shared logins are the most common weakness in small practices, and they are invisible until somebody leaves. Every person who gets in should have their own credentials, and you should be able to see the full list of who currently has access to what, and remove any of it in one action. If removing a person requires contacting the vendor, that is a real operational risk rather than a theoretical one.
Multi factor authentication, available and required
Available is not the same as in use. Check whether the product allows you to require a second factor for your own staff, and whether it offers one to clients. Requiring it internally is the higher value half, because a compromised staff account sees every client while a compromised client account sees one. Both are worth having; only one is worth arguing about.
A log you can read, and encryption you can verify
You want to be able to answer who opened this document and when, without asking the vendor. That means an access log that is visible in the product rather than available on request. Encryption in transit and at rest should be stated plainly in the vendor's documentation. What your practice is obliged to do beyond this depends on your regulator, your jurisdiction and your own advisers, and no software vendor can tell you.
Questions people ask about secure client portals
Are secure client portals safer than encrypted email?
Usually, mostly because access can be withdrawn afterwards and email cannot. A document sent by email exists in an inbox forever, on whatever devices that inbox syncs to.
What certifications should we look for?
They tell you about the vendor's own operations, which is useful context. They tell you nothing about whether your practice has shared logins, so treat them as necessary background rather than as an answer.
Who is responsible if client data leaks from a portal?
That depends on your contracts, your jurisdiction and the circumstances, and it is a question for your own legal adviser. Practically, assume you will be answering for it to your client either way.