Security

Healthcare data deserves a specific operating model, not a badge wall.

Wizia processes the minimum data needed to identify, activate, and verify approved interventions. Contract, access, consent, retention, and evidence controls are defined with each customer before launch.

HIPAA and BAAs

Wizia can act as a business associate and enter a BAA when handling PHI on behalf of a covered entity or business associate customer.

SOC 2 controls

Qualified customers and prospects can request access to Wizia's current SOC 2 report under appropriate confidentiality terms.

Minimum necessary

Each deployment documents approved data sources, permitted purposes, required fields, users, destinations, and retention expectations.

PHI handling

PHI is processed only for customer-authorized healthcare operations and intervention workflows under the applicable services agreement and BAA.

  • Encryption in transit and at rest for covered production data
  • Logical separation and role-based access aligned to job responsibilities
  • Authentication, logging, access review, and workforce confidentiality controls
  • Controlled exports and customer-approved delivery destinations
  • Environment, vulnerability, backup, and incident-response procedures

Consent and opt-outs

The customer defines the legal and operational basis for each intervention and channel. Wizia implements the approved rules and does not treat one channel's permission as universal permission.

  • Channel-specific consent and eligibility rules are documented before activation
  • Suppression and opt-out signals are honored across the applicable Wizia workflow
  • Communications identify the approved sender and provide required disclosures
  • Clinical and emergency decisions remain with qualified customer or provider personnel

Access controls

Customer and workforce access is limited by role and operational need. Access is provisioned, reviewed, logged, and removed through documented processes.

  • Unique user identities and least-privilege role design
  • Administrative access restrictions and stronger authentication controls
  • Audit logging for sensitive workflows and production access
  • Joiner, mover, leaver, and periodic access-review procedures

Retention and deletion

Retention is set by data category, contract, legal requirements, and the deployment's measurement window. Wizia supports return or deletion of customer data at termination, subject to documented backup and legal-retention exceptions.

Specific schedules belong in the customer agreement and BAA; this page does not override those documents.

Subprocessors

Wizia maintains a documented subprocessor process covering diligence, contractual protections, access, change management, and customer notice where required by agreement.

Customers may request the current subprocessor list and relevant data-location information during diligence.

Incident response

Wizia maintains procedures to identify, contain, investigate, remediate, document, and notify customers of security incidents in accordance with contractual and legal requirements.

Security diligence

Request the documents your review requires.

Qualified prospects can request the security overview, BAA, SOC 2 report, subprocessor information, data-flow details, and questionnaire support.

Read the privacy policy