HIPAA safeguards
Wait List Open handles appointment openings for independent practices, so patient information is treated as protected health information from the moment it is entered. These are the administrative, physical, and technical safeguards we enforce in the product.
Minimum necessary by default
Public listings never include a patient's name, phone, email, or reason for the visit. Those details live in a separate, locked table and are only reachable by the single office that holds the booking.
Audited access to patient details
A business cannot bulk-read contact information. Each record is opened one at a time through a server-side check, and every view — plus every denied attempt — is written to a tamper-resistant access log that staff cannot edit or delete.
Automatic logoff
Signed-in sessions end after 15 minutes of inactivity, with a one-minute warning, so an unattended screen at a front desk does not leave patient details exposed.
Encryption and least privilege
All traffic is TLS-encrypted and data is encrypted at rest. Row-level security scopes every query to the signed-in account, column-level grants hide office phone, address, and calendar URLs from anonymous visitors, and roles are stored separately so they cannot be self-assigned.
Retention limits and patient control
Contact details are automatically deleted 30 days after the appointment ends, and are removed immediately when a patient cancels their booking. Logs and telemetry are scrubbed of names, emails, phone numbers, and tokens before they are stored.
Strong authentication
Email confirmation is required, passwords are checked against known breach lists, sign-in errors never reveal whether an account exists, and password resets use single-use links.
Business Associate Agreements — how to get one
Technical safeguards are only half of HIPAA. A covered entity — a dental office, clinic, therapy practice — also needs a signed Business Associate Agreement with every vendor that stores or transmits protected health information, including the hosting and database layer behind this app. The default shared infrastructure this app runs on is not BAA-covered, so until a BAA is executed for your practice, operate in PHI-light mode (see below).
- 1. Request a BAA. Email baa@waitlistopen.com from a practice address with your legal entity name, NPI (if applicable), and the locations you want covered. We reply with a draft BAA and a short security questionnaire within two business days.
- 2. We move you to BAA-covered infrastructure. Covered practices are provisioned on a dedicated, BAA-backed database and hosting tier with the same product features. Your existing account, openings, and audit history migrate with you.
- 3. Sign and go live. Once both parties countersign, your dashboard shows a “BAA in force” badge, PHI-restricted free-text fields are unlocked for your staff, and audit-log exports become available on demand for your compliance officer.
- 4. Ongoing obligations. The BAA covers breach notification within 60 days, subcontractor flow-down, return or destruction of PHI at termination, and annual access-log review. We can provide a written safeguards summary for your HIPAA risk assessment.
Timeline is typically 5–10 business days from request to countersignature. There is no additional charge for the BAA on the Pro plan.
Never put PHI in free-text fields
Opening notes and “reason for visit” fields are for scheduling logistics only. Whether or not a BAA is in force, keep the following out of them:
- Diagnoses, symptoms, test or lab results, medications
- Medical record numbers, insurance or claim IDs, dates of birth, SSNs
- Anything that identifies a specific patient by name in a note
Safe examples: “30 min cleaning,” “new patient welcome,” “chair 2, front entrance.” The product repeats this reminder next to every free-text field.
Questions about a specific safeguard, or need an access-log export for an audit? Email privacy@waitlistopen.com. See also our Privacy Policy.