Security

Security review starts with the workflow.

Wattson Health supports healthcare launch reviews with BAA support, encryption, role-based access patterns, audit history, consent-aware workflows, and staff escalation policies.

Book a security review
Procurement questions
  • 1What patient and workflow data is collected?
  • 2Which actions are automated or staff-confirmed?
  • 3Which systems, roles, and retention rules apply?
Responsibility matrix

Clear ownership before launch.

AreaWattson providesCustomer configures
BAA and permitted useBAA support for healthcare workflows that process patient access dataCovered workflow scope and contracting path
EncryptionEncryption in transit and at rest for systems that process workflow dataConnected systems and transmission path
Role-based accessStaff and administrator access patterns for operational workflowsUsers, roles, and least-privilege policy
Audit historyActivity history for workflow events, handoffs, and security reviewReview ownership and retention expectations
Consent and recordingWorkflow configuration for SMS, email, voice consent, and call recording behaviorState-specific language, recording settings, and routing rules
Human reviewStaff handoffs with context when automation is not the right pathEscalation criteria, confidence thresholds, and queue owners
Retention and deletionImplementation review for the data each launched workflow needs to retainRetention policy, deletion requirements, and legal hold rules
Subprocessors and vendorsVendor review support and launch controls for connected workflow servicesCustomer-required vendor review inputs
Incident responseSecurity investigation support through workflow logs and operational historyNotification contacts and internal response path
Verified controls

The questions a security review needs to answer.

What data and agreements are in scope?

Business Associate Agreement support for healthcare workflows that process patient access and engagement data.

How is workflow data protected?

Encryption in transit and at rest for systems that process patient request, scheduling, intake, and follow-up data.

Who can access the workflow?

Role-based access patterns for staff users, administrators, and workflow configuration surfaces.

What is logged and reviewed?

Activity history and operational logs for workflow review, security investigation, and vendor review.

How is consent configured?

Customer-controlled consent language, call recording settings, outreach rules, and routing behavior.

When does staff review take over?

Escalation policies and staff handoffs for workflows that need review before action is completed.

Review-ready before launch

Map controls to the first workflow.

Book a security review
  • Business Associate Agreement
  • Data flow and access review
  • Consent and recording configuration
  • Escalation and incident contacts