NOWaiTHIPAA Compliance

HIPAA Compliance

How NOWaiT protects your practice and patient data

Our Commitment

NOWaiT is purpose-built for healthcare practices. We understand the regulatory requirements of handling patient communications and have designed our platform with HIPAA compliance as a foundational requirement, not an afterthought. We provide Business Associate Agreements (BAAs) to all customers and maintain strict data handling procedures across our entire technology stack.

Encryption at Rest & In Transit

All data is encrypted using AES-256 at rest and TLS 1.2+ in transit. Voice recordings, transcripts, patient names, and contact information are encrypted end-to-end.

SOC 2 Type II Infrastructure

NOWaiT is built on Supabase (SOC 2 Type II certified) and deployed on Vercel with enterprise-grade security. Our voice AI partner, Retell AI, is SOC 2 Type II certified and HIPAA compliant.

Role-Based Access Controls

Row-Level Security (RLS) ensures each practice can only access their own data. Multi-tenant isolation is enforced at the database level, not the application level.

Business Associate Agreements

We execute BAAs with all sub-processors that handle Protected Health Information (PHI). BAAs are available for all NOWaiT customers upon request.

Minimal PHI Exposure

NOWaiT is designed as a marketing and front-office automation platform. We minimize PHI exposure by focusing on scheduling, communication, and review management rather than clinical data.

Audit Logging

All user actions are logged in an immutable activity log. Access events, data modifications, and system activities are tracked for compliance auditing.

Data We Handle

What We Process

  • Patient names and contact information (phone, email)
  • Appointment scheduling data
  • Voice call recordings and transcripts
  • SMS message content
  • Online review content
  • Intake form submissions

What We Do NOT Process

  • Clinical records or treatment plans
  • Medical imaging or diagnostic data
  • Insurance claim details or billing codes
  • Prescription or medication data
  • Electronic health records (EHR)

Sub-Processor Compliance

ProviderPurposeCertifications
SupabaseDatabase & AuthenticationSOC 2 Type II, HIPAA
Retell AIVoice AI AgentSOC 2 Type II, HIPAA
TwilioSMS MessagingSOC 2, HIPAA eligible
VercelApplication HostingSOC 2 Type II
StripePayment ProcessingPCI DSS Level 1, SOC 2
AnthropicAI Content GenerationSOC 2 Type II

Request a BAA

We provide Business Associate Agreements to all NOWaiT customers at no additional cost. To request a BAA or discuss your practice's specific compliance requirements, contact us:

Last updated: March 2026 · Top Performer LLC · nowait.club