






See how WaitWell meets SOC 2 Type 2, HIPAA, and NIST CSF standards to keep your data secure. Get clear answers to the compliance questions that matter most.
When a city government, hospital, or university picks a new queue management or appointment platform, features are great, but what seals the deal? It’s often trust. Can this vendor be trusted with resident data? Patient records? Student information? For regulated industries, security is the price of entry, not a nice-to-have. This is why, as part of WaitWell’s commitment to client success, security and compliance are top priorities.
WaitWell holds SOC 2 Type 2 certification, aligns its security program with the NIST Cybersecurity Framework, and is HIPAA compliant.
Every customer gets their own isolated database, role-based access control, and encrypted data at rest and in transit. Servers run in parallel across separate AWS data centers in North America, replicating data in real time so service continues even if one location goes down. Clients can also add single sign-on and multi-factor authentication, and they control their own data retention: PII can be anonymized or purged at any time. It’s a security posture built for the organizations that can least afford to get it wrong.
Certifications only mean something if the work behind them holds up. At WaitWell, that work happens daily. Controls are monitored continuously, an independent firm runs penetration tests every year, and policies stay current so clients never have to wonder whether what we say matches what we actually do.
We sat down with Chris Karhut, a Senior Product Manager at WaitWell, who works closely with the security and compliance team to help clients and prospects understand WaitWell’s posture, to talk about what that looks like day to day.
What does your role in compliance at WaitWell involve?
I’m not the one running audits, but I sit right next to the work. My job is to make sure what our security team builds actually reaches the people who need to trust it: prospects evaluating us during procurement, clients filling out their own regulatory paperwork, and internal teams who need to explain our posture in plain language.
That means I help translate our SOC 2 report, our NIST alignment, and our HIPAA status into materials people can actually use, respond to security questionnaires alongside our security lead, and keep our Trust Centre and public-facing security content current. As we bring on more government and healthcare clients, the bar keeps rising, and we’d rather stay ahead of it than catch up later. Our security team uses a platform called Drata to continuously monitor our controls and flag anything that drifts out of compliance, so we’re never scrambling before an audit, and I’m never caught flat-footed when a client asks a hard question.
Why does WaitWell hold all three frameworks when most platforms have just one or two?
It comes down to who our clients are. Government agencies, healthcare organizations, and public institutions all have different regulatory requirements, and we made a deliberate decision early on to meet them where they are rather than ask them to make exceptions for us.
SOC 2 Type 2 is the baseline expectation for any serious enterprise software vendor. HIPAA is non-negotiable if you’re working with healthcare-adjacent organizations handling patient information. NIST CSF is increasingly what government clients look to as a signal that a security program is mature and structured, not just reactive.
Holding all three means we can walk into virtually any enterprise or government procurement process with confidence. It removes a barrier that stops a lot of our competitors from even getting to the table.
What kind of WaitWell clients require this level of security posture, and why does it matter to them?
Our clients include municipal governments, airports, universities, and healthcare organizations. These are environments where the stakes around data security are genuinely high. They can’t afford a breach, a compliance gap, or a vendor that can’t answer hard questions about where data lives and who can access it.
A city government answers to its residents for how personal information is handled. A healthcare organization has patient data protected by law. An airport faces layers of regulatory oversight that touch every vendor in its ecosystem. When these organizations choose WaitWell, our compliance posture is often what gets us through procurement, and what keeps the relationship strong once we’re in.
What does SOC 2 Type 2 actually prove for WaitWell, in plain terms?
SOC 2 Type 2 is an independent audit that answers a simple question: does this company actually do what it says it does when it comes to security?
The “Type 2” part is what matters most. A Type 1 audit just checks whether the right controls are in place on a given day. Type 2 goes further. It verifies that those controls operated consistently and effectively over an extended period, typically six to twelve months. You can’t fake that kind of track record.
WaitWell’s SOC 2 Type 2 audit is conducted annually by an independent auditing firm. The report covers how we protect data, control access, respond to incidents, and maintain availability, and it’s available to clients who want to see the detail behind our security claims.
What does NIST CSF alignment mean day to day?
NIST CSF, the National Institute of Standards and Technology Cybersecurity Framework, gives us a structured way to think about security across five areas: identifying risks, protecting against them, detecting threats, responding when something happens, and recovering quickly if it does.
In practical terms, our security program isn’t ad hoc. Every control WaitWell has maps back to a recognized standard. We’re asking whether we can demonstrate, against an established benchmark, that we’re doing the right things. For government clients especially, NIST alignment signals that we speak their language and take security as seriously as they do.
What does HIPAA compliance cover, and what’s WaitWell’s status?
WaitWell is HIPAA compliant, meaning we meet the federal requirements for handling protected health information, or PHI. In practice, this covers how we store, transmit, and control access to any data that could be linked to an individual’s health.
This matters most in healthcare-adjacent settings, like clinics or hospital outpatient departments, that use our platform to manage patient flow and appointments. HIPAA compliance means those organizations can deploy WaitWell with confidence that patient information is handled according to federal law. We also have Business Associate Agreements in place with healthcare clients, which HIPAA requires whenever a vendor handles PHI on behalf of a covered entity.
How is patient and customer data actually protected?
A few layers work together here. Every client on WaitWell has a completely isolated database, so your data never sits alongside another organization’s, and that separation has been independently verified through penetration testing.
All data is encrypted, whether it’s moving between systems or sitting in storage, using the same standards banks and government agencies rely on. Access is tightly controlled through role-based permissions, so staff only see what they need to do their job and nothing more. Organizations can also add single sign-on and multi-factor authentication, using SAML to integrate with tools like Azure and ADFS, or federate through Google and Microsoft. And how much personal information gets collected in the first place is entirely up to the client: they can choose to collect as little as a ticket number, with no personal information at all, and can anonymize or purge PII from the database at any time.
On top of that, our servers run in parallel across separate AWS data centers in North America, so service keeps running even if one location is affected, and we monitor our systems around the clock for threats, run daily automated security scans, and bring in an independent firm every year to try to find vulnerabilities before anyone else does. In our most recent test, they found zero critical or high-risk issues.
How can a client get proof of WaitWell’s compliance, like audit reports and certifications?
All of our compliance documentation lives in our Trust Centre, powered by Drata. Clients and prospective clients can request access and review our SOC 2 Type 2 audit report, penetration test results, security policies, and more, all in one place.
Transparency is part of what good security looks like. If you’re trusting us with your data and your users, you should be able to see the evidence behind our claims, not just take our word for it.
Security and compliance aren’t a phase WaitWell moves past. They’re something the team lives every day, so the governments, healthcare organizations, and schools that depend on WaitWell never have to choose between great service and a secure platform.


















