Security and data protection

How Wazzy protects your patients’ data on WhatsApp

The Wazzy teamUpdated

Hands holding a phone with a WhatsApp conversation, a shield and padlock beside it

WhatsApp has become one of the main ways patients and clinics talk to each other. People use it to book appointments, move them, check opening hours, ask about treatments or confirm a booking.

That makes it enormously convenient. It also means personal data travels through that channel, and sometimes, when a patient explains a problem or a treatment, information about their health.

When a clinic hands part of those conversations to artificial intelligence, the question follows naturally: how is that information protected?

At Wazzy, security does not rest on one measure. Several layers do the work: the official WhatsApp Business infrastructure, encryption of the traffic with the platform, protection of certain stored data, access controls, traceability and backups.

The first step: using the official WhatsApp infrastructure

Not every WhatsApp automation out there works the same way. Some tools use unofficial methods built on automating WhatsApp Web or imitating the behaviour of a handset.

Wazzy works on the official WhatsApp Business Platform and operates as a Meta Tech Provider. That matters, because it means building on the mechanisms Meta provides specifically so that businesses and technology providers can connect WhatsApp to their systems.

As well as making the integration steadier, it means not depending on techniques designed to imitate an ordinary WhatsApp session.

What happens when a patient sends a message

From the patient’s side, nothing changes. They open WhatsApp, write to the clinic’s number, and have a conversation.

Behind that, the business infrastructure lets the message reach the systems the clinic has authorised to handle it.

WhatsApp explains that its traffic uses cryptography to protect messages while they travel. In a business setting, once the message reaches the company it can be handled by its staff or by authorised technology providers, under the relevant privacy and security practices.

That last part matters more than it first appears. WhatsApp protecting the journey does not remove the responsibility of the clinic, or of whoever processes the message afterwards. Security has to carry on once the conversation has reached the systems that handle it.

Wazzy protects its traffic with HTTPS/TLS

When information moves between Wazzy’s public services, it travels over HTTPS/TLS.

That protects the data on the way and makes it hard for anyone else to read or change it while it crosses public networks. In security this layer is usually called encryption in transit.

It does not only cover the contents of a conversation. It also covers a user’s browser talking to the reception panel, and every other exchange that goes over a secure public connection.

What happens when the information is stored

The second important moment comes when the data stops moving and has to be kept.

Wazzy uses AES-256-GCM to encrypt particularly sensitive information, including the contents of stored messages, certain sensitive internal records, and certain credentials and secrets used by integrations, such as WhatsApp and Google Calendar tokens.

That adds a layer of protection over specific fields that deserve it.

It is worth being precise here. Saying that a platform encrypts certain sensitive data at rest is not necessarily the same as saying the whole database, or the whole disk, is encrypted field by field with that same mechanism.

Precision matters in security more than almost anywhere. At Wazzy, the information the architecture marks as sensitive gets its own encryption, while other layers of the infrastructure are protected by isolation, network controls and access control.

Data hosted in the European Union

Where the infrastructure sits is part of the picture too. The data Wazzy handles directly is hosted on servers inside the European Union.

That simplifies an important part of the architecture from the point of view of European data handling. It does not, on its own, make any processing lawful. The GDPR still requires the clinic to decide why it holds data, on what legal basis, for how long, and everything else that follows.

But where the systems are is something a clinic should know before signing with any provider.

Controlling who can get in

Not every security risk comes from an attacker outside. A good part of protecting data is limiting access inside.

Wazzy lets you use tiered permissions to decide which people on the team can reach which information and which features. That matters especially when a clinic uses the medical CRM.

Reception may need to look at a patient’s appointments and conversations without needing their whole clinical history. The clinic can keep that kind of information to certain roles.

That way the technology can apply the principle of least privilege: each person gets the access they need to do their job.

A trail of what was done

As important as controlling who can get in is being able to see what happens once they are in.

Wazzy keeps a trail of what users do. When a conversation is handled from the inbox, it records which member of the team stepped in. In the same way, actions taken on the platform are tied to the person who took them.

That trail does several jobs. It lets you look into an incident, reconstruct what happened with a particular case, and keep continuity between reception shifts.

It also works as a security measure in its own right, because it stops anything that matters from being completely anonymous.

Backups and recovery

Protecting data is not only about keeping the wrong people out. It is also about not losing it.

A hardware failure, a human error or a technical incident can take a system down with nobody trying to steal anything. That is why backups belong in a security strategy.

Wazzy takes automated backups and protects those copies with encryption. The infrastructure is built so information can be recovered when something goes wrong.

That lines up with one of the principles in article 32 of the GDPR: having the means to restore the availability of, and access to, personal data after a physical or technical incident.

Monitoring and availability

A platform used to look after patients needs to be up. Wazzy monitors its infrastructure continuously and runs on high availability services.

Security is not only about stopping somebody reading data. It also means the systems being there when you need them. A clinic that depends on its schedule and its WhatsApp conversations needs to reach them during the working day.

That is why modern security looks at confidentiality, integrity and availability together.

Wazzy does not use the data to train public models

Another common worry arrives with artificial intelligence. Plenty of people assume that any conversation sent to an AI system automatically becomes part of the data used to train future models.

It does not have to be that way.

Wazzy states that the patient data its platform processes is not used to train public artificial intelligence models. That distinction matters in healthcare.

Using artificial intelligence to handle one particular conversation should not automatically be confused with reusing that information as a public training set.

The clinic keeps control of its information

The operational information the platform produces belongs to the clinic, and it should be manageable with clear rules on access and retention.

That control matters most when the software starts becoming a central part of reception. Changing provider or rearranging your technology should not mean losing the operational knowledge built up over years.

So beyond security, a clinic should also weigh up export, portability and what happens when the service ends.

Security does not mean zero risk

No serious technology provider should promise zero risk.

Neither official infrastructure, nor a particular encryption algorithm, nor European servers removes every possible threat. Security is about reducing risk with several layers, and having procedures for spotting and responding to incidents.

The GDPR itself takes a risk based approach when it talks about appropriate technical and organisational measures.

Technology, procedures and people

A platform can have good security measures and still be used badly.

Sharing passwords, leaving old employees’ accounts active, giving everyone full access, or sending sensitive information through unauthorised channels can undermine even good infrastructure.

So the security of patient data rests on three things that have to work together: the technology, the clinic’s procedures, and the people using the system.

Wazzy provides the infrastructure and the means to control access, protect information and keep a trail. The clinic has to use them properly.

Protecting the conversation end to end

When a patient writes on WhatsApp, protecting their data should not stop when the message reaches the server. It has to carry on for the whole life of that information.

From the journey to the storage. From reception’s access to the clinical team’s. From the daily work to the backups.

That layered view is what lets a clinic use WhatsApp and artificial intelligence without treating security as a box to tick.

Because when there is a patient behind every conversation, protecting their information is part of looking after them properly.

Sources and references

More in Security and data protection

See all articles