This page lists everything wawa needs from your clinic, your IT team and your vendors to set up an integration. Share
it with them before kick-off. Integrations rarely wait on building; they wait on access, credentials and paperwork, so
the sooner these are in hand, the sooner you go live.
The essentials
| Essential | What we need | Why | Who provides it |
|---|
| Named contacts | A technical contact with authority over the system and its network (for example firewall rules and service accounts), a clinic owner who signs off testing, and the vendor's technical contact | Nothing can start without someone who can make changes on your side | Clinic, vendor |
| A network path | A Site-to-Site VPN or a customer-managed public URL to each system wawa must reach | wawa connects from the cloud; systems inside your clinic need a secure route | Clinic IT |
| Credentials | A dedicated, least-privilege account for wawa on each system, with a generated password of at least 20 characters | wawa signs in to each system as its own user | Clinic IT or vendor |
| Certificates | Nothing for public CA certificates; your root CA certificate for self-signed or internal-CA certificates | So wawa can verify it is talking to your system | Clinic IT |
| Vendor paperwork | Agreements, subscriptions, licences and any certification the vendor requires | Many vendors release connection details only after these | Clinic, with the vendor |
| Data and test material | Identifiers, code lists, time zones, de-identified samples, and a test environment if one exists | So records match correctly and we can test safely | Clinic, vendor |
| Testing time | Clinic staff to run the test plan with us | An integration goes live only after clinic sign-off | Clinic |
How to send us credentials and certificates
- Use a secure channel. We send you a secure share (1Password by default). Never send passwords, keys or
certificates by email, chat, support tickets or forms.
- Keep them separate from forms. The VPN screening form collects network details only; credentials follow
separately.
- Root CA certificates go as one PEM file (
-----BEGIN CERTIFICATE-----) containing the root itself, with no private
key.
- Client certificates (when a system authenticates wawa by certificate) are exchanged as agreed with you or the
vendor.
- Tell us before rotating a credential or certificate, so we can update it without an outage. Revoke credentials
when an integration is retired.
Network access
For each system wawa must reach (an integration target), choose one model. See
Choosing a model.
Private: Site-to-Site VPN (details). About your gateway:
| Input | What to give us |
|---|
| Region | Which wawa region the tunnel should land in (normally your account's) |
| Public gateway IP | Static IP of your firewall's tunnel endpoint, or its NAT public IP |
| Gateway | Vendor, model and OS version |
| Internal prefixes | The narrowest ranges hosting the targets (a /28 or /29 per system) |
| Routing and IKE | BGP (with ASN) or static routes; IKEv1 or IKEv2; whether two tunnels are supported |
| NAT and gateway type | Whether the gateway performs NAT; route-based or policy-based |
| Contacts | Email addresses for tunnel notifications and alerts |
Public: customer-managed (details). You host and secure the endpoint; wawa gives you its
egress IPs to allowlist.
For each target, either way:
| Input | What to give us |
|---|
| Address | A private IP and port (VPN), or a public URL resolving to a public IP you assigned (public) |
| Protocol | We typically prefer HTTPS; other TCP- or UDP-based protocols can be supported |
| Certificate | A public CA certificate, or your root CA certificate |
| Credentials | As listed for the integration below |
By integration
Each guide explains every input in full. Requirements for integrations still in development are shared when they become
available; contact support if you are interested in one.
Imaging
| Integration | What we need from you |
|---|
| DICOM / DICOMweb | Server root URL and DICOMweb path; a dedicated account; server time zone; scanners sending Structured Reports with the wawa patient ID; for worklists (Orthanc): the REST Worklists plugin, each scan room's AE Title, and which appointment types are ultrasound scans |
| Orthanc deployment | Your IT team deploys and secures the server; the validation checks pass |
| GE ViewPoint | As for DICOM, with ViewPoint sending studies including the Structured Report to your DICOM server |
Laboratory
| Integration | What we need from you |
|---|
| HL7 v2 lab interface | An order endpoint and health check; how results reach us; credentials; code lists; which statuses you send; the order reference echoed on results; de-identified sample messages |
| The Doctors Laboratory (TDL) | Your TDL account code (source code); any custom profiles and prices |
| Australian Clinical Labs | A clinic representative to start delivery with ACL; your ACL account details |
Embryology
| Integration | What we need from you |
|---|
| EmbryoScope | The ES Public API reachable on port 4000 (TLS 1.2); a WSA user and password per instrument |
| CHLOE | A CHLOE account for your region (US, EU or AU); the wawa patient ID used in EmbryoScope and CHLOE |
Witnessing
| Integration | What we need from you |
|---|
| RI Witness | The RI Witness Web Service URL and a Basic-auth account per server; which server serves each clinic; pilot patient IDs |
Cryostorage
| Integration | What we need from you |
|---|
| TMRW | TMRW Connect URL; a dedicated TMRW user and password; tank types |
Pharmacy
| Integration | What we need from you |
|---|
| Stork | Stork CT identifier; Stork's prescription inbox; each prescriber's subject ID |
| DoseSpot | A DoseSpot clinic account; a DoseSpot user (with NPI) per prescriber |
Finance
| Integration | What we need from you |
|---|
| Xero | A Xero user to authorise one organisation; default revenue, manual payments and deposits accounts |
| Adyen | Adyen KYC for each legal entity; your online store and terminal names |
Calendar, EMR and devices
| Integration | What we need from you |
|---|
| Microsoft Outlook | A Microsoft 365 administrator to grant consent; staff and room mappings; room mailboxes for room calendars |
| Accuro EMR | Accuro UUID; QHR API subscription key; an Accuro user to authorise; provider, appointment and folder mappings |
| Label printers | Supported printers; the print software on each workstation; label stock size |
Identity
| Integration | What we need from you |
|---|
| Single sign-on | Usually nothing; staff invited with the same email as their Google or Microsoft account; administrator approval only if your tenant restricts third-party apps |
Data migration
Moving from another EMR? See Preparing your data for the questionnaire, the export
formats we accept and the people we need.
Questions we will ask at scoping
Answering these early removes most of the back-and-forth:
- Scope. What problem the integration solves and for whom, which clinics and countries need it, what the workflow
looks like before and after, what "done" means, and whether there is a committed date.
- Vendor. Whether you have a contract with the vendor; whether they require a signed agreement (for example a DPA,
BAA or data-sharing agreement) before sharing technical details; whether they run a certification programme; who
their technical contact is.
- Technology. Whether the system is cloud-hosted or inside the clinic; the authentication model (OAuth 2, API key,
mutual TLS, session login); the environments available (sandbox, test, production); the data format and direction
(REST/JSON, SOAP, HL7 v2, DICOM, files); rate limits or freshness requirements; data-residency constraints.
- Compliance. What data crosses the integration (health data, personal data, financial), country-specific regulatory
requirements, and whether a security review is needed before production.
- Ownership. Who owns the relationship with the vendor and with your IT team, and who signs off testing.
Before go-live
- Test Connection passes in wawa against the production system.
- The clinic's test plan is complete and signed off.
- The first real transaction is checked end to end by the clinic and wawa.
- You know how to spot a problem (each integration's Events tab or error messages) and how to reach us.