Skip to main content

What we need from you

This page lists everything wawa needs from your clinic, your IT team and your vendors to set up an integration. Share it with them before kick-off. Integrations rarely wait on building; they wait on access, credentials and paperwork, so the sooner these are in hand, the sooner you go live.

The essentials​

EssentialWhat we needWhyWho provides it
Named contactsA technical contact with authority over the system and its network (for example firewall rules and service accounts), a clinic owner who signs off testing, and the vendor's technical contactNothing can start without someone who can make changes on your sideClinic, vendor
A network pathA Site-to-Site VPN or a customer-managed public URL to each system wawa must reachwawa connects from the cloud; systems inside your clinic need a secure routeClinic IT
CredentialsA dedicated, least-privilege account for wawa on each system, with a generated password of at least 20 characterswawa signs in to each system as its own userClinic IT or vendor
CertificatesNothing for public CA certificates; your root CA certificate for self-signed or internal-CA certificatesSo wawa can verify it is talking to your systemClinic IT
Vendor paperworkAgreements, subscriptions, licences and any certification the vendor requiresMany vendors release connection details only after theseClinic, with the vendor
Data and test materialIdentifiers, code lists, time zones, de-identified samples, and a test environment if one existsSo records match correctly and we can test safelyClinic, vendor
Testing timeClinic staff to run the test plan with usAn integration goes live only after clinic sign-offClinic

How to send us credentials and certificates​

  • Use a secure channel. We send you a secure share (1Password by default). Never send passwords, keys or certificates by email, chat, support tickets or forms.
  • Keep them separate from forms. The VPN screening form collects network details only; credentials follow separately.
  • Root CA certificates go as one PEM file (-----BEGIN CERTIFICATE-----) containing the root itself, with no private key.
  • Client certificates (when a system authenticates wawa by certificate) are exchanged as agreed with you or the vendor.
  • Tell us before rotating a credential or certificate, so we can update it without an outage. Revoke credentials when an integration is retired.

Network access​

For each system wawa must reach (an integration target), choose one model. See Choosing a model.

Private: Site-to-Site VPN (details). About your gateway:

InputWhat to give us
RegionWhich wawa region the tunnel should land in (normally your account's)
Public gateway IPStatic IP of your firewall's tunnel endpoint, or its NAT public IP
GatewayVendor, model and OS version
Internal prefixesThe narrowest ranges hosting the targets (a /28 or /29 per system)
Routing and IKEBGP (with ASN) or static routes; IKEv1 or IKEv2; whether two tunnels are supported
NAT and gateway typeWhether the gateway performs NAT; route-based or policy-based
ContactsEmail addresses for tunnel notifications and alerts

Public: customer-managed (details). You host and secure the endpoint; wawa gives you its egress IPs to allowlist.

For each target, either way:

InputWhat to give us
AddressA private IP and port (VPN), or a public URL resolving to a public IP you assigned (public)
ProtocolWe typically prefer HTTPS; other TCP- or UDP-based protocols can be supported
CertificateA public CA certificate, or your root CA certificate
CredentialsAs listed for the integration below

By integration​

Each guide explains every input in full. Requirements for integrations still in development are shared when they become available; contact support if you are interested in one.

Imaging​

IntegrationWhat we need from you
DICOM / DICOMwebServer root URL and DICOMweb path; a dedicated account; server time zone; scanners sending Structured Reports with the wawa patient ID; for worklists (Orthanc): the REST Worklists plugin, each scan room's AE Title, and which appointment types are ultrasound scans
Orthanc deploymentYour IT team deploys and secures the server; the validation checks pass
GE ViewPointAs for DICOM, with ViewPoint sending studies including the Structured Report to your DICOM server

Laboratory​

IntegrationWhat we need from you
HL7 v2 lab interfaceAn order endpoint and health check; how results reach us; credentials; code lists; which statuses you send; the order reference echoed on results; de-identified sample messages
The Doctors Laboratory (TDL)Your TDL account code (source code); any custom profiles and prices
Australian Clinical LabsA clinic representative to start delivery with ACL; your ACL account details

Embryology​

IntegrationWhat we need from you
EmbryoScopeThe ES Public API reachable on port 4000 (TLS 1.2); a WSA user and password per instrument
CHLOEA CHLOE account for your region (US, EU or AU); the wawa patient ID used in EmbryoScope and CHLOE

Witnessing​

IntegrationWhat we need from you
RI WitnessThe RI Witness Web Service URL and a Basic-auth account per server; which server serves each clinic; pilot patient IDs

Cryostorage​

IntegrationWhat we need from you
TMRWTMRW Connect URL; a dedicated TMRW user and password; tank types

Pharmacy​

IntegrationWhat we need from you
StorkStork CT identifier; Stork's prescription inbox; each prescriber's subject ID
DoseSpotA DoseSpot clinic account; a DoseSpot user (with NPI) per prescriber

Finance​

IntegrationWhat we need from you
XeroA Xero user to authorise one organisation; default revenue, manual payments and deposits accounts
AdyenAdyen KYC for each legal entity; your online store and terminal names

Calendar, EMR and devices​

IntegrationWhat we need from you
Microsoft OutlookA Microsoft 365 administrator to grant consent; staff and room mappings; room mailboxes for room calendars
Accuro EMRAccuro UUID; QHR API subscription key; an Accuro user to authorise; provider, appointment and folder mappings
Label printersSupported printers; the print software on each workstation; label stock size

Identity​

IntegrationWhat we need from you
Single sign-onUsually nothing; staff invited with the same email as their Google or Microsoft account; administrator approval only if your tenant restricts third-party apps

Data migration​

Moving from another EMR? See Preparing your data for the questionnaire, the export formats we accept and the people we need.

Questions we will ask at scoping​

Answering these early removes most of the back-and-forth:

  • Scope. What problem the integration solves and for whom, which clinics and countries need it, what the workflow looks like before and after, what "done" means, and whether there is a committed date.
  • Vendor. Whether you have a contract with the vendor; whether they require a signed agreement (for example a DPA, BAA or data-sharing agreement) before sharing technical details; whether they run a certification programme; who their technical contact is.
  • Technology. Whether the system is cloud-hosted or inside the clinic; the authentication model (OAuth 2, API key, mutual TLS, session login); the environments available (sandbox, test, production); the data format and direction (REST/JSON, SOAP, HL7 v2, DICOM, files); rate limits or freshness requirements; data-residency constraints.
  • Compliance. What data crosses the integration (health data, personal data, financial), country-specific regulatory requirements, and whether a security review is needed before production.
  • Ownership. Who owns the relationship with the vendor and with your IT team, and who signs off testing.

Before go-live​

  • Test Connection passes in wawa against the production system.
  • The clinic's test plan is complete and signed off.
  • The first real transaction is checked end to end by the clinic and wawa.
  • You know how to spot a problem (each integration's Events tab or error messages) and how to reach us.