Selling into healthcare means proving it before you start
Special category data under GDPR, DPIAs that have to stay current, and hospital procurement asking questions you need one answer to. Wizard keeps that answer in one place and up to date.
The buyer is also the regulator
In digital health the pressure does not come from a notified body, it comes from the customer. A hospital group, a health service, an insurer. They ask for your DPIA, your data flows, your sub-processors, your retention schedule and your incident procedure, and they ask before the contract exists.
Every one of those answers exists somewhere. The data flow diagram is in a slide deck from last year, the DPIA was written for a feature that has since changed, and the sub-processor list is in an email. Individually defensible, collectively out of date.
Then a new integration goes live, or a sub-processor changes, and nothing in the documentation moves with it.
Privacy documentation is treated as a document, not a system
Static artefacts describing a moving system. A DPIA written once and stored is accurate on the day it is signed. The product changes weekly.
Nothing connects the pieces. Your data flows, your DPIAs, your sub-processors and your retention rules describe the same reality. When one changes and the others do not, nobody notices until someone asks.
Procurement questions do not fit a security tool. Health procurement asks about clinical safety, data residency and processing purpose. A tool built for ISO 27001 has no place to put those answers.
Documentation that changes when the product does
Records of processing that stay connected. Data flows and DPIAs linked to the systems and sub-processors they describe, so a change in one surfaces in the others. PLACEHOLDER: product screenshot, records of processing linked to systems.
A sub-processor register with review cycles. Named owners, review dates and contract detail, so the list is current when a hospital asks rather than reconstructed. PLACEHOLDER: product screenshot, sub-processor and supplier register.
One evidence base for procurement. The answers health buyers ask for, maintained continuously rather than assembled per tender. PLACEHOLDER: product screenshot, evidence library.
Extends when a health service asks for ISO 27001. Without starting a second system alongside the first. PLACEHOLDER: product screenshot, multiple frameworks in one workspace.
Where Wizard fits, and where it does not
Against a privacy management tool. Dedicated privacy platforms handle records of processing and DPIAs well. They tend not to cover security controls or supplier risk in the same system, so you end up running two.
Against your DPO's own files. If you have an experienced DPO with well-maintained records, that may be enough. It stops being enough when you have several products, several sub-processors, and more than one person answering procurement questions.
Against an automated security platform. Those tools are strong on infrastructure evidence for ISO 27001 and SOC 2. Health procurement asks about processing purpose, data residency and clinical context, and those have nowhere to live in a tool built for security controls.
What Wizard is not. It is not legal advice, and it will not tell you whether your processing basis is sound. That is your DPO's job.
Built by people who have been audited, and who have audited others
Wizard was designed by people who spent years building these systems inside regulated organisations before they built software for them. What follows is their professional background. These were consultancy and audit engagements, not Wizard implementations, and we mention them because the design decisions in this product came directly from that work. Read more about the team.
Eoghan Kenny, Co-Founder and CEO. Over twenty years implementing governance, risk and compliance systems in regulated organisations. He has worked as an external Data Protection Officer for organisations processing special category health data, including Loci Ortho, Perfuze and Amara Therapeutics, and has provided data protection and compliance advisory services to health organisations such as OneTouch Health. His privacy and information security work covers ISO 27001 and ISO 27701.
Derek Mizak, Co-Founder and CTO. Over thirty years across cybersecurity, audit and systems architecture. He has audited management systems as a certification body auditor for Certification Europe (now Amtivo), which means he has seen which records hold under examination and which ones only look like they do.
Dominic O'Toole, Co-Founder and CPO. Over twenty years building enterprise software, including at IBM and Fidelity.
None of this makes Wizard the right fit for every organisation. It does mean the people who designed it have implemented, maintained and audited the systems it manages.
Common questions
Does Wizard handle records of processing and DPIAs?
Yes, as connected registers. Records of processing and DPIAs link to your sub-processor register, so when one changes a workflow can flag the others. Those relationships and workflows are set up by your team or your consultant. Nothing is detected automatically, and the links are the ones you define.
We already have a privacy management tool. Why would we change?
Often you would not. The question is whether your security controls, supplier risk and procurement answers live in the same place, or in three. If a hospital asks one question that spans all three, how long does the answer take to assemble?
Can it hold the answers health procurement asks for?
That is the intent. Procurement questions tend to span privacy, security and operational detail, which is why they are difficult to answer from a tool built for only one of those.
Where is our data held?
Microsoft Azure, with enterprise-grade access controls. Our sub-processor list and data processing agreement are published on the site.
Are you certified to ISO 27001 yourselves?
Wizard is built to ISO 27001 requirements and hosted on Microsoft Azure in Ireland, with our security architecture, Data Processing Agreement and sub-processor list published on our Legal, Privacy and Security page.
What does it cost?
Standard plans start at 600 euro per month billed annually for up to 30 active users. Consultant accounts are free and do not count toward the limit.
See it against your next procurement question
Request a demo and we will walk through how this works for your product and your buyers. If you would rather see where you stand first, the Health Check takes five minutes. Request a demo.