Join a team of talented individuals building a new era of dental billing

Become a biller

Learn more about our services

Contact us
In the News

Security You Don't Have to Take Our Word For

A closer look at how Wisdom protects patient data, meets HIPAA requirements, and independently validates its security controls through SOC 2 Type II.

No items found.
Team Wisdom

Dental practices are trusting us with patient data and revenue — so we've built (and documented) security controls that go well beyond what most billing partners show you. You don't need to read all of it. That's the point: it's there, it's audited, and it's thorough.

Wisdom maintains HIPAA compliance and has completed its SOC 2 Type II examination in September 2026. 

Independently Examined

Wisdom is proud to announce the completion of its first SOC 2® Type II examination covering the period April 1 through June 30, 2026. Our attestation report covers the Security, Availability, and Confidentiality Trust Services Criteria set forth by the American Institute of Certified Public Accountants (AICPA). This attestation evidences that Wisdom’s security controls operated across a multi-month period.

What is a SOC 2? A SOC 2 attestation helps organizations prove their information security controls by having an independent auditor come in and assess the organization. This framework helps service organizations prove they securely manage and protect customer data. 

The full SOC 2 Type II report is available to current customers and prospective customers through our Trust Center. Wisdom’s next SOC 2 Type II report will cover the period July 1, 2026 through June 30, 2027 and will be available in late 2027.

HIPAA Compliance

No government body certifies a company as HIPAA compliant. A vendor showing you a "HIPAA Certified" seal is showing you a logo their training provider made for them.

Here is what is true for Wisdom. We operate as a HIPAA Business Associate, and a Business Associate Agreement (BAA) is part of our standard client agreement. Any vendors or subcontractors that work with Wisdom are required to operate as a HIPAA Business Subcontractor Associate and sign a Business Subcontractor Associate Agreement (BASA) and are required to follow the same HIPAA compliance standards as Wisdom.

Our program is built and monitored against the HIPAA Security Rule and the controls that protect your patients' information were examined in our SOC 2 audit.

Five layers of controls, each independently audited

  • Infrastructure security — encryption in transit and at rest, strict access controls, MFA-enforced remote access with least-privilege, and emergency access procedures for the Wisdom App
  • Organizational security — background-checked employees, signed confidentiality agreements, managed device policies, and tracked hardware/media handling on company devices
  • Product security — annual disaster recovery testing, multi-location production environments, periodic offsite backups, and cybersecurity insurance is maintained
  • Internal security procedures — annual risk assessments, tested incident response plans, board-level cybersecurity briefings, and third-party vendor agreements with confidentiality commitments
  • Data & privacy — formal information classification and data retention/disposal policies and procedures (for HIPAA compliance and applicable law)

Why this matters right now

With ransomware attacks increasingly targeting dental and healthcare billing vendors, an untested incident response plan or unmonitored vendor relationship isn't a hypothetical risk — it's the exact gap attackers look for. Wisdom tests its incident response plan annually, maintains disaster recovery across multiple locations, and carries cybersecurity insurance specifically to limit the blast radius if something does happen.

Vetted vendor ecosystem

Every subprocessor we use — cloud infrastructure, identity, collaboration tools — is disclosed and continuously monitored for compliance, not just onboarded once and forgotten.

Documented, not just implied

Policies covering access control, incident response, business continuity, data management, and secure development are all published and available on request — because "trust us" isn't a security posture.

FAQs