Live data from Hacker News

Viewing profile — chasb

chasb

HN member
Joined
Fri, May 10, 2013, 4:19 PM UTC
HN karma
803
Public activity
215 items

About chasb

Hi, my name is Chas Ballew. I'm one of the co-founders of Aptible (YC S14). We spun Conveyor out of Aptible in 2021, now I work on that.

I know security, privacy, and software development. If you have questions related to those concepts, or HIPAA, SOC 2, ISO 27001, GDPR, HITRUST, or other frameworks, please feel free to email me at chas@conveyor.com.

Recent public activity

  1. comment
    Comment #33555847

    My 27 year old sister got CAR-T for leukemia earlier this year after a failed stem cell transplant. She's in remission. It's incredible, literally curing cancer.

  2. comment
    Comment #22743668

    I wrote this a while back for our customers: https://www.aptible.com/hipaa/what-is-a-baa/

  3. comment
    Comment #20597584

    As a kid I loved "Motel of the Mysteries," reimagining the discovery of our culture today as if it was Howard Carter opening King Tut's tomb. https://www.washingtonpost.com/news/ac…

  4. comment
    Comment #18446817

    We (Aptible) are distributed-first. Many of our team members really appreciate the flexibility the remote culture brings and use it to spend more time with their families. Shameles…

  5. comment
    Comment #17990468

    Premise: > In North America (perhaps elsewhere) you are required to have at least a Master's degree to practise Psychology and you should have a doctorate if you want any mobility …

  6. comment
    Comment #17982268

    The article (and the crisis) pertains to social psychology, not clinical psychology.

  7. comment
    Comment #16956900

    Literally the only thing the landing page says is the purpose and what your email is used for: "Join the Slack workspace Aptible Gridiron GDPR Slack", and "Verify your email"

  8. comment
    Comment #16956145

    For anyone interested we (Aptible) made this Slack community to answer questions about GDPR: https://join.slack.com/t/gridiron-gdpr/shared_invite/enQtMzQ... Disclaimer: we are a ve…

  9. comment
    Comment #16946014

    (Just a heads up "Ask HN" generally refers to asking the community, not YC itself. I don't think the YC legal team reads this.) I'm a lawyer, YC alum, and have a CIPP/E cert. I too…

  10. comment
    Comment #16770478

    It really depend on your reasons for retaining the backups in the first place. GDPR forces you to be able to articulate why you collect or process regulated personal data. If you p…

  11. comment
    Comment #16740768

    Not in your personal capacity, no. As mentioned in the other comments to this parent, HIPAA only applies to "covered entities" like doctors that take insurance and insurance compan…

  12. comment
    Comment #16615351

    HN probably doesn't fall within the material scope of GDPR, unless they perform business activity that falls within the scope of EU law that I'm not aware of. That would be differe…

  13. comment
    Comment #16610842

    The ICO is seen as a leading voice, with some very good guidance, e.g.: https://ico.org.uk/for-organisations/guide-to-the-general-da... They're widely respected, but you're right i…

  14. comment
    Comment #16610826

    GDPR puts the burden on the company to comply if it processes any in-scope personal data, regardless of whether it's possible for the data subjects themselves to minimize that data…

  15. comment
    Comment #16610789

    There are a lot of businesses that market and sell in the EU, or that recruit or hire contractors in the EU. GDPR affects not only your CRM, but your marketing and sales stack, you…

  16. comment
    Comment #16610770

    The cost of compliance will fall drastically. My company (Aptible) started in HIPAA and is doing a lot with GDPR. They are very similar in a lot of ways, including the emergence of…

  17. comment
    Comment #16610758

    The data protection officer does not have to be a full-time role. It can be part of someone's other duties, or performed by a contractor (Art 37 ¶ (6): https://gdpr-info.eu/art-37-…

  18. comment
    Comment #16610746

    Proposed, not yet effective: https://iapp.org/news/a/polands-proposed-gdpr-exemptions-spa...

  19. comment
    Comment #16610741

    GDPR's "Right of access by the data subject" (Article 15) is here: https://gdpr-info.eu/art-15-gdpr/ The right can only be enforced against a "controller," which is the entity that…

  20. comment
    Comment #16610716

    Be aware, this article is not a list of GDPR requirements. It is, however, a good list of questions that every business processing data in the cloud should be aware of. You need to…

  21. comment
    Comment #16610707

    My company (Aptible) makes a product called Gridiron that does this. All of the data that a requester is entitled to can be pre-structured and organized in a source of truth. That'…

  22. comment
    Comment #16542073

    Matt, if you read this, I am so sorry for your loss. My heart goes out to you and your family.

  23. comment
    Comment #16499440

    (OP) I help run a Rock Health portfolio company and sometimes feel divorced from the outcomes we help enable. I thought this was a great project to show how technology helps real p…

  24. story
  25. comment
    Comment #16496086

    HHS prefers not to use civil monetary penalties, but they hit when they do: https://www.hhs.gov/hipaa/for-professionals/compliance-enfor...