Viewing profile — chasb
chasb
HN member- Joined
- Fri, May 10, 2013, 4:19 PM UTC
- HN karma
- 803
- Public activity
- 215 items
- HN profile
- View on Hacker News ↗
About chasb
I know security, privacy, and software development. If you have questions related to those concepts, or HIPAA, SOC 2, ISO 27001, GDPR, HITRUST, or other frameworks, please feel free to email me at chas@conveyor.com.
Recent public activity
-
comment
Comment #33555847
My 27 year old sister got CAR-T for leukemia earlier this year after a failed stem cell transplant. She's in remission. It's incredible, literally curing cancer.
-
comment
Comment #22743668
I wrote this a while back for our customers: https://www.aptible.com/hipaa/what-is-a-baa/
-
comment
Comment #20597584
As a kid I loved "Motel of the Mysteries," reimagining the discovery of our culture today as if it was Howard Carter opening King Tut's tomb. https://www.washingtonpost.com/news/ac…
-
comment
Comment #18446817
We (Aptible) are distributed-first. Many of our team members really appreciate the flexibility the remote culture brings and use it to spend more time with their families. Shameles…
-
comment
Comment #17990468
Premise: > In North America (perhaps elsewhere) you are required to have at least a Master's degree to practise Psychology and you should have a doctorate if you want any mobility …
-
comment
Comment #17982268
The article (and the crisis) pertains to social psychology, not clinical psychology.
-
comment
Comment #16956900
Literally the only thing the landing page says is the purpose and what your email is used for: "Join the Slack workspace Aptible Gridiron GDPR Slack", and "Verify your email"
-
comment
Comment #16956145
For anyone interested we (Aptible) made this Slack community to answer questions about GDPR: https://join.slack.com/t/gridiron-gdpr/shared_invite/enQtMzQ... Disclaimer: we are a ve…
-
comment
Comment #16946014
(Just a heads up "Ask HN" generally refers to asking the community, not YC itself. I don't think the YC legal team reads this.) I'm a lawyer, YC alum, and have a CIPP/E cert. I too…
-
comment
Comment #16770478
It really depend on your reasons for retaining the backups in the first place. GDPR forces you to be able to articulate why you collect or process regulated personal data. If you p…
-
comment
Comment #16740768
Not in your personal capacity, no. As mentioned in the other comments to this parent, HIPAA only applies to "covered entities" like doctors that take insurance and insurance compan…
-
comment
Comment #16615351
HN probably doesn't fall within the material scope of GDPR, unless they perform business activity that falls within the scope of EU law that I'm not aware of. That would be differe…
-
comment
Comment #16610842
The ICO is seen as a leading voice, with some very good guidance, e.g.: https://ico.org.uk/for-organisations/guide-to-the-general-da... They're widely respected, but you're right i…
-
comment
Comment #16610826
GDPR puts the burden on the company to comply if it processes any in-scope personal data, regardless of whether it's possible for the data subjects themselves to minimize that data…
-
comment
Comment #16610789
There are a lot of businesses that market and sell in the EU, or that recruit or hire contractors in the EU. GDPR affects not only your CRM, but your marketing and sales stack, you…
-
comment
Comment #16610770
The cost of compliance will fall drastically. My company (Aptible) started in HIPAA and is doing a lot with GDPR. They are very similar in a lot of ways, including the emergence of…
-
comment
Comment #16610758
The data protection officer does not have to be a full-time role. It can be part of someone's other duties, or performed by a contractor (Art 37 ¶ (6): https://gdpr-info.eu/art-37-…
-
comment
Comment #16610746
Proposed, not yet effective: https://iapp.org/news/a/polands-proposed-gdpr-exemptions-spa...
-
comment
Comment #16610741
GDPR's "Right of access by the data subject" (Article 15) is here: https://gdpr-info.eu/art-15-gdpr/ The right can only be enforced against a "controller," which is the entity that…
-
comment
Comment #16610716
Be aware, this article is not a list of GDPR requirements. It is, however, a good list of questions that every business processing data in the cloud should be aware of. You need to…
-
comment
Comment #16610707
My company (Aptible) makes a product called Gridiron that does this. All of the data that a requester is entitled to can be pre-structured and organized in a source of truth. That'…
-
comment
Comment #16542073
Matt, if you read this, I am so sorry for your loss. My heart goes out to you and your family.
-
comment
Comment #16499440
(OP) I help run a Rock Health portfolio company and sometimes feel divorced from the outcomes we help enable. I thought this was a great project to show how technology helps real p…
- story
-
comment
Comment #16496086
HHS prefers not to use civil monetary penalties, but they hit when they do: https://www.hhs.gov/hipaa/for-professionals/compliance-enfor...